Hermes CTI

← Back to all reports

threat updated

From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

● CRITICAL Confidence: 95% · Version 3

Executive summary

Sourced behaviors include user execution of a malicious MSI, msiexec execution, DLL side-loading, process injection, PowerShell, network discovery, RDP/SMB/WinRM lateral movement, NTDS credential access, and ransomware impact. The observable set contains 11 IPv4 addresses, 2 URLs, 3 MD5 hashes, 3 SHA-256 hashes, and 79 parser-domain results. Parser-domain output is retained for traceability; executable names, filenames, code tokens, redacted values, and other non-domain strings are explicitly false positives and are not blocklist recommendations.

Technical analysis

Sourced behaviors include user execution of a malicious MSI, msiexec execution, DLL side-loading, process injection, PowerShell, network discovery, RDP/SMB/WinRM lateral movement, NTDS credential access, and ransomware impact. The observable set contains 11 IPv4 addresses, 2 URLs, 3 MD5 hashes, 3 SHA-256 hashes, and 79 parser-domain results. Parser-domain output is retained for traceability; executable names, filenames, code tokens, redacted values, and other non-domain strings are explicitly false positives and are not blocklist recommendations.

Evidence and sources

The DFIR Report published From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira on 2026-06-29, describing Bing SEO poisoning, a trojanized MSI, Bumblebee, AdaptixC2 activity, lateral movement, credential access, and Akira ransomware; the report lists the associated network, URL, hash, and parser-domain observations.

Authoritative Source Advisories
Verified Evidence Claims

The DFIR Report published From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira on 2026-06-29, describing Bing SEO poisoning, a trojanized MSI, Bumblebee, AdaptixC2 activity, lateral movement, credential access, and Akira ransomware; the report lists the associated network, URL, hash, and parser-domain observations.

