盗取已安装的邮件客户端相关的信息
key: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Microsoft Outlook\Capabilities\Hidden
key: HKEY_LOCAL_MACHINE\Software\Clients\Mail\Microsoft Outlook\Capabilities
key: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Microsoft Outlook\Capabilities\FileAssociations
投放文件
1cfc573c-542a-4cd7-886e-45020020d69b
文件名 |
1cfc573c-542a-4cd7-886e-45020020d69b |
相关文件 |
- C:\Windows\sysnative\LogFiles\Scm\1cfc573c-542a-4cd7-886e-45020020d69b
|
文件大小 |
20 bytes |
文件类型 |
data |
MD5 |
7eb4dee4c725fe2772930ddece2c19d6 |
SHA1 |
bfe0a8642def9e637901698c27c7675d79d5a7dc |
SHA256 |
997abb3b13bca2c1d52521c395b4c099eac68dc4c0b0e054805e1b754cc908cd |
SHA512 |
c4a6d88477ff2a573949091846157c8b78c375a1de05e7917b43a459a05e315e5fa84b07c7b8e8d89c283092ea1e5e9e4be10052752ba6457cf027cbabc011e9 |
Ssdeep |
3:WFd:WFd |
Yara |
无匹配
|
VirusTotal |
搜索相关分析 |