{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Bumblebee is a high-confidence precursor to Akira ransomware; identifying it at the delivery and C2 stage prevents catastrophic data exfiltration and encryption."
      },
      "name": "Bumblebee Delivery and C2 Establishment",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1189",
        "attack.t1583.008",
        "attack.t1204.002",
        "attack.t1574.002",
        "attack.t1071.001",
        "attack.t1568.002",
        "attack.t1055",
        "command and control",
        "credential access",
        "discovery",
        "execution",
        "exfiltration",
        "impact",
        "initial access",
        "lateral movement"
      ],
      "series": {
        "slug": "from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira",
        "index": 1,
        "title": "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira",
        "total": 3
      },
      "related": [
        {
          "hunt": "bumblebee-discovery-and-persistence",
          "reason": "Once established, Bumblebee performs discovery and installs RustDesk for persistence.",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This hunt pivots across three telemetry surfaces (DNS, Process, and Network) to connect a user's web activity to an execution anomaly and subsequent C2 callout, providing the full context needed to differentiate an admin performing a legitimate install from an intruder using a trojanized decoy.",
      "coverage": [
        {
          "stage": "initial-access-seo-redirection",
          "steps": [
            "lead-dns-lookups"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-dll-side-loading",
          "steps": [
            "detect-sideloading",
            "rare-binaries-in-user-paths"
          ],
          "status": "covered"
        },
        {
          "stage": "c2-establishment-adaptix",
          "steps": [
            "detect-c2-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "internal-discovery-and-persistence",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-tunneling",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-harvesting",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "data-exfiltration-sftp",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "impact-ransomware-encryption",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "SEO Poisoning Redirection",
            "slug": "initial-access-seo-redirection",
            "tactic": "initial-access",
            "techniques": [
              "T1189",
              "T1583.008"
            ],
            "observables": [
              "opmanager.pro",
              "download-center.online",
              "ip-scanner.org",
              "download-server.online",
              "soft-server.online",
              "soft-hub.pro",
              "netml.shop",
              "/Get?q="
            ]
          },
          {
            "name": "Bumblebee DLL Side-Loading",
            "slug": "execution-dll-side-loading",
            "tactic": "execution",
            "techniques": [
              "T1204.002",
              "T1574.002"
            ],
            "observables": [
              "ManageEngine-OpManager.msi",
              "consent.exe",
              "msimg32.dll",
              "%TEMP%\\ApplicationInstallationFolder_11",
              "ApplicationInstallationFolder_11"
            ]
          },
          {
            "name": "AdaptixC2 Infrastructure Setup",
            "slug": "c2-establishment-adaptix",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1568.002",
              "T1055"
            ],
            "observables": [
              "AdgNsy.exe",
              "4.239.95.1:8080",
              "84.32.84.32"
            ]
          },
          {
            "name": "Internal Reconnaissance and Persistence",
            "slug": "internal-discovery-and-persistence",
            "tactic": "discovery",
            "techniques": [
              "T1082",
              "T1016",
              "T1136.002",
              "T1543.003"
            ],
            "observables": [
              "systeminfo",
              "nltest",
              "RustDesk",
              "Enterprise Admin accounts"
            ]
          },
          {
            "name": "SSH Tunneling and RDP Pivot",
            "slug": "lateral-movement-tunneling",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001",
              "T1572"
            ],
            "observables": [
              "reverse SSH tunnel",
              "RDP proxy traffic"
            ]
          },
          {
            "name": "Active Directory and Veeam Credential Harvesting",
            "slug": "credential-access-harvesting",
            "tactic": "credential-access",
            "techniques": [
              "T1003.003",
              "T1003.001",
              "T1552.004"
            ],
            "observables": [
              "wbadmin.exe",
              "ntds.dit",
              "lsassy",
              "Veeam credential dumping script"
            ]
          },
          {
            "name": "Data Exfiltration via SFTP",
            "slug": "data-exfiltration-sftp",
            "tactic": "exfiltration",
            "techniques": [
              "T1048.003",
              "T1020"
            ],
            "observables": [
              "FileZilla.exe",
              "75GB exfiltrated",
              "Ukrainian IP space"
            ]
          },
          {
            "name": "Akira Ransomware Impact",
            "slug": "impact-ransomware-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486",
              "T1490",
              "T1047"
            ],
            "observables": [
              "locker.exe",
              "delete Volume Shadow Copies",
              "WMI"
            ]
          }
        ],
        "summary": "Threat actors utilized Bing SEO poisoning to deliver Bumblebee malware via trojanized software installers, leading to the deployment of AdaptixC2 for network discovery. The attackers leveraged RDP over SSH tunnels to move laterally and harvest credentials from NTDS.dit and LSASS before exfiltrating 75GB of data and deploying Akira ransomware."
