This hunt detects adversary activity involving known Indicators of Compromise (IOCs) linked to the Medusa threat actor, which often targets financial and enterprise sectors through sophisticated phishing and lateral movement tactics. Proactively hunting for these 47 IOCs in Azure Sentinel is critical to identify early-stage intrusions before they escalate into significant data breaches or ransomware events.
Malware Family: Medusa Total IOCs: 47 IOC Types: md5_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| md5_hash | 047ac6aebe0fe80f9f09c5c548233407 | payload | 2026-09-02 | 50% |
| md5_hash | 084132b20ed65b2930129b156b99f5b3 | payload | 2026-09-02 | 50% |
| md5_hash | 0e43a0f747a60855209b311d727a20bf | payload | 2026-09-02 | 50% |
| md5_hash | 0f76936e237bd87dfa2378106099a673 | payload | 2026-09-02 | 50% |
| md5_hash | 1079d416e093ba40aa9e95a4c2a5b61f | payload | 2026-09-02 | 50% |
| md5_hash | 129ba90886c5f5eb0c81d901ad10c622 | payload | 2026-09-02 | 50% |
| md5_hash | 1b7aee68f384e252286559abc32e6dd1 | payload | 2026-09-02 | 50% |
| md5_hash | 1d89b48548ea1ddf0337741ebdb89d92 | payload | 2026-09-02 | 50% |
| md5_hash | 2716c60c28cf7f7568f55ac33313468b | payload | 2026-09-02 | 50% |
| md5_hash | 2c28ec2d541f555b2838099ca849f965 | payload | 2026-09-02 | 50% |
| md5_hash | 2bade2a5ec166d3a226761f78711ce2f | payload | 2026-09-02 | 50% |
| md5_hash | 381b7a2a6d581e3482c829bfb542a7de | payload | 2026-09-02 | 50% |
| md5_hash | 3a8a60416b7b0e1aa5d17eefb0a45a16 | payload | 2026-09-02 | 50% |
| md5_hash | 3c7316012cba3bbfa8a95d7277cda873 | payload | 2026-09-02 | 50% |
| md5_hash | 4282de95cc54829d7ac275e436e33b78 | payload | 2026-09-02 | 50% |
| md5_hash | 48f9bbdb670f89fce9c51ad433b4f200 | payload | 2026-09-02 | 50% |
| md5_hash | 4d5e4f64a9b56067704a977ed89aa641 | payload | 2026-09-02 | 50% |
| md5_hash | 4fb72d580241f27945ec187855efd84a | payload | 2026-09-02 | 50% |
| md5_hash | 568074d60dd4759e963adc5fe9f15eb1 | payload | 2026-09-02 | 50% |
| md5_hash | 4ddca39b05103aeb075ebb0e03522064 | payload | 2026-09-02 | 50% |
| md5_hash | 5d232b72378754f7a6433f93e6380737 | payload | 2026-09-02 | 50% |
| md5_hash | 61ab3f6401d60ec36cd3ac980a8deb75 | payload | 2026-09-02 | 50% |
| md5_hash | 62bed88bd426f91ddbbbcfcd8508ed6a | payload | 2026-09-02 | 50% |
| md5_hash | 6e248f5424810ea67212f1f2e4616aa5 | payload | 2026-09-02 | 50% |
| md5_hash | 827d8ae502e3a4d56e6c3a238ba855a7 | payload | 2026-09-02 | 50% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Medusa
let malicious_hashes = dynamic(["047ac6aebe0fe80f9f09c5c548233407", "084132b20ed65b2930129b156b99f5b3", "0e43a0f747a60855209b311d727a20bf", "0f76936e237bd87dfa2378106099a673", "1079d416e093ba40aa9e95a4c2a5b61f", "129ba90886c5f5eb0c81d901ad10c622", "1b7aee68f384e252286559abc32e6dd1", "1d89b48548ea1ddf0337741ebdb89d92", "2716c60c28cf7f7568f55ac33313468b", "2c28ec2d541f555b2838099ca849f965", "2bade2a5ec166d3a226761f78711ce2f", "381b7a2a6d581e3482c829bfb542a7de", "3a8a60416b7b0e1aa5d17eefb0a45a16", "3c7316012cba3bbfa8a95d7277cda873", "4282de95cc54829d7ac275e436e33b78", "48f9bbdb670f89fce9c51ad433b4f200", "4d5e4f64a9b56067704a977ed89aa641", "4fb72d580241f27945ec187855efd84a", "568074d60dd4759e963adc5fe9f15eb1", "4ddca39b05103aeb075ebb0e03522064", "5d232b72378754f7a6433f93e6380737", "61ab3f6401d60ec36cd3ac980a8deb75", "62bed88bd426f91ddbbbcfcd8508ed6a", "6e248f5424810ea67212f1f2e4616aa5", "827d8ae502e3a4d56e6c3a238ba855a7", "876787f76867ecf654019bd19409c5b8", "89339821cdf6e9297000f3e6949f0404", "8e80b40b1298f022c7f3a96599806c43", "969d7f092ed05c72f27eef5f2c8158d6", "9c428a35d9fc1fdaf31af186ff6eec08", "9ea86dccd5bbde47f8641b62a1eeff07", "9ef5266a9fdd25474227c3e33b8e6d77", "a7cd7b61d13256f5478feb28ab34be72", "b754237c7b5e9461389a6d960156db1e", "bca2ccff0596a9f102550976750e2a89", "bd6e38b6ff85ab02c1a4325e8af29ce4", "c870ea6a598c12218e6ac36d791032b5", "c9c00c627015bd78fda22fa28fd11cd7", "c9f2476bf8db102fea7310abadeb9e01", "cd3e9e4df7e607f4fe83873b9d1142e3", "d18a5f1e8c321472a31c27f4985834a4", "e2cdf2a3380d0197aa11ff98a34cc59e", "ecb34a068eeb2548c0cbe2de00e53ed2", "ed9be20fea9203f4c4557c66c5b9686c", "f41ad99b8a8c95e4132e850b3663cb40", "fcb742b507e3c074da5524d1a7c80f7f", "fd3834d566a993c549a13a52d843a4e1"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios and corresponding filters for the ThreatFox: Medusa IOCs detection rule in an enterprise environment:
Scenario: Security Team Manual Threat Hunting
User Account or Process Name. Exclude alerts generated by accounts belonging to the “SOC-Admins” group (e.g., svc_soc_hunter, admin_threat_intel) and processes running from the SIEM agent binary path (e.g., C:\Program Files\Microsoft Defender\MpCmdRun.exe or splunkd.exe).Scenario: Scheduled Vulnerability Scanning
Source IP belongs to the dedicated vulnerability scanning subnet (e.g., 10.20.40.x) or exclude the scanner service account (e.g., svc_vuln_scan).Scenario: Endpoint Protection Signature Updates