This detection rule identifies adversary activity linked to the Stealc information stealer by monitoring for specific Indicators of Compromise (IOCs) known to facilitate credential theft and data exfiltration. Proactively hunting for these IOCs within Azure Sentinel is critical because early identification of Stealc infections allows SOC teams to mitigate lateral movement risks