Attribution: The DFIR Report
95% Confidence Analysis 🔍

IOCs

109.205.195.211
ipv4 🔍
170.130.55.223
ipv4 🔍
171.22.183.43
ipv4 🔍
172.96.137.160
ipv4 🔍
185.174.100.203
ipv4 🔍
188.40.187.145
ipv4 🔍
192.121.22.94
ipv4 🔍
193.242.184.150
ipv4 🔍
194.127.178.21
ipv4 🔍
4.239.95.1
ipv4 🔍
84.32.84.32
ipv4 🔍
124a48b78060fa851e1cc077ca35713c
md5 🔍
8c113b3aa82c81eee7c6b4ed0ba9a90f
md5 🔍
ca8646dfc88423bb9fffda811160cebe
md5 🔍
186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da
sha256 🔍
a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331
sha256 🔍
de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19d
sha256 🔍
https://tria.ge/250530-ttmjhayzhw
url 🔍
https://tria.ge/250812-zw4tfszpy4
url 🔍
1.ps1
parser_domain 🔍
10.redacted
parser_domain 🔍
2rxyt8yrhq0bgj.org
parser_domain 🔍
2rxyt9urhq0bgj.org
parser_domain 🔍
5ka8rxp6t6eup2.org
parser_domain 🔍
6cimu4mc085em8.org
parser_domain 🔍
8doj8uvx604eck.org
parser_domain 🔍
adgnsy.exe
parser_domain 🔍
advanced-ip-scanner.msi
parser_domain 🔍
asazqzdjz.avhdx
parser_domain 🔍
atexec.py
parser_domain 🔍
certgraveyard.org
parser_domain 🔍
cmd.exe
parser_domain 🔍
comsvcs.dll
parser_domain 🔍
consent.exe
parser_domain 🔍
d1hmxkpwby0d4s.org
parser_domain 🔍
delete.me
parser_domain 🔍
detection.fyi
parser_domain 🔍
download-center.online
parser_domain 🔍
download-server.online
parser_domain 🔍
ev2sirbd269o5j.org
parser_domain 🔍
ewujsfb1dp5ran.org
parser_domain 🔍
explorer.exe
parser_domain 🔍
g7wo.sys
parser_domain 🔍
hlpdrv.sys
parser_domain 🔍
hosts1.txt
parser_domain 🔍
icardagt.exe
parser_domain 🔍
ip-scanner.org
parser_domain 🔍
kernelbase.dll
parser_domain 🔍
ks501oz9nm3v05.org
parser_domain 🔍
kwywztxoo2xdot.org
parser_domain 🔍
ky1d1p1daahe5t.org
parser_domain 🔍
locker.exe
parser_domain 🔍
manageengine-opmanager.msi
parser_domain 🔍
mmc20.application
parser_domain 🔍
mmcexec.py
parser_domain 🔍
msimg32.dll
parser_domain 🔍
msimg32d.dll
parser_domain 🔍
n.exe
parser_domain 🔍
net.exe
parser_domain 🔍
netml.shop
parser_domain 🔍
nltest.exe
parser_domain 🔍
ntdll.dll
parser_domain 🔍
ntds.dit
parser_domain 🔍
opmanager.pro
parser_domain 🔍
ovh1kn1tcqw5kp.org
parser_domain 🔍
powershell.exe
parser_domain 🔍
psql.exe
parser_domain 🔍
recentservers.xml
parser_domain 🔍
redacted.lan
parser_domain 🔍
redacted.lan.txt
parser_domain 🔍
redacted.txt
parser_domain 🔍
rundll32.exe
parser_domain 🔍
rustdesk.exe
parser_domain 🔍
rwdrv.sys
parser_domain 🔍
shares.txt
parser_domain 🔍
shopping5.shop
parser_domain 🔍
sigmasearchengine.com
parser_domain 🔍
smbexec.py
parser_domain 🔍
soft-hub.pro
parser_domain 🔍
soft-server.online
parser_domain 🔍
spn.txt
parser_domain 🔍
ssh.exe
parser_domain 🔍
taskmgr.exe
parser_domain 🔍
tria.ge
parser_domain 🔍
trustanchors.txt
parser_domain 🔍
u8vfsh.docx
parser_domain 🔍
urlscan.io
parser_domain 🔍
v5rjsdqogstopr.org
parser_domain 🔍
vector
parser_domain 🔍
version.dll
parser_domain 🔍
wab.exe
parser_domain 🔍
wbadmin.exe
parser_domain 🔍
whoami.exe
parser_domain 🔍
win.exe
parser_domain 🔍
wmiexec.py
parser_domain 🔍
wmiprvse.exe
parser_domain 🔍
yj6jurm5qqkye5.org
parser_domain 🔍
zenmap.pro
parser_domain 🔍

CVEs and affected products

No CVE or affected product is available.

ATT&CK mapping

Drive-by Compromise

Tactic: initial-access

User Execution: Malicious File

Tactic: execution

System Binary Proxy Execution: Msiexec

Tactic: defense-evasion

Hijack Execution Flow: DLL Side-Loading

Tactic: persistence

Process Injection

Tactic: defense-evasion

PowerShell

Tactic: execution

Remote System Discovery

Tactic: discovery

Remote Services: RDP

Tactic: lateral-movement

SMB/Windows Admin Shares

Tactic: lateral-movement

Windows Remote Management

Tactic: lateral-movement

OS Credential Dumping: NTDS

Tactic: credential-access

Data Encrypted for Impact

Tactic: impact

Detection content

Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.

Open dedicated detections page →

Threat hunting

Hypothesis-driven hunt procedures and telemetry checklist.

Open dedicated hunt page →

Remediation

Containment actions, patching notes, and credential steps.

Open dedicated remediation page →

Historical relationships

No published historical relationship is available.

Timeline and change history

Source publication: The DFIR Report published From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira.

Confidence and caveats

0.95

⚠️ Public threat intelligence only; no organizational exposure claim.

⚠️ VirusTotal/OTX enrichment is time-sensitive context, not proof of current maliciousness.

⚠️ AbuseIPDB returned HTTP 401 and supplied no score.

⚠️ Parser-domain results are not validated domains and include false positives.

⚠️ No YARA rule is generated because the supplied evidence contains hashes and observable behavior but no file or memory byte/string evidence.