Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\tor] 'Start' = '00000002'
- '%PROGRAM_FILES%\Tor\tor.exe' --install --options -ControlPort 9051
- '%TEMP%\install-201657858.exe' /I
- %PROGRAM_FILES%\Tor\tor.exe
- <SYSTEM32>\config\systemprofile\Local Settings\Application Data\Windows Internet Name Service\wins.exe
- <SYSTEM32>\config\systemprofile\Local Settings\Application Data\Windows Internet Name Service\049e7fb749be2cdf169e28bb0a27254f\181084e525a65ef540c63d60ce07f836.ct
- %TEMP%\install-201657858.exe
- <SYSTEM32>\config\systemprofile\Local Settings\Application Data\Windows Internet Name Service\049e7fb749be2cdf169e28bb0a27254f\181084e525a65ef540c63d60ce07f836.ph
- '94.##2.214.145':80
- 94.##2.214.145/submit.php?he#################################################