Two engagements, traced step by step
From question to retrieval, one step at a time.
The walkthroughs below are illustrative and composite — they show how the loop runs, not a specific customer incident. Each links to a published report demonstrating comparable observation capability.
- T+00:00 Ingress pushes a hidden, randomly named binary into a world-writable temp directory over SSHone SSH session per step; the filename changes with every drop, the hash does not
- T+00:01 Ingress marks the dropped file executablea second session from the same source, one second later
- T+00:05 Ingress launches it detached, output redirected to a hidden sibling logmark-executable, then a detached launch from a temp path: a pre-encryption detection seam
- T+00:07 Maneuver starts, then unlinks its own binary, log and lock filegone from disk within seconds, still held open by the running process
- T+ ··:·· Maneuver enumerates running processes and stops database enginesbefore any file is touched; failures are logged, not blocking
- T+01:13 Effects writes a victim-ID file whose name encodes the infection timethe filename alone dates the infection to the nanosecond
- T+01:13 Effects encrypts user files and appends a new extension241 files in about 15 seconds in one observed cycle
- T+ ··:·· Maneuver fans out SSH brute-force scanning from the same processconcurrent with encryption: by the time files change, the next targets are already being tried
- T+01:28 Effects completes the encryption passa zero-byte marker flags the host as already processed; its path, not its hash, is the indicator
Illustrative sequence based on published OHIIHO Research: Catching Sorry-worm in the wild [1/3] ↗. Composite and sanitized; timings from the published session record, untimed steps are ordered, not timed.
Example A — Contact Point / access validation
Question — is this appliance profile receiving broad scanning or systematic credential validation?
Exposure — a selected Internet-facing persona.
Engagement — repeated authentication interaction on a Contact Point.
Observations — credential sequence, timing, source context and client characteristics.
- Observed activity
- Repeated credential validation against a selected appliance persona
- Mission relevance
- Sector-relevant
- Why it matters
- Behavior is more consistent with access validation than isolated opportunistic scanning
- Supporting material
- Authentication events, timing cluster, related fingerprints
- Suggested action
- Review exposed credential risk, adjust monitoring and brief the relevant team
- Delivery
- Surface Console · MCP · API — pull-based
Comparable capability in public Research: Residential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions ↗
Example B — Live Host / post-access behavior
Question — what does an operator do after obtaining a shell?
Engagement — the actor authenticates to a controlled Live Host.
Observations — commands, tools, transferred files, attempted persistence or pivots, and related network activity.
- Observed activity
- Operator activity on a controlled Live Host
- Mission relevance
- Profile-specific
- Why it matters
- Structured assessment of the operator's post-access objective and tradecraft
- Supporting material
- Session replay, files and hashes, command sequence, network context
- Suggested action
- Feed detection engineering, hunting content and incident-readiness exercises
- Delivery
- Inspectable in the Surface Console
Comparable capability in public Research: Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid ↗
The loop is grounded in primary observation.
OHIIHO Research is the editorial research function of the same organization. Explore evidence from Research ↗