| MD5 | 1fce0e0b05bd516c507ee13f5f1b9640 |
| SHA1 | edac2789d1ebc2b8fc6080baf91296165cc826e2 |
| Domains | [hnb.net] [firecheerleaders.fr] [ladiesdehaan.be] [chonburicoop.net] [passlift.com] [actionpourisrael.com] |
| IP Addresses | [222.165.133.242] [213.186.33.171] [62.210.92.9] [27.254.96.151] [217.116.196.239] [213.186.33.4] |
| Antivirus | [BackDoor-FDCH!1FCE0E0B05BD] |
| [Mal/Wonton-BZ] | |
| [Ransom*Win32/Tescrypt!rfn] | |
| [Ransom.Crowti.WR7] | |
| [Trojan-Ransom.Win32.Bitman.hzn] | |
| [Trojan.Inject1.56622] | |
| [Trojan.MalPack.PK] | |
| [W32/Agent.XL.gen!Eldorado] | |
| [Win32*Malware-gen] | |
| [Win32/Kryptik.ENJD] |