Molerats__2019__suspected-molerats-new-attack-in-the-middle-east-cn.pdf
ID: dda523f3-4661-46a5-a7f6-44a97013e254
STIX ID: report--dda523f3-4661-46a5-a7f6-44a97013e254
Threat Score
80/100
Uploaded: 2026-08-19
Published Date: 2019-02-15
Last Modified Date: 2019-02-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
360 Threat Intelligence Center analyzed a Molerats-attributed targeted campaign that delivered a backdoor via Arabic-language Word documents containing malicious VBA macros which drop and run an Enigma Virtual Box–packed payload (ihelp.exe); the report includes static and dynamic analysis, network protocol details (SFML-based HTTP POST), C2 information (smartweb9.com and associated IPs), sample hashes, keyword-based command protocol, sinkhole evidence for the C2, and recommended mitigations.
