This hunt detects adversary activity linked to the Aisuru threat actor by validating network and endpoint telemetry against a specific set of nine high-fidelity Indicators of Compromise (IOCs). Proactively hunting for these signals in Azure Sentinel is critical to identify early-stage intrusions or lateral movement attempts before they escalate into confirmed incidents, ensuring rapid containment within the cloud environment.
Malware Family: Aisuru Total IOCs: 9 IOC Types: domain, ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | ceranet.goliath.st | botnet_cc | 2026-07-12 | 100% |
| domain | 5748.reformuk.st | botnet_cc | 2026-07-12 | 100% |
| domain | s.goliath.st | botnet_cc | 2026-07-12 | 100% |
| domain | hardload.su | botnet_cc | 2026-07-12 | 100% |
| domain | u.idsource.su | botnet_cc | 2026-07-12 | 100% |
| ip:port | 164[.]92[.]179[.]21:12345 | botnet_cc | 2026-07-12 | 100% |
| ip:port | 206[.]189[.]146[.]157:8443 | botnet_cc | 2026-07-12 | 100% |
| ip:port | 206[.]189[.]119[.]212:8443 | botnet_cc | 2026-07-12 | 100% |
| ip:port | 178[.]128[.]208[.]65:9034 | botnet_cc | 2026-07-12 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Aisuru
let malicious_ips = dynamic(["206.189.119.212", "164.92.179.21", "206.189.146.157", "178.128.208.65"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["206.189.119.212", "164.92.179.21", "206.189.146.157", "178.128.208.65"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Aisuru
let malicious_domains = dynamic(["ceranet.goliath.st", "5748.reformuk.st", "s.goliath.st", "hardload.su", "u.idsource.su"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the ThreatFox: Aisuru IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Endpoint Protection Scanning of Quarantine Artifacts
C:\ProgramData\ThreatFox\Quarantine directory. During these scans, the EDR agent may generate network telemetry or file access logs that match Aisuru IOCs if a previous legitimate threat report was cached in this folder, triggering the rule even though no active infection exists on the host.CrowdStrike.exe, MsMpEng.exe) when accessing paths containing “ThreatFox” or “Quarantine.” Additionally, filter out events where the process integrity is marked as “Verified” by the OS.Scheduled Threat Intelligence Feed Updates
Process Name being powershell.exe or python.exe combined with a specific Parent Process (e.g., TaskScheduler.exe). Furthermore, restrict the rule to trigger only outside of standard business hours (02:00–06:00 UTC) if the scheduled job runs during maintenance windows.**IT Admin Manual Investigation and IOC