logo

Molerats__2019__suspected-molerats-new-attack-in-the-middle-east-cn.pdf

ID: dda523f3-4661-46a5-a7f6-44a97013e254

STIX ID: report--dda523f3-4661-46a5-a7f6-44a97013e254

Threat Score

80/100

Uploaded: 2026-08-19

Published Date: 2019-02-15

Last Modified Date: 2019-02-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
360 Threat Intelligence Center analyzed a Molerats-attributed targeted campaign that delivered a backdoor via Arabic-language Word documents containing malicious VBA macros which drop and run an Enigma Virtual Box–packed payload (ihelp.exe); the report includes static and dynamic analysis, network protocol details (SFML-based HTTP POST), C2 information (smartweb9.com and associated IPs), sample hashes, keyword-based command protocol, sinkhole evidence for the C2, and recommended mitigations.