| MD5 | c9aff9030e9ca1d3ce35d5ee66f810fe |
| SHA1 | 9019b9cd4eed3a7a453b49b13a02d12251644f3d |
| Domains | [buxnfuoim27a3yvh.onion.link] [api.ipify.org] |
| IP Addresses | [103.198.0.2] [54.221.194.87] |
| Antivirus | [Backdoor.Androm.knt] |
| [Ransom:Win32/Critroni] | |
| [Ransomware-FTT!C9AFF9030E9C] | |
| [Ransom_Critroni.R021C0DIP16] | |
| [Trj/GdSda.A] | |
| [Trojan-Ransom.Win32.Polyglot.c] | |
| [Trojan.Downloader] | |
| [Trojan.MulDrop6.57335] | |
| [Trojan.Polyglot!] |