| MD5 | 37b272fc007ed3ad0de5354cf4276ceb | 
| SHA1 | dc15e958aec7f1ebdad3710eb62ad554c6e9bd57 | 
| Filename | refund scan 416B8C.wsf | 
| Domains | [uuhlkqcnayivgnl.info] [ytstyytin.su] [immunts.work] [photosetbook.ru] [oduhfmyyy.xyz] [aouywdvddcydgqj.click] [eytjfreg.biz] [yqicpejtnl.su] [rtufsjr.org] [uowyjjlticwtha.info] | 
| Antivirus | [HEUR.JS.Trojan.b] | 
| [JS.eIframeDownloader.12C6] | |
| [Js.Trojan.Raas.Auto] | |
| [JS/Nemucod.89E6!tr.dldr] | |
| [JS/Nemucod.oi] |