From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Executive summary
Sourced behaviors include user execution of a malicious MSI, msiexec execution, DLL side-loading, process injection, PowerShell, network discovery, RDP/SMB/WinRM lateral movement, NTDS credential access, and ransomware impact. The observable set contains 11 IPv4 addresses, 2 URLs, 3 MD5 hashes, 3 SHA-256 hashes, and 79 parser-domain results. Parser-domain output is retained for traceability; executable names, filenames, code tokens, redacted values, and other non-domain strings are explicitly false positives and are not blocklist recommendations.
Technical analysis
Sourced behaviors include user execution of a malicious MSI, msiexec execution, DLL side-loading, process injection, PowerShell, network discovery, RDP/SMB/WinRM lateral movement, NTDS credential access, and ransomware impact. The observable set contains 11 IPv4 addresses, 2 URLs, 3 MD5 hashes, 3 SHA-256 hashes, and 79 parser-domain results. Parser-domain output is retained for traceability; executable names, filenames, code tokens, redacted values, and other non-domain strings are explicitly false positives and are not blocklist recommendations.
Evidence and sources
The DFIR Report published From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira on 2026-06-29, describing Bing SEO poisoning, a trojanized MSI, Bumblebee, AdaptixC2 activity, lateral movement, credential access, and Akira ransomware; the report lists the associated network, URL, hash, and parser-domain observations.
The DFIR Report published From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira on 2026-06-29, describing Bing SEO poisoning, a trojanized MSI, Bumblebee, AdaptixC2 activity, lateral movement, credential access, and Akira ransomware; the report lists the associated network, URL, hash, and parser-domain observations.
IOCs
109.205.195.211
170.130.55.223
171.22.183.43
172.96.137.160
185.174.100.203
188.40.187.145
192.121.22.94
193.242.184.150
194.127.178.21
4.239.95.1
84.32.84.32
124a48b78060fa851e1cc077ca35713c
8c113b3aa82c81eee7c6b4ed0ba9a90f
ca8646dfc88423bb9fffda811160cebe
186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da
a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331
de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19d
https://tria.ge/250530-ttmjhayzhw
https://tria.ge/250812-zw4tfszpy4
1.ps1
10.redacted
2rxyt8yrhq0bgj.org
2rxyt9urhq0bgj.org
5ka8rxp6t6eup2.org
6cimu4mc085em8.org
8doj8uvx604eck.org
adgnsy.exe
advanced-ip-scanner.msi
asazqzdjz.avhdx
atexec.py
certgraveyard.org
cmd.exe
comsvcs.dll
consent.exe
d1hmxkpwby0d4s.org
delete.me
detection.fyi
download-center.online
download-server.online
ev2sirbd269o5j.org
ewujsfb1dp5ran.org
explorer.exe
g7wo.sys
hlpdrv.sys
hosts1.txt
icardagt.exe
ip-scanner.org
kernelbase.dll
ks501oz9nm3v05.org
kwywztxoo2xdot.org
ky1d1p1daahe5t.org
locker.exe
manageengine-opmanager.msi
mmc20.application
mmcexec.py
msimg32.dll
msimg32d.dll
n.exe
net.exe
netml.shop
nltest.exe
ntdll.dll
ntds.dit
opmanager.pro
ovh1kn1tcqw5kp.org
powershell.exe
psql.exe
recentservers.xml
redacted.lan
redacted.lan.txt
redacted.txt
rundll32.exe
rustdesk.exe
rwdrv.sys
shares.txt
shopping5.shop
sigmasearchengine.com
smbexec.py
soft-hub.pro
soft-server.online
spn.txt
ssh.exe
taskmgr.exe
tria.ge
trustanchors.txt
u8vfsh.docx
urlscan.io
v5rjsdqogstopr.org
vector
version.dll
wab.exe
wbadmin.exe
whoami.exe
win.exe
wmiexec.py
wmiprvse.exe
yj6jurm5qqkye5.org
zenmap.pro
CVEs and affected products
No CVE or affected product is available.
ATT&CK mapping
Drive-by Compromise
Tactic: initial-access
User Execution: Malicious File
Tactic: execution
System Binary Proxy Execution: Msiexec
Tactic: defense-evasion
Hijack Execution Flow: DLL Side-Loading
Tactic: persistence
Process Injection
Tactic: defense-evasion
PowerShell
Tactic: execution
Remote System Discovery
Tactic: discovery
Remote Services: RDP
Tactic: lateral-movement
SMB/Windows Admin Shares
Tactic: lateral-movement
Windows Remote Management
Tactic: lateral-movement
OS Credential Dumping: NTDS
Tactic: credential-access
Data Encrypted for Impact
Tactic: impact
Detection content
Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.
Threat hunting
Hypothesis-driven hunt procedures and telemetry checklist.
Remediation
Containment actions, patching notes, and credential steps.
Historical relationships
No published historical relationship is available.
Timeline and change history
Confidence and caveats
0.95
⚠️ Public threat intelligence only; no organizational exposure claim.
⚠️ VirusTotal/OTX enrichment is time-sensitive context, not proof of current maliciousness.
⚠️ AbuseIPDB returned HTTP 401 and supplied no score.
⚠️ Parser-domain results are not validated domains and include false positives.
⚠️ No YARA rule is generated because the supplied evidence contains hashes and observable behavior but no file or memory byte/string evidence.