| MD5 | 394a7e45d263839ee7e5bafe02f321f7 |
| SHA1 | 813b9f8bfc448d6160af27bea10a9385eef673d7 |
| Filename | winhlp.exe |
| Domains | [whatismyipaddress.com] |
| Antivirus | [Infostealer.Limitail] |
| [Ransom.Troldesh.NSIS] | |
| [Ransom:Win32/Troldesh.A] | |
| [Ransom_c.BUA] | |
| [TR/AD.NsisInject.lvkhj] | |
| [Trojan-Ransom.Win32.Shade.kvn] | |
| [Trojan.Dos.Code.egouyv] | |
| [Trojan.Encoder.858] | |
| [Trojan/Win32.Shade.N2120934619] |