← All hunts high TLP:CLEAR Part 1 of 3

Bumblebee Delivery and C2 Establishment

An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.

Based on research by The DFIR Report 2026-09-29 12 steps · 4 queries T1055 T1071.001 T1189 T1204.002 T1568.002 T1574.002 T1583.008

Brief

Why this hunt

The DFIR Report recently detailed a campaign where Bing search results led directly to Akira ransomware in their article, From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira. The intrusion begins with a trojanized ManageEngine installer delivered via SEO poisoning. This hunt focuses on identifying the early stages of this infection: the initial web redirection and the side-loading execution on the endpoint.

How the hunt flows

The first step in this hunt is identifying the entry point. The hunt searches DNS telemetry for resolutions to domains known to host the malicious redirection infrastructure. The adversary uses domains like opmanager.pro and download-center.online to trick users who are searching for legitimate administrative software. By starting with these high-fidelity leads, the hunt narrows the scope of the investigation from the entire fleet to only those hosts that have interacted with the reported delivery mechanism.

Once the hunt confirms a DNS lead, it pivots to endpoint process activity. It looks for instances of the legitimate Windows binary consent.exe executing from user-writable directories. In the Bumblebee campaign, the adversary side-loads their loader by placing a malicious DLL alongside this system binary in folders within the AppData or Temp paths. Seeing a system binary like consent.exe run from anywhere other than C:\Windows\System32 is a strong indicator of this side-loading technique.

In parallel, the hunt performs frequency analysis on all binaries running from these same user-writable paths. By stacking these processes across the environment, the hunt highlights rare binaries that may be unique to the infection. This captures the dropped Bumblebee loader or the renamed Address Book utility, often seen as AdgNsy.exe, which the adversary uses for shellcode injection.

The final phase correlates these execution leads with network telemetry. It looks for outbound connections to known AdaptixC2 infrastructure or traffic originating from the suspicious processes identified in the previous steps. This multi-surface pivot provides the context necessary to distinguish a standard software installation from an active intrusion.

What the hunt cannot see

Visibility relies heavily on telemetry retention and path-aware auditing. If DNS logs do not cover the initial redirection window, the hunt misses the entry point. If process monitoring does not capture the full execution path for system binaries, the side-loading of consent.exe from AppData appears as a legitimate system process. The hunt also cannot see the initial search query on the search engine, only the resulting domain resolution.

In this series

Steps

  1. Lead: DNS lookups to SEO look-alike domains

    Query · scoping

    Identify hosts that interacted with the reported SEO poisoning infrastructure to narrow the hunt scope.

    reads hb_dns_activitysql
    SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{seo_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A host resolving one of the lookalike domains. Silence means no recorded interaction with the known delivery infrastructure.

  2. Examine DNS lead

    Agent triage

    Evaluate if the DNS activity suggests a user was redirected to the malicious infrastructure.

  3. Decide to proceed with deeper investigation

    Decision

    Avoid expensive host-wide queries if no initial lead is found.

  4. Detect side-loading of consent.exe from AppData or Temp

    Query · detection candidate

    Identify the execution of a legitimate Windows binary from a non-standard, user-writable path.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(process_name) LIKE '%\consent.exe' AND (LOWER(process_name) LIKE '%\appdata\%' OR LOWER(process_name) LIKE '%\temp\%') AND LOWER(process_name) NOT LIKE 'c:\windows\system32\%' AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A row showing consent.exe executing from a folder like ApplicationInstallationFolder_11 under AppData.

  5. Rare binaries in AppData or Temp

    Query · baseline

    Stack-count processes running from user-writable paths to find rare Bumblebee-related binaries like AdgNsy.exe or dropped loaders.

    reads hb_process_activitysql
    SELECT LOWER(process_name) AS name, LOWER(process_path) AS path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '%\temp\%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY name, path HAVING hosts <= 3 ORDER BY hosts ASC

    What a hit looks like. A process seen on only one or two hosts in the fleet, specifically targeting user-writable directories.

  6. Detect AdaptixC2 and Bumblebee C2 traffic

    Query · enrichment

    Corroborate the execution lead with network traffic to known malicious IPs or from the injected Address Book process.

    reads hb_network_connectionsql
    SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR LOWER(process_name) LIKE '%\adgnsy.exe') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Network connections to reported Azure C2 IPs or outbound traffic from AdgNsy.exe.

  7. Final infection triage

    Agent triage

    Correlate the DNS visit, the side-loading execution, and the C2 callback to provide a high-confidence verdict.

