Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'OverlordAgent-3bc582ad' = '"%APPDATA%\Microsoft\DeviceSync\ovd_5dcbde762352.exe"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\agent-990163630.tmp
- %TEMP%\qtkdlaue.ve4.exe
- %APPDATA%\microsoft\devicesync\agent-75857463.tmp
- from %APPDATA%\microsoft\devicesync\agent-75857463.tmp to %APPDATA%\microsoft\devicesync\ovd_5dcbde762352.exe
- '31.##.219.155':5173
- '31.##.219.155':5173
- '%TEMP%\qtkdlaue.ve4.exe'