{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Amatera targets high-value cryptocurrency and identity assets. Its use of module stomping and dead-drop resolution makes traditional rule-based detection difficult. A phased hunt that correlates early infection with follow-on theft is necessary to confirm the full intrusion chain."
      },
      "name": "Amatera Stealer and Follow-on Payloads",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1574.002",
        "attack.t1059.001",
        "attack.t1555",
        "attack.t1115",
        "attack.t1218.011"
      ],
      "series": {
        "slug": "clearfake-webdav-infection-chain-delivers-amatera-stealer-zigcryptostealer-and-netsupport-manage",
        "index": 2,
        "title": "ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager",
        "total": 2
      },
      "related": [
        {
          "hunt": "webdav-rundll32-execution",
          "reason": "The initial delivery mechanism (WebDAV UNC paths and rundll32 ordinals) is handled by a separate hunt focused on delivery.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule on telegra.ph resolution is too noisy. This hunt uses a phased approach: scoping by infrastructure, corroborating via memory-evasion indicators (module activity), and confirming via behavioral theft patterns (file activity). Only the agent's consolidated read provides high-confidence confirmation.",
      "coverage": [
        {
          "stage": "stealthy-loader-evasion",
          "steps": [
            "loader-hollowing-dbghelp"
          ],
          "status": "covered"
        },
        {
          "stage": "amatera-c2-resolution",
          "steps": [
            "telegraph-c2-resolution"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-and-crypto-theft",
          "steps": [
            "cryptocurrency-wallet-access"
          ],
          "status": "covered"
        },
        {
          "stage": "secondary-payload-deployment",
          "steps": [
            "secondary-payload-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "clearfake-etherhiding-delivery",
          "reason": "Belongs to another part of the 'ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "clickfix-social-engineering",
          "reason": "Belongs to another part of the 'ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "webdav-rundll32-execution",
          "reason": "Belongs to another part of the 'ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "EtherHiding via BNB Smart Chain",
            "slug": "clearfake-etherhiding-delivery",
            "tactic": "initial-access",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "bsc-testnet-rpc.publicnode.com",
              "0x886d310Ac23e05EA705e24E513D19f53793832A9",
              "0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff",
              "0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5"
            ]
          },
          {
            "name": "ClickFix Fake CAPTCHA Overlay",
            "slug": "clickfix-social-engineering",
            "tactic": "execution",
            "observables": [
              "cjs_id cookie",
              "Fake Google CAPTCHA UI",
              "Run dialog clipboard paste prompt"
            ]
          },
          {
            "name": "WebDAV DLL Execution",
            "slug": "webdav-rundll32-execution",
            "tactic": "execution",
            "techniques": [
              "T1218.011"
            ],
            "observables": [
              "rundll32.exe",
              "leaguejazire.com",
              "pf.ch",
              "verification.google",
              "ordinal #1",
              "WebClient service start"
            ]
          },
          {
            "name": "DLL Hollowing and VEH Unpacking",
            "slug": "stealthy-loader-evasion",
            "tactic": "defense-evasion",
            "techniques": [
              "T1574.002"
            ],
            "observables": [
              "dbghelp.dll module hollowing",
              "Vectored Exception Handling (VEH)",
              "LZNT1 decoding",
              "WoW64 syscall stubs",
              "TpAllocWork function callback"
            ]
          },
          {
            "name": "Amatera Dead Drop C2 Resolution",
            "slug": "amatera-c2-resolution",
            "tactic": "command-and-control",
            "observables": [
              "telegra.ph/Functions-04-03",
              "145.249.109.147",
              "GETWELLV2 string",
              "Auxiliary Function Driver (AFD) socket"
            ]
          },
          {
            "name": "Credential and Wallet Collection",
            "slug": "credential-and-crypto-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1555",
              "T1115"
            ],
            "observables": [
              "Browser credential store access",
              "Cryptocurrency wallet directory scanning",
              "Clipboard monitoring"
            ]
          },
          {
            "name": "Secondary Payload Installation",
            "slug": "secondary-payload-deployment",
            "tactic": "persistence",
            "techniques": [
              "T1574.002",
              "T1059.001"
            ],
            "observables": [
              "secur32.dll sideloading",
              "NetSupport Manager",
              "ZigCryptoStealer",
              "riyazinikokar.xyz"
            ]
          }
        ],
        "summary": "The ClearFake campaign utilizes EtherHiding via BNB Smart Chain and social engineering through fake Google CAPTCHA overlays to trick users into executing malicious commands. These commands trigger a WebDAV-based DLL execution via rundll32.exe, deploying the Amatera stealer which subsequently installs secondary payloads like ZigCryptoStealer and NetSupport Manager."
