{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Interlock RAT is a precursor to ransomware. Detecting its C2 and movement early prevents wide-scale encryption and data theft."
      },
      "name": "Interlock RAT C2 and RDP Lateral Movement",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1071.001",
        "attack.t1572",
        "attack.t1021.001"
      ],
      "series": {
        "slug": "kongtuke-filefix-leads-to-new-interlock-rat-variant",
        "index": 2,
        "title": "KongTuke FileFix Leads to New Interlock RAT Variant",
        "total": 2
      },
      "related": [
        {
          "hunt": "interlock-rat-persistence-and-discovery",
          "reason": "Persistence via Run keys and automated discovery are handled in a separate hunt focused on local endpoint artifacts.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "interlock-rat-endpoint-execution-recon",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "Simple rules for Cloudflare traffic are often suppressed. This hunt correlates DNS leads with fallback IP connections and a specific PHP execution pattern across three telemetry surfaces, providing the context an analyst needs to differentiate a RAT from legitimate tunneling.",
      "coverage": [
        {
          "stage": "c2-cloudflare-tunneling",
          "steps": [
            "dns-c2-leads",
            "fallback-network-connections"
          ],
          "status": "covered"
        },
        {
          "stage": "lateral-movement-rdp",
          "steps": [
            "anomalous-rdp-logons"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-web-inject",
          "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "powershell-stager-execution",
          "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "php-rat-deployment",
          "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "automated-and-manual-discovery",
          "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-registry-run",
          "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Social Engineering via Web-Inject",
            "slug": "initial-access-web-inject",
            "tactic": "initial-access",
            "techniques": [
              "T1189",
              "T1204.002"
            ],
            "observables": [
              "captcha verification prompt",
              "human verification steps",
              "clipboard paste into run command"
            ]
          },
          {
            "name": "PowerShell Stager Execution",
            "slug": "powershell-stager-execution",
            "tactic": "execution",
            "techniques": [
              "T1059.001",
              "T1105"
            ],
            "observables": [
              "schtasks /delete /tn Updater /f",
              "New-Object System.Net.WebClient",
              "DownloadString",
              "deadly-programming-attorneys-our.trycloudflare.com",
              "User-Agent: PowerShell"
            ]
          },
          {
            "name": "Interlock RAT (PHP) Deployment",
            "slug": "php-rat-deployment",
            "tactic": "execution",
            "techniques": [
              "T1059"
            ],
            "observables": [
              "AppData\\Roaming\\php\\php.exe",
              "wefs.cfg",
              "php.exe -d extension=zip -d extension_dir=ext",
              "28a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d3",
              "8afd6c0636c5d70ac0622396268786190a428635e9cf28ab23add939377727b0"
            ]
          },
          {
            "name": "Automated and Manual Discovery",
            "slug": "automated-and-manual-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1082",
              "T1057",
              "T1018",
              "T1087",
              "T1069",
              "T1016"
            ],
            "observables": [
              "Get-NetNeighbor -AddressFamily IPv4",
              "systeminfo /FO CSV",
              "tasklist /svc",
              "Get-Service",
              "Get-PSDrive",
              "[Security.Principal.WindowsIdentity]::GetCurrent()",
              "[adsiSearcher]\"(ObjectClass=computer)\"",
              "nltest /dclist:",
              "net user %USERNAME% /domain"
            ]
          },
          {
            "name": "Registry Run Key Persistence",
            "slug": "persistence-registry-run",
            "tactic": "persistence",
            "techniques": [
              "T1547.001"
            ],
            "observables": [
              "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
              "php.exe AppData\\Roaming\\php\\wefs.cfg"
            ]
          },
          {
            "name": "Cloudflare Tunnel C2",
            "slug": "c2-cloudflare-tunneling",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1572"
            ],
            "observables": [
              "existed-bunch-balance-councils.trycloudflare.com",
              "ferrari-rolling-facilities-lounge.trycloudflare.com",
              "galleries-physicians-psp-wv.trycloudflare.com",
              "evidence-deleted-procedure-bringing.trycloudflare.com",
              "nowhere-locked-manor-hs.trycloudflare.com",
              "ranked-accordingly-ab-hired.trycloudflare.com",
              "64.95.12.71",
              "184.95.51.165"
            ]
          },
          {
            "name": "Lateral Movement via RDP",
            "slug": "lateral-movement-rdp",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001"
            ],
            "observables": [
              "Remote Desktop Protocol usage"
            ]
          }
        ],
        "summary": "The Interlock ransomware group utilizes KongTuke web-injects to deliver a PHP-based RAT through a multi-stage PowerShell stager executed via social engineering. The malware conducts extensive automated and manual reconnaissance of system profiles and Active Directory, maintains persistence through registry Run keys, and leverages Cloudflare Tunnels for resilient C2 before facilitating lateral movement via RDP."
