| MD5 | 384990371dec0562fd27c04f49e214ba | 
| SHA1 | 5cd46d5500e42fbaef080f07924446d5ec41af8a | 
| Filename | dh398699.exe | 
| Domains | [win7.398699.com] [s4.cnzz.com] [z11.cnzz.com] [c.cnzz.com] [123.sogou.com] [upd13.sogoucdn.com] [upd14.sogoucdn.com] [123p1.sogoucdn.com] [123p3.sogoucdn.com] [123p0.sogoucdn.com] | 
| IP Addresses | [14.18.141.148] [123.138.67.81] [42.156.140.84] [106.120.188.38] [42.56.64.25] [42.56.76.15] [111.202.98.159] [42.56.76.16] [121.29.54.143] [121.29.54.144] | 
| Antivirus | [Hacktool.Win32.Autoit.H] | 
| [IMWorm.Sohanad] | |
| [PossibleThreat] | |
| [RDN/YahLover.worm] | |
| [Trojan.Click3.13555] | |
| [TrojWare.Win32.Hider.REXR] | |
| [W32.HfsAtSTIL.81BA] | |
| [W32/Trojan.IJBN-1595] | |
| [W32/Trojan2.NVGH] | |
| [Win.Trojan.8468349] |