  8. Route based on infection verdict

    Decision

    Contain confirmed infections or escalate for review.

  9. Isolate infected host

    Response action

    Contain the Bumblebee beachhead to prevent ransomware deployment.

  10. Analyst review

    Analyst task

    Resolve indeterminate verdicts and verify findings.

  11. Close out

    Analyst task

    Document findings and visibility gaps.

Coverage

Scenario coverage

StageCoveredHow, or why not
SEO Poisoning Redirection
T1189 · T1583.008
Yes lead-dns-lookups
Bumblebee DLL Side-Loading
T1204.002 · T1574.002
Yes detect-sideloading, rare-binaries-in-user-paths
AdaptixC2 Infrastructure Setup
T1071.001 · T1568.002 · T1055
Yes detect-c2-activity
Internal Reconnaissance and Persistence
T1082 · T1016 · T1136.002 · T1543.003
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.
SSH Tunneling and RDP Pivot
T1021.001 · T1572
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.
Active Directory and Veeam Credential Harvesting
T1003.003 · T1003.001 · T1552.004
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.
Data Exfiltration via SFTP
T1048.003 · T1020
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.
Akira Ransomware Impact
T1486 · T1490 · T1047
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.

Blind spots

  • Needs long-term hb_dns_activity logs. A host infected weeks ago would be missed if the redirection event is no longer in the logs. It would answer whether a host visited the malicious domains outside the current retention window.
  • Needs endpoint auditing of System32 binaries running from user-writable paths. Without path-aware process auditing, the side-loading of msimg32.dll goes unobserved. It would answer whether consent.exe was executed from a non-standard path.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
c2_ipslist[ip]84.32.84.32, 4.239.95.1Known C2 and staging IPs associated with this Bumblebee/Adaptix wave.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—List of hostnames to narrow the expensive fan-out queries; populate from the lead query results.
seo_domainslist[domain]opmanager.pro, download-center.online, ip-scanner.org, download-server.online, soft-server.online, soft-hub.pro, zenmap.pro, netml.shopLook-alike and delivery domains identified in the Bumblebee campaign.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Network telemetrynetworknetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: This hunt pivots across three telemetry surfaces (DNS, Process, and Network)
  to connect a user's web activity to an execution anomaly and subsequent C2 callout,
  providing the full context needed to differentiate an admin performing a legitimate
  install from an intruder using a trojanized decoy.
blind_spots:
- id: no-dns-retention
  question: whether a host visited the malicious domains outside the current retention
    window
  requires: long-term hb_dns_activity logs
  risk: A host infected weeks ago would be missed if the redirection event is no longer
    in the logs.
  stage: initial-access-seo-redirection
- id: no-process-visibility
  question: whether consent.exe was executed from a non-standard path
  requires: endpoint auditing of System32 binaries running from user-writable paths
  risk: Without path-aware process auditing, the side-loading of msimg32.dll goes
    unobserved.
  stage: execution-dll-side-loading
coverage:
- stage: initial-access-seo-redirection
  status: covered
  steps:
  - lead-dns-lookups
- stage: execution-dll-side-loading
  status: covered
  steps:
  - detect-sideloading
  - rare-binaries-in-user-paths
- stage: c2-establishment-adaptix
  status: covered
  steps:
  - detect-c2-activity
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: internal-discovery-and-persistence
  status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: lateral-movement-tunneling
  status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: credential-access-harvesting
  status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: data-exfiltration-sftp
  status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: impact-ransomware-encryption
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Bumblebee is a high-confidence precursor to Akira ransomware; identifying
    it at the delivery and C2 stage prevents catastrophic data exfiltration and encryption.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder has lured an administrator to a look-alike download page via
  SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe
  and establishes AdaptixC2.
labels:
- hunt
- attack.t1189
- attack.t1583.008
- attack.t1204.002
- attack.t1574.002
- attack.t1071.001
- attack.t1568.002
- attack.t1055
- command and control
- credential access
- discovery
- execution
- exfiltration
- impact
- initial access
- lateral movement
name: Bumblebee Delivery and C2 Establishment
parameters:
  c2_ips:
    default:
    - 84.32.84.32