      },
      "severity": "high",
      "rationale": "Start with hosts resolving trycloudflare subdomains. The hunt dynamically pivots by having the agent correlate these hosts with network and process telemetry.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has established a PHP-based RAT beachhead and is using Cloudflare Tunnels for C2 before moving laterally via RDP.",
      "parameters": {
        "c2_domains": {
          "from": {
            "ref": "dfir-report-2025-07-14",
            "kind": "article",
            "observed": "2025-07-14"
          },
          "type": "list[domain]",
          "default": [
            "existed-bunch-balance-councils.trycloudflare.com",
            "ferrari-rolling-facilities-lounge.trycloudflare.com",
            "galleries-physicians-psp-wv.trycloudflare.com",
            "evidence-deleted-procedure-bringing.trycloudflare.com",
            "nowhere-locked-manor-hs.trycloudflare.com",
            "ranked-accordingly-ab-hired.trycloudflare.com"
          ],
          "description": "Known TryCloudflare subdomains used by Interlock RAT."
        },
        "fallback_ips": {
          "from": {
            "ref": "dfir-report-2025-07-14",
            "kind": "article",
            "observed": "2025-07-14"
          },
          "type": "list[ip]",
          "default": [
            "64.95.12.71",
            "184.95.51.165"
          ],
          "description": "Hardcoded fallback IP addresses for Interlock RAT C2."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://thedfirreport.com/2025/07/14/kongtuke-filefix-leads-to-new-interlock-rat-variant/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://thedfirreport.com/2025/07/14/kongtuke-filefix-leads-to-new-interlock-rat-variant/",
          "name": "The DFIR Report - KongTuke FileFix Leads to New Interlock RAT Variant"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-rdp-visibility",
          "risk": "Lateral movement between servers using local accounts would not appear in centralized authentication logs.",
          "stage": "lateral-movement-rdp",
          "question": "Did the attacker move between systems using local accounts or sessions not captured by the central provider?",
          "requires": "hb_auth_signin with logon type and local session tracking"
        },
        {
          "id": "cloudflare-legitimate-usage",
          "risk": "Legitimate use of Cloudflare Tunnels can create false positives, requiring correlation with PHP behavioral artifacts to confirm the RAT.",
          "stage": "c2-cloudflare-tunneling",
          "question": "Is the Cloudflare Tunnel traffic malicious or legitimate administrative usage?",
          "requires": "Proxy logs with SNI and HTTP header inspection"
        }
      ]
    },
    "name": "Interlock RAT C2 and RDP Lateral Movement",
    "description": "This hunt identifies the post-exploitation phases of the Interlock RAT campaign, specifically targeting command-and-control communication through Cloudflare Tunnel subdomains and hardcoded fallback IP addresses. It correlates these network indicators with behavioral evidence of PHP execution from user-writable paths and subsequent RDP lateral movement originating from the beachhead hosts. The hunt provides a holistic view of the intrusion lifecycle from the first beacon to internal spread."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "kongtuke-filefix-leads-to-new-interlock-rat-variant",
          "index": 2,
          "title": "KongTuke FileFix Leads to New Interlock RAT Variant",
          "total": 2
        },
        "coverage": [
          {
            "stage": "c2-cloudflare-tunneling",
            "steps": [
              "dns-c2-leads",
              "fallback-network-connections"
            ],
            "status": "covered"
          },
          {
            "stage": "lateral-movement-rdp",
            "steps": [
              "anomalous-rdp-logons"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-web-inject",
            "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "powershell-stager-execution",
            "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "php-rat-deployment",
            "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "automated-and-manual-discovery",
