| MD5 | b2491e140edaa3fe92d8a652fc919408 | 
| SHA1 | 44762a0c53943be317134f3d86685d8d3d6e6636 | 
| Filename | SpellPicture.exe | 
| IPs | [204.79.197.203] | 
| IPs | [134.170.184.137] | 
| IPs | [192.150.16.64] | 
| IPs | [134.170.188.84] | 
| Domains | [a-0003.a-msedge.net] [www.go.microsoft.akadns.net] [www.wip4.adobe.com] [lb1.www.ms.akadns.net] [www.msn.com] [go.microsoft.com] [www.adobe.com] [www.microsoft.com] [tyuocruz1312.net] | 
| IP Addresses | [204.79.197.203] [134.170.184.137] [192.150.16.64] [134.170.188.84] | 
| Antivirus | [Downloader.Generic14.DUQ] | 
| [Malware-gen*Win32*Malware-gen] | |
| [RDN/Downloader.a!tr] | |
| [Spyware.Zbot.ED] | |
| [TR/Dofoil.A.210] | |
| [Troj/Agent-AJQG] | |
| [Trojan.GenericKD.1948287] | |
| [Trojan.Win32.Yakes] | |
| [Trojan.Win32.Yakes.gxff] |