| MD5 | 3ab87c84f79f3791ca4990e37bc05265 | 
| SHA1 | f79abc50920d65194af3f129c4ed74cc22c245aa | 
| Filename | 0e9fca7ea8612aca81b23fa213f895f49c671a9b44fcc554709fb5aa0de93827 | 
| Domains | [www.58ad.cn] [www.go890.com] [www.haosou.com] | 
| IP Addresses | [119.97.143.21] [8.37.232.5] [106.120.160.134] | 
| Antivirus | [Artemis!F14D9DF2F619] | 
| [Backdoor.Win32.Yobdam.lkj] | |
| [Backdoor.Yobdam] | |
| [Backdoor.Yobdam!7dQLcUiWzfs] | |
| [Backdoor.Yobdam.r8] | |
| [Backdoor.Yobdam.Win32.1820] | |
| [Backdoor/W32.Yobdam.933888.B] | |
| [Luhe.Packed.AP] | |
| [PE:Packer.Win32.StartPage.c!1075357398] | |
| [Suspicious.Graybird.1] |