Answer the question
In order to leave comments, you need to log in
How to scan the system for malware?
The provider forwarded a message from NCCKI with the following content:
NKTsKI has confirmed information about the introduction of
Trojan-Banker.Win32.RTM malware onto an object located in the address space of
your company.
In the period from June 25 to July 10, the facts of interaction
of the IP address presented in the attachment with the remote control center
(C&C) were recorded. To obtain C&C IP addresses, malware makes a request to
hxxps://chain[.]so/api/v2/get_tx_received/BTC/ (IP addresses 104.25.48.99,
104.25.47.99). The response contains a set of transactions to the crypto wallet account.
Answer the question
In order to leave comments, you need to log in
Verify the authenticity of the message: does the IP belong to you and are there any specified requests in the logs.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question