This detection rule identifies adversary activity leveraging Evilginx’s advanced man-in-the-middle phishing capabilities to intercept and manipulate multi-factor authentication sessions. A proactive hunt is essential within Azure Sentinel to uncover stealthy credential theft attacks that bypass traditional MFA defenses by analyzing real-time traffic against known Evilginx indicators of compromise.
Malware Family: Evilginx Total IOCs: 2 IOC Types: ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 198[.]135[.]54[.]91:2030 | botnet_cc | 2026-08-18 | 75% |
| ip:port | 185[.]212[.]128[.]51:9000 | botnet_cc | 2026-08-18 | 75% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Evilginx
let malicious_ips = dynamic(["198.135.54.91", "185.212.128.51"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["198.135.54.91", "185.212.128.51"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
Here are the documented false positive scenarios for the ThreatFox: Evilginx IOCs detection rule, including specific contexts and recommended filters:
Scenario: Scheduled Cloud Backup Synchronization
Scenario: Automated Software Patching via WSUS/SCCM
*.update.microsoft.com). Implement a filter based on the User-Agent string containing “Microsoft-Update” to distinguish patching traffic from user browser sessions.Scenario: Enterprise SSO and Identity Federation Traffic