Rewterz Threat Alert – New Molerats Suspected Attack in the Middle East

Thursday, February 14, 2019

Severity: HIGH

Analysis Summary

Security analysts have found a bait document being circulated in the Middle East, designed specifically for Arabic users. It is an Office Word document with malicious macros embedded to drop and execute a backdoor packed by Enigma Virtual Box. It looks like this:

The backdoor program has a built-in keyword list containing names of people or opera movies to communicate with C2, which distributes control commands to further control the victim’s computer device. Investigations suggested that the attack is being carried out by Molerats.
The IP address (198[.]54[.]117[.]244) that took over the C2 domain name is bound with a large number of malicious domain names, and is not controlled by the threat actors currently.

System Compromise

Malware Infection

Indicators of Compromise

IP(s) / Hostname(s)





  • 1.doc
  • HelpPane.exe
  • 02ded0222bde1e7584fd9f3058aa71ade9fbe881b57e546c599fd955eef1718c.sample

Malware Hash (MD5/SHA1/SH256)

  • 02ded0222bde1e7584fd9f3058aa71ade9fbe881b57e546c599fd955eef1718c
  • 063a50e5e4b4d17a23ac8c8b33501719
  • 46173adc26721fb54f6e1a1091a892d4


  • Block the threat indicators at their respective controls.
  • Spread awareness about Phishing attacks in your organization.
  • Do not open unexpected emails even if they look harmless.
  • Do not download document files attached in emails from unknown sources and strictly refrain from enabling macros when the source isn’t reliable.

Data Sheets

Corporate Brochure

Our Story



Managed Security

Upcoming Rewterz Trainings/Events

Rewterz News

  • 2, May 2019 Rewterz Threat Advisory – CVE-2019-2725 – WebLogic Server Vulnerability
  • 11, April 2019 Rewterz threat Advisory – Microsoft Internet Explorer Multiple Vulnerabilities
  • 11, April 2019 Rewterz Threat Advisory – Microsoft SharePoint Multiple Products Multiple Script Insertion Vulnerabilities
  • 11, April 2019 Rewterz Threat Advisory – Microsoft Exchange Server OWA Multiple Spoofing Vulnerabilities

Copyright © Rewterz. All rights reserved.