← Back to SOC feed Coverage →

ThreatFox: Remcos IOCs

ioc-hunt HIGH ThreatFox
CommonSecurityLogDeviceNetworkEvents
iocthreatfoxwin-remcos
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-09-01T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt hypothesis targets adversaries leveraging Remcos Remote Access Trojans delivered through phishing campaigns to establish persistent command-and-control channels for data exfiltration and remote execution. Proactively hunting for these indicators in Azure Sentinel is critical due to Remcos’s high severity impact, which allows attackers to maintain long-term access to sensitive environments while evading standard perimeter defenses.

IOC Summary

Malware Family: Remcos Total IOCs: 7 IOC Types: ip:port

TypeValueThreat TypeFirst SeenConfidence
ip:port64[.]89[.]160[.]127:2891botnet_cc2026-09-01100%
ip:port155[.]103[.]70[.]232:14555botnet_cc2026-09-01100%
ip:port194[.]59[.]31[.]179:9714botnet_cc2026-09-0175%
ip:port96[.]9[.]229[.]38:2404botnet_cc2026-09-0175%
ip:port91[.]92[.]42[.]115:2418botnet_cc2026-09-01100%
ip:port208[.]91[.]65[.]109:2404botnet_cc2026-09-01100%
ip:port217[.]60[.]195[.]233:3231botnet_cc2026-09-01100%

KQL: Ip Hunt

// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Remcos
let malicious_ips = dynamic(["96.9.229.38", "208.91.65.109", "155.103.70.232", "194.59.31.179", "217.60.195.233", "91.92.42.115", "64.89.160.127"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc

KQL: Ip Hunt Device

// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["96.9.229.38", "208.91.65.109", "155.103.70.232", "194.59.31.179", "217.60.195.233", "91.92.42.115", "64.89.160.127"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DeviceNetworkEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 4 specific false positive scenarios for the ThreatFox: Remcos IOCs detection rule, including targeted filters and exclusions:

Original source: https://threatfox.abuse.ch/browse/malware/win.remcos/