Hunt package for 4 IOCs associated with Quasar RAT
Malware Family: Quasar RAT Total IOCs: 4 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | gbp.cn.com | botnet_cc | 2026-03-18 | 100% |
| domain | obf.uk.com | botnet_cc | 2026-03-18 | 100% |
| domain | akashmehndiandtattooart.in.net | botnet_cc | 2026-03-18 | 100% |
| domain | fly88-zz.site | botnet_cc | 2026-03-18 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Quasar RAT
let malicious_domains = dynamic(["gbp.cn.com", "obf.uk.com", "akashmehndiandtattooart.in.net", "fly88-zz.site"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |