{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Unauthorized RMM deployment is a major vector for persistent access and ransomware preparation. This hunt ensures that even if individual file indicators rotate, the behavioral pattern of RMM tools communicating with non-standard IPs and ports is captured."
      },
      "name": "RMM Command and Control and Redundancy",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1090.003",
        "attack.t1572",
        "attack.t1021.001",
        "attack.t1566"
      ],
      "series": {
        "slug": "rogue-screenconnect-installations-across-unrelated-hosts-suggest-worm-like-activity",
        "index": 2,
        "title": "Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity",
        "total": 2
      },
      "related": [
        {
          "hunt": "rmm-vbs-script-execution-patterns",
          "reason": "This hunt focuses on network and process identity; a sibling hunt focuses on the internal VBS script content analysis via hb_script_activity.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "rogue-screenconnect-host-execution-persistence",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule on ScreenConnect or UltraViewer is too noisy for many environments. This hunt uses stack-counting (prevalence) to isolate rare installations and correlates them with network plane indicators (port 8041, known C2 IPs) that a static process rule would ignore.",
      "coverage": [
        {
          "stage": "network-c2-and-staged-download",
          "steps": [
            "lead-network-connections",
            "dns-c2-lookup"
          ],
          "status": "covered"
        },
        {
          "stage": "secondary-rmm-redundancy",
          "steps": [
            "rare-rmm-processes"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-social-engineering",
          "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "rogue-screenconnect-execution",
          "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "host-profiling-and-discovery",
          "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-via-run-key",
          "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "powershell-payload-decryption",
          "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Initial Access via Social Engineering",
            "slug": "initial-access-social-engineering",
            "tactic": "initial-access",
            "techniques": [
              "T1566",
              "T1021.001"
            ],
            "observables": [
              "Quick Assist",
              "ScreenConnect.ClientSetup.msi",
              "Geek Squad refund form"
            ]
          },
          {
            "name": "Rogue ScreenConnect and Script Execution",
            "slug": "rogue-screenconnect-execution",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "ScreenConnect.WindowsClient.exe",
              "ScreenConnect.Client.exe",
              "wscript.exe",
              "1.vbs",
              "2.vbs",
              "3.vbs",
              "4.vbs"
            ]
          },
          {
            "name": "Host Profiling and EDR Discovery",
            "slug": "host-profiling-and-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "1.vbs",
              "value.txt",
              "Huntress",
              "Cisco AMP",
              "CrowdStrike",
              "SentinelOne",
              "Sophos",
              "Malwarebytes",
              "Microsoft Defender",
              "RAM check > 5GB"
            ]
          },
          {
            "name": "Persistence via Registry Run Key",
            "slug": "persistence-via-run-key",
            "tactic": "persistence",
            "techniques": [
              "T1547.001"
            ],
            "observables": [
              "WindowsServiceHost",
              "WindowsServiceHost.vbs",
              "WindowsServiceHost.bat",
              "AppData"
            ]
          },
          {
            "name": "Network C2 and Staged Download",
            "slug": "network-c2-and-staged-download",
            "tactic": "command-and-control",
            "techniques": [
              "T1090.003",
              "T1572"
            ],
            "observables": [
              "45.13.237.190",
              "131.123.40.98",
              "15.204.185.204",
              "tele-sync.opik.net",
              "borertors92.anondns.net",
              "port 8041",
              "Dropbox",
              "map.txt",
              "user.enc",
              "acc.enc",
              "combo.enc"
            ]
          },
          {
            "name": "PowerShell Payload Decryption and Execution",
            "slug": "powershell-payload-decryption",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "runner.ps1",
              "PyTorchFix.ps1",
              "sys_cache.zip",
              "out.enc",
              "AES-CBC"
            ]
          },
          {
            "name": "Secondary RMM Deployment",
            "slug": "secondary-rmm-redundancy",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001"
            ],
            "observables": [
              "UltraViewer",
              "146.59.55.107",
              "45.32.192.150"
            ]
          }
        ],
        "summary": "Attackers leverage social engineering or phishing to deploy rogue ScreenConnect instances, which then execute a multi-stage VBScript chain to profile the host and bypass security products. The campaign establishes persistence through registry Run keys and downloads encrypted payloads from Dropbox, including secondary RMM tools like UltraViewer and tunneling utilities, with some samples exhibiting worm-like propagation via connected ScreenConnect endpoints."
