Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'OverlordAgent-1dcc3f18' = '"%APPDATA%\Microsoft\DeviceSync\ovd_2467cfedabaf.exe"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\agent-3026114907.tmp
- %APPDATA%\microsoft\devicesync\agent-1469285031.tmp
- %APPDATA%\microsoft\devicesync\agent-1469285031.tmp в %APPDATA%\microsoft\devicesync\ovd_2467cfedabaf.exe
- 'pa###bin.com':443
- '15#.#4.210.209':5173
- 'ap#.#pify.org':443
- '15#.#4.210.209':5173
- DNS ASK pa###bin.com
- DNS ASK ap#.#pify.org