logo

Piecing Together the Puzzle: A Qilin Ransomware Investigation

ID: c976df38-6157-57c8-91c3-60da94281a2b

STIX ID: report--c976df38-6157-57c8-91c3-60da94281a2b

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-22

Date Updated: 2026-07-18

Author: Sponsored by Huntress Labs

...
...

Huntress Labs investigated a Qilin ransomware incident where a rogue ScreenConnect instance (pointing to 94.156.232.40) was installed via malicious MSI, three files (r.ps1, s.exe, ss.exe) were transferred, Windows Defender was disabled, and ransom notes were observed; analysts used Event Logs, PCA logs, AmCache, and VirusTotal to recover artifacts and hashes despite the agent being installed post-incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.