| MD5 | 26044053fcf00cd7e8c0257eda90686b | 
| SHA1 | a11f40c776fab2467a259bdc4140478820ee2d1a | 
| Domains | [www.update.microsoft.com.nsatc.net] [windowsupdate.microsoft.com] | 
| IP Addresses | [134.170.58.222] [191.232.80.55] | 
| Antivirus | [Downloader.Agent.16.AA] | 
| [Downloader.Cabby.Win32.781] | |
| [Downloader.Ponik] | |
| [Ransom-CTB!26044053FCF0] | |
| [TR/Cabhot.A.95] | |
| [Troj/Agent-ALFM] | |
| [Trojan-Downloader.Win32.Cabby.cbtj] | |
| [Trojan-Downloader.Win32.Upatre] |