| MD5 | 394857f4b44f21a3d1654d48e0b6c03d | 
| SHA1 | 10822dfc96dab33f1db0b45a43578589ba330f5c | 
| Filename | RegWorkshop.exe | 
| IPs | [173.252.110.27] | 
| Domains | [facebook.com] [yqagbsgseehnb.com] [gwutvuvvoxbr.com] [ooyuhowfcpnt.com] [blzyictxmpnrjh.com] [0.pool.ntp.org] | 
| IP Addresses | [173.252.110.27] | 
| Antivirus | [Backdoor.Necurs] | 
| [Dropper.Generic9.NMU] | |
| [HW32.CDB.0969] | |
| [HW32.Packed.969B] | |
| [PE:Malware.XPACK-HIE/Heur!1.9C48] | |
| [TR/NecursX.A.21] | |
| [Trj/dtcontx.J] | |
| [Troj/Necurs-AX] | |
| [Trojan-Dropper.Win32.Necurs.ssd] |