盗取已安装的邮件客户端相关的信息
key: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Microsoft Outlook\Capabilities\Hidden
key: HKEY_LOCAL_MACHINE\Software\Clients\Mail\Microsoft Outlook\Capabilities
key: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Microsoft Outlook\Capabilities\FileAssociations
网络分析
域名解析
域名 |
响应 |
dns.msftncsi.com |
A 131.107.255.255
|
dns.msftncsi.com |
AAAA fd3e:4f5a:5b81::1
|
UDP连接
IP地址 |
端口 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.255 |
138 |
192.168.122.69 |
53197 |
224.0.0.252 |
5355 |
239.255.255.250 |
1900 |
40.69.40.157 |
123 |