| MD5 | 735c75f840ba2e20eae53fad6482e355 |
| SHA1 | 43edfcfcf67ed55bf5632e5fd9b9d8a402f061e1 |
| Filename | f85e0364f7992cf94046434d874c7b6fa5ede3906c65c88910896383b5dfa37a.exe |
| Domains | [ip.tyk.nu] [toysfortheneedyandaid.org] |
| IP Addresses | [144.76.253.225] [97.107.141.123] |
| Antivirus | [Inject3.ZGA] |
| [Ransom:Win32/Tescrypt!rfn] | |
| [Suspicious.Cloud.2] | |
| [Trojan-Banker.Win32.Shifu.acq] | |
| [Trojan.Encoder.3663] | |
| [Trojan.PWS.Shifu!] | |
| [Trojan.Win32.Injector] | |
| [Trojan[Banker]/Win32.Shifu] |