Molerats__2019__suspected-molerats-new-attack-in-the-middle-east-en.pdf
ID: 928e0c5d-9304-4af2-98b1-20e28e2585a5
STIX ID: report--928e0c5d-9304-4af2-98b1-20e28e2585a5
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2019-02-15
Last Modified Date: 2019-02-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
360 Threat Intelligence Center analyzed a targeted campaign suspected to be carried out by the Molerats APT: an Arabic Word document with malicious VBA macros drops a Base64-decoded VBS and an Enigma Virtual Box–packed backdoor (ihelp.exe) that contacts C2 (smartweb9.com) using SFML-based HTTP POSTs, supports remote shell and file operations, uses keyword-based encoded payload blocks, and whose C2 was subsequently sinkholed; the report includes IoCs (file hashes, domains, IPs), behavioral analysis, and contextual attribution to Molerats.