      },
      "severity": "high",
      "rationale": "Focus on standard user workstations rather than servers, as the attack relies on social engineering and Quick Assist which are user-centric. Prioritize hosts where ScreenConnect is not a standard business tool.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker is using rogue ScreenConnect instances and secondary RMM tools to maintain persistence, identified by non-standard port connections and rare binaries running from user-writable directories.",
      "parameters": {
        "c2_ips": {
          "from": {
            "ref": "huntress-rogue-screenconnect",
            "kind": "article",
            "observed": "2026-09-03"
          },
          "type": "list[ip]",
          "default": [
            "45.13.237.190",
            "131.123.40.98",
            "15.204.185.204",
            "146.59.55.107",
            "45.32.192.150"
          ],
          "description": "C2 and relay IP addresses observed in the report."
        },
        "rmm_port": {
          "from": {
            "ref": "huntress-rogue-screenconnect",
            "kind": "article",
            "observed": "2026-09-03"
          },
          "type": "number",
          "default": "8041",
          "description": "The specific port used by the rogue ScreenConnect client for C2 communications."
        },
        "c2_domains": {
          "from": {
            "ref": "huntress-rogue-screenconnect",
            "kind": "article",
            "observed": "2026-09-03"
          },
          "type": "list[domain]",
          "default": [
            "tele-sync.opik.net",
            "borertors92.anondns.net"
          ],
          "description": "C2 domains linked to the IPs during August."
        },
        "rare_below": {
          "from": {
            "ref": "standard-prevalence",
            "kind": "manual",
            "observed": "2026-09-03"
          },
          "type": "number",
          "default": "3",
          "description": "Threshold for stack-counting rare processes across the estate."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-lookback",
            "kind": "manual",
            "observed": "2026-09-03"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/rogue-screenconnect-installations",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/rogue-screenconnect-installations",
          "name": "Huntress \u2014 Rogue ScreenConnect Installations Across Unrelated Hosts"
        }
      ],
      "blind_spots": [
        {
          "id": "encrypted-dns",
          "risk": "Resolutions to anondns.net would be invisible to standard DNS logs, making the DNS query step miss the activity.",
          "stage": "network-c2-and-staged-download",
          "question": "whether the attacker used DNS-over-HTTPS to resolve C2 domains",
          "requires": "hb_dns_activity with DoH decryption"
        },
        {
          "id": "http-path-visibility",
          "risk": "Without URL path visibility, we cannot distinguish legitimate Dropbox traffic from the attacker retrieving the staging map.",
          "stage": "network-c2-and-staged-download",
          "question": "whether the Dropbox download of map.txt occurred",
          "requires": "hb_http_activity with full URL path"
        }
      ]
    },
    "name": "RMM Command and Control and Redundancy",
    "description": "This hunt focuses on the network and software footprint of rogue ScreenConnect and UltraViewer deployments. It follows a funnel flow: starting with network leads on observed C2 ports and IPs, then fanning out to identify rare process metadata and dynamic DNS resolutions. By correlating these surfaces, the hunt identifies unauthorized remote management tools that bypass standard application controls and security product enumeration."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "rogue-screenconnect-installations-across-unrelated-hosts-suggest-worm-like-activity",
          "index": 2,
          "title": "Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity",
          "total": 2
        },
        "coverage": [
          {
            "stage": "network-c2-and-staged-download",
            "steps": [
              "lead-network-connections",
              "dns-c2-lookup"
            ],
            "status": "covered"
          },
          {
            "stage": "secondary-rmm-redundancy",
            "steps": [
              "rare-rmm-processes"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-social-engineering",
            "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "rogue-screenconnect-execution",
            "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "host-profiling-and-discovery",
            "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-via-run-key",
            "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "powershell-payload-decryption",
            "reason": "Belongs to another part of the 'Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker is using rogue ScreenConnect instances and secondary RMM tools to maintain persistence, identified by non-standard port connections and rare binaries running from user-writable directories.",
        "blind_spots": [
          {
            "id": "encrypted-dns",
            "risk": "Resolutions to anondns.net would be invisible to standard DNS logs, making the DNS query step miss the activity.",
            "stage": "network-c2-and-staged-download",
            "question": "whether the attacker used DNS-over-HTTPS to resolve C2 domains",
            "requires": "hb_dns_activity with DoH decryption"
          },
          {
            "id": "http-path-visibility",
            "risk": "Without URL path visibility, we cannot distinguish legitimate Dropbox traffic from the attacker retrieving the staging map.",
            "stage": "network-c2-and-staged-download",
            "question": "whether the Dropbox download of map.txt occurred",
            "requires": "hb_http_activity with full URL path"
          }
        ],
        "scoping_notes": "Focus on standard user workstations rather than servers, as the attack relies on social engineering and Quick Assist which are user-centric. Prioritize hosts where ScreenConnect is not a standard business tool.",
        "beyond_detection": "A single rule on ScreenConnect or UltraViewer is too noisy for many environments. This hunt uses stack-counting (prevalence) to isolate rare installations and correlates them with network plane indicators (port 8041, known C2 IPs) that a static process rule would ignore."
