MuddyWater__2019__The_Muddy_Waters_of_APT_Attacks.pdf
ID: ef0f6110-da79-410d-9e22-a34d2fe2498c
STIX ID: report--ef0f6110-da79-410d-9e22-a34d2fe2498c
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2019-04-20
Last Modified Date: 2019-04-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Check Point report analyzes a MuddyWater APT campaign that uses spear-phishing Word documents with malicious macros to drop Delphi/UPX executables (CiscoAny.exe), create INF-based persistence, and deploy a second-stage uploader that posts system details to a hardcoded C2 (185.117.75.116) and retrieves PowerShell payloads (commonly POWERSTATS). The report documents the full infection flow, anti-analysis techniques, VBA/macro similarities across multiple samples, sample SHA‑256 hashes, domains/IPs used for C2, and defensive detection recommendations.
