| MD5 | 7445d52e3ac3891e17792f83b1927a4d |
| SHA1 | b82b5f0711691a4e25185ab7f21d70e4a80cd731 |
| Filename | 3e997d9d.exe |
| Domains | [ip-addr.es] [foundersomaha.net] [monarchestatemanagement.com] [mineralesdelsur.com] [hechtelshobbycenter.be] [medicalmarijuanamiamiflorida.com] |
| IP Addresses | [188.165.164.184] [50.63.42.1] [72.167.131.9] [192.254.233.175] [62.182.61.62] [50.62.104.1] |
| Antivirus | [Artemis!7445D52E3AC3] |
| [Artemis!Trojan] | |
| [Ransom:Win32/Crowti.A] | |
| [Trojan.Encoder.514] | |
| [Trojan.Win32.Filecoder] | |
| [TROJ_CRYPWALL.QWQ] | |
| [W32/Filecoder.CO!tr] | |
| [Win32.Trojan.Inject.Auto] | |
| [Win32/Filecoder.CO] |