| 18261.js | |
| ASCII text, with very long lines | 9694 bytes |
| 2016-12-01 14:48:46 | |
| db02967b133120581584fc4465e40b91 | |
| 4c487c955b0c658e002d806f362871096cf36de6 | |
| c3c8c46ef3a0925ba3f1be6f4b46afa5c554ddb72ce6a352c68a878903860316 | |
| 74946bac47aa94e62c55bc7c3e2e50a7ff8394b37be427d81c69c88ffd567692adebd082de3b06703b5261538b94d7a095d641a1bd7fea8fbde6c6c8d0785ec8 | |
| 192:gogpgXGpq/1T4SbZ5S8SakUK4HQxo96BZExMTJubrpzj:gr6D9EuwZgwJ8MTIzj | |
| N/A | |
| N/A | |
| Source: |

| Antiy-AVL | Trojan/Generic.ASVCS3S.435 |
| Cyren | JS/Nemucod.ES2!Eldorado |
| F-Prot | JS/Nemucod.ES2!Eldorado |
| Fortinet | JS/Nemucod.3CB4!tr.dldr |
| Ikarus | Trojan-Downloader.JS.Nemucod |
| HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System |
| HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor |
| HKEY_CURRENT_USER\Software\Microsoft\Command Processor |
| HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale |
| HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts |
| HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups |