| MD5 | 153bb03a3c54e37ab5082d20c3ea3f98 | 
| SHA1 | 2210ab8eb77cc45339a59efd0266695395c9be03 | 
| Filename | necurs.exe | 
| IPs | [134.170.185.46] | 
| IPs | [132.163.4.101] | 
| IPs | [15.125.94.239] | 
| Domains | [microsoft.com] [hzwfqpxmujzot.com] [fxymgihssdn.com] [ydyvemrkzfspyj.com] [paknmvoroflhd.com] [0.pool.ntp.org] [1.pool.ntp.org] [2.pool.ntp.org] | 
| IP Addresses | [134.170.185.46] [132.163.4.101] [15.125.94.239] | 
| Antivirus | [Backdoor/Win32.Necurs] | 
| [Dropper.Necurs.Win32.2624] | |
| [HW32.CDB.669c] | |
| [PE:Malware.XPACK-HIE/Heur!1.9C48] | |
| [Suspicious_Gen4.FVIRY] | |
| [Trojan-Dropper.Win32.Necurs.tdq] | |
| [Trojan.DR.Necurs!xR235f6R+kY] | |
| [Trojan.GenericKD.1579332] |