      },
      "severity": "high",
      "rationale": "Focus on high-privileged IT administrator workstations and management servers, as these are the primary targets for ManageEngine look-alike decoys.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.",
      "parameters": {
        "c2_ips": {
          "from": {
            "ref": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/",
            "kind": "article",
            "observed": "2025-07-01"
          },
          "type": "list[ip]",
          "default": [
            "84.32.84.32",
            "4.239.95.1"
          ],
          "description": "Known C2 and staging IPs associated with this Bumblebee/Adaptix wave."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames to narrow the expensive fan-out queries; populate from the lead query results."
        },
        "seo_domains": {
          "from": {
            "ref": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/",
            "kind": "article",
            "observed": "2025-07-01"
          },
          "type": "list[domain]",
          "default": [
            "opmanager.pro",
            "download-center.online",
            "ip-scanner.org",
            "download-server.online",
            "soft-server.online",
            "soft-hub.pro",
            "zenmap.pro",
            "netml.shop"
          ],
          "description": "Look-alike and delivery domains identified in the Bumblebee campaign."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/",
          "name": "The DFIR Report \u2014 From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira"
        }
      ],
      "blind_spots": [
        {
          "id": "no-dns-retention",
          "risk": "A host infected weeks ago would be missed if the redirection event is no longer in the logs.",
          "stage": "initial-access-seo-redirection",
          "question": "whether a host visited the malicious domains outside the current retention window",
          "requires": "long-term hb_dns_activity logs"
        },
        {
          "id": "no-process-visibility",
          "risk": "Without path-aware process auditing, the side-loading of msimg32.dll goes unobserved.",
          "stage": "execution-dll-side-loading",
          "question": "whether consent.exe was executed from a non-standard path",
          "requires": "endpoint auditing of System32 binaries running from user-writable paths"
        }
      ]
    },
    "name": "Bumblebee Delivery and C2 Establishment",
    "description": "The adversary lulls administrators into a false sense of security with high-fidelity lookalike download pages for tools like ManageEngine OpManager. This hunt first searches for the cheap lead: DNS lookups to known SEO-poisoned redirection infrastructure. If a lead is found, it fans out to examine host-level process anomalies: the legitimate Windows binary consent.exe executed from unusual user-writable paths like AppData or Temp, and the prevalence of rare binaries in those same paths. The hunt then corroborates these hits with network connections to AdaptixC2 infrastructure or traffic from the renamed Address Book utility used for shellcode injection."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira",
          "index": 1,
          "title": "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira",
          "total": 3
        },
        "coverage": [
          {
            "stage": "initial-access-seo-redirection",
            "steps": [
              "lead-dns-lookups"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-dll-side-loading",
            "steps": [
              "detect-sideloading",
              "rare-binaries-in-user-paths"
            ],
            "status": "covered"
          },
          {
            "stage": "c2-establishment-adaptix",
            "steps": [
              "detect-c2-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "internal-discovery-and-persistence",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-tunneling",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-harvesting",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "data-exfiltration-sftp",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "impact-ransomware-encryption",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.",
        "blind_spots": [
          {
            "id": "no-dns-retention",
            "risk": "A host infected weeks ago would be missed if the redirection event is no longer in the logs.",
            "stage": "initial-access-seo-redirection",
            "question": "whether a host visited the malicious domains outside the current retention window",
            "requires": "long-term hb_dns_activity logs"
          },
          {
            "id": "no-process-visibility",
            "risk": "Without path-aware process auditing, the side-loading of msimg32.dll goes unobserved.",
            "stage": "execution-dll-side-loading",
            "question": "whether consent.exe was executed from a non-standard path",
            "requires": "endpoint auditing of System32 binaries running from user-writable paths"
          }
        ],
        "scoping_notes": "Focus on high-privileged IT administrator workstations and management servers, as these are the primary targets for ManageEngine look-alike decoys.",
        "beyond_detection": "This hunt pivots across three telemetry surfaces (DNS, Process, and Network) to connect a user's web activity to an execution anomaly and subsequent C2 callout, providing the full context needed to differentiate an admin performing a legitimate install from an intruder using a trojanized decoy."
