{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "ErrTraffic is a growing distribution framework used to deliver multiple infostealer families. Compromised company infrastructure serving malware to external visitors presents a high reputational and legal risk."
      },
      "name": "ErrTraffic Infrastructure and Delivery Monitoring",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1071",
        "attack.t1059.001"
      ],
      "series": {
        "slug": "errtraffic-a-growing-clickfix-malware-distribution-framework",
        "index": 1,
        "title": "ErrTraffic: A Growing ClickFix Malware Distribution Framework",
        "total": 2
      },
      "related": [
        {
          "hunt": "clipboard-command-injection-clickfix",
          "reason": "This hunt identifies the delivery server; the sibling hunt identifies client-side execution via the clipboard.",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This hunt pivots between server-side process identification, unauthorized file changes, specific JS delivery paths, and the underlying blockchain resolution behavior, requiring correlation across four different surfaces that a single static rule cannot achieve.",
      "coverage": [
        {
          "stage": "backdoor-persistence",
          "steps": [
            "wordpress-persistence-files"
          ],
          "status": "covered"
        },
        {
          "stage": "blockchain-c2-resolution",
          "steps": [
            "blockchain-resolution-dns"
          ],
          "status": "covered"
        },
        {
          "stage": "clickfix-lure-delivery",
          "steps": [
            "lure-delivery-endpoints"
          ],
          "status": "covered"
        },
        {
          "stage": "wordpress-credential-compromise",
          "reason": "Belongs to another part of the 'ErrTraffic: A Growing ClickFix Malware Distribution Framework' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "clipboard-command-injection",
          "reason": "Belongs to another part of the 'ErrTraffic: A Growing ClickFix Malware Distribution Framework' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "powershell-payload-execution",
          "reason": "Belongs to another part of the 'ErrTraffic: A Growing ClickFix Malware Distribution Framework' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "infostealer-credential-access",
          "reason": "Belongs to another part of the 'ErrTraffic: A Growing ClickFix Malware Distribution Framework' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "WordPress Account Compromise",
            "slug": "wordpress-credential-compromise",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "harvested credentials",
              "WordPress sites",
              "Exploit.IN forum"
            ]
          },
          {
            "name": "PHP Backdoor Deployment",
            "slug": "backdoor-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "PHP backdoors",
              "malicious WordPress plugin",
              "ErrTraffic framework injection"
            ]
          },
          {
            "name": "EtherHiding C2 Resolution",
            "slug": "blockchain-c2-resolution",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "Polygon blockchain",
              "0x08207B087F61d7e95E441E15fd6d40BEfd6eD308",
              "Quicknode RPC",
              "llc-image-ico.click",
              ".beer",
              ".cfd",
              ".club",
              ".click",
              ".cyou",
              ".lat",
              ".sbs",
              ".shop",
              ".xyz"
            ]
          },
          {
            "name": "Social Engineering Lure Delivery",
            "slug": "clickfix-lure-delivery",
            "tactic": "execution",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "/cf.js",
              "/api/css.js",
              "/api/index.php",
              "BSOD lure",
              "reCAPTCHA lure",
              "Cloudflare Turnstile lure"
            ]
          },
          {
            "name": "Malicious Clipboard Injection",
            "slug": "clipboard-command-injection",
            "tactic": "collection",
            "techniques": [
              "T1115"
            ],
            "observables": [
              "PowerShell command copied to clipboard"
            ]
          },
          {
            "name": "User-Executed PowerShell Payload",
            "slug": "powershell-payload-execution",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "powershell.exe",
              "Net.WebClient download",
              "mode=download"
            ]
          },
          {
            "name": "Infostealer Data Theft",
            "slug": "infostealer-credential-access",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Vidar",
              "Stealc",
              "Remus",
              "Salat"
            ]
          }
        ],
        "summary": "ErrTraffic is a Malware-as-a-Service (MaaS) framework that compromises WordPress sites to distribute infostealers using the 'ClickFix' social engineering technique. It uses the EtherHiding technique to resolve its command-and-control infrastructure via blockchain smart contracts and delivers malicious PowerShell commands that victims are tricked into executing manually."
