| MD5 | baf3947937254c5d2112d879bc059994 |
| SHA1 | 828d6783742e3b6f7b0142b116621a53e848c061 |
| Filename | bot.exe |
| Domains | [ip-addr.es] [kaplicarehberi.com] [stangemes.com] [orzz.tw] |
| IP Addresses | [188.165.164.184] [95.173.183.176] [5.9.147.176] [54.186.241.202] |
| Antivirus | [HEUR/QVM07.1.Malware.Gen] |
| [Hoax.Blocker] | |
| [PE:Malware.Obscure/Heur!1.9E03] | |
| [Ransom:Win32/Crowti] | |
| [RDN/Trojan-FDWH!a] | |
| [Spyware.Password] | |
| [Trj/Multidropper.BRZ] | |
| [Troj/Fondu-EM] | |
| [Trojan-Ransom.Win32.Blocker.gtvd] | |
| [Trojan.Agent/Gen-Injector] |