| MD5 | cce6ed7bf51f18d871a670d20f5e1bc5 | 
| SHA1 | e729a18ae19f5481c7d00330f94a0e1316e3bb22 | 
| Domains | [www.update.microsoft.com.nsatc.net] [connect-twoo.com] [update.microsoft.com] [connect-server.com.ua] [microsoft-server51232.net] [microsoft-qqq1332019.net] | 
| IP Addresses | [134.170.58.221] [65.55.50.158] [185.25.119.84] | 
| Antivirus | [Backdoor.Androm] | 
| [Backdoor.Androm.eumt.upvt] | |
| [Backdoor.Androm.rw5] | |
| [BackDoor.Andromeda.267] | |
| [Backdoor.Win32.Androm.eumt] | |
| [Malware-gen*Win32*Malware-gen] | |
| [Troj/Agent-AIQH] | |
| [Trojan-Spy.Zbot] | |
| [Trojan.Psuedo.inj] | |
| [TROJ_SPNR.35JG14] |