| MD5 | 402b94e60ace708587fe752ff136c867 | 
| SHA1 | 257a46da0d207de9da2bdd57b72a927672b1f5d7 | 
| Filename | syshost.exe | 
| Domains | [facebook.com] [jvfhcdwvcc.com] [nflpqbvsngvkhk.com] [xvpfitzvewobul.com] [wlrkdgampnhlxi.com] [0.pool.ntp.org] [1.pool.ntp.org] [2.pool.ntp.org] [megashara.bit] | 
| IP Addresses | [31.13.76.68] [108.61.194.85] [132.163.4.102] [129.250.35.250] | 
| Antivirus | [Backdoor.Bot.F] | 
| [Dropper.Necurs.Win32.1280] | |
| [HW32.Packed.7D13] | |
| [Trj/OCJ.E] | |
| [Troj/Zbot-FOL] | |
| [Trojan-Dropper.Win32.Necurs!O] | |
| [Trojan-Dropper.Win32.Necurs.pfo] | |
| [Trojan-Dropper/W32.Necurs.60416] | |
| [Trojan.DR.Necurs!fezQh23ZQr0] |