Technical Information
- <SYSTEM32>\cmmon32.exe
- %TEMP%\ghfe2c.tmp
- %APPDATA%\tor\state.tmp
- from %APPDATA%\tor\state.tmp to %APPDATA%\tor\state
- 'localhost':49179
- 'localhost':49181
- '11#.#7.12.40':9001
- '94.##.31.131':443
- '14#.#17.32.158':9002
- '37.##.120.47':110
- '21#.#96.147.77':443
- '17#.#5.193.9':80
- '46.##9.55.118':9001
- '18#.#20.101.200':8443
- '62.##2.84.241':9001
- '20#.#3.164.118':443
- '<SYSTEM32>\cmmon32.exe'