This detection rule identifies adversary behavior characterized by the deployment of an unknown Remote Access Trojan (RAT) through specific Indicators of Compromise (IOCs). Proactive hunting for these signals in Azure Sentinel is critical to rapidly isolate potential lateral movement and data exfiltration threats before they evolve into a persistent compromise.
Malware Family: Unknown RAT Total IOCs: 2 IOC Types: url, ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| url | hxxps://encalabrino.life/.ssa-auth-connect/scn/reff/ScreenConnect.ClientSetup.exe | payload_delivery | 2026-06-28 | 75% |
| ip:port | 91[.]92[.]33[.]132:9999 | botnet_cc | 2026-06-27 | 75% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Unknown RAT
let malicious_ips = dynamic(["91.92.33.132"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["91.92.33.132"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - Unknown RAT
let malicious_urls = dynamic(["https://encalabrino.life/.ssa-auth-connect/scn/reff/ScreenConnect.ClientSetup.exe"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: Unknown RAT IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Enterprise Endpoint Management Agent Updates
svc_falcon, Microsoft.AccountsControl) and filter out network connections originating from known vendor IP ranges listed in the ThreatFox intelligence feed for “Trusted Vendors.”IT Administration Remote Support Sessions
IT-Admins or HelpDesk security groups, suppress the alert. Additionally, whitelist the specific executable paths of these approved remote support tools (e.g., C:\Program Files\TeamViewer\TeamViewer_Service.exe).**Automated Backup and Data Synchronization Jobs