Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'OverlordAgent-224e44bc' = '"%APPDATA%\Microsoft\DeviceSync\svchost.exe"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\agent-2947031311.tmp
- %APPDATA%\microsoft\devicesync\agent-1040772119.tmp
- from %APPDATA%\microsoft\devicesync\agent-1040772119.tmp to %APPDATA%\microsoft\devicesync\svchost.exe
- '74.##8.117.130':5173
- '74.##8.117.130':5173