      },
      "severity": "high",
      "rationale": "The hunt should start with endpoints communicating with telegra.ph. If no matches are found, broaden the scope to servers and workstations running rundll32.exe with unusually high module activity.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.",
      "parameters": {
        "c2_domains": {
          "from": {
            "ref": "talos",
            "kind": "article",
            "observed": "2026-09-08"
          },
          "type": "list[domain]",
          "default": [
            "telegra.ph",
            "leaguejazire.com",
            "riyazinikokar.xyz",
            "verification.google",
            "pf.ch"
          ],
          "description": "Domains used for dead-drop resolution and command-and-control."
        },
        "scope_hosts": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-09-08"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus the hunt; leave empty to scan the entire estate."
        },
        "lookback_days": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-09-08"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "secondary_payload_names": {
          "from": {
            "ref": "talos",
            "kind": "article",
            "observed": "2026-09-08"
          },
          "type": "list[string]",
          "default": [
            "client32.exe",
            "secur32.dll"
          ],
          "description": "Process and module names associated with secondary payloads."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/clearfake-webdav-infection-chain/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/clearfake-webdav-infection-chain/",
          "name": "Talos \u2014 ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager"
        }
      ],
      "blind_spots": [
        {
          "id": "incomplete-telemetry",
          "risk": "A host without the hb_module_activity surface cannot be assessed for DLL hollowing, leading to false negatives.",
          "stage": "stealthy-loader-evasion",
          "question": "whether the module stomping occurred on unmanaged hosts",
          "requires": "endpoint agent on all devices"
        },
        {
          "id": "memory-resident-evasion",
          "risk": "Amatera is memory-resident; a negative result on hb_file_activity does not prove the absence of the stealer if it was never written to disk.",
          "stage": "stealthy-loader-evasion",
          "question": "the presence of the final Amatera payload",
          "requires": "memory scanning"
        }
      ]
    },
    "name": "Amatera Stealer and Follow-on Payloads",
    "description": "This hunt identifies the post-infection lifecycle of the Amatera stealer, focusing on its specific evasion and persistence techniques. Amatera often employs module stomping (DLL hollowing) in dbghelp.dll to hide its memory-resident payload and resolves its C2 server via encoded strings on Telegraph pages. Once established, the stealer scans the host for browser credentials and cryptocurrency wallet directories. The hunt uses a phased approach: first scoping the estate for early infection signals, then pivoting to identify evidence of theft and the deployment of secondary payloads like NetSupport Manager or ZigCryptoStealer."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "clearfake-webdav-infection-chain-delivers-amatera-stealer-zigcryptostealer-and-netsupport-manage",
          "index": 2,
          "title": "ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager",
          "total": 2
        },
        "coverage": [
          {
            "stage": "stealthy-loader-evasion",
            "steps": [
              "loader-hollowing-dbghelp"
            ],
            "status": "covered"
          },
          {
            "stage": "amatera-c2-resolution",
            "steps": [
              "telegraph-c2-resolution"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-and-crypto-theft",
            "steps": [
              "cryptocurrency-wallet-access"
            ],
            "status": "covered"
          },
          {
            "stage": "secondary-payload-deployment",
            "steps": [
              "secondary-payload-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "clearfake-etherhiding-delivery",
            "reason": "Belongs to another part of the 'ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "clickfix-social-engineering",
            "reason": "Belongs to another part of the 'ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "webdav-rundll32-execution",
            "reason": "Belongs to another part of the 'ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.",
        "blind_spots": [
          {
            "id": "incomplete-telemetry",
            "risk": "A host without the hb_module_activity surface cannot be assessed for DLL hollowing, leading to false negatives.",
            "stage": "stealthy-loader-evasion",
            "question": "whether the module stomping occurred on unmanaged hosts",
            "requires": "endpoint agent on all devices"
          },
          {
            "id": "memory-resident-evasion",
            "risk": "Amatera is memory-resident; a negative result on hb_file_activity does not prove the absence of the stealer if it was never written to disk.",
            "stage": "stealthy-loader-evasion",
            "question": "the presence of the final Amatera payload",
            "requires": "memory scanning"
          }
        ],
        "scoping_notes": "The hunt should start with endpoints communicating with telegra.ph. If no matches are found, broaden the scope to servers and workstations running rundll32.exe with unusually high module activity.",
        "beyond_detection": "A single rule on telegra.ph resolution is too noisy. This hunt uses a phased approach: scoping by infrastructure, corroborating via memory-evasion indicators (module activity), and confirming via behavioral theft patterns (file activity). Only the agent's consolidated read provides high-confidence confirmation."
