Technical Information
- %PROGRAM_FILES%\Tomfile\Tomfile.exe
- %PROGRAM_FILES%\Tomfile\Tomfile.exe (downloaded from the Internet)
- %PROGRAM_FILES%\Tomfile\Tomfile.exe
- 'to##ile.com':80
- to##ile.com/app/Tomfile.exe
- DNS ASK to##ile.com
- '<Private IP address>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''