      }
    },
    {
      "id": "lead-network-connections",
      "type": "query",
      "label": "Network connections to C2 IPs and RMM ports",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR dst_endpoint_port = {{rmm_port}}) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_network_connection",
        "description": "Identify hosts communicating with the report's C2 infrastructure or using the ScreenConnect C2 port.",
        "expected_signal": "Rows indicating connections to known bad IPs or the specific RMM port. Silence suggests these network indicators are absent from the logs."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Network connections to C2 IPs and RMM ports",
        "reads": [
          "device_hostname",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "process_name",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR dst_endpoint_port = {{rmm_port}}) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Rows indicating connections to known bad IPs or the specific RMM port. Silence suggests these network indicators are absent from the logs.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "dns-c2-lookup",
      "type": "query",
      "label": "DNS resolutions for C2 domains",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Check for lookup activity against the reported dynamic DNS domains.",
        "expected_signal": "Hosts resolving the malicious domains. Silence means no lookups occurred in the monitored window."
      },
      "parents": [
        {
          "id": "lead-network-connections"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS resolutions for C2 domains",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Hosts resolving the malicious domains. Silence means no lookups occurred in the monitored window.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "rare-rmm-processes",
      "type": "query",
      "label": "Rare RMM binaries in user directories",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_original_file_name, COUNT(DISTINCT device_hostname) AS hosts FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_name) LIKE '%ultraviewer%' OR LOWER(process_original_file_name) IN ('screenconnect.client.exe', 'ultraviewer_desktop.exe')) AND (LOWER(process_path) LIKE '%\\temp\\%' OR LOWER(process_path) LIKE '%\\appdata\\%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3, 4 HAVING hosts <= {{rare_below}}",
        "surface": "hb_process_activity",
        "description": "Find RMM software running from suspicious user-writable paths and stack-count them to find outliers.",
        "expected_signal": "A few hosts running RMM software from temporary or application data folders. Large counts across the estate suggest legitimate usage."
      },
      "parents": [
        {
          "id": "lead-network-connections"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare RMM binaries in user directories",
        "reads": [
          "device_hostname",
          "process_name",
          "process_original_file_name",
          "process_path",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_original_file_name, COUNT(DISTINCT device_hostname) AS hosts FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_name) LIKE '%ultraviewer%' OR LOWER(process_original_file_name) IN ('screenconnect.client.exe', 'ultraviewer_desktop.exe')) AND (LOWER(process_path) LIKE '%\\temp\\%' OR LOWER(process_path) LIKE '%\\appdata\\%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3, 4 HAVING hosts <= {{rare_below}}",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A few hosts running RMM software from temporary or application data folders. Large counts across the estate suggest legitimate usage.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_original_file_name",
            "process_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "triage-rmm-behavior",
      "type": "analytic",
      "label": "Triage RMM activity",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "lead-network-connections",
          "dns-c2-lookup",
          "rare-rmm-processes"
        ],
        "objective": "Identify hosts where ScreenConnect or UltraViewer are making connections to known C2 IPs, using port 8041, or resolving dynamic DNS, specifically when the processes are running from Temp or AppData paths. Note if any wscript.exe activity is visible in the process context.",
        "description": "Analyze network and process evidence to determine if the activity represents unauthorized RMM deployment and C2.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict of malicious | suspicious | benign.",
        "success_criteria": "The agent identifies malicious hosts with high-confidence network and process overlap."
      },
      "parents": [
        {
          "id": "dns-c2-lookup",
          "kind": "merge"
        },
        {
          "id": "rare-rmm-processes",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-rmm-behavior verdict is malicious for at least one host",
        "condition": "the triage-rmm-behavior verdict is malicious for at least one host",
        "blind_spot": "encrypted-dns",
        "confidence": "high",
        "description": "Direct the hunt based on the agent's findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-rmm-behavior"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Halt C2 and potential lateral movement from a confirmed rogue RMM deployment.",
        "instructions": "Isolate the host immediately via the EDR console and revoke active sessions for the impacted user.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-investigation",
      "type": "task",
      "label": "Analyst investigation",
      "config": {
        "assignee": "analyst",
        "description": "Manually verify the findings and check for the presence of the VBS loader chain.",
        "instructions": "Review the process tree for the identified hosts. Look for ScreenConnect.WindowsClient.exe spawning wscript.exe. Check the user's AppData and Temp directories for 1.vbs through 4.vbs or WindowsServiceHost.vbs."
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "default"
        },
        {
          "id": "route-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and determine if the lead query should be converted to a standing rule.",
        "instructions": "Record which hosts were true positives. If legitimate RMM tools were flagged, provide their paths as exclusions for the lead query. Update detection engineering if unauthorized software was found that was not already covered by a rule."
      },
      "parents": [
        {
          "id": "analyst-investigation"
        }
      ]
    }
  ]
}