This detection rule identifies potential unknown malware infections by correlating network and endpoint telemetry against a curated set of 33 Indicators of Compromise (IOCs) from ThreatFox. Proactive hunting for these signals in Azure Sentinel is critical to uncover stealthy threats that evade signature-based defenses, allowing the SOC team to rapidly isolate affected assets before lateral movement occurs.
Malware Family: Unknown malware Total IOCs: 33 IOC Types: url, domain, ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 141[.]11[.]109[.]12:7443 | botnet_cc | 2026-08-26 | 100% |
| ip:port | 49[.]235[.]130[.]208:60000 | botnet_cc | 2026-08-26 | 75% |
| domain | mail.spark-trail95.xyz | botnet_cc | 2026-08-26 | 100% |
| ip:port | 45[.]83[.]207[.]111:8443 | botnet_cc | 2026-08-26 | 75% |
| domain | shieldprotect.duckdns.org | botnet_cc | 2026-08-26 | 100% |
| url | hxxps://storyfinder.us/ | payload_delivery | 2026-08-26 | 90% |
| url | hxxps://cdken.com/ | payload_delivery | 2026-08-26 | 90% |
| domain | lean.brilliancespontaneous.shop | botnet_cc | 2026-08-26 | 100% |
| ip:port | 158[.]94[.]210[.]86:443 | botnet_cc | 2026-08-26 | 100% |
| domain | skullcode1.myddns.me | botnet_cc | 2026-08-26 | 100% |
| ip:port | 213[.]152[.]162[.]110:43148 | botnet_cc | 2026-08-26 | 75% |
| domain | darkprn3d3udnhpuxknsrhft3376lrz5tenhgkrxge5hxqe46pkbrwid.onion | botnet_cc | 2026-08-26 | 100% |
| domain | jsqsgn6vehow5jnjqohteaqnhko6pmdvjzbim57bdvdtgobrmoibjzad.onion | botnet_cc | 2026-08-26 | 100% |
| domain | frwvvaqob3ofmegrbc4q2ovtwyf5u7ozyyv35unib3saq3ppx2pkwuad.onion | botnet_cc | 2026-08-26 | 100% |
| domain | 667k2ck7qlzoqt52i6dq7evcfzko2ezfrhgv6zziccjet2cc653kvbid.onion | botnet_cc | 2026-08-26 | 100% |
| domain | e6q3vpkqpqjnerdtseb5wkgmuluqfsluu2sgwjghtrlf2u2pzybrlzid.onion | botnet_cc | 2026-08-26 | 100% |
| domain | kic4bflgzxoo2oq5wn52frqpzba2b75iodhqjgtdulchdeph73kq6zqd.onion | botnet_cc | 2026-08-26 | 100% |
| domain | 7y6rr2oawf63yf2zjdidijun7p6gtjqye7b44vqyvilva3or324k3kad.onion | botnet_cc | 2026-08-26 | 100% |
| domain | x4emye5homuwkrvrfaoql53hc5spbazkvcw3m4pv6jaj5tjqmjizleqd.onion | botnet_cc | 2026-08-26 | 100% |
| domain | 2zl5qc3mqap7vziqfis65oyjcgdiedigoequxbqsn6uwian7ieozvoqd.onion | botnet_cc | 2026-08-26 | 100% |
| domain | pokttabd2hod47ladeeoin22wmq4remyo3wshwvxfuhgqygcbezq2qqd.onion | botnet_cc | 2026-08-26 | 100% |
| domain | x2jz63qemhcbhyskzt3pie757oicdkctk2rh5dpykmxsw2yoayeqs5yd.onion | botnet_cc | 2026-08-26 | 100% |
| domain | t2ru74fbgut26xnagtrl4ajeh5vqytrl6cpr6cubmr6sqdxk5guh5mqd.onion | botnet_cc | 2026-08-26 | 100% |
| domain | wjcml4mxpcvsmjxm33zhjb46nzutxk6g3f5w23fopgpwj6pqjcidiyqd.onion | botnet_cc | 2026-08-26 | 100% |
| domain | 3i5px2hibsyityv6jixnqba35yz25jekbwwumjdxjqzt3euqsygjx5id.onion | botnet_cc | 2026-08-26 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Unknown malware
let malicious_ips = dynamic(["213.152.162.110", "141.11.109.12", "158.94.210.86", "49.235.130.208", "45.83.207.111", "45.95.168.149"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["213.152.162.110", "141.11.109.12", "158.94.210.86", "49.235.130.208", "45.83.207.111", "45.95.168.149"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Unknown malware
