| MD5 | 3f6587c5803a4a33157bde56256292a1 | 
| SHA1 | 3851bbf815e69e5be28c605be501542fa7bb73a1 | 
| Filename | qmbfnml.exe | 
| IPs | [46.19.37.108] | 
| IPs | [62.210.92.11] | 
| IPs | [194.109.206.212] | 
| IPs | [171.25.193.9] | 
| Domains | [ip.telize.com] [3fdzgtam4qk625n6.onion.gq] [3fdzgtam4qk625n6.onion.cab] [3fdzgtam4qk625n6.tor2web.fi] [3fdzgtam4qk625n6.tor2web.org] [3fdzgtam4qk625n6.onion.lt] [3fdzgtam4qk625n6.tor2web.blutmagie.de] | 
| IP Addresses | [46.19.37.108] [62.210.92.11] [194.109.206.212] [171.25.193.9] [188.138.122.22] [194.150.168.74] [65.112.221.20] [82.94.251.220] | 
| Antivirus | [Adware.Win32.iBryte.DGLQ] | 
| [Adware.Win32.iBryte.DGNC] | |
| [Artemis!3F6587C5803A] | |
| [HW32.Packed.425B] | |
| [Mal/Generic-L] | |
| [Ransom:Win32/Critroni.B] | |
| [Trojan.GenericKD.2327000] | |
| [Trojan.Win32.Generic.pak!cobra] | |
| [TROJ_FRS.0NA000DS15] |