This rule detects the presence of known indicators of compromise associated with the “Unknown RAT” malware family, which often leverages these IOCs for initial access or command-and-control communication. Proactively hunting for these signatures in Azure Sentinel allows the SOC team to identify compromised endpoints or network artifacts before the adversary can establish persistence or execute lateral movement within the environment.
Malware Family: Unknown RAT Total IOCs: 177 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | watfmedia.com | payload_delivery | 2026-09-09 | 100% |
| domain | wavehouse.info | payload_delivery | 2026-09-09 | 100% |
| domain | widecalfboots4u.com | payload_delivery | 2026-09-09 | 100% |
| domain | wikiverification.com | payload_delivery | 2026-09-09 | 100% |
| domain | winkyface.studio | payload_delivery | 2026-09-09 | 100% |
| domain | wizetup.com | payload_delivery | 2026-09-09 | 100% |
| domain | ybdstudiovn.com | payload_delivery | 2026-09-09 | 100% |
| domain | zeuzz.de | payload_delivery | 2026-09-09 | 100% |
| domain | zsiregetoshop.com | payload_delivery | 2026-09-09 | 100% |
| domain | tidepoch.com | payload_delivery | 2026-09-09 | 100% |
| domain | timelessadvisor.com | payload_delivery | 2026-09-09 | 100% |
| domain | toom-peerstall.de | payload_delivery | 2026-09-09 | 100% |
| domain | troovir.com | payload_delivery | 2026-09-09 | 100% |
| domain | turkab.org | payload_delivery | 2026-09-09 | 100% |
| domain | twopintplc.com | payload_delivery | 2026-09-09 | 100% |
| domain | underthebigskyfest.com | payload_delivery | 2026-09-09 | 100% |
| domain | updatespecialists.com | payload_delivery | 2026-09-09 | 100% |
| domain | urbancommunitycareers.com | payload_delivery | 2026-09-09 | 100% |
| domain | urbanous.com | payload_delivery | 2026-09-09 | 100% |
| domain | vdsverhuur.be | payload_delivery | 2026-09-09 | 100% |
| domain | veasysport.com | payload_delivery | 2026-09-09 | 100% |
| domain | veroniq.shop | payload_delivery | 2026-09-09 | 100% |
| domain | visionsofsuccess.com | payload_delivery | 2026-09-09 | 100% |
| domain | wackytronic.de | payload_delivery | 2026-09-09 | 100% |
| domain | sunset-journeys.com | payload_delivery | 2026-09-09 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Unknown RAT
let malicious_domains = dynamic(["watfmedia.com", "wavehouse.info", "widecalfboots4u.com", "wikiverification.com", "winkyface.studio", "wizetup.com", "ybdstudiovn.com", "zeuzz.de", "zsiregetoshop.com", "tidepoch.com", "timelessadvisor.com", "toom-peerstall.de", "troovir.com", "turkab.org", "twopintplc.com", "underthebigskyfest.com", "updatespecialists.com", "urbancommunitycareers.com", "urbanous.com", "vdsverhuur.be", "veasysport.com", "veroniq.shop", "visionsofsuccess.com", "wackytronic.de", "sunset-journeys.com", "surfszkola.pl", "susanteacuppuppies.com", "sussmanmarketingservices.com", "t24.is", "tatibudapest.com", "techempowerhub.net", "tehranjarsaghil.com", "teloreparogasteiz.com", "tevisystems.fi", "tfbworkwear.com", "thebus4u.co.uk", "theglobalbpo.com", "thehomepros.us", "thenaptimereviewer.com", "sethgillihan.com", "shop.use-domer-fotografie.de", "sideeffect.events", "signsexpressmedia.com", "simplenutrition.com.au", "skydivemp.com", "slareviews.com", "smalamed.com", "sob-fit.de", "softwords.us", "sportowepasje.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Scenario: Legacy Application Deployment via Group Policy
svchost.exe or explorer.exe path for its installer or updater. The ThreatFox IOC list may flag these generic paths or specific hash values if the software is outdated and not yet whitelisted in the threat intelligence feed.gpupdate.exe or gpedit.msc, or specifically whitelist the executable hash and path (e.g., C:\Program Files\LegacyApp\install.exe) if the application is confirmed as internal and signed by a known corporate certificate.Scenario: Scheduled Maintenance Jobs for Third-Party Tools
Task Scheduler job) runs a third-party utility like 7-Zip, WinRAR, or a specific log rotation script that uses a generic name such as update.exe or helper.exe. If the ThreatFox IOC list includes generic names or hashes associated with older versions of these tools, the scheduled execution will trigger the rule.schtasks.exe or Task Scheduler and the command line contains known maintenance keywords (e.g., /clean, /rotate, /backup). Alternatively, whitelist the specific scheduled task ID or the full command line string for these known utilities.Scenario: Development Environment Testing with Debuggers
WinDbg, x64dbg, or OllyDbg to analyze binaries. These tools often inject code or create temporary files with generic names (