| MD5 | b16fae92ccfa45f4b33e800107a306ad |
| SHA1 | d3807410250b8b7db4852741b92196c469612aa5 |
| Filename | greetings.exe |
| Domains | [ladiesdehaan.be] [chonburicoop.net] [passlift.com] [actionpourisrael.com] [hnb.net] [www.hnb.net] [firecheerleaders.fr] |
| IP Addresses | [62.210.92.9] [217.116.196.239] [213.186.33.4] [222.165.133.242] [213.186.33.171] |
| Antivirus | [Mal/Ransom-EC] |
| [Ransom.FileLocker] | |
| [Ransom:Win32/Tescrypt.H] | |
| [Ransomware-FDS!B16FAE92CCFA] | |
| [Ransom_CRYPTESLA.SMJ3] | |
| [Trojan-Banker.Win32.Shifu.aus] | |
| [Trojan-Spy/W32.Banker.552960.AX] | |
| [Trojan.Banker.Shifu.bv] | |
| [Trojan.Encoder.3852] |