Technical Information
- '%PROGRAMDATA%\arinzeh4927.com'
- arinedf.exe
- %PROGRAMDATA%\arinzeh4927.com
- %APPDATA%\arindhf\arinedf.exe
- %APPDATA%\arindhf\arinedf.exe:zoneidentifier
- http://uz###sse.top/arinze/arinze.exe
- DNS ASK uz###sse.top
- '%APPDATA%\arindhf\arinedf.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\microsoft.net\framework\v2.0.50727\dw20.exe' -x -s 468