“GoldenHelper” was discovered on July 14, 2020 embedded in Golden Tax Invoicing Software, an invoice issuing software used by Chinese banks. This malware variant seems to have been active between January 2018 and July 2019.
Press enter or click to view image in full size
Fig 1.0: First bytes of malware sample
Press enter or click to view image in full size
Fig 1.1: File header in PE studio
The following details were obtained from initial static analysis:
PE Studio identified ~1870 strings, the following have been highlighted:
The following appear to be files that will be loaded during runtime http://%s/app/taxver[.]jpg http://%s/app/tps32[.]gif http://%s/data/msabs[.]dat http://%s/data/msabb[.]rar http://%s/data/tax32[.]zip…