---
analysis: This hunt uses a phased approach to correlate vulnerability presence, masqueraded
  execution, and persistent C2. It specifically hunts for rare source IPs and 'Living-off-the-Land'
  masquerading behavior using hash rarity that would be missed by single-surface rules.
blind_spots:
- id: incomplete-telemetry
  question: whether exploitation attempts occurred on unmonitored web servers
  requires: hb_http_activity on all perimeter servers
  risk: A compromised server without HTTP logging will show payload execution but
    not the entry vector.
  stage: initial-access-vulnerability-exploitation
- id: obfuscated-vpn-traffic
  question: what activity occurs inside the SoftEther VPN tunnel
  requires: Decrypted network inspection or process-to-network correlation
  risk: Once the VPN tunnel is established, exfiltration within that tunnel is invisible
    to standard network sensors.
  stage: command-and-control-obfuscated-channels
coverage:
- stage: initial-access-vulnerability-exploitation
  status: covered
  steps:
  - affected-vulnerable-hosts
  - web-exploitation-probes
- stage: execution-malware-payload
  status: covered
  steps:
  - masqueraded-initial-payload
- stage: persistence-vpn-installation
  status: covered
  steps:
  - vpn-masquerading-persistence
- stage: defence-evasion-masquerading
  status: covered
  steps:
  - masqueraded-initial-payload
  - vpn-masquerading-persistence
- stage: command-and-control-obfuscated-channels
  status: covered
  steps:
  - c2-infrastructure-traffic
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
    Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
  stage: credential-access-eburst-spraying
  status: out_of_scope
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
    Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
  stage: collection-mailbox-exfiltration
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Integrity Technology Group is targeting critical infrastructure using
    a blend of automated scanning and manual exploitation. Identifying the transition
    from perimeter probe to persistent VPN foothold is critical for preventing data
    exfiltration.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary exploits vulnerable web services to execute masqueraded payloads
  and establishes persistence through a renamed VPN client with a unique hash communicating
  with Integrity Tech infrastructure.
labels:
- hunt
- attack.t1190
- attack.t1059.001
- attack.t1059.006
- attack.t1133
- attack.t1036.003
- attack.t1071
- collection
- command and control
- credential access
- defense evasion
- execution
- initial access
- persistence
name: Perimeter Exploitation and Evasive VPN Persistence
parameters:
  c2_domains:
    default:
    - dns.studiocloud.xyz
    - 98aiblog.com
    - hmbcloud.com
    - hmbcloud.net
    - hmbiplc-01.com
    - iepl.node.cm
    - javacheck.ooguy.com
    - javaupdate.giize.com
    - sexytube0.com
    - twimg.co.uk
    description: Infrastructure domains associated with Integrity Technology Group.
    from:
      kind: article
      observed: '2026-10-08'
      ref: AA26-281A
    type: list[domain]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Hostnames to narrow the search; leave empty to hunt across the entire
      estate.
    type: list[host]
  target_cves:
    default:
    - CVE-2014-6278
    - CVE-2015-3306
    - CVE-2015-5477
    - CVE-2016-3081
    - CVE-2019-11510
    - CVE-2021-22205
    - CVE-2021-3199
    - CVE-2023-22894
    description: Vulnerabilities frequently targeted by this actor group.
    from:
      kind: article
      observed: '2026-10-08'
      ref: AA26-281A
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Begin with hosts identified as vulnerable in the scoping step. If no vulnerable
  hosts are returned, run the hunt across the entire estate to detect potential use
  of 0-day exploits or scanner blind spots.
references:
- name: 'CISA AA26-281A: Chinese Government-linked Cyber Threat Actors'
  url: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
related:
- hunt: password-spraying-eburst-analysis
  reason: This hunt focuses on vulnerability exploitation; EBurst password spraying
    belongs to an identity-centric hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Web and Service Exploitation
    observables:
    - BBScan
    - dirsearch
    - Fscan
    - ksubdomain
    - masscan
    - NMAP
    - OneForAll
    - ShuiZe
    - wpscan
    - MicroScan
    - XSS payloads targeting JavaScript
    - Exploits for CVE-2016-3081
    - Exploits for CVE-2019-11510
    - Exploits for CVE-2021-22205
    - Targeting ports 21, 22, 53, 80, 443, 1080
    - PHP/ASP enumeration
    slug: initial-access-vulnerability-exploitation
    tactic: initial-access
    techniques:
    - T1190
    - T1189
  - name: Malware Execution
    observables:
    - live700_v1.exe
    - DiagTrack.exe
    - Python-based exploit scripts
    - Go-based exploit utilities
    - Password-protected .zip files containing executables
    slug: execution-malware-payload
    tactic: execution
    techniques:
    - T1059.006
    - T1059.007
    - T1059.001
  - name: VPN-based Persistence
    observables:
    - SoftEther VPN installers
    - conhost.exe (renamed installer)
    - dllhost.exe (renamed installer)
    - curl or wget used to download SoftEther on Linux
    - PowerShell used to download SoftEther on Windows
    - Automatic reconnection configuration on startup
    slug: persistence-vpn-installation
    tactic: persistence
    techniques:
    - T1133
  - name: Service and Process Masquerading
    observables:
    - DiagTrack.exe
    - conhost.exe
    - dllhost.exe
    slug: defence-evasion-masquerading
    tactic: defence-evasion
    techniques:
    - T1036.003
  - name: EBurst Password Spraying
    observables:
    - EBurst tool
    - Password spraying against ECP
    - Password spraying against EWS
    - Password spraying against OWA
    - Password spraying against ActiveSync
    - Password spraying against MAPI/RPC
    slug: credential-access-eburst-spraying
    tactic: credential-access
    techniques:
    - T1110.003
    - T1110.001
  - name: Multi-protocol Command and Control
    observables:
    - dns.studiocloud.xyz
    - 98aiblog.com
    - hmbcloud.com
    - hmbcloud.net
    - hmbiplc-01.com
    - iepl.node.cm
    - javacheck.ooguy.com
    - javaupdate.giize.com
    - sexytube0.com
    - twimg.co.uk
    - HTTP-based C2 communications
    slug: command-and-control-obfuscated-channels
    tactic: command-and-control
    techniques:
    - T1071
  - name: Email Data Collection
    observables:
    - Querying user mailbox data via DiagTrack.exe
    slug: collection-mailbox-exfiltration
    tactic: collection
    techniques:
    - T1041
  summary: Chinese government-linked threat actors, enabled by Integrity Technology
    Group, use a combination of automated scanning tools like MicroScan and manual
    exploitation to target global organizations. They establish persistence using
    legitimate VPN software like SoftEther and perform large-scale password spraying
    with EBurst to exfiltrate sensitive email data and credentials.
series:
  index: 1
  slug: chinese-government-linked-cyber-threat-actors-combine-automated-and-hands-on-hacking-tools-to-st
  title: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on
    Hacking Tools to Steal Sensitive Data
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Perimeter Exploitation and Evasive VPN Persistence

