← All hunts high TLP:CLEAR Part 2 of 2

Amatera Stealer and Follow-on Payloads

An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.

Based on research by Cisco Talos 2026-09-28 12 steps · 5 queries T1059.001 T1115 T1218.011 T1555 T1574.002

Brief

Background

The ClearFake infection chain recently evolved to deliver a variety of stealers and remote access tools. A recent report by Talos (https://blog.talosintelligence.com/clearfake-webdav-infection-chain/) details how this chain now deploys the Amatera stealer. This malware employs specific evasion and persistence techniques that bypass standard security controls. This hunt identifies the post-infection lifecycle of Amatera, focusing on its residency, command-and-control resolution, and subsequent theft activities.

Hunt Flow

The hunt begins with a scoping phase to identify endpoints communicating with known infrastructure. The first query searches DNS activity for resolution of reported C2 domains and Telegraph. This step identifies the set of hosts where the infection likely exists, allowing the analyst to focus the more intensive behavioral queries on a subset of the estate.

Following the scoping phase, the hunt pivots into two parallel searches for residency. One search identifies instances where rundll32.exe loads dbghelp.dll. While this module is legitimate, Amatera use it for module stomping to hide its payload in memory. Simultaneously, the hunt looks for HTTP traffic to specific URL paths on telegra.ph. These paths serve as dead-drops where the malware retrieves its actual C2 configuration. An analyst or agent confirms the beachhead by correlating these two signals on the same host.

The final phase identifies the impact and any follow-on activity. The hunt searches for unusual processes accessing sensitive file paths associated with cryptocurrency wallets such as Atomic or Exodus, as well as browser login data. At the same time, it looks for the execution of known secondary payloads like NetSupport Manager (client32.exe) running from user-writable directories like AppData or Public. This phase distinguishes a transient infection from a successful compromise where the adversary has begun to act on their objectives.

Blind Spots

The primary blind spot involves endpoint telemetry. If a host lacks the specific surface for module activity, the hunt cannot detect the DLL hollowing of dbghelp.dll. This limits the ability to confirm the residency phase of the infection. Furthermore, because Amatera is primarily memory-resident, it may not leave a significant file system footprint. If the stealer never writes its final payload to disk, traditional file-based detection will fail.

Steps

  1. Scope hosts by known C2 DNS traffic

    Query · scoping

    Identify endpoints that have resolved the reported C2 or dead-drop domains to focus the search.

    reads hb_dns_activitysql
    SELECT DISTINCT device_hostname FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A list of hostnames communicating with reported infrastructure. Silence suggests the C2 is not currently active via these domains.

  2. DLL hollowing of dbghelp.dll

    Query · triage

    Detect the overwriting of legitimate modules, specifically targeting dbghelp.dll in rundll32 processes.

    reads hb_module_activitysql
    SELECT device_hostname, process_name, module_name, module_path, time FROM hb_module_activity WHERE LOWER(module_name) = 'dbghelp.dll' AND LOWER(process_name) LIKE '%rundll32.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Instances of rundll32 loading dbghelp.dll. While legitimate, their combination in a transient process is an indicator of module stomping.

  3. Telegraph dead-drop resolution

    Query · triage

    Identify HTTP requests to the dead-drop pages used to resolve the C2 server IP.

    reads hb_http_activitysql
    SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE LOWER(url_hostname) = 'telegra.ph' AND (LOWER(url_path) LIKE '/functions-%' OR LOWER(url_path) LIKE '/getwell%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. HTTP requests to specific URIs on telegra.ph. Silence proving the dead-drop has not been accessed using these known paths.

  4. Triage the early infection

    Agent triage

    Evaluate whether the combination of module loading and network patterns confirms a beachhead.

  5. Cryptocurrency wallet and credential access

    Query · baseline

    Find unusual processes accessing wallet directories or browser data.

    reads hb_file_activitysql
    SELECT device_hostname, process_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_access FROM hb_file_activity WHERE (instr(LOWER(file_path), 'wallets') > 0 OR instr(LOWER(file_path), 'atomic') > 0 OR instr(LOWER(file_path), 'exodus') > 0 OR LOWER(file_name) = 'login data') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_path HAVING access_count < 50

    What a hit looks like. Unusual processes reading wallet files. Stack-counting helps isolate theft from normal browser updates.

  6. ZigCrypto and NetSupport activity

    Query · detection candidate

    Detect secondary tools deployed by the Amatera loader, such as NetSupport Manager or sideloaded modules.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE (instr(',' || '{{secondary_payload_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{secondary_payload_names}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '%\users\public\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. NetSupport (client32.exe) or sideloaded ZigCrypto components running from user-writable paths. Absence suggests secondary payloads have not yet been deployed.

