Bank_Security

GoldenSpy backdoor trojan IOCS CHINA BANK

Jun 26th, 2020
17,822
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.17 KB | None | 0 0
  1. GoldenSpy backdoor trojan found in a Chinese bank's official tax software
  2.  
  3. http://192.168.176.1:9006/download/ncat
  4. http://192.168.176.1:9006/download/ncat”
  5. http://192.168.176.1:9006/file/download/libeay32.dll”
  6. http://192.168.176.1:9006/file/download/ncat.exe”
  7. http://192.168.176.1:9006/file/download/ssleay32.dll”
  8. http://cdn.i-xinnuo.com/cdn/setup.
  9. http://cdn.i-xinnuo.com/cdn/setup.ec.v.1.1.r.exenanjing
  10. http://download.ningzhidata.com/download/svminstall.exe
  11. http://upgrade.i-xinnuo.com
  12. http://upgrade.i-xinnuo.com.•
  13. http://www.ningzhidata.com:9006/
  14. http://www.ningzhidata.com:9006/softserver/reqprotocolsvm.exe
  15. 2020-04-16ningzhidata.com
  16. 70www.ningzhidata.com
  17. 71www.ningzhidata.com
  18. 73www.ningzhidata.com
  19. malware25trustwave.com
  20. trojanwww.ningzhidata.com
  21. cdn.i-xinnuo.com
  22. codeningzhidata.com
  23. dc.i-xinnuo.com
  24. download.ningzhidata.com
  25. i-xinnuo.com
  26. ningzhidata.com
  27. trustwave.com
  28. upgrade.i-xinnuo.com
  29. www.ningzhidata.com
  30. 1.0.0.1
  31. 1.2.0.0
  32. 110.110.110.0
  33. 110.110.110.1
  34. 124.152.41.85
  35. 172.46.16.23
  36. 192.168.176.1
  37. 223.112.21.2
  38. 40.81.188.85
  39. 42.56.76.93
  40. 49.232.156.177
  41. 59.83.204.14
  42. 04f100f771ed8dd238fdf41a0f85977a
  43. 05b0e15a989182e97e6068344840406f
  44. 0852402f8f75c9a75a74114af75f34c5
  45. 134d9ffc9c65366e690c2a4852ec6835
  46. 2c5557250cbd3f7ff3f778aa4fc6e479
  47. 2d9427f26131249333c60139d0995f88
  48. 39393db9ff05b587ef42ae6340f03a85
  49. 3cb5a5dc5701c2961742bdb05a43c6d0
  50. 52a64ae155ef5ec37966e787ab1678a2
  51. 696721fb92e109010b03304fda0c960f
  52. 7593a2422d0ea17fac214af4a1efa194
  53. 7b8d8a81b32209a80fb974cf89697116
  54. 7c348eac40b9dbf6bd52db2985abee42
  55. 84ff122838c0da5ab5ddcaa8f45f7011
  56. 85223e82337f409697b951207a2d91e6
  57. 8d5692af55e44e471a27a0fc401ac6ba
  58. 8ecc9a53cc99bde757df9e718fd3af17
  59. 946945ee4555fc7f7aced80904fe802f
  60. b672963bb8fc75b7c122082b5e567058
  61. b914c8064becf3df1df39b0517bda053
  62. b94c7fc5528f5e233a9900991c7757ca
  63. cf9933a40f9a348b412da0953a7de6f3
  64. f8246f3e4391c50c53c2417b9fea3a33
  65. 12f65238e7b3a8ddd719fb19a5
  66. 177afe2bcd5cb2de6349329c4263
  67. 177ffbeaa5947fc467fce27c765a4e
  68. 18ff8715972713c3b6645d1aef3d4c1
  69. 18ff8715972713c3b6645d1aef3d4c1n
  70. 323ace1f7248293bfd57982dea1a67
  71. 323ace1f7248293bfd57982dea1a67svm
  72. 32fa5fe6b7b4d97fda7bf17ec58c9
  73. 32fa5fe6b7b4d97fda7bf17ec58c9usv
  74. 3c9ebc312267eef6d1bb47b44c44aa
Add Comment
Please, Sign In to add comment