This hunt hypothesis targets adversaries leveraging Remcos Remote Access Trojans delivered through phishing campaigns to establish persistent command-and-control channels for data exfiltration and remote execution. Proactively hunting for these indicators in Azure Sentinel is critical due to Remcos’s high severity impact, which allows attackers to maintain long-term access to sensitive environments while evading standard perimeter defenses.
Malware Family: Remcos Total IOCs: 7 IOC Types: ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 64[.]89[.]160[.]127:2891 | botnet_cc | 2026-09-01 | 100% |
| ip:port | 155[.]103[.]70[.]232:14555 | botnet_cc | 2026-09-01 | 100% |
| ip:port | 194[.]59[.]31[.]179:9714 | botnet_cc | 2026-09-01 | 75% |
| ip:port | 96[.]9[.]229[.]38:2404 | botnet_cc | 2026-09-01 | 75% |
| ip:port | 91[.]92[.]42[.]115:2418 | botnet_cc | 2026-09-01 | 100% |
| ip:port | 208[.]91[.]65[.]109:2404 | botnet_cc | 2026-09-01 | 100% |
| ip:port | 217[.]60[.]195[.]233:3231 | botnet_cc | 2026-09-01 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Remcos
let malicious_ips = dynamic(["96.9.229.38", "208.91.65.109", "155.103.70.232", "194.59.31.179", "217.60.195.233", "91.92.42.115", "64.89.160.127"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["96.9.229.38", "208.91.65.109", "155.103.70.232", "194.59.31.179", "217.60.195.233", "91.92.42.115", "64.89.160.127"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: Remcos IOCs detection rule, including targeted filters and exclusions:
Scenario: Legitimate Remote Management via Admin Tools
ProcessName IN ("ccmexec.exe", "ivanti_agent.exe", "TeamViewer_Service.exe") AND DigitalSignatureIssuer = "Microsoft Corporation" OR "Ivanti"Scenario: Scheduled Backup and Data Exfiltration Jobs
SourceProcessName IN ("VeeamTransport.exe", "AcronisBackupService.exe") AND UserAccount = "DOMAIN\BackupSvc" AND TimeOfDay BETWEEN 01:00 AND 05:00Scenario: Internal DevOps and CI/CD Pipeline Agents