| MD5 | cb8f1eadf23905942285f7cf6533ed1e |
| SHA1 | 42a7bdf49078ae8a23e590d5267563bb3935c78e |
| Domains | [www.update.microsoft.com.nsatc.net] [109.120.180.29] [faumoussuperstars.ru] [powerrembo.ru] [update.microsoft.com] [lunaizemlya.ru] |
| IP Addresses | [134.170.58.222] [134.170.58.221] [109.120.180.29] [109.120.155.30] |
| Antivirus | [BackDoor.Andromeda.614] |
| [Backdoor.Trojan] | |
| [Backdoor.Win32.Androm.hwty] | |
| [Mal/Wonton-BB] | |
| [Malware-gen*Win32*Malware-gen] | |
| [Ransom.Crowti.B4] | |
| [Trojan.Agent] | |
| [W32/Agent.XL.gen!Eldorado] | |
| [W32/Kryptik.DTNB!tr] | |
| [Win32/Kryptik.DTNB] |