      },
      "severity": "high",
      "rationale": "The hunt targets WordPress servers by identifying active PHP and web server processes associated with WordPress directories, ensuring it catches unmanaged or containerized installations alongside managed software inventory.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Limit the hunt to specific hosts; leave empty to scan all WordPress-identified servers."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "suspicious_tlds": {
          "from": {
            "ref": "sekoia-errtraffic",
            "kind": "article",
            "observed": "2026-06-22"
          },
          "type": "list[string]",
          "default": [
            ".beer",
            ".cfd",
            ".sbs",
            ".click",
            ".cyou",
            ".lat",
            ".shop",
            ".xyz"
          ],
          "description": "Suspicious TLDs observed in ErrTraffic C2 infrastructure."
        },
        "errtraffic_endpoints": {
          "from": {
            "ref": "sekoia-errtraffic",
            "kind": "article",
            "observed": "2026-06-22"
          },
          "type": "list[string]",
          "default": [
            "/cf.js",
            "/api/css.js",
            "/api/index.php"
          ],
          "description": "Specific HTTP endpoints used by ErrTraffic clusters to serve lures."
        },
        "blockchain_rpc_domains": {
          "from": {
            "ref": "sekoia-errtraffic",
            "kind": "article",
            "observed": "2026-06-22"
          },
          "type": "list[domain]",
          "default": [
            "polygon-rpc.com",
            "quiknode.pro",
            "quicknode.com"
          ],
          "description": "Public blockchain RPC endpoints used for EtherHiding C2 resolution."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework",
          "name": "ErrTraffic: A Growing ClickFix Malware Distribution Framework"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-telemetry",
          "risk": "Attackers may modify existing core WordPress files with minimal code changes that lack high-fidelity process signals.",
          "stage": "backdoor-persistence",
          "question": "whether a PHP file was legitimately updated or maliciously modified",
          "requires": "detailed file hashing and change auditing"
        },
        {
          "id": "blockchain-obfuscation",
          "risk": "If the RPC traffic is encrypted or the smart contract logic changes, identifying the secondary C2 via DNS alone becomes harder.",
          "stage": "blockchain-c2-resolution",
          "question": "the specific C2 domain being retrieved from the smart contract",
          "requires": "deep packet inspection of RPC traffic"
        }
      ]
    },
    "name": "ErrTraffic Infrastructure and Delivery Monitoring",
    "description": "The ErrTraffic Malware-as-a-Service (MaaS) distribution framework delivers payloads using the ClickFix social engineering technique. The adversary compromises WordPress servers to host the framework. The framework relies on EtherHiding, a technique where C2 domains are retrieved from blockchain smart contracts, allowing for rapid infrastructure rotation. This hunt monitors for server-side components of this framework on compromised WordPress infrastructure. The hunt identifies servers running WordPress processes or containing WordPress directories. It then collects evidence from three telemetry surfaces: HTTP activity targeting known delivery endpoints, file system changes involving unauthorized PHP backdoors, and DNS resolution of blockchain RPC providers or suspicious TLDs. An agent weighs these signals to determine if a server acts as a distribution point, and an analyst performs final forensic verification."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "errtraffic-a-growing-clickfix-malware-distribution-framework",
          "index": 1,
          "title": "ErrTraffic: A Growing ClickFix Malware Distribution Framework",
          "total": 2
        },
        "coverage": [
          {
            "stage": "backdoor-persistence",
            "steps": [
              "wordpress-persistence-files"
            ],
            "status": "covered"
          },
          {
            "stage": "blockchain-c2-resolution",
            "steps": [
              "blockchain-resolution-dns"
            ],
            "status": "covered"
          },
          {
            "stage": "clickfix-lure-delivery",
            "steps": [
              "lure-delivery-endpoints"
            ],
            "status": "covered"
          },
          {
            "stage": "wordpress-credential-compromise",
            "reason": "Belongs to another part of the 'ErrTraffic: A Growing ClickFix Malware Distribution Framework' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "clipboard-command-injection",
            "reason": "Belongs to another part of the 'ErrTraffic: A Growing ClickFix Malware Distribution Framework' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "powershell-payload-execution",
