Finding family: AccessFinding family: Engagement

Two engagements, traced step by step

01 · WORKED EXAMPLE

From question to retrieval, one step at a time.

The walkthroughs below are illustrative and composite — they show how the loop runs, not a specific customer incident. Each links to a published report demonstrating comparable observation capability.

Action stream Illustrative sequence
  1. T+00:00 Ingress pushes a hidden, randomly named binary into a world-writable temp directory over SSHone SSH session per step; the filename changes with every drop, the hash does not
  2. T+00:01 Ingress marks the dropped file executablea second session from the same source, one second later
  3. T+00:05 Ingress launches it detached, output redirected to a hidden sibling logmark-executable, then a detached launch from a temp path: a pre-encryption detection seam
  4. T+00:07 Maneuver starts, then unlinks its own binary, log and lock filegone from disk within seconds, still held open by the running process
  5. T+ ··:·· Maneuver enumerates running processes and stops database enginesbefore any file is touched; failures are logged, not blocking
  6. T+01:13 Effects writes a victim-ID file whose name encodes the infection timethe filename alone dates the infection to the nanosecond
  7. T+01:13 Effects encrypts user files and appends a new extension241 files in about 15 seconds in one observed cycle
  8. T+ ··:·· Maneuver fans out SSH brute-force scanning from the same processconcurrent with encryption: by the time files change, the next targets are already being tried
  9. T+01:28 Effects completes the encryption passa zero-byte marker flags the host as already processed; its path, not its hash, is the indicator

Illustrative sequence based on published OHIIHO Research: Catching Sorry-worm in the wild [1/3] ↗. Composite and sanitized; timings from the published session record, untimed steps are ordered, not timed.

Example A — Contact Point / access validation

Question — is this appliance profile receiving broad scanning or systematic credential validation?
Exposure — a selected Internet-facing persona.
Engagement — repeated authentication interaction on a Contact Point.
Observations — credential sequence, timing, source context and client characteristics.

HIIH FindingFinding family: Access Illustrative example
Confidence High
Observed activity
Repeated credential validation against a selected appliance persona
Mission relevance
Sector-relevant
Why it matters
Behavior is more consistent with access validation than isolated opportunistic scanning
Supporting material
Authentication events, timing cluster, related fingerprints
Suggested action
Review exposed credential risk, adjust monitoring and brief the relevant team
Delivery
Surface Console · MCP · API — pull-based

Comparable capability in public Research: Residential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions ↗

Example B — Live Host / post-access behavior

Question — what does an operator do after obtaining a shell?
Engagement — the actor authenticates to a controlled Live Host.
Observations — commands, tools, transferred files, attempted persistence or pivots, and related network activity.

HIIH FindingFinding family: Engagement Illustrative example
Confidence Medium
Observed activity
Operator activity on a controlled Live Host
Mission relevance
Profile-specific
Why it matters
Structured assessment of the operator's post-access objective and tradecraft
Supporting material
Session replay, files and hashes, command sequence, network context
Suggested action
Feed detection engineering, hunting content and incident-readiness exercises
Delivery
Inspectable in the Surface Console

Comparable capability in public Research: Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid ↗

Analytical restraint
Observation is direct. Interpretation stays disciplined.
HIIH collects richer target-side evidence; it does not manufacture certainty. Source IP is not actor identity; a payload is not attribution; a single command may not establish intent; and some activity stays noise and never becomes a Finding. Confidence depends on repeated behavior, context and supporting material.
02 · RESEARCH EVIDENCE

The loop is grounded in primary observation.

Finding family: Engagement
Deep engagement / post-access behavior
Observed — a Go ransomware-worm executing inside a controlled target. Supporting material — session records, files and tooling recovered during the engagement. Outcome — behavioral analysis plus detection and hunting content.
Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid · 2026-05 Read the research →
Finding family: Engagement
Agentic operator workflow
Observed — AI-enabled tooling used to assemble and run an intrusion-support workflow, seen inside a controlled environment. Supporting material — session activity, generated artifacts and operating patterns. Outcome — analysis of how AI-assisted tooling reshapes an intrusion, with defensive framing.
The AI Did Not Write the Phish. It Built the Business. · 2026-06 Read the research →
Finding family: Access
Artifact recovery to detection output
Observed — exploitation pressure against an exposed appliance profile, captured from the target side. Supporting material — request patterns, tooling and the sequence of what was attempted. Outcome — the controls that interrupted the activity, plus shareable detection content.
FortiBleed from the Target Side: What Stops Them · 2026-06 Read the research →
Finding family: Access
Selected exposure / access validation
Observed — residential-sourced credential-validation activity, probing SSH across multiple regions, captured target-side. Supporting material — authentication sequences, client characteristics, timing and infrastructure patterns. Outcome — indicators and detection context for credential-validation behavior distinct from broad scanning.
Residential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions · 2026-06 Read the research →

OHIIHO Research is the editorial research function of the same organization. Explore evidence from Research ↗