Rewterz Threat Alert – Muddy Water Summer Mirage Campaign – IOC’s

Monday, January 13, 2020



Analysis Summary

Prevailion uncovered two new malicious documents; one which discussed Stephen Moore’s appointment to the Federal Reserve, the second document discussed companies that extract and process crude oil. Both of these documents relied upon socially engineering their victims into enabling macros in order to infect the targeted workstation. Once macros were enabled, the threat actor-written code would attempt to obtain a trojan hosted on an adversarial payload command and control node. This was a fully functional remote access trojan, that would allow the threat actors to interact with the compromised workstation via the adversarial interactive command and control node. 



  • Credential theft
  • Exposure of sensitive information

Indicators of Compromise


  • 1f738218a4da659f3d58ff4abaa4edd7
  • 34f759180146dcce3990e2c61677d949
  • 72f92f81721fe832316f7b27ad328e17
  • b0de46b50e209b185987010238fc65f0


  • f779ccc3da9d8c62a9596c3567b38cabfa1b1292129c1a77db67aaffb7828fe2
  • f327abed77b4b19b4471eaebf722295b8e50a47f36a4d7662cac91b1a622e64a
  • 4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1
  • 95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce


  • b28317940c141824586d92aa0ccf08994ebf2560
  • dbdf6617b5f2d065e1e2dac06b64cdfb88dfe105
  • 24dd2472b98af30daa1df4a6e22f4f80c06b6669
  • 196b1e7c0918eb262d2a55ec23d86ce1776b8c61


  • http[:]//194[.]187[.]249[.]78/
  • http[:]//38[.]132[.]99[.]167/crf[.]txt
  • http[:]//91[.]132[.]139[.]196/prxy[.]php?rCecms=H3OpAirStrike
  • http[:]//104[.]237[.]255[.]195/p[.]txt


  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.

Data Sheets

Corporate Brochure

Our Story



Managed Security

Upcoming Rewterz Trainings/Events

Rewterz News

  • 17, February 2020 Rewterz Threat Alert – Satan ransomware rebrands as 5ss5c ransomware
  • 20, January 2020 Rewterz Threat Alert – Iranian APT Group “MuddyWater” Resurfaces
  • 20, January 2020 Rewterz Threat Alert – STOP (djvu) Ransomware Actively Spread
  • 20, January 2020 Rewterz Threat Advisory – Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

Copyright © Rewterz. All rights reserved.