This hunt detects adversary activity by correlating network and endpoint telemetry against a curated set of 33 Indicators of Compromise (IOCs) specifically linked to the Remus threat actor. Proactively hunting for these IOCs in Azure Sentinel is critical because early identification of Remus-associated artifacts enables rapid containment before the adversary establishes persistence or exfiltrates sensitive data.
Malware Family: Remus Total IOCs: 33 IOC Types: url, ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| url | hxxp://mrlketo.shop:8932/customers | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://bravplo.click:7713/sessions | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://vexdico.shop:8539/imports | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://bravplo.click:7713/settings | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://uiccvbk.click:8839/tokens | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://mrlketo.shop:8932/products | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://mrlketo.shop:8932/images | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://vexdico.shop:8539/events | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://vexdico.shop:8539/categories | botnet_cc | 2026-08-15 | 75% |
| ip:port | 62[.]72[.]59[.]224:7713 | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://bravplo.click:7713/reviews | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://vexdico.shop:8539/tokens | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://vexdico.shop:8539/teams | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://mrlketo.shop:8932/orders | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://mrlketo.shop:8932/files | botnet_cc | 2026-08-15 | 75% |
| ip:port | 38[.]242[.]157[.]137:7242 | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://palaera.click:7242/workspaces | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://mrlketo.shop:8932/contacts | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://bravplo.click:7713/users | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://mrlketo.shop:8932/tasks | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://vexdico.shop:8539/documents | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://vexdico.shop:8539/settings | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://shkpiva.shop:5627/imports | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://mrlketo.shop:8932/events | botnet_cc | 2026-08-15 | 75% |
| url | hxxp://bravplo.click:7713/webhooks | botnet_cc | 2026-08-14 | 75% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Remus
let malicious_ips = dynamic(["38.242.157.137", "62.72.59.224"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["38.242.157.137", "62.72.59.224"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - Remus
let malicious_urls = dynamic(["http://mrlketo.shop:8932/customers", "http://bravplo.click:7713/sessions", "http://vexdico.shop:8539/imports", "http://bravplo.click:7713/settings", "http://uiccvbk.click:8839/tokens", "http://mrlketo.shop:8932/products", "http://mrlketo.shop:8932/images", "http://vexdico.shop:8539/events", "http://vexdico.shop:8539/categories", "http://bravplo.click:7713/reviews", "http://vexdico.shop:8539/tokens", "http://vexdico.shop:8539/teams", "http://mrlketo.shop:8932/orders", "http://mrlketo.shop:8932/files", "http://palaera.click:7242/workspaces", "http://mrlketo.shop:8932/contacts", "http://bravplo.click:7713/users", "http://mrlketo.shop:8932/tasks", "http://vexdico.shop:8539/documents", "http://vexdico.shop:8539/settings", "http://shkpiva.shop:5627/imports", "http://mrlketo.shop:8932/events", "http://bravplo.click:7713/webhooks", "http://mrlketo.shop:8932/tags", "http://vexdico.shop:8539/workspaces", "http://solirpa.click:9048/tags", "http://vexdico.shop:8539/products", "http://topxgax.click:4930/files", "http://mrlketo.shop:8932/messages", "http://vexdico.shop:8539/images"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: Remus IOCs rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Scheduled Antivirus Definition Updates via Microsoft Defender
Microsoft Defender Antivirus Service running as a scheduled task on all endpoints.MsMpEng.exe) and Parent Process (Task Scheduler or svchost.exe). Additionally, exclude traffic originating from the specific Microsoft update distribution point IP ranges (e.g., *.update.microsoft.com) if the IOC is a URL.Scenario: Enterprise Backup Jobs Utilizing Veeam or Commvault
C:\Program Files\Veeam\ or C:\Program Files\Commvault\. If the IOC is a specific file hash, add that hash to the global allowlist for these backup service accounts (e.g., DOMAIN\VeeamServiceAccount).Scenario: Endpoint Detection and Response (EDR) Telemetry Collection