    - 4.239.95.1
    description: Known C2 and staging IPs associated with this Bumblebee/Adaptix wave.
    from:
      kind: article
      observed: '2025-07-01'
      ref: https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
    type: list[ip]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: List of hostnames to narrow the expensive fan-out queries; populate
      from the lead query results.
    type: list[host]
  seo_domains:
    default:
    - opmanager.pro
    - download-center.online
    - ip-scanner.org
    - download-server.online
    - soft-server.online
    - soft-hub.pro
    - zenmap.pro
    - netml.shop
    description: Look-alike and delivery domains identified in the Bumblebee campaign.
    from:
      kind: article
      observed: '2025-07-01'
      ref: https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
    type: list[domain]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Focus on high-privileged IT administrator workstations and management servers,
  as these are the primary targets for ManageEngine look-alike decoys.
references:
- name: "The DFIR Report \u2014 From Bing Search to Ransomware: Bumblebee and AdaptixC2\
    \ Deliver Akira"
  url: https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
related:
- hunt: bumblebee-discovery-and-persistence
  reason: Once established, Bumblebee performs discovery and installs RustDesk for
    persistence.
  relation: follows
scenario:
  stages:
  - name: SEO Poisoning Redirection
    observables:
    - opmanager.pro
    - download-center.online
    - ip-scanner.org
    - download-server.online
    - soft-server.online
    - soft-hub.pro
    - netml.shop
    - /Get?q=
    slug: initial-access-seo-redirection
    tactic: initial-access
    techniques:
    - T1189
    - T1583.008
  - name: Bumblebee DLL Side-Loading
    observables:
    - ManageEngine-OpManager.msi
    - consent.exe
    - msimg32.dll
    - '%TEMP%\ApplicationInstallationFolder_11'
    - ApplicationInstallationFolder_11
    slug: execution-dll-side-loading
    tactic: execution
    techniques:
    - T1204.002
    - T1574.002
  - name: AdaptixC2 Infrastructure Setup
    observables:
    - AdgNsy.exe
    - 4.239.95.1:8080
    - 84.32.84.32
    slug: c2-establishment-adaptix
    tactic: command-and-control
    techniques:
    - T1071.001
    - T1568.002
    - T1055
  - name: Internal Reconnaissance and Persistence
    observables:
    - systeminfo
    - nltest
    - RustDesk
    - Enterprise Admin accounts
    slug: internal-discovery-and-persistence
    tactic: discovery
    techniques:
    - T1082
    - T1016
    - T1136.002
    - T1543.003
  - name: SSH Tunneling and RDP Pivot
    observables:
    - reverse SSH tunnel
    - RDP proxy traffic
    slug: lateral-movement-tunneling
    tactic: lateral-movement
    techniques:
    - T1021.001
    - T1572
  - name: Active Directory and Veeam Credential Harvesting
    observables:
    - wbadmin.exe
    - ntds.dit
    - lsassy
    - Veeam credential dumping script
    slug: credential-access-harvesting
    tactic: credential-access
    techniques:
    - T1003.003
    - T1003.001
    - T1552.004
  - name: Data Exfiltration via SFTP
    observables:
    - FileZilla.exe
    - 75GB exfiltrated
    - Ukrainian IP space
    slug: data-exfiltration-sftp
    tactic: exfiltration
    techniques:
    - T1048.003
    - T1020
  - name: Akira Ransomware Impact
    observables:
    - locker.exe
    - delete Volume Shadow Copies
    - WMI
    slug: impact-ransomware-encryption
    tactic: impact
    techniques:
    - T1486
    - T1490
    - T1047
  summary: Threat actors utilized Bing SEO poisoning to deliver Bumblebee malware
    via trojanized software installers, leading to the deployment of AdaptixC2 for
    network discovery. The attackers leveraged RDP over SSH tunnels to move laterally
    and harvest credentials from NTDS.dit and LSASS before exfiltrating 75GB of data
    and deploying Akira ransomware.
series:
  index: 1
  slug: from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira
  title: 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira'
  total: 3
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
tlp: clear
type: investigation
---


# Bumblebee Delivery and C2 Establishment

The adversary lulls administrators into a false sense of security with high-fidelity lookalike download pages for tools like ManageEngine OpManager. This hunt first searches for the cheap lead: DNS lookups to known SEO-poisoned redirection infrastructure. If a lead is found, it fans out to examine host-level process anomalies: the legitimate Windows binary consent.exe executed from unusual user-writable paths like AppData or Temp, and the prevalence of rare binaries in those same paths. The hunt then corroborates these hits with network connections to AdaptixC2 infrastructure or traffic from the renamed Address Book utility used for shellcode injection.

