- UID
- 78976
注册时间2014-11-2
阅读权限20
最后登录1970-1-1
以武会友
TA的每日心情 | 开心 2020-12-30 07:25 |
---|
签到天数: 210 天 [LV.7]常住居民III
|
发表于 2016-4-13 00:31:51
|
显示全部楼层
不明白为什么还要联网。。。
https://habo.qq.com/file/showdetail?pk=ADQGbl1pB28IPFs9
网络行为
行为描述: 联网打开网址
详情信息:
InternetOpenUrlA: http://<FAKE_SERVER_IP>:128/wpad.dat, hInternet = 0x00cc0010, Flags = 0x00000010
行为描述: 连接指定站点
详情信息:
InternetConnectA: ServerName = e.******om, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
InternetConnectA: ServerName = <FAKE_SERVER_IP>, PORT = 128, UserName = , Password = , hSession = 0x00cc0010, hConnect = 0x00cc0014, Flags = 0x00000010
行为描述: 打开HTTP连接
详情信息:
InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489), hSession = 0x00cc0004
InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 8.0; Win32; Trident/4.0), hSession = 0x00cc0010
行为描述: 建立到一个指定的套接字连接
详情信息:
URL: wpad, IP: <FAKE_SERVER_IP>:128, SOCKET = 0x000003d8
URL: e.******om, IP: <FAKE_SERVER_IP>:80, SOCKET = 0x000003e4
URL: e.******om, IP: <FAKE_SERVER_IP>:80, SOCKET = 0x000004dc
行为描述: 读取网络文件
详情信息:
hFile = 0x00cc0018, BytesToRead =4010, BytesRead = 4010.
hFile = 0x00cc000c, BytesToRead =4096, BytesRead = 4096.
行为描述: 发送HTTP包
详情信息:
GET /wpad.dat HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32; Trident/4.0) Host: <FAKE_SERVER_IP>:128
GET /?v=5.3&t=791ce HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: e.******om Connection: Keep-Alive
行为描述: 打开HTTP请求
详情信息:
HttpOpenRequestA: e.******om:80/?v=5.3&t=791ce, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400200
HttpOpenRequestA: <FAKE_SERVER_IP>:128/wpad.dat, hConnect = 0x00cc0014, hRequest = 0x00cc0018, Verb: GET, Referer: , Flags = 0x00000010
HttpOpenRequestA: e.******om:80/?v=5.3&t=791ce, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400010
行为描述: 按名称获取主机地址
详情信息:
GetAddrInfoW: computer
GetAddrInfoW: wpad
GetAddrInfoW: e.******om
|
|