This hypothesis targets the presence of known Remcos Remote Access Trojan indicators, which adversaries deploy to establish persistent, stealthy control over compromised endpoints for data exfiltration and lateral movement. Proactively hunting for these IOCs in Azure Sentinel is critical because Remcos is a high-severity threat frequently used in targeted attacks, allowing the SOC to identify and isolate infected systems before the malware can fully establish its foothold or escalate privileges.
Malware Family: Remcos Total IOCs: 34 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | cashicash.workablegoods.com | botnet_cc | 2026-09-16 | 100% |
| domain | coachile.monimachirismanu.com | botnet_cc | 2026-09-16 | 100% |
| domain | mastama.akijinkuu.com | botnet_cc | 2026-09-16 | 100% |
| domain | monjiso.v6.army | botnet_cc | 2026-09-16 | 100% |
| domain | puremoni.weydneycross.com | botnet_cc | 2026-09-16 | 100% |
| domain | newjosmoo.ddns.net | botnet_cc | 2026-09-16 | 100% |
| domain | 68gbsg.com | botnet_cc | 2026-09-16 | 100% |
| domain | f5tech.in | botnet_cc | 2026-09-16 | 100% |
| domain | trcasinobets.com | botnet_cc | 2026-09-16 | 100% |
| domain | u88.mex.com | botnet_cc | 2026-09-16 | 100% |
| domain | u88.run | botnet_cc | 2026-09-16 | 100% |
| domain | u888bet.pro | botnet_cc | 2026-09-16 | 100% |
| domain | u888casino.vip | botnet_cc | 2026-09-16 | 100% |
| domain | ug8828.com | botnet_cc | 2026-09-16 | 100% |
| domain | ajaib168slot.com | botnet_cc | 2026-09-16 | 100% |
| domain | bj38-top.online | botnet_cc | 2026-09-16 | 100% |
| domain | bj38.jpn.com | botnet_cc | 2026-09-16 | 100% |
| domain | bj38.nl | botnet_cc | 2026-09-16 | 100% |
| domain | bj88-vnd.com | botnet_cc | 2026-09-16 | 100% |
| domain | bj88.fifa55we.com | botnet_cc | 2026-09-16 | 100% |
| domain | bj884.com | botnet_cc | 2026-09-16 | 100% |
| domain | bj88g.com | botnet_cc | 2026-09-16 | 100% |
| domain | cravenw.tv | botnet_cc | 2026-09-16 | 100% |
| domain | damac-suncity.in.net | botnet_cc | 2026-09-16 | 100% |
| domain | e2bet.technology | botnet_cc | 2026-09-16 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Remcos
let malicious_domains = dynamic(["cashicash.workablegoods.com", "coachile.monimachirismanu.com", "mastama.akijinkuu.com", "monjiso.v6.army", "puremoni.weydneycross.com", "newjosmoo.ddns.net", "68gbsg.com", "f5tech.in", "trcasinobets.com", "u88.mex.com", "u88.run", "u888bet.pro", "u888casino.vip", "ug8828.com", "ajaib168slot.com", "bj38-top.online", "bj38.jpn.com", "bj38.nl", "bj88-vnd.com", "bj88.fifa55we.com", "bj884.com", "bj88g.com", "cravenw.tv", "damac-suncity.in.net", "e2bet.technology", "ebet188.co", "fifa55dd.com", "fifa55n.com", "gama-casino-rzb.buzz", "ratu88hoki.com", "sifang.buzz", "188toto.co", "samara2026.duckdns.org", "mikosmtmiaomu.ddns.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Image or File path matches the specific application directory (e.g., C:\Program Files\SAP\FrontEnd\) and the User is a service account or known application admin.ParentImage is C:\Windows\System32\svchost.exe (specifically the DcomLaunch or RPC service) or where the User belongs to the SCCM_Admin or Patch_Service security group.Environment: Staging or Dev in their CMDB attributes, or where the User is a member of the Dev_Team or QA_Team group.Computer name matches the designated honeyp