      }
    },
    {
      "id": "scope-hosts-by-dns",
      "type": "query",
      "label": "Scope hosts by known C2 DNS traffic",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Identify endpoints that have resolved the reported C2 or dead-drop domains to focus the search.",
        "expected_signal": "A list of hostnames communicating with reported infrastructure. Silence suggests the C2 is not currently active via these domains."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope hosts by known C2 DNS traffic",
        "reads": [
          "device_hostname",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames communicating with reported infrastructure. Silence suggests the C2 is not currently active via these domains.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "loader-hollowing-dbghelp",
      "type": "query",
      "label": "DLL hollowing of dbghelp.dll",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, module_name, module_path, time FROM hb_module_activity WHERE LOWER(module_name) = 'dbghelp.dll' AND LOWER(process_name) LIKE '%rundll32.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_module_activity",
        "description": "Detect the overwriting of legitimate modules, specifically targeting dbghelp.dll in rundll32 processes.",
        "expected_signal": "Instances of rundll32 loading dbghelp.dll. While legitimate, their combination in a transient process is an indicator of module stomping."
      },
      "parents": [
        {
          "id": "scope-hosts-by-dns"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "DLL hollowing of dbghelp.dll",
        "reads": [
          "device_hostname",
          "process_name",
          "module_name",
          "module_path",
          "time"
        ],
        "source": "hb_module_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, module_name, module_path, time FROM hb_module_activity WHERE LOWER(module_name) = 'dbghelp.dll' AND LOWER(process_name) LIKE '%rundll32.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Instances of rundll32 loading dbghelp.dll. While legitimate, their combination in a transient process is an indicator of module stomping.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "telegraph-c2-resolution",
      "type": "query",
      "label": "Telegraph dead-drop resolution",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE LOWER(url_hostname) = 'telegra.ph' AND (LOWER(url_path) LIKE '/functions-%' OR LOWER(url_path) LIKE '/getwell%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Identify HTTP requests to the dead-drop pages used to resolve the C2 server IP.",
        "expected_signal": "HTTP requests to specific URIs on telegra.ph. Silence proving the dead-drop has not been accessed using these known paths."
      },
      "parents": [
        {
          "id": "scope-hosts-by-dns"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Telegraph dead-drop resolution",
        "reads": [
          "device_hostname",
          "url_hostname",
          "url_path",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE LOWER(url_hostname) = 'telegra.ph' AND (LOWER(url_path) LIKE '/functions-%' OR LOWER(url_path) LIKE '/getwell%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "HTTP requests to specific URIs on telegra.ph. Silence proving the dead-drop has not been accessed using these known paths.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-early-triage",
      "type": "analytic",
      "label": "Triage the early infection",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "loader-hollowing-dbghelp",
          "telegraph-c2-resolution"
        ],
        "objective": "Determine which hosts show early Amatera behavior, specifically the hollowing of dbghelp.dll or Telegraph C2 resolution.",
        "description": "Evaluate whether the combination of module loading and network patterns confirms a beachhead.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict on early-stage infection likelihood.",
        "success_criteria": "A list of hosts with confirmed or suspicious loader presence."