      }
    },
    {
      "id": "lead-dns-lookups",
      "type": "query",
      "label": "Lead: DNS lookups to SEO look-alike domains",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{seo_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Identify hosts that interacted with the reported SEO poisoning infrastructure to narrow the hunt scope.",
        "expected_signal": "A host resolving one of the lookalike domains. Silence means no recorded interaction with the known delivery infrastructure."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Lead: DNS lookups to SEO look-alike domains",
        "reads": [
          "device_hostname",
          "query_hostname",
          "process_name",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{seo_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A host resolving one of the lookalike domains. Silence means no recorded interaction with the known delivery infrastructure.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "gate-read",
      "type": "analytic",
      "label": "Examine DNS lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "lead-dns-lookups"
        ],
        "objective": "Determine if any host in the lead query results resolved the malicious SEO domains during the lookback window.",
        "description": "Evaluate if the DNS activity suggests a user was redirected to the malicious infrastructure.",
        "max_iterations": 3,
        "expected_signal": "A verdict on whether the DNS activity warrants host-level process and network analysis.",
        "success_criteria": "Confirm the presence of relevant DNS resolutions."
      },
      "parents": [
        {
          "id": "lead-dns-lookups"
        }
      ]
    },
    {
      "id": "gate-decision",
      "type": "checkpoint",
      "label": "Decide to proceed with deeper investigation",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the gate-read verdict finds at least one host resolved a malicious SEO domain",
        "condition": "the gate-read verdict finds at least one host resolved a malicious SEO domain",
        "blind_spot": "no-dns-retention",
        "confidence": "high",
        "description": "Avoid expensive host-wide queries if no initial lead is found.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "gate-read"
        }
      ]
    },
    {
      "id": "detect-sideloading",
      "type": "query",
      "label": "Detect side-loading of consent.exe from AppData or Temp",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(process_name) LIKE '%\\consent.exe' AND (LOWER(process_name) LIKE '%\\appdata\\%' OR LOWER(process_name) LIKE '%\\temp\\%') AND LOWER(process_name) NOT LIKE 'c:\\windows\\system32\\%' AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify the execution of a legitimate Windows binary from a non-standard, user-writable path.",
        "expected_signal": "A row showing consent.exe executing from a folder like ApplicationInstallationFolder_11 under AppData."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Detect side-loading of consent.exe from AppData or Temp",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "parent_process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(process_name) LIKE '%\\consent.exe' AND (LOWER(process_name) LIKE '%\\appdata\\%' OR LOWER(process_name) LIKE '%\\temp\\%') AND LOWER(process_name) NOT LIKE 'c:\\windows\\system32\\%' AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A row showing consent.exe executing from a folder like ApplicationInstallationFolder_11 under AppData.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "rare-binaries-in-user-paths",
      "type": "query",
      "label": "Rare binaries in AppData or Temp",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(process_name) AS name, LOWER(process_path) AS path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_path) LIKE '%\\appdata\\%' OR LOWER(process_path) LIKE '%\\temp\\%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY name, path HAVING hosts <= 3 ORDER BY hosts ASC",
        "surface": "hb_process_activity",
        "description": "Stack-count processes running from user-writable paths to find rare Bumblebee-related binaries like AdgNsy.exe or dropped loaders.",
        "expected_signal": "A process seen on only one or two hosts in the fleet, specifically targeting user-writable directories."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare binaries in AppData or Temp",
        "reads": [
          "process_name",
          "process_path",
