This hunt targets adversary activity involving specific Indicators of Compromise (IOCs) linked to the Aisuru threat actor, which may indicate reconnaissance or initial access attempts within the network. Proactively hunting for these signatures in Azure Sentinel is critical because early detection of these high-severity IOCs allows the SOC team to isolate potential threats before they escalate into a full-blown incident.
Malware Family: Aisuru Total IOCs: 10 IOC Types: ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 167[.]172[.]80[.]107:8001 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 161[.]35[.]125[.]247:8001 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 159[.]65[.]143[.]171:8001 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 168[.]144[.]135[.]136:8001 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 137[.]184[.]135[.]42:8001 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 162[.]243[.]163[.]143:8001 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 207[.]148[.]66[.]2:12345 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 45[.]77[.]32[.]3:8001 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 45[.]76[.]146[.]2:34567 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 149[.]28[.]158[.]66:8443 | botnet_cc | 2026-07-19 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Aisuru
let malicious_ips = dynamic(["161.35.125.247", "162.243.163.143", "159.65.143.171", "207.148.66.2", "45.76.146.2", "167.172.80.107", "45.77.32.3", "137.184.135.42", "168.144.135.136", "149.28.158.66"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["161.35.125.247", "162.243.163.143", "159.65.143.171", "207.148.66.2", "45.76.146.2", "167.172.80.107", "45.77.32.3", "137.184.135.42", "168.144.135.136", "149.28.158.66"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: Aisuru IOCs detection rule, along with suggested filters and exclusions tailored for an enterprise environment:
Scheduled Vulnerability Scanning by Qualys or Tenable
10.20.50.0/24) or filter out events where the source process is identified as qualysagent.exe or tenable-agent.Automated Threat Intelligence Feed Updates via CrowdStrike Falcon
443 (HTTPS) and the source process path matches the EDR installation directory (e.g., C:\Program Files\CrowdStrike\fs.exe) during the designated maintenance window (e.g., 02:00–04:00 local time).IT Admin Manual Investigation using Microsoft Defender for Endpoint