      },
      "parents": [
        {
          "id": "loader-hollowing-dbghelp",
          "kind": "merge"
        },
        {
          "id": "telegraph-c2-resolution",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "cryptocurrency-wallet-access",
      "type": "query",
      "label": "Cryptocurrency wallet and credential access",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_access FROM hb_file_activity WHERE (instr(LOWER(file_path), 'wallets') > 0 OR instr(LOWER(file_path), 'atomic') > 0 OR instr(LOWER(file_path), 'exodus') > 0 OR LOWER(file_name) = 'login data') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_path HAVING access_count < 50",
        "surface": "hb_file_activity",
        "description": "Find unusual processes accessing wallet directories or browser data.",
        "expected_signal": "Unusual processes reading wallet files. Stack-counting helps isolate theft from normal browser updates."
      },
      "parents": [
        {
          "id": "agent-early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Cryptocurrency wallet and credential access",
        "reads": [
          "device_hostname",
          "process_name",
          "file_path",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_access FROM hb_file_activity WHERE (instr(LOWER(file_path), 'wallets') > 0 OR instr(LOWER(file_path), 'atomic') > 0 OR instr(LOWER(file_path), 'exodus') > 0 OR LOWER(file_name) = 'login data') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_path HAVING access_count < 50",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Unusual processes reading wallet files. Stack-counting helps isolate theft from normal browser updates.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "file_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "secondary-payload-activity",
      "type": "query",
      "label": "ZigCrypto and NetSupport activity",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE (instr(',' || '{{secondary_payload_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{secondary_payload_names}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND (LOWER(process_path) LIKE '%\\appdata\\%' OR LOWER(process_path) LIKE '%\\users\\public\\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect secondary tools deployed by the Amatera loader, such as NetSupport Manager or sideloaded modules.",
        "expected_signal": "NetSupport (client32.exe) or sideloaded ZigCrypto components running from user-writable paths. Absence suggests secondary payloads have not yet been deployed."
      },
      "parents": [
        {
          "id": "agent-early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "ZigCrypto and NetSupport activity",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "parent_process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE (instr(',' || '{{secondary_payload_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{secondary_payload_names}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND (LOWER(process_path) LIKE '%\\appdata\\%' OR LOWER(process_path) LIKE '%\\users\\public\\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "NetSupport (client32.exe) or sideloaded ZigCrypto components running from user-writable paths. Absence suggests secondary payloads have not yet been deployed.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-follow-on-triage",
      "type": "analytic",
      "label": "Triage the full infection lifecycle",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "agent-early-triage",
          "cryptocurrency-wallet-access",
          "secondary-payload-activity"
        ],
        "objective": "Determine if any host shows the complete lifecycle of Amatera: loader mechanics, C2 resolution, wallet access, and secondary payload deployment.",
        "description": "Consolidate the early beachhead with evidence of impact and follow-on payloads.",
        "max_iterations": 4,
        "expected_signal": "A detailed assessment of the intrusion per host.",
        "success_criteria": "A per-host verdict citing specific rows from all behavioral surfaces."
      },
      "parents": [
        {
          "id": "cryptocurrency-wallet-access",
          "kind": "merge"
        },
        {
          "id": "secondary-payload-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "decision-route",
      "type": "checkpoint",
      "label": "Route on final verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the agent-follow-on-triage verdict is malicious or suspicious for at least one host",
        "condition": "the agent-follow-on-triage verdict is malicious or suspicious for at least one host",
        "blind_spot": "incomplete-telemetry",
        "confidence": "high",
        "description": "Route confirmed intrusions to containment.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-follow-on-triage"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Prevent exfiltration by isolating infected endpoints.",
        "instructions": "Isolate the host identified by the agent and block all traffic to 145.249.109.147.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "decision-route",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Manually verify the agent's findings and collect forensic artifacts.",
        "instructions": "Review the cited module activity for dbghelp.dll hollowing and verify the process tree of any wallet access events."
      },
      "parents": [
        {
          "id": "decision-route",
          "branch": "default"
        },
        {
          "id": "decision-route",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record tuning notes.",
        "instructions": "Summarize findings and document any observed secondary payload paths for detection engineering."
      },
      "parents": [
        {
          "id": "decision-route",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}