let malicious_domains = dynamic(["mail.spark-trail95.xyz", "shieldprotect.duckdns.org", "lean.brilliancespontaneous.shop", "skullcode1.myddns.me", "darkprn3d3udnhpuxknsrhft3376lrz5tenhgkrxge5hxqe46pkbrwid.onion", "jsqsgn6vehow5jnjqohteaqnhko6pmdvjzbim57bdvdtgobrmoibjzad.onion", "frwvvaqob3ofmegrbc4q2ovtwyf5u7ozyyv35unib3saq3ppx2pkwuad.onion", "667k2ck7qlzoqt52i6dq7evcfzko2ezfrhgv6zziccjet2cc653kvbid.onion", "e6q3vpkqpqjnerdtseb5wkgmuluqfsluu2sgwjghtrlf2u2pzybrlzid.onion", "kic4bflgzxoo2oq5wn52frqpzba2b75iodhqjgtdulchdeph73kq6zqd.onion", "7y6rr2oawf63yf2zjdidijun7p6gtjqye7b44vqyvilva3or324k3kad.onion", "x4emye5homuwkrvrfaoql53hc5spbazkvcw3m4pv6jaj5tjqmjizleqd.onion", "2zl5qc3mqap7vziqfis65oyjcgdiedigoequxbqsn6uwian7ieozvoqd.onion", "pokttabd2hod47ladeeoin22wmq4remyo3wshwvxfuhgqygcbezq2qqd.onion", "x2jz63qemhcbhyskzt3pie757oicdkctk2rh5dpykmxsw2yoayeqs5yd.onion", "t2ru74fbgut26xnagtrl4ajeh5vqytrl6cpr6cubmr6sqdxk5guh5mqd.onion", "wjcml4mxpcvsmjxm33zhjb46nzutxk6g3f5w23fopgpwj6pqjcidiyqd.onion", "3i5px2hibsyityv6jixnqba35yz25jekbwwumjdxjqzt3euqsygjx5id.onion", "tjaaioz32salcoj63ttxra6nfqggwbcezkzpwnhyoiwq5tuimzmsb3qd.onion", "voidravenfortress.com", "facturacionmexico.net", "russk22.icu", "bratusferramentas.grupomoltz.com.br"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - Unknown malware
let malicious_urls = dynamic(["https://storyfinder.us/", "https://cdken.com/", "https://facturacionmexico.net/ok.js", "https://russk22.icu/"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Scenario: The enterprise’s endpoint protection suite (e.g., CrowdStrike Falcon or Microsoft Defender for Endpoint) automatically downloads and stages new definition updates containing IOCs that have not yet been fully cataloged in the internal threat intelligence platform. This often triggers when a “silent” update runs during off-hours, generating 30+ new hash signatures that match the rule’s threshold but represent legitimate vendor updates rather than unknown threats.
C:\Program Files\Microsoft Defender\MpCmdRun.exe or C:\ProgramData\CrowdStrike\FalconSensor\bin\csfalcon.exe, and filter out events occurring between 02:00 and 04:00 local time on weekdays.Scenario: A scheduled administrative job using PowerShell to perform a bulk software inventory scan across the domain utilizes a script that queries external threat intelligence APIs (such as VirusTotal or Hybrid-Analysis) for new application hashes. The script generates a batch of 35 IOCs representing newly installed legitimate business applications (e.g., Adobe Acrobat updates, Zoom client versions) which are currently marked as “unknown” in the local database until manual review is completed.
DOMAIN\svc-inventory or DOMAIN\admin-batch, and exclude IOCs associated with file paths under C:\Windows\SoftwareDistribution\Download or C:\Program Files (x86)\.Scenario: The organization’s DevOps pipeline executes a nightly CI/CD deployment where the build server pulls container images from an internal registry. During this process, the security scanner analyzes the image layers and generates IOCs for temporary build artifacts and dependencies that are not yet indexed in the global IOC repository, resulting in a high volume of “unknown” alerts during the deployment window