盗取已安装的邮件客户端相关的信息
key: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Microsoft Outlook\Capabilities\Hidden
key: HKEY_LOCAL_MACHINE\Software\Clients\Mail\Microsoft Outlook\Capabilities
key: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Microsoft Outlook\Capabilities\FileAssociations
行为分析
互斥量(Mutexes)
- Local\ZoneAttributeCacheCounterMutex
- Local\ZonesCacheCounterMutex
- Local\ZonesLockedCacheCounterMutex
- Local\MSCTF.Asm.MutexDefault1
执行的命令
- "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\test\AppData\Local\Temp\httpErrorPagesScripts_1_
- C:\Users\test\AppData\Local\Temp\httpErrorPagesScripts_1_
- C:\Windows\system32\svchost.exe -k netsvcs
创建的服务
无信息
进程
cmd.exe PID: 2520, 上一级进程 PID: 2556
services.exe PID: 452, 上一级进程 PID: 356
svchost.exe PID: 1220, 上一级进程 PID: 452
rundll32.exe PID: 1552, 上一级进程 PID: 2520
读取的文件
- \Device\KsecDD
- C:\Users\test\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
- C:\Users\test\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db
- C:\Users\test\Desktop\desktop.ini
- C:\
- C:\Users\desktop.ini
- C:\Users
- C:\Users\test
- C:\Users\test\Searches\desktop.ini
- C:\Users\test\Videos\desktop.ini
- C:\Users\test\Pictures\desktop.ini
- C:\Users\test\Contacts\desktop.ini
- C:\Users\test\Favorites\desktop.ini
- C:\Users\test\Music\desktop.ini
- C:\Users\test\Downloads\desktop.ini
- C:\Users\test\Documents\desktop.ini
- C:\Users\test\Links\desktop.ini
- C:\Users\test\Saved Games\desktop.ini
- C:\Windows\System32\shdocvw.dll
- C:\Windows\AppPatch\sysmain.sdb
- C:\Windows\System32\
- C:\Windows\System32\rundll32.exe
- C:\Windows\SysWOW64\cmd.exe
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\sysnative\appmgmt\S-1-5-21-2280033686-3172497658-3481507381-1000\AppMgmt.ini
- C:\Windows\System32\shell32.dll
- C:\Windows\System32\shell32.dll.123.Manifest
- C:\Windows\SysWOW64\shell32.dll
- C:\Windows\Fonts\staticcache.dat
- C:\Windows\System32\EhStorShell.dll
- C:\Windows\System32\zh-CN\EhStorShell.dll.mui
- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
- C:\Program Files (x86)\Microsoft Office\Office14\
- C:\Program Files (x86)\Microsoft Office\Office14\2052\GrooveIntlResource.dll
- C:\Windows\System32\ntshrui.dll
- C:\Windows\System32\imageres.dll
- C:\Windows\System32\zh-CN\imageres.dll.mui
- C:\Windows\sysnative\zh-CN\imageres.dll.mui
- C:\Windows\System32\zh-Hans\imageres.dll.mui
- C:\Windows\System32\zh\imageres.dll.mui
- C:\Windows\System32\en-US\imageres.dll.mui
- C:\Program Files (x86)\desktop.ini
- C:\Program Files (x86)
- C:\Program Files (x86)\Adobe
- C:\Program Files (x86)\Adobe\Reader 11.0
- C:\Program Files (x86)\Adobe\Reader 11.0\Reader
- C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
- C:\Windows
- C:\Windows\ehome
- C:\Windows\ehome\ehshell.exe
- C:\Program Files (x86)\Internet Explorer
- C:\Program Files (x86)\Internet Explorer\iexplore.exe
- C:\Windows\System32
- C:\Windows\System32\mspaint.exe
- C:\Windows\System32\notepad.exe
- C:\Program Files (x86)\Microsoft Office
- C:\Program Files (x86)\Microsoft Office\Office14
- C:\Program Files (x86)\Microsoft Office\Office14\OIS.EXE
- C:\Program Files (x86)\Windows Photo Viewer
- C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll
- C:\Program Files (x86)\Windows Photo Viewer\zh-CN\PhotoViewer.dll.mui
- C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
- C:\Windows\SysWOW64\wmploc.DLL
- C:\Program Files (x86)\Windows Media Player
- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
- C:\Program Files (x86)\Windows NT
- C:\Program Files (x86)\Windows NT\Accessories
- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
- C:\program files (x86)\windows nt\accessories\wordpad.exe
- C:\program files (x86)\windows photo viewer\photoviewer.dll
- C:\program files (x86)\windows photo viewer\zh-CN\photoviewer.dll.mui
- C:\program files (x86)\windows media player\wmplayer.exe
- C:\program files (x86)\microsoft office\Office14\WINWORD.EXE
- C:\program files (x86)\internet explorer\iexplore.exe
- C:\program files (x86)\Adobe\reader 11.0\Reader\AcroRd32.exe
修改的文件
无信息
删除的文件
无信息
修改的注册表键
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\\OpenWithList
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Windows\eHome\ehshell.exe
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Windows\system32\mspaint.exe
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\PROGRA~2\MICROS~1\Office14\OIS.EXE
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\1C\AAF68885\LanguageList
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\1C\AAF68885\@wmploc.dll,-102
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files (x86)\Windows Media Player\wmplayer.exe
- HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE
删除的注册表键
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName