| MD5 | cfd12e5a6aebba97f7fdf55d39f21122 |
| SHA1 | 8f4c4a6b56cd9a3ec9a930f819a5bc59cc7ec108 |
| Filename | SpellPicture.exe |
| IPs | [204.79.197.203] |
| IPs | [134.170.189.4] |
| IPs | [192.150.16.64] |
| IPs | [172.226.90.203] |
| Domains | [a-0003.a-msedge.net] [www.go.microsoft.akadns.net] [www.wip4.adobe.com] [e10088.dscb.akamaiedge.net] [www.msn.com] [go.microsoft.com] [tyuocruz1312.net] [www.adobe.com] [www.microsoft.com] |
| IP Addresses | [204.79.197.203] [134.170.189.4] [192.150.16.64] [172.226.90.203] |
| Antivirus | [Backdoor.DarkKomet] |
| [Downloader.Generic14.DUQ] | |
| [Generic-FAVG!CFD12E5A6AEB] | |
| [Spyware.Zbot.ED] | |
| [TR/Dropper.Gen] | |
| [Troj/Agent-AJQG] | |
| [Trojan.Sharik.r6] | |
| [Trojan.Win32.Generic] | |
| [Trojan.Win32.Inject] |