It uses a data file called AF.dat and connect to bittorrent.
this must be measuring downloads/hits from btdigg.org (only), so someone is linking directly to it and relying on them to jump clients into the DHT perhaps?
file(1) has nothing to say about it but at a glance it doesn't look like a uniform encrypted blob...
Discussion: https://news.ycombinator.com/item?id=10574011
File name: AF.dat
Detection ratio: 0 / 55
https://www.virustotal.com/en/file/459b05fe2dbd56cb0f31babdf...