← Back to SOC feed Coverage →

ThreatFox: AdaptixC2 IOCs

ioc-hunt HIGH ThreatFox
CommonSecurityLogDeviceNetworkEvents
aptiocthreatfoxwin-adaptix_c2
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-09-15T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt targets the presence of known AdaptixC2 indicators of compromise to identify potential command-and-control infrastructure or compromised assets within the environment. Proactively hunting for these IOCs is critical because AdaptixC2 is a high-severity threat often used for persistent access, allowing the SOC to detect and isolate adversaries before they can establish a foothold or execute further malicious actions.

IOC Summary

Malware Family: AdaptixC2 Total IOCs: 6 IOC Types: ip:port

TypeValueThreat TypeFirst SeenConfidence
ip:port69[.]48[.]229[.]91:8080botnet_cc2026-09-15100%
ip:port69[.]48[.]229[.]91:80botnet_cc2026-09-15100%
ip:port69[.]48[.]229[.]91:443botnet_cc2026-09-15100%
ip:port69[.]48[.]229[.]91:9443botnet_cc2026-09-15100%
ip:port38[.]54[.]88[.]188:65432botnet_cc2026-09-1575%
ip:port185[.]164[.]57[.]60:4999botnet_cc2026-09-1575%

KQL: Ip Hunt

// Hunt for network connections to known malicious IPs
// Source: ThreatFox - AdaptixC2
let malicious_ips = dynamic(["69.48.229.91", "38.54.88.188", "185.164.57.60"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc

KQL: Ip Hunt Device

// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["69.48.229.91", "38.54.88.188", "185.164.57.60"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DeviceNetworkEventsEnsure this data connector is enabled

References

False Positive Guidance

Original source: https://threatfox.abuse.ch/browse/malware/win.adaptix_c2/