          "device_hostname",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_name) AS name, LOWER(process_path) AS path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_path) LIKE '%\\appdata\\%' OR LOWER(process_path) LIKE '%\\temp\\%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY name, path HAVING hosts <= 3 ORDER BY hosts ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A process seen on only one or two hosts in the fleet, specifically targeting user-writable directories.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "name",
            "path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "detect-c2-activity",
      "type": "query",
      "label": "Detect AdaptixC2 and Bumblebee C2 traffic",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR LOWER(process_name) LIKE '%\\adgnsy.exe') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_network_connection",
        "description": "Corroborate the execution lead with network traffic to known malicious IPs or from the injected Address Book process.",
        "expected_signal": "Network connections to reported Azure C2 IPs or outbound traffic from AdgNsy.exe."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Detect AdaptixC2 and Bumblebee C2 traffic",
        "reads": [
          "device_hostname",
          "process_name",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR LOWER(process_name) LIKE '%\\adgnsy.exe') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Network connections to reported Azure C2 IPs or outbound traffic from AdgNsy.exe.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "final-triage",
      "type": "analytic",
      "label": "Final infection triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "gate-read",
          "detect-sideloading",
          "rare-binaries-in-user-paths",
          "detect-c2-activity"
        ],
        "objective": "Determine if any host shows the complete chain of SEO redirection followed by suspicious consent.exe execution and C2 network activity. Check for Bumblebee patterns such as the system locale check and specific ApplicationInstallationFolder_11 paths.",
        "description": "Correlate the DNS visit, the side-loading execution, and the C2 callback to provide a high-confidence verdict.",
        "max_iterations": 6,
        "expected_signal": "A detailed verdict citing the timing and sequence of redirection, execution, and C2.",
        "success_criteria": "A per-host verdict of malicious, suspicious, or benign based on the available telemetry."
      },
      "parents": [
        {
          "id": "detect-sideloading",
          "kind": "merge"
        },
        {
          "id": "rare-binaries-in-user-paths",
          "kind": "merge"
        },
        {
          "id": "detect-c2-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route based on infection verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the final-triage verdict is malicious for at least one host",
        "condition": "the final-triage verdict is malicious for at least one host",
        "blind_spot": "no-process-visibility",
        "confidence": "high",
        "description": "Contain confirmed infections or escalate for review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "final-triage"
        }
      ]
    },
    {
      "id": "quarantine-host",
      "type": "action",
      "label": "Isolate infected host",
      "config": {
        "target": "endpoint",
        "description": "Contain the Bumblebee beachhead to prevent ransomware deployment.",
        "instructions": "Isolate the host immediately via the EDR. Capture a memory dump of the AdgNsy.exe process if possible.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Resolve indeterminate verdicts and verify findings.",
        "instructions": "Review the cited DNS lookups and process execution paths for consent.exe. Check for signs of ManageEngine-OpManager.msi execution on the desktop or downloads folder."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "quarantine-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and visibility gaps.",
        "instructions": "Record the hosts examined and reasons for closing. Document any new SEO domains found during analysis."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "default"
        },
        {
          "id": "gate-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "gate-decision",
          "branch": "on_refutes"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}