This hunt hypothesis targets adversary behavior where malicious actors deploy MetaStealer to exfiltrate sensitive credentials and system data by matching network traffic against a curated set of 128 known Indicators of Compromise (IOCs). Proactively hunting for these specific IOCs in Azure Sentinel is critical because it enables the SOC team to rapidly identify early-stage infections across the cloud environment before the stealer establishes persistence or expands its lateral movement.
Malware Family: MetaStealer Total IOCs: 128 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | yyowcsswsesksomi.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyqewussumqweisi.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyqisgekkgammukq.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyqkageayymeoses.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyqokiuoyqkuwiog.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yywesmeciecsmksk.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yquagqysgcsuceqs.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqukwqcwqgceousm.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqusqqumoekaqaoq.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqwqkcaiaeemoouq.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqwysiuoiyomosec.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqyoccyuaoysckmm.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqyueyuoukmsmqem.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyaqcymcosceugwu.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyaygggumsoywcwk.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyeckmeayawguoim.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyeoguuueeoaggwi.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yygiiasyoqkgsqee.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyigcsagquigikkq.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yyiicoewgysyayam.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqaaywumkgiuoegk.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqagqiuauqoyuwkw.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqaiqmaygauogoyk.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqckmsmisoycykgc.xyz | botnet_cc | 2026-07-16 | 100% |
| domain | yqeaqqsiqwgaoyws.xyz | botnet_cc | 2026-07-16 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - MetaStealer
let malicious_domains = dynamic(["yyowcsswsesksomi.xyz", "yyqewussumqweisi.xyz", "yyqisgekkgammukq.xyz", "yyqkageayymeoses.xyz", "yyqokiuoyqkuwiog.xyz", "yywesmeciecsmksk.xyz", "yquagqysgcsuceqs.xyz", "yqukwqcwqgceousm.xyz", "yqusqqumoekaqaoq.xyz", "yqwqkcaiaeemoouq.xyz", "yqwysiuoiyomosec.xyz", "yqyoccyuaoysckmm.xyz", "yqyueyuoukmsmqem.xyz", "yyaqcymcosceugwu.xyz", "yyaygggumsoywcwk.xyz", "yyeckmeayawguoim.xyz", "yyeoguuueeoaggwi.xyz", "yygiiasyoqkgsqee.xyz", "yyigcsagquigikkq.xyz", "yyiicoewgysyayam.xyz", "yqaaywumkgiuoegk.xyz", "yqagqiuauqoyuwkw.xyz", "yqaiqmaygauogoyk.xyz", "yqckmsmisoycykgc.xyz", "yqeaqqsiqwgaoyws.xyz", "yqegkgwweowiowmw.xyz", "yqiiwqcuyquwcmse.xyz", "yqkquakgsccocsqg.xyz", "yqkyggoocksesowc.xyz", "yqmaimewwksoksue.xyz", "yqmcoeokqwwmmaea.xyz", "yqqccumwacwqowuo.xyz", "yqqioagmmsciwquq.xyz", "yqsacwmwiwukwuig.xyz", "yqsciwsaaeeucqaa.xyz", "ykoqymcuwwwggkqw.xyz", "ykqegysecaamkage.xyz", "ykqeoegaiwmekyiy.xyz", "ykqwogyoeasiaugw.xyz", "ykugyiiicguawywq.xyz", "ykuiqqumgamwwgia.xyz", "ykuqogqmoqmgsyow.xyz", "ykwgeqoaawkkemos.xyz", "ykwmoukgikemiauc.xyz", "ykwosqoemowmuqyu.xyz", "ykyieuyoesksuqiw.xyz", "ykyiieuemcesiuwe.xyz", "ykyoiggwuoyeskkw.xyz", "yoigusekcwamuoqe.xyz", "yeyaqmgqcmwukkmi.xyz"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: MetaStealer IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
Endpoint Protection Scanning of Quarantine Directories
C:\ProgramData\ThreatFox\Quarantine directory. If a previous MetaStealer IOC was ingested into the threat intelligence platform and cached locally as a benign reference file or a test artifact, the EDR’s background scanning process will trigger a match against these 128 IOCs during its routine integrity check.C:\Program Files\CrowdStrike\csagent.exe, MsMpEng.exe) accessing files within the specific threat intelligence cache or quarantine paths used by your SOC infrastructure.Scheduled Threat Intelligence Ingestion Jobs
\Microsoft\ThreatIntel\SyncJob) downloads updated IOC feeds from internal repositories to refresh local detection signatures. This script often reads and writes the specific hash values or file paths associated with MetaStealer as part of its validation logic, triggering a “file access” or “process execution” alert for these IOCs even though no malicious activity is occurring.System account or the specific service account (e.g., svc-threat-intel) running under the context of known scheduled tasks related to threat feed synchronization, specifically when the parent process is powershell.exe or svchost.exe with a high-confidence signature.Software Deployment and Patch Management