Tor is used to host the bot .
Here is the sample : hxxp://kdsk3afdiolpgejs.onion.to/sphinx/bot.exe
Looking up kdsk3afdiolpgejs.onion.to…
Resolved to:
217.197.83.197
Other hosts contacted by the bot :
193.23.244.244
212.112.245.170
76.73.17.194
Hosting Infos :
http://whois.domaintools.com/217.197.83.197
Steven K - October 19, 2015 at 9:45 am
this is know as 'Sphinx' by IBM