<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>MuddyWater on Melted in Hex</title>
    <link>https://meltedinhex.com/tags/muddywater/</link>
    <description>Recent content in MuddyWater on Melted in Hex</description>
    <image>
      <title>Melted in Hex</title>
      <url>https://meltedinhex.com/images/og-social.png</url>
      <link>https://meltedinhex.com/images/og-social.png</link>
    </image>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 11 Jan 2019 22:00:00 +0530</lastBuildDate>
    <atom:link href="https://meltedinhex.com/tags/muddywater/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A new MuddyWater APT campaign spreads Backdoor RAT</title>
      <link>https://meltedinhex.com/posts/a-new-muddywater-apt-campaign-spreads/</link>
      <pubDate>Fri, 11 Jan 2019 22:00:00 +0530</pubDate>
      <guid>https://meltedinhex.com/posts/a-new-muddywater-apt-campaign-spreads/</guid>
      <description>&lt;p&gt;MuddyWater is an APT group that has been active throughout 2017, targeting victims in the Middle East with in-memory vectors leveraging PowerShell.&lt;/p&gt;
&lt;p&gt;In October 2018, Kaspersky Lab published a &lt;a href=&#34;https://securelist.com/muddywater/88059/&#34;&gt;good analysis report&lt;/a&gt; on the malware by this APT group.&lt;/p&gt;
&lt;p&gt;Here I am publishing my analysis report on recent malware by this APT group which targeted several parts of the Middle East.&lt;/p&gt;
&lt;p&gt;Sample -  8899c0dac9f6bb73ce750ae7b3250dbd (&lt;a href=&#34;https://www.virustotal.com/#/file/c873532e009f2fc7d3b111636f3bbaa307465e5a99a7f4386bebff2ef8a37a20/detection&#34;&gt;Virustotal&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;References :&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.vmray.com/analyses/c873532e009f/report/overview.html&#34;&gt;https://www.vmray.com/analyses/c873532e009f/report/overview.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://twitter.com/360TIC/status/1081080752438009856&#34;&gt;https://twitter.com/360TIC/status/1081080752438009856&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.virustotal.com/#/file/c873532e009f2fc7d3b111636f3bbaa307465e5a99a7f4386bebff2ef8a37a20/detection&#34;&gt;https://www.virustotal.com/#/file/c873532e009f2fc7d3b111636f3bbaa307465e5a99a7f4386bebff2ef8a37a20/detection&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img loading=&#34;lazy&#34; src=&#34;https://meltedinhex.com/images/a-new-muddywater-apt-campaign-spreads/doc1-85a3eec5.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;The document has obfuscated macro code which contains encrypted binary data. On execution, it decrypts the data, drops files and executes them.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