            "reason": "Belongs to another part of the 'ErrTraffic: A Growing ClickFix Malware Distribution Framework' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "infostealer-credential-access",
            "reason": "Belongs to another part of the 'ErrTraffic: A Growing ClickFix Malware Distribution Framework' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.",
        "blind_spots": [
          {
            "id": "limited-telemetry",
            "risk": "Attackers may modify existing core WordPress files with minimal code changes that lack high-fidelity process signals.",
            "stage": "backdoor-persistence",
            "question": "whether a PHP file was legitimately updated or maliciously modified",
            "requires": "detailed file hashing and change auditing"
          },
          {
            "id": "blockchain-obfuscation",
            "risk": "If the RPC traffic is encrypted or the smart contract logic changes, identifying the secondary C2 via DNS alone becomes harder.",
            "stage": "blockchain-c2-resolution",
            "question": "the specific C2 domain being retrieved from the smart contract",
            "requires": "deep packet inspection of RPC traffic"
          }
        ],
        "scoping_notes": "The hunt targets WordPress servers by identifying active PHP and web server processes associated with WordPress directories, ensuring it catches unmanaged or containerized installations alongside managed software inventory.",
        "beyond_detection": "This hunt pivots between server-side process identification, unauthorized file changes, specific JS delivery paths, and the underlying blockchain resolution behavior, requiring correlation across four different surfaces that a single static rule cannot achieve."
      }
    },
    {
      "id": "wordpress-process-identification",
      "type": "query",
      "label": "Identify WordPress servers via processes",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%wordpress%' OR LOWER(current_directory) LIKE '%wordpress%' OR LOWER(process_name) IN ('php-fpm', 'httpd', 'nginx', 'apache2')) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find hosts running web servers or PHP processes associated with WordPress to identify managed and unmanaged installations.",
        "expected_signal": "A list of hosts likely serving WordPress based on active processes. Silence indicates no active WordPress processes were observed."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify WordPress servers via processes",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "current_directory",
          "process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%wordpress%' OR LOWER(current_directory) LIKE '%wordpress%' OR LOWER(process_name) IN ('php-fpm', 'httpd', 'nginx', 'apache2')) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts likely serving WordPress based on active processes. Silence indicates no active WordPress processes were observed.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "lure-delivery-endpoints",
      "type": "query",
      "label": "Monitor for lure delivery endpoints",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{errtraffic_endpoints}}' || ',', ',' || CASE WHEN url_path LIKE '/%' THEN LOWER(url_path) ELSE '/' || LOWER(url_path) END || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Identify HTTP requests directed at specific ErrTraffic JavaScript delivery paths, normalizing for leading slashes.",
        "expected_signal": "Requests to /cf.js, /api/css.js, or /api/index.php regardless of the source log's slash convention. This is a high-fidelity indicator of an active lure delivery node."
      },
      "parents": [
        {
          "id": "wordpress-process-identification"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Monitor for lure delivery endpoints",
        "reads": [
          "device_hostname",
          "url_hostname",
          "url_path",
          "src_endpoint_ip",
          "user_agent",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{errtraffic_endpoints}}' || ',', ',' || CASE WHEN url_path LIKE '/%' THEN LOWER(url_path) ELSE '/' || LOWER(url_path) END || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Requests to /cf.js, /api/css.js, or /api/index.php regardless of the source log's slash convention. This is a high-fidelity indicator of an active lure delivery node.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "wordpress-persistence-files",
      "type": "query",
      "label": "Unauthorized PHP file persistence",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_path, process_name, actor_user_name, time FROM hb_file_activity WHERE activity_id IN (1, 3) AND LOWER(file_path) LIKE '%.php' AND (LOWER(file_path) LIKE '%wp-content/plugins%' OR LOWER(file_path) LIKE '%wp-content/themes%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Find new or modified PHP files within WordPress plugin and theme directories.",
        "expected_signal": "Unusual PHP files created or modified by web server processes. This represents the persistence stage."
