Has anyone gutted an infected box to determine whether it's going to go for
or a hardcoded IP?


Most folks have probably seen this, but this analysis
  is very good and should help to alleviate ambiguities.

Hardcoded IP.


No rush. There is no source and it is a Windows binary.