








| MD5 | 4dbdf9e73db481b001774b8b9b522ebe |
| SHA1 | a24a01345a2cfd13dbb0f4cbc2854d5997841318 |
| Filename | payroll_report.scr |
| Domains | [197.149.90.166:12142] [icanhazip.com] [197.149.90.166:12141] [stun.iptel.org] |
| IP Addresses | [197.149.90.166] [104.238.145.30] [212.79.111.155] [104.238.136.31] [104.238.141.75] |
| Antivirus | [Downloader.Upatre] |
| [Downloader.Upatre.Win32.52729] | |
| [Heur/Downloader.ZALY!suspicious] | |
| [Malware.SubId.124826008] | |
| [TR/AD.Yarwi.Y.110] | |
| [Troj/Dyreza-IU] | |
| [Trojan-Downloader.Win32.Upatre] | |
| [Trojan-Downloader.Win32.Upatre.etfn] | |
| [Trojan.PWS.Panda.8013] | |
| [Trojan.Upatre] |