This hunt targets adversary activity linked to the Kuiper threat campaign by correlating Azure Sentinel logs against a curated set of 24 high-fidelity Indicators of Compromise (IOCs). Proactively hunting for these specific signatures is critical to detect early-stage reconnaissance or lateral movement that may evade standard alerting, ensuring rapid containment before the threat establishes persistence within the environment.
Malware Family: Kuiper Total IOCs: 24 IOC Types: sha256_hash, sha1_hash, md5_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| md5_hash | 43e647b9d685e1e5be276026df86d7e4 | payload | 2026-07-05 | 95% |
| md5_hash | 69ac856f989a3dc0d8bff532c6f7f331 | payload | 2026-07-05 | 95% |
| sha256_hash | 46880af4b7bbb74def06569aecda2d96702de4b8b7723b05af927674928ce327 | payload | 2026-07-05 | 95% |
| sha1_hash | 3acbcfe403d42d59ce337403a39201cad1107ad4 | payload | 2026-07-05 | 95% |
| sha256_hash | ccbf818a36523c19051d066f8e5edad655a478516afc916cd915aacca80dbcd2 | payload | 2026-07-05 | 95% |
| sha1_hash | a6b87c3a216ef6e26d483fa69151174b27a7c6f8 | payload | 2026-07-05 | 95% |
| sha256_hash | 422c55e0219b09d0262782b25420c601304f5d1b46a325f2b4859ef77244ff42 | payload | 2026-07-05 | 95% |
| sha1_hash | 116af423f975819cd0668484d7e0fb7c83460fb8 | payload | 2026-07-05 | 95% |
| md5_hash | 99755cc0b98e663e73aac9be9aa33c13 | payload | 2026-07-05 | 95% |
| sha256_hash | d9f15a43821328bf482e2945ff9da40fa05f382777819d8e9fa3aaae8704862d | payload | 2026-07-05 | 95% |
| sha1_hash | 612fb6725b2c4b8f2c0edf6a2de5b1e53c8b8a76 | payload | 2026-07-05 | 95% |
| md5_hash | ba3544437b369bbd4687a2ce30077a3f | payload | 2026-07-05 | 95% |
| sha1_hash | 114777ca06522cfb98a8c9e93fed5330e78dff56 | payload | 2026-07-05 | 95% |
| md5_hash | 1d870228df077b8fe89d4ab2043743d4 | payload | 2026-07-05 | 95% |
| sha256_hash | 0c422e9fc527cc1d97a81606a42a6bea2c83295552ec3ebd49adcb41e50650c8 | payload | 2026-07-05 | 95% |
| sha1_hash | 69e258ea6cb572bdb95f031ff22de0ccf5cfed05 | payload | 2026-07-05 | 95% |
| md5_hash | 17cd659fb2b7797352e5c33ce77d6cdc | payload | 2026-07-05 | 95% |
| sha256_hash | ef8fb137711aba179550d97b4dacda5644d17482b64e142934f429306044ce6b | payload | 2026-07-05 | 95% |
| sha1_hash | a6bb5b9f1835a0408ede5418fab2505702bc2f53 | payload | 2026-07-05 | 95% |
| md5_hash | 5744f69e672856a6879875f6118744f5 | payload | 2026-07-05 | 95% |
| sha256_hash | 1d3699b153b816e2e9129ecc2b5f7dcbe40d5aeee08bfa655d5f01b808d01906 | payload | 2026-07-05 | 95% |
| md5_hash | fafa05e543e97b4a881b864b5b4babb6 | payload | 2026-07-05 | 95% |
| sha256_hash | aff0445b3068a5edbb0a827fe06bbd1153d8939c1709f997d8f583252ba71359 | payload | 2026-07-05 | 95% |
| sha1_hash | 243c572dde1e2562bf66e526693a4ef53d83e185 | payload | 2026-07-05 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Kuiper
let malicious_hashes = dynamic(["43e647b9d685e1e5be276026df86d7e4", "69ac856f989a3dc0d8bff532c6f7f331", "46880af4b7bbb74def06569aecda2d96702de4b8b7723b05af927674928ce327", "3acbcfe403d42d59ce337403a39201cad1107ad4", "ccbf818a36523c19051d066f8e5edad655a478516afc916cd915aacca80dbcd2", "a6b87c3a216ef6e26d483fa69151174b27a7c6f8", "422c55e0219b09d0262782b25420c601304f5d1b46a325f2b4859ef77244ff42", "116af423f975819cd0668484d7e0fb7c83460fb8", "99755cc0b98e663e73aac9be9aa33c13", "d9f15a43821328bf482e2945ff9da40fa05f382777819d8e9fa3aaae8704862d", "612fb6725b2c4b8f2c0edf6a2de5b1e53c8b8a76", "ba3544437b369bbd4687a2ce30077a3f", "114777ca06522cfb98a8c9e93fed5330e78dff56", "1d870228df077b8fe89d4ab2043743d4", "0c422e9fc527cc1d97a81606a42a6bea2c83295552ec3ebd49adcb41e50650c8", "69e258ea6cb572bdb95f031ff22de0ccf5cfed05", "17cd659fb2b7797352e5c33ce77d6cdc", "ef8fb137711aba179550d97b4dacda5644d17482b64e142934f429306044ce6b", "a6bb5b9f1835a0408ede5418fab2505702bc2f53", "5744f69e672856a6879875f6118744f5", "1d3699b153b816e2e9129ecc2b5f7dcbe40d5aeee08bfa655d5f01b808d01906", "fafa05e543e97b4a881b864b5b4babb6", "aff0445b3068a5edbb0a827fe06bbd1153d8939c1709f997d8f583252ba71359", "243c572dde1e2562bf66e526693a4ef53d83e185"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the ThreatFox: Kuiper IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
Automated Vulnerability Scanning by Qualys
svc_qualys_scanner). Additionally, exclude traffic destined to the internal mirror server’s IP range if it is known to host these feeds.Patch Management Deployment via SCCM/MECM
TaskScheduler\Microsoft\SccmClient\SoftwareUpdates). Whitelist the destination domain of the threat intelligence API if it is a trusted vendor endpoint.Endpoint Detection and Response (EDR) Telemetry Upload