This hypothesis posits that adversaries are actively deploying the Hook malware to establish persistence and exfiltrate sensitive data through its three distinct indicators of compromise within the Azure environment. Proactive hunting for these specific IOCs is critical to identify early-stage infections before they escalate into widespread lateral movement or data breaches, leveraging Azure Sentinel’s real-time correlation capabilities to mitigate high-severity risks.
Malware Family: Hook Total IOCs: 3 IOC Types: ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 118[.]107[.]45[.]29:50555 | botnet_cc | 2026-07-12 | 75% |
| ip:port | 118[.]107[.]45[.]70:50555 | botnet_cc | 2026-07-12 | 75% |
| ip:port | 118[.]107[.]45[.]73:50555 | botnet_cc | 2026-07-12 | 75% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Hook
let malicious_ips = dynamic(["118.107.45.70", "118.107.45.29", "118.107.45.73"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["118.107.45.70", "118.107.45.29", "118.107.45.73"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: Hook IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
Endpoint Protection Policy Deployment via SCCM/Intune
Process_Name is ccmexec.exe, MicrosoftEdgeUpdate.exe, or IntuneManagementExtension.exe, and the File_Hash matches the known internal artifact hashes stored in the CMDB for the current month’s deployment cycle.Scheduled Database Maintenance Jobs
Event_ID 104 (Task Scheduler) where the Task_Name contains keywords like “DB_Maintenance,” “Index_Optimization,” or “Log_Backup,” and the execution path is restricted to the internal C:\Program Files\EnterpriseTools\SQLJobs\ directory.Legacy Application Patching via WSUS