## lead-dns-lookups
<!-- Lead: DNS lookups to SEO look-alike domains -->
Identify hosts that interacted with the reported SEO poisoning infrastructure to narrow the hunt scope.

```sqlite target=endpoint role=scoping params=(lookback_days=lookback_days, seo_domains=seo_domains)
~~~yaml
expected: A host resolving one of the lookalike domains. Silence means no recorded
  interaction with the known delivery infrastructure.
reads:
- device_hostname
- query_hostname
- process_name
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{seo_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```

## gate-read
<!-- Examine DNS lead -->
```agent target=hunter
cite: required
context:
- lead-dns-lookups
max_iterations: 3
objective: Determine if any host in the lead query results resolved the malicious
  SEO domains during the lookback window.
success_criteria: Confirm the presence of relevant DNS resolutions.
tools:
- endpoint
- network
```

## gate-decision
<!-- Decide to proceed with deeper investigation -->
if~: "the gate-read verdict finds at least one host resolved a malicious SEO domain" (confidence: high, judge=hunter)
then: → investigate-infection
indeterminate: → close-out
unavailable: → close-out (blind_spot: no-dns-retention)
else: → close-out

## investigate-infection
<!-- Fan-out investigation -->
parallel:
- → detect-sideloading
- → rare-binaries-in-user-paths
- → detect-c2-activity
join: → final-triage

## detect-sideloading
<!-- Detect side-loading of consent.exe from AppData or Temp -->
Identify the execution of a legitimate Windows binary from a non-standard, user-writable path.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A row showing consent.exe executing from a folder like ApplicationInstallationFolder_11
  under AppData.
reads:
- device_hostname
- process_name
- process_cmd_line
- parent_process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(process_name) LIKE '%\consent.exe' AND (LOWER(process_name) LIKE '%\appdata\%' OR LOWER(process_name) LIKE '%\temp\%') AND LOWER(process_name) NOT LIKE 'c:\windows\system32\%' AND time >= datetime('now', '-{{lookback_days}} days')
```

## rare-binaries-in-user-paths
<!-- Rare binaries in AppData or Temp -->
Stack-count processes running from user-writable paths to find rare Bumblebee-related binaries like AdgNsy.exe or dropped loaders.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A process seen on only one or two hosts in the fleet, specifically targeting
  user-writable directories.
prevalence:
  by: device_hostname
  key:
  - name
  - path
  rare_below: 3
reads:
- process_name
- process_path
- device_hostname
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT LOWER(process_name) AS name, LOWER(process_path) AS path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '%\temp\%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY name, path HAVING hosts <= 3 ORDER BY hosts ASC
```

## detect-c2-activity
<!-- Detect AdaptixC2 and Bumblebee C2 traffic -->
Corroborate the execution lead with network traffic to known malicious IPs or from the injected Address Book process.

```sqlite target=network role=enrichment params=(lookback_days=lookback_days, c2_ips=c2_ips, scope_hosts=scope_hosts)
~~~yaml
expected: Network connections to reported Azure C2 IPs or outbound traffic from AdgNsy.exe.
reads:
- device_hostname
- process_name
- dst_endpoint_ip
- dst_endpoint_port
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR LOWER(process_name) LIKE '%\adgnsy.exe') AND time >= datetime('now', '-{{lookback_days}} days')
```

## final-triage
<!-- Final infection triage -->
```agent target=hunter
cite: required
context:
- gate-read
- detect-sideloading
- rare-binaries-in-user-paths
- detect-c2-activity
max_iterations: 6
objective: Determine if any host shows the complete chain of SEO redirection followed
  by suspicious consent.exe execution and C2 network activity. Check for Bumblebee
  patterns such as the system locale check and specific ApplicationInstallationFolder_11
  paths.
success_criteria: A per-host verdict of malicious, suspicious, or benign based on
  the available telemetry.
tools:
- endpoint
- network
```

## route-on-verdict
<!-- Route based on infection verdict -->
if~: "the final-triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → quarantine-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: no-process-visibility)
else: → close-out

## quarantine-host
<!-- Isolate infected host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host immediately via the EDR. Capture a memory dump of the AdgNsy.exe process if possible.
```
→ analyst-review

## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the cited DNS lookups and process execution paths for consent.exe. Check for signs of ManageEngine-OpManager.msi execution on the desktop or downloads folder.
```
→ close-out

## close-out
<!-- Close out -->
```manual target=analyst
Record the hosts examined and reasons for closing. Document any new SEO domains found during analysis.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.