| MD5 | c5481d34929edfdb1a7a0229e044a07c |
| SHA1 | 85613114cb117952ab67547050d519f69c32f9d6 |
| Filename | syshost.bin |
| Domains | [facebook.com] [ynutdxycbpvx.com] [ziqfbpkxmahrv.com] [fpcrdhskfgzi.com] [cherfsosiib.com] [0.pool.ntp.org] [1.pool.ntp.org] [jvgyfkkgyswmp.com] [zvsjfgzedfcov.com] [qcmbartuop.bit] |
| IP Addresses | [69.171.230.68] [66.228.59.187] [108.59.2.24] [23.100.122.175] [107.170.224.8] |
| Antivirus | [Downloader.Necurs.Win32.168] |
| [Packed-EQ!C5481D34929E] | |
| [PE:Malware.RDM.20!5.1A[F1]] | |
| [Ransom.Crowti.G4] | |
| [Troj/Necurs-DI] | |
| [Trojan-Downloader.Win32.Necurs] | |
| [Trojan-Dropper/W32.Necurs.114176] | |
| [Trojan.Click3.12222] |