This hunt detects adversary activity by correlating network and endpoint telemetry against eleven specific Indicators of Compromise (IOCs) linked to the Remus threat actor. A SOC team should proactively hunt for these signals in Azure Sentinel to identify early-stage intrusions that may evade standard signature-based detections, ensuring timely containment of this high-severity threat.
Malware Family: Remus Total IOCs: 11 IOC Types: url
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| url | hxxp://piarl.site:9048/categories | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://flreaow.click:6527/files | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://piarl.site:9048/messages | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://gofkaxz.click:8137/sessions | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://nopxs.shop:8839/users | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://piarl.site:9048/profiles | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://uiccvbk.click:8839/addresses | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://flreaow.click:6527/tags | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://piarl.site:9048/reviews | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://luwerae.click:7748/articles | botnet_cc | 2026-08-28 | 75% |
| url | hxxp://piarl.site:9048/tasks | botnet_cc | 2026-08-28 | 75% |
// Hunt for access to known malicious URLs
// Source: ThreatFox - Remus
let malicious_urls = dynamic(["http://piarl.site:9048/categories", "http://flreaow.click:6527/files", "http://piarl.site:9048/messages", "http://gofkaxz.click:8137/sessions", "http://nopxs.shop:8839/users", "http://piarl.site:9048/profiles", "http://uiccvbk.click:8839/addresses", "http://flreaow.click:6527/tags", "http://piarl.site:9048/reviews", "http://luwerae.click:7748/articles", "http://piarl.site:9048/tasks"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
UrlClickEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios and corresponding filters for the ThreatFox: Remus IOCs detection rule in an enterprise environment:
Scenario: Scheduled Antivirus or EDR Definition Updates
ProcessName of the EDR agent updater service (e.g., C:\Program Files\CrowdStrike\csagent.exe).Scenario: Admin-Initiated Security Baseline Scans
UserAccount containing “Admin” or “Service” prefixes, combined with a time-window filter (e.g., exclude alerts occurring between 02:00 and 06:00 UTC) to capture scheduled maintenance jobs.Scenario: Cloud Backup and Synchronization Services