| MD5 | eaa9f063e0754db3c4e51f39d4e91fb2 |
| SHA1 | cb9eb2d3b7599de9541d3167dfdacf20ae6e5177 |
| Filename | E0B8.tmp.exe |
| Domains | [nlenergyworks.com] [joannarowsell.com] [davidswebsite.com] [jinanglasgow.com] [ylanding.com] [basketsandgiftscollection.com] [lasvegaschristmaslighting.com] [aznetgroup.com] [kewlprojects.com] [thesixthspace.com] |
| IP Addresses | [127.0.0.1] [87.106.147.11] [74.50.7.45] [23.229.175.72] [74.220.219.81] [67.227.191.224] [69.89.31.242] [103.27.62.181] [209.59.169.135] [192.185.175.159] |
| Antivirus | [Mal/Ransom-DK] |
| [Ransom.Crowti.r4] | |
| [Ransom:Win32/Crowti.A] | |
| [RansomCWall-FBJ!EAA9F063E075] | |
| [Ransome.Crowti.OB4] | |
| [Ransom_CRYWALL.CPH15C7] | |
| [Trj/GdSda.A] | |
| [Trojan.DownLoader17.61635] | |
| [Trojan.FileCoder.Win32.11] |