      },
      "parents": [
        {
          "id": "wordpress-process-identification"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Unauthorized PHP file persistence",
        "reads": [
          "device_hostname",
          "file_path",
          "process_name",
          "actor_user_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_path, process_name, actor_user_name, time FROM hb_file_activity WHERE activity_id IN (1, 3) AND LOWER(file_path) LIKE '%.php' AND (LOWER(file_path) LIKE '%wp-content/plugins%' OR LOWER(file_path) LIKE '%wp-content/themes%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Unusual PHP files created or modified by web server processes. This represents the persistence stage.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "blockchain-resolution-dns",
      "type": "query",
      "label": "Blockchain RPC and suspicious TLD lookups",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) as count FROM hb_dns_activity WHERE (instr(',' || '{{blockchain_rpc_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR instr(',' || '{{suspicious_tlds}}' || ',', ',' || '.' || REPLACE(LOWER(query_hostname), RTRIM(LOWER(query_hostname), 'abcdefghijklmnopqrstuvwxyz'), '') || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname",
        "surface": "hb_dns_activity",
        "description": "Identify EtherHiding C2 resolution by monitoring for blockchain RPCs and suspicious TLDs using a robust suffix match.",
        "expected_signal": "Hosts resolving blockchain RPCs or domains ending in suspicious TLDs like .beer or .cfd. Robust suffix matching ensures TLDs of any length are captured."
      },
      "parents": [
        {
          "id": "wordpress-process-identification"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Blockchain RPC and suspicious TLD lookups",
        "reads": [
          "device_hostname",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) as count FROM hb_dns_activity WHERE (instr(',' || '{{blockchain_rpc_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR instr(',' || '{{suspicious_tlds}}' || ',', ',' || '.' || REPLACE(LOWER(query_hostname), RTRIM(LOWER(query_hostname), 'abcdefghijklmnopqrstuvwxyz'), '') || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts resolving blockchain RPCs or domains ending in suspicious TLDs like .beer or .cfd. Robust suffix matching ensures TLDs of any length are captured.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "errtraffic-triage",
      "type": "analytic",
      "label": "Triage ErrTraffic activity",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "wordpress-process-identification",
          "lure-delivery-endpoints",
          "wordpress-persistence-files",
          "blockchain-resolution-dns"
        ],
        "objective": "Determine if any WordPress servers show a combination of unauthorized PHP file changes, lookups to blockchain RPCs or suspicious TLDs, and HTTP traffic on lure delivery endpoints.",
        "description": "Evaluate the combined evidence of HTTP delivery, file persistence, and DNS C2 resolution per host.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict on whether the server is a compromised ErrTraffic delivery node.",
        "success_criteria": "A verdict of malicious, suspicious, or benign per host citing specific rows."
      },
      "parents": [
        {
          "id": "lure-delivery-endpoints",
          "kind": "merge"
        },
        {
          "id": "wordpress-persistence-files",
          "kind": "merge"
        },
        {
          "id": "blockchain-resolution-dns",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "errtraffic-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for any server showing correlated indicators across multiple telemetry surfaces",
        "condition": "the triage verdict is malicious for any server showing correlated indicators across multiple telemetry surfaces",
        "blind_spot": "limited-telemetry",
        "confidence": "high",
        "description": "Determine if immediate isolation is required based on the agent's findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "errtraffic-triage"
        }
      ]
    },
    {
      "id": "isolate-server",
      "type": "action",
      "label": "Isolate compromised server",
      "config": {
        "target": "endpoint",
        "description": "Prevent further delivery of malware lures to visitors by taking the node offline.",
        "instructions": "Isolate the host at the network level and revoke any active WordPress administrative sessions to prevent the adversary from maintaining access.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "errtraffic-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-forensic-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Manually inspect the identified PHP files and HTTP traffic to confirm ErrTraffic presence.",
        "instructions": "Inspect the identified PHP files for XOR-obfuscated or Base64-encoded strings. Verify if the HTTP Referer routing matches the behaviors described in the Sekoia report."
      },
      "parents": [
        {
          "id": "errtraffic-verdict",
          "branch": "default"
        },
        {
          "id": "errtraffic-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-server"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Remediation and close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt by documenting results and resolving any remaining gaps.",
        "instructions": "If malicious activity was confirmed, ensure all unauthorized plugins are removed and core WordPress files are restored from known good backups. Document the entry vector to prevent re-infection."
      },
      "parents": [
        {
          "id": "errtraffic-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-forensic-review"
        }
      ]
    }
  ]
}