            "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-registry-run",
            "reason": "Belongs to another part of the 'KongTuke FileFix Leads to New Interlock RAT Variant' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has established a PHP-based RAT beachhead and is using Cloudflare Tunnels for C2 before moving laterally via RDP.",
        "blind_spots": [
          {
            "id": "limited-rdp-visibility",
            "risk": "Lateral movement between servers using local accounts would not appear in centralized authentication logs.",
            "stage": "lateral-movement-rdp",
            "question": "Did the attacker move between systems using local accounts or sessions not captured by the central provider?",
            "requires": "hb_auth_signin with logon type and local session tracking"
          },
          {
            "id": "cloudflare-legitimate-usage",
            "risk": "Legitimate use of Cloudflare Tunnels can create false positives, requiring correlation with PHP behavioral artifacts to confirm the RAT.",
            "stage": "c2-cloudflare-tunneling",
            "question": "Is the Cloudflare Tunnel traffic malicious or legitimate administrative usage?",
            "requires": "Proxy logs with SNI and HTTP header inspection"
          }
        ],
        "scoping_notes": "Start with hosts resolving trycloudflare subdomains. The hunt dynamically pivots by having the agent correlate these hosts with network and process telemetry.",
        "beyond_detection": "Simple rules for Cloudflare traffic are often suppressed. This hunt correlates DNS leads with fallback IP connections and a specific PHP execution pattern across three telemetry surfaces, providing the context an analyst needs to differentiate a RAT from legitimate tunneling."
      }
    },
    {
      "id": "dns-c2-leads",
      "type": "query",
      "label": "DNS leads to Cloudflare Tunnels",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) AS resolution_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname",
        "surface": "hb_dns_activity",
        "description": "Identify potential beachheads by resolution of known C2 domains.",
        "expected_signal": "Hosts resolving attacker subdomains indicate a likely beachhead. Silence proves no resolution attempts to these specific subdomains occurred."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "DNS leads to Cloudflare Tunnels",
        "reads": [
          "device_hostname",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) AS resolution_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts resolving attacker subdomains indicate a likely beachhead. Silence proves no resolution attempts to these specific subdomains occurred.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "fallback-network-connections",
      "type": "query",
      "label": "Connections to fallback C2 IPs",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE instr(',' || '{{fallback_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_network_connection",
        "description": "Check for direct IP connections to hardcoded fallback C2 infrastructure.",
        "expected_signal": "Network connections to hardcoded IPs correlate with the report's fallback mechanism."
      },
      "parents": [
        {
          "id": "dns-c2-leads"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Connections to fallback C2 IPs",
        "reads": [
          "device_hostname",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE instr(',' || '{{fallback_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Network connections to hardcoded IPs correlate with the report's fallback mechanism.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "php-execution-indicators",
      "type": "query",
      "label": "PHP execution with config files",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_path) LIKE '%\\appdata\\roaming\\php\\php.exe' OR LOWER(process_name) = 'php.exe') AND (LOWER(process_cmd_line) LIKE '%.cfg%' OR LOWER(process_cmd_line) LIKE '%extension=zip%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find behavioral signs of the PHP Interlock variant executing from roaming profiles.",
        "expected_signal": "PHP executing with .cfg files from a user profile is highly suspicious in this context."