This hunt targets the phased intrusion tactics of Integrity Technology Group. It begins by identifying vulnerable perimeter assets and looking for rare web exploitation probes or masqueraded payloads like DiagTrack.exe. The hunt then pivots to find evidence of persistence via VPN software (SoftEther) that has been renamed to masquerade as native Windows processes, identifying these by their rare hashes. Finally, it correlates this behavior with network traffic to known malicious infrastructure while excluding benign browser noise.

## affected-vulnerable-hosts
<!-- Identify vulnerable perimeter hosts -->
Scope the hunt to assets with known vulnerabilities in Jenkins, WordPress, or Exchange mentioned in the advisory.

```sqlite target=endpoint role=scoping params=(target_cves=target_cves)
~~~yaml
expected: A list of device_uids and the specific CVEs they are vulnerable to. Silence
  means no known vulnerable software is exposed.
reads:
- affected_package_name
- cve_uid
- device_uid
- severity
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_uid, cve_uid, affected_package_name, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0
```

## early-indicators
<!-- Hunt for early breach indicators -->
parallel:
- → web-exploitation-probes
- → masqueraded-initial-payload
join: → early-stage-triage

## web-exploitation-probes
<!-- Search for web exploitation probes -->
Find rare url_path values or access to administrative configuration files from external IPs.

