This hunt detects adversary activity by correlating network and endpoint telemetry against twelve specific Indicators of Compromise (IOCs) linked to the Kuiper threat actor within Azure Sentinel. Proactive hunting is critical because these IOCs represent known high-severity artifacts that may indicate early-stage reconnaissance or lateral movement before automated alerts trigger, allowing the SOC team to validate exposure and accelerate incident response.
Malware Family: Kuiper Total IOCs: 12 IOC Types: sha256_hash, md5_hash, sha1_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha256_hash | 862e54dc3f126e9bdc1c1be9c2abf1cea7348c39d22044b20bab193e74871e8e | payload | 2026-07-14 | 95% |
| sha1_hash | 5f9b041f77fb0af092e1e5a567cb3882e843fa64 | payload | 2026-07-14 | 95% |
| md5_hash | e22497172f8d4c6b9a465fdee1cd1c94 | payload | 2026-07-14 | 95% |
| sha256_hash | 3d37860fe035a6172640cdafc011fffcbf72f3a80674cc9cb4999cdc4da24a2f | payload | 2026-07-14 | 95% |
| sha1_hash | a468b7bb7e5f2e81da0aeb48ae1f962ce176ae0c | payload | 2026-07-14 | 95% |
| md5_hash | 04476cdf1450037de677bd47af342410 | payload | 2026-07-14 | 95% |
| sha256_hash | d9c0b912f48061c64b6603bc3d1f2958bc3d9752bc4934a5a9e1dceb3b90fe72 | payload | 2026-07-14 | 95% |
| sha1_hash | 3e20757561ad9ebd3141199994a3057a9eaf2eed | payload | 2026-07-14 | 95% |
| md5_hash | 684060325606206e6547f97e6cc8e423 | payload | 2026-07-14 | 95% |
| md5_hash | 071115ffd93938e9703e32d309dc887a | payload | 2026-07-14 | 95% |
| sha256_hash | 49e4ba4a041e13fd07567d4f5be07a4d9b26b356546ae1ba035dff0719c2ee63 | payload | 2026-07-14 | 95% |
| sha1_hash | 683d65ce0d91e87a2caa9a7591053a34b9745972 | payload | 2026-07-14 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Kuiper
let malicious_hashes = dynamic(["862e54dc3f126e9bdc1c1be9c2abf1cea7348c39d22044b20bab193e74871e8e", "5f9b041f77fb0af092e1e5a567cb3882e843fa64", "e22497172f8d4c6b9a465fdee1cd1c94", "3d37860fe035a6172640cdafc011fffcbf72f3a80674cc9cb4999cdc4da24a2f", "a468b7bb7e5f2e81da0aeb48ae1f962ce176ae0c", "04476cdf1450037de677bd47af342410", "d9c0b912f48061c64b6603bc3d1f2958bc3d9752bc4934a5a9e1dceb3b90fe72", "3e20757561ad9ebd3141199994a3057a9eaf2eed", "684060325606206e6547f97e6cc8e423", "071115ffd93938e9703e32d309dc887a", "49e4ba4a041e13fd07567d4f5be07a4d9b26b356546ae1ba035dff0719c2ee63", "683d65ce0d91e87a2caa9a7591053a34b9745972"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: Kuiper IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
Scheduled Vulnerability Scanning by Qualys or Tenable
qualyspc.exe, tenable_agent.exe, or similar scanner executables.Automated Patch Deployment via Microsoft SCCM/MECM
ccmexec.exe process (SCCM) where the destination domain matches known internal Content Distribution Point (CDP) FQDNs or specific external Microsoft Update CDN ranges that overlap with Kuiper IOCs.Cloud Backup and Replication Jobs by Veeam or Commvault