      },
      "parents": [
        {
          "id": "dns-c2-leads"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "PHP execution with config files",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "process_name",
          "process_path",
          "time",
          "user_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_path) LIKE '%\\appdata\\roaming\\php\\php.exe' OR LOWER(process_name) = 'php.exe') AND (LOWER(process_cmd_line) LIKE '%.cfg%' OR LOWER(process_cmd_line) LIKE '%extension=zip%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "PHP executing with .cfg files from a user profile is highly suspicious in this context.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "anomalous-rdp-logons",
      "type": "query",
      "label": "Anomalous RDP logon prevalence",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT dst_endpoint_name, actor_user_name, src_endpoint_ip, MIN(time) AS first_seen, COUNT(*) AS logon_count FROM hb_auth_signin WHERE (LOWER(auth_protocol) = 'rdp' OR activity_id = 1) AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_name, actor_user_name, src_endpoint_ip HAVING logon_count < 5",
        "surface": "hb_auth_signin",
        "description": "Identify rare RDP logons; the agent will filter these for movement originating from beachheads.",
        "expected_signal": "Rare RDP logons reveal lateral movement. The agent will compare these source IPs to the identified C2 beachheads."
      },
      "parents": [
        {
          "id": "dns-c2-leads"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Anomalous RDP logon prevalence",
        "reads": [
          "activity_id",
          "actor_user_name",
          "auth_protocol",
          "dst_endpoint_name",
          "src_endpoint_ip",
          "status_id",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT dst_endpoint_name, actor_user_name, src_endpoint_ip, MIN(time) AS first_seen, COUNT(*) AS logon_count FROM hb_auth_signin WHERE (LOWER(auth_protocol) = 'rdp' OR activity_id = 1) AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_name, actor_user_name, src_endpoint_ip HAVING logon_count < 5",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare RDP logons reveal lateral movement. The agent will compare these source IPs to the identified C2 beachheads.",
        "verified": "dry-run",
        "prevalence": {
          "by": "dst_endpoint_name",
          "key": [
            "actor_user_name",
            "src_endpoint_ip"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "agent-triage",
      "type": "analytic",
      "label": "Correlate C2 and movement",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network"
        ],
        "context": [
          "dns-c2-leads",
          "fallback-network-connections",
          "php-execution-indicators",
          "anomalous-rdp-logons"
        ],
        "objective": "Determine if any host exhibits Cloudflare C2 traffic or fallback IP connections, and whether those hosts coincide with the Interlock RAT PHP execution pattern or initiate RDP lateral movement.",
        "description": "The agent evaluates all results to confirm the intrusion chain from beaconing to movement.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict linking C2 domains, fallback IPs, and RDP movement.",
        "success_criteria": "A per-host verdict of malicious | suspicious | benign citing specific rows from all four queries."
      },
      "parents": [
        {
          "id": "fallback-network-connections",
          "kind": "merge"
        },
        {
          "id": "php-execution-indicators",
          "kind": "merge"
        },
        {
          "id": "anomalous-rdp-logons",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-infection",
      "type": "checkpoint",
      "label": "Route on infection verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The triage verdict is malicious for at least one host, indicating confirmed C2 traffic and suspicious lateral movement.",
        "condition": "The triage verdict is malicious for at least one host, indicating confirmed C2 traffic and suspicious lateral movement.",
        "blind_spot": "limited-rdp-visibility",
        "confidence": "high",
        "description": "Direct confirmed infections to isolation and ambiguous cases to analyst review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-triage"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Stop further spread by isolating the identified beachhead.",
        "instructions": "Isolate the identified host using the endpoint agent and revoke active user sessions.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-infection",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-investigation",
      "type": "task",
      "label": "Manual investigation",
      "config": {
        "assignee": "analyst",
        "description": "Review the intrusion chain and confirm all impacted accounts.",
        "instructions": "Review the process logs on isolated hosts for evidence of NodeSnake (Node.js variant) deployment. Map all accounts used for RDP from the beachheads."
      },
      "parents": [
        {
          "id": "route-infection",
          "branch": "default"
        },
        {
          "id": "route-infection",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record findings.",
        "instructions": "Document impacted systems and recommend blocks for the identified subdomains. Promote the PHP behavioral query to a standing rule."
      },
      "parents": [
        {
          "id": "route-infection",
          "branch": "on_refutes"
        },
        {
          "id": "manual-investigation"
        }
      ]
    }
  ]
}