```sqlite target=web role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Rarely accessed configuration files or specific scanner user-agents. Silence
  suggests no automated probing matched these signatures.
prevalence:
  by: device_hostname
  key:
  - url_path
  rare_below: 3
reads:
- device_hostname
- src_endpoint_ip
- time
- url_path
- user_agent
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT src_endpoint_ip, url_path, user_agent, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%config.php' OR LOWER(url_path) LIKE '%web.config' OR LOWER(user_agent) LIKE '%dirsearch%' OR LOWER(user_agent) LIKE '%fscan%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, url_path, user_agent HAVING host_count < 3 ORDER BY host_count ASC
```

## masqueraded-initial-payload
<!-- Detect masqueraded payload execution -->
Find execution of DiagTrack.exe that is either fileless (injected) or running from a non-standard path.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: DiagTrack.exe running from outside System32 or with on_disk=0 is a high-confidence
  indicator of masquerading. Silence proves absence on monitored hosts.
reads:
- device_hostname
- on_disk
- parent_process_name
- process_name
- process_path
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, process_path, parent_process_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\diagtrack.exe' AND (on_disk = 0 OR LOWER(process_path) NOT LIKE 'c:\\windows\\system32\\%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-stage-triage
<!-- Assess early breach indicators -->
```agent target=hunter
cite: required
context:
- affected-vulnerable-hosts
- web-exploitation-probes
- masqueraded-initial-payload
max_iterations: 4
objective: Determine if any host showing suspicious HTTP traffic also executed a masqueraded
  binary within a tight time window.
success_criteria: A verdict of malicious | suspicious | benign citing specific rows.
tools:
- endpoint
- web
```

## follow-on-indicators
<!-- Hunt for persistence and C2 -->
parallel:
- → vpn-masquerading-persistence
- → c2-infrastructure-traffic
join: → full-intrusion-triage

## vpn-masquerading-persistence
<!-- Identify VPN binary masquerading -->
Find renamed VPN binaries (conhost.exe, dllhost.exe) by searching for rare hashes that differ from the native Windows files.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A rare hash for conhost.exe or dllhost.exe. Native Windows binaries will
  have a very high host count; a renamed SoftEther client will be rare.
prevalence:
  by: device_hostname
  key:
  - process_hash_sha256
  rare_below: 3
reads:
- device_hostname
- process_cmd_line
- process_hash_sha256
- process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT process_hash_sha256, process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\conhost.exe' OR LOWER(process_name) LIKE '%\\dllhost.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_hash_sha256, process_name, process_cmd_line HAVING hosts < 3 ORDER BY hosts ASC
```

## c2-infrastructure-traffic
<!-- Detect C2 infrastructure traffic -->
Match DNS requests against infrastructure domains attributed to Integrity Technology Group, excluding benign browser noise.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, c2_domains=c2_domains, scope_hosts=scope_hosts)
~~~yaml
expected: DNS resolutions for the specified domains from non-browser processes. Silence
  proves absence only for these specific IOCs.
reads:
- device_hostname
- process_name
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND LOWER(process_name) NOT LIKE '%chrome.exe' AND LOWER(process_name) NOT LIKE '%msedge.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## full-intrusion-triage
<!-- Evaluate full intrusion chain -->
```agent target=hunter
cite: required
context:
- early-stage-triage
- vpn-masquerading-persistence
- c2-infrastructure-traffic
max_iterations: 6
objective: Establish if the suspicious binary execution or VPN persistence is linked
  to the identified C2 domains or exploitation probes across the Phased flow.
success_criteria: A final verdict citing the linkage between initial execution and
  persistent C2 behavior.
tools:
- endpoint
- web
```

## route-on-verdict
<!-- Route on verdict -->
if~: "the full-intrusion-triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: incomplete-telemetry)
else: → analyst-review

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host from the network and collect the masqueraded binaries for forensic analysis.
```
→ analyst-review

## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the rows cited by the agents. Verify the rarity of the URL paths and process hashes. Confirm if the 'diagtrack.exe' instances were indeed masqueraded or legitimate telemetry service activity.
```
→ close-out

## close-out
<!-- Close out hunt -->
```manual target=analyst
Summarize the hunt results. If renamed binaries like DiagTrack.exe or rare conhost.exe hashes were confirmed, promote the detection-candidate query to a standing rule and update the local blocklist with the identified SHA256 hashes.
```
→ end