  7. Triage the full infection lifecycle

    Agent triage

    Consolidate the early beachhead with evidence of impact and follow-on payloads.

  8. Route on final verdict

    Decision

    Route confirmed intrusions to containment.

  9. Isolate host

    Response action

    Prevent exfiltration by isolating infected endpoints.

  10. Analyst review

    Analyst task

    Manually verify the agent's findings and collect forensic artifacts.

  11. Close out

    Analyst task

    Finalize the hunt and record tuning notes.

Coverage

Scenario coverage

StageCoveredHow, or why not
DLL Hollowing and VEH Unpacking
T1574.002
Yes loader-hollowing-dbghelp
Amatera Dead Drop C2 Resolution Yes telegraph-c2-resolution
Credential and Wallet Collection
T1555 · T1115
Yes cryptocurrency-wallet-access
Secondary Payload Installation
T1574.002 · T1059.001
Yes secondary-payload-activity
EtherHiding via BNB Smart Chain
T1059.001
Out of scope Belongs to another part of the 'ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.
ClickFix Fake CAPTCHA Overlay Out of scope Belongs to another part of the 'ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.
WebDAV DLL Execution
T1218.011
Out of scope Belongs to another part of the 'ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.

Blind spots

  • Needs endpoint agent on all devices. A host without the hb_module_activity surface cannot be assessed for DLL hollowing, leading to false negatives. It would answer whether the module stomping occurred on unmanaged hosts.
  • Needs memory scanning. Amatera is memory-resident; a negative result on hb_file_activity does not prove the absence of the stealer if it was never written to disk. It would answer the presence of the final Amatera payload.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
c2_domainslist[domain]telegra.ph, leaguejazire.com, riyazinikokar.xyz, verification.google, pf.chDomains used for dead-drop resolution and command-and-control.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Optional list of hostnames to focus the hunt; leave empty to scan the entire estate.
secondary_payload_nameslist[string]client32.exe, secur32.dllProcess and module names associated with secondary payloads.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: 'A single rule on telegra.ph resolution is too noisy. This hunt uses a phased
  approach: scoping by infrastructure, corroborating via memory-evasion indicators
  (module activity), and confirming via behavioral theft patterns (file activity).
  Only the agent''s consolidated read provides high-confidence confirmation.'
blind_spots:
- id: incomplete-telemetry
  question: whether the module stomping occurred on unmanaged hosts
  requires: endpoint agent on all devices
  risk: A host without the hb_module_activity surface cannot be assessed for DLL hollowing,
    leading to false negatives.
  stage: stealthy-loader-evasion
- id: memory-resident-evasion
  question: the presence of the final Amatera payload
  requires: memory scanning
  risk: Amatera is memory-resident; a negative result on hb_file_activity does not
    prove the absence of the stealer if it was never written to disk.
  stage: stealthy-loader-evasion
coverage:
- stage: stealthy-loader-evasion
  status: covered
  steps:
  - loader-hollowing-dbghelp
- stage: amatera-c2-resolution
  status: covered
  steps:
  - telegraph-c2-resolution
- stage: credential-and-crypto-theft
  status: covered
  steps:
  - cryptocurrency-wallet-access
- stage: secondary-payload-deployment
  status: covered
  steps:
  - secondary-payload-activity
- reason: Belongs to another part of the 'ClearFake WebDAV infection chain delivers
    Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.
  stage: clearfake-etherhiding-delivery
  status: out_of_scope
- reason: Belongs to another part of the 'ClearFake WebDAV infection chain delivers
    Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.
  stage: clickfix-social-engineering
  status: out_of_scope
- reason: Belongs to another part of the 'ClearFake WebDAV infection chain delivers
    Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.
  stage: webdav-rundll32-execution
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: Amatera targets high-value cryptocurrency and identity assets. Its
    use of module stomping and dead-drop resolution makes traditional rule-based detection
    difficult. A phased hunt that correlates early infection with follow-on theft
    is necessary to confirm the full intrusion chain.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder has deployed the Amatera stealer, characterized by DLL hollowing
  of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for
  cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.
labels:
- hunt
- attack.t1574.002
- attack.t1059.001
- attack.t1555
- attack.t1115
- attack.t1218.011
name: Amatera Stealer and Follow-on Payloads
