banking trojan

img14.poco.cn(HTTP Banking trojan hosted in China Shanghai Chinanet Shanghai Province Network)

Resolved : [img14.poco.cn] To [101.226.200.132] Resolved : [img14.poco.cn] To [101.226.200.130] Resolved : [img14.poco.cn] To [61.183.42.151] Resolved : [img14.poco.cn] To [101.226.200.134] Resolved : [img14.poco.cn] To [101.226.200.152] Resolved : [img14.poco.cn] To [61.183.42.150] Samples: hxxp://www.ccfyi.com/notepad.exe hxxp://www.ccfyi.com/mstsc.exe hxxp://www.ccfyi.com/cc.tx timg14.poco.cn GET /mypoco/myphoto/20130323/19/874940020130323195257040.jpg hxxp://174.139.56.114:54321/1.txt 1.txt: 67.198.167.37 keb.co.kr 67.198.167.37 keb.co.kr 67.198.167.37 www.keb.co.kr 67.198.167.37 www.keb.co.kr 67.198.167.37 citibank.co.kr 67.198.167.37 citibank.co.kr 67.198.167.37 www.citibank.co.kr 67.198.167.37 www.citibank.co.kr