| MD5 | fcd9452772b584931a63e9e8fdbfd3ab | 
| SHA1 | 9fd96b244c76b2f244e8b4415d1643123c3f7075 | 
| Filename | WellsFargo.Documents.exe | 
| IPs | [72.52.238.172] | 
| IPs | [111.90.133.127] | 
| IPs | [95.211.192.195] | 
| IPs | [114.150.36.222] | 
| IPs | [118.237.62.27] | 
| IPs | [70.66.226.202] | 
| IPs | [115.126.143.176] | 
| IPs | [75.34.17.193] | 
| IPs | [119.225.38.58] | 
| IPs | [60.244.81.6] | 
| IPs | [85.100.41.9] | 
| IPs | [61.21.85.139] | 
| IPs | [121.6.47.237] | 
| IPs | [119.172.162.34] | 
| IPs | [206.205.226.130] | 
| IPs | [172.245.217.122] | 
| Domains | [dataseek.com.br] [xpwboard.biz] | 
| IP Addresses | [72.52.238.172] [111.90.133.127] [95.211.192.195] [114.150.36.222] [118.237.62.27] [70.66.226.202] [115.126.143.176] [75.34.17.193] [119.225.38.58] [60.244.81.6] | 
| Antivirus | [Heuristic.LooksLike.Win32.SuspiciousPE.J] | 
| [Malware.QVM19.Gen] | |
| [PE:Malware.FakePDF@CV!1.9C28] |