parameters:
  c2_domains:
    default:
    - telegra.ph
    - leaguejazire.com
    - riyazinikokar.xyz
    - verification.google
    - pf.ch
    description: Domains used for dead-drop resolution and command-and-control.
    from:
      kind: article
      observed: '2026-09-08'
      ref: talos
    type: list[domain]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: manual
      observed: '2026-09-08'
      ref: default
    type: number
  scope_hosts:
    default: []
    description: Optional list of hostnames to focus the hunt; leave empty to scan
      the entire estate.
    from:
      kind: manual
      observed: '2026-09-08'
      ref: default
    type: list[host]
  secondary_payload_names:
    default:
    - client32.exe
    - secur32.dll
    description: Process and module names associated with secondary payloads.
    from:
      kind: article
      observed: '2026-09-08'
      ref: talos
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: The hunt should start with endpoints communicating with telegra.ph. If
  no matches are found, broaden the scope to servers and workstations running rundll32.exe
  with unusually high module activity.
references:
- name: "Talos \u2014 ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer,\
    \ and NetSupport Manager"
  url: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
related:
- hunt: webdav-rundll32-execution
  reason: The initial delivery mechanism (WebDAV UNC paths and rundll32 ordinals)
    is handled by a separate hunt focused on delivery.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: EtherHiding via BNB Smart Chain
    observables:
    - bsc-testnet-rpc.publicnode.com
    - '0x886d310Ac23e05EA705e24E513D19f53793832A9'
    - '0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff'
    - '0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5'
    slug: clearfake-etherhiding-delivery
    tactic: initial-access
    techniques:
    - T1059.001
  - name: ClickFix Fake CAPTCHA Overlay
    observables:
    - cjs_id cookie
    - Fake Google CAPTCHA UI
    - Run dialog clipboard paste prompt
    slug: clickfix-social-engineering
    tactic: execution
  - name: WebDAV DLL Execution
    observables:
    - rundll32.exe
    - leaguejazire.com
    - pf.ch
    - verification.google
    - 'ordinal #1'
    - WebClient service start
    slug: webdav-rundll32-execution
    tactic: execution
    techniques:
    - T1218.011
  - name: DLL Hollowing and VEH Unpacking
    observables:
    - dbghelp.dll module hollowing
    - Vectored Exception Handling (VEH)
    - LZNT1 decoding
    - WoW64 syscall stubs
    - TpAllocWork function callback
    slug: stealthy-loader-evasion
    tactic: defense-evasion
    techniques:
    - T1574.002
  - name: Amatera Dead Drop C2 Resolution
    observables:
    - telegra.ph/Functions-04-03
    - 145.249.109.147
    - GETWELLV2 string
    - Auxiliary Function Driver (AFD) socket
    slug: amatera-c2-resolution
    tactic: command-and-control
  - name: Credential and Wallet Collection
    observables:
    - Browser credential store access
    - Cryptocurrency wallet directory scanning
    - Clipboard monitoring
    slug: credential-and-crypto-theft
    tactic: credential-access
    techniques:
    - T1555
    - T1115
  - name: Secondary Payload Installation
    observables:
    - secur32.dll sideloading
    - NetSupport Manager
    - ZigCryptoStealer
    - riyazinikokar.xyz
    slug: secondary-payload-deployment
    tactic: persistence
    techniques:
    - T1574.002
    - T1059.001
  summary: The ClearFake campaign utilizes EtherHiding via BNB Smart Chain and social
    engineering through fake Google CAPTCHA overlays to trick users into executing
    malicious commands. These commands trigger a WebDAV-based DLL execution via rundll32.exe,
    deploying the Amatera stealer which subsequently installs secondary payloads like
    ZigCryptoStealer and NetSupport Manager.
series:
  index: 2
  slug: clearfake-webdav-infection-chain-delivers-amatera-stealer-zigcryptostealer-and-netsupport-manage
  title: ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer,
    and NetSupport Manager
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Amatera Stealer and Follow-on Payloads

This hunt identifies the post-infection lifecycle of the Amatera stealer, focusing on its specific evasion and persistence techniques. Amatera often employs module stomping (DLL hollowing) in dbghelp.dll to hide its memory-resident payload and resolves its C2 server via encoded strings on Telegraph pages. Once established, the stealer scans the host for browser credentials and cryptocurrency wallet directories. The hunt uses a phased approach: first scoping the estate for early infection signals, then pivoting to identify evidence of theft and the deployment of secondary payloads like NetSupport Manager or ZigCryptoStealer.

