| MD5 | 1f6493b1d55c7e25a5f4b475f93aae24 |
| SHA1 | c9b3701bdb9d3eda647ed371d74e2bea582b04c4 |
| Filename | newPayload.exe |
| IPs | [46.19.37.108] |
| IPs | [188.138.122.22] |
| IPs | [194.109.206.212] |
| IPs | [86.59.21.38] |
| IPs | [62.210.92.11] |
| Domains | [ip.telize.com] [zsn5qtrgfpu4tmpg.onion.cab] [zsn5qtrgfpu4tmpg.onion.gq] [zsn5qtrgfpu4tmpg.onion.lt] [zsn5qtrgfpu4tmpg.tor2web.org] [zsn5qtrgfpu4tmpg.tor2web.fi] |
| IP Addresses | [46.19.37.108] [188.138.122.22] [194.109.206.212] [86.59.21.38] [62.210.92.11] [82.94.251.220] [194.150.168.70] [194.150.168.74] |
| Antivirus | [Gen:Heur.Kelios.1] |
| [HW32.Packed.D064] | |
| [Mal/Harnig-B] | |
| [PE:Malware.XPACK-HIE/Heur!1.9C48] | |
| [Ransom-FTX!1F6493B1D55C] | |
| [Ransom:Win32/Critroni.B] | |
| [Ransomware.CTBLocker.A1] | |
| [SScope.TrojanRansom.Crytroni] | |
| [Suspicious_GEN.F47V0503] |