## scope-hosts-by-dns
<!-- Scope hosts by known C2 DNS traffic -->
Identify endpoints that have resolved the reported C2 or dead-drop domains to focus the search.

```sqlite target=endpoint role=scoping params=(c2_domains=c2_domains, lookback_days=lookback_days)
~~~yaml
expected: A list of hostnames communicating with reported infrastructure. Silence
  suggests the C2 is not currently active via these domains.
reads:
- device_hostname
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT DISTINCT device_hostname FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## parallel-early-infection
<!-- Parallel hunt for early infection stages -->
parallel:
- → loader-hollowing-dbghelp
- → telegraph-c2-resolution
join: → agent-early-triage

## loader-hollowing-dbghelp
<!-- DLL hollowing of dbghelp.dll -->
Detect the overwriting of legitimate modules, specifically targeting dbghelp.dll in rundll32 processes.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Instances of rundll32 loading dbghelp.dll. While legitimate, their combination
  in a transient process is an indicator of module stomping.
reads:
- device_hostname
- process_name
- module_name
- module_path
- time
silence: not_evidence_of_absence
source: hb_module_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, module_name, module_path, time FROM hb_module_activity WHERE LOWER(module_name) = 'dbghelp.dll' AND LOWER(process_name) LIKE '%rundll32.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## telegraph-c2-resolution
<!-- Telegraph dead-drop resolution -->
Identify HTTP requests to the dead-drop pages used to resolve the C2 server IP.

```sqlite target=web role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: HTTP requests to specific URIs on telegra.ph. Silence proving the dead-drop
  has not been accessed using these known paths.
reads:
- device_hostname
- url_hostname
- url_path
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE LOWER(url_hostname) = 'telegra.ph' AND (LOWER(url_path) LIKE '/functions-%' OR LOWER(url_path) LIKE '/getwell%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## agent-early-triage
<!-- Triage the early infection -->
```agent target=hunter
cite: required
context:
- loader-hollowing-dbghelp
- telegraph-c2-resolution
max_iterations: 3
objective: Determine which hosts show early Amatera behavior, specifically the hollowing
  of dbghelp.dll or Telegraph C2 resolution.
success_criteria: A list of hosts with confirmed or suspicious loader presence.
tools:
- endpoint
- web
```

## parallel-follow-on
<!-- Hunt for theft and impact -->
parallel:
- → cryptocurrency-wallet-access
- → secondary-payload-activity
join: → agent-follow-on-triage

## cryptocurrency-wallet-access
<!-- Cryptocurrency wallet and credential access -->
Find unusual processes accessing wallet directories or browser data.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Unusual processes reading wallet files. Stack-counting helps isolate theft
  from normal browser updates.
prevalence:
  by: device_hostname
  key:
  - file_path
  rare_below: 3
reads:
- device_hostname
- process_name
- file_path
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_access FROM hb_file_activity WHERE (instr(LOWER(file_path), 'wallets') > 0 OR instr(LOWER(file_path), 'atomic') > 0 OR instr(LOWER(file_path), 'exodus') > 0 OR LOWER(file_name) = 'login data') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_path HAVING access_count < 50
```

## secondary-payload-activity
<!-- ZigCrypto and NetSupport activity -->
Detect secondary tools deployed by the Amatera loader, such as NetSupport Manager or sideloaded modules.

```sqlite target=endpoint role=detection-candidate params=(secondary_payload_names=secondary_payload_names, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: NetSupport (client32.exe) or sideloaded ZigCrypto components running from
  user-writable paths. Absence suggests secondary payloads have not yet been deployed.
reads:
- device_hostname
- process_name
- process_cmd_line
- parent_process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE (instr(',' || '{{secondary_payload_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{secondary_payload_names}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '%\users\public\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## agent-follow-on-triage
<!-- Triage the full infection lifecycle -->
```agent target=hunter
cite: required
context:
- agent-early-triage
- cryptocurrency-wallet-access
- secondary-payload-activity
max_iterations: 4
objective: 'Determine if any host shows the complete lifecycle of Amatera: loader
  mechanics, C2 resolution, wallet access, and secondary payload deployment.'
success_criteria: A per-host verdict citing specific rows from all behavioral surfaces.
tools:
- endpoint
- web
```

## decision-route
<!-- Route on final verdict -->
if~: "the agent-follow-on-triage verdict is malicious or suspicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: incomplete-telemetry)
else: → close-out

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host identified by the agent and block all traffic to 145.249.109.147.
```
→ analyst-review

## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the cited module activity for dbghelp.dll hollowing and verify the process tree of any wallet access events.
```
→ close-out

## close-out
<!-- Close out -->
```manual target=analyst
Summarize findings and document any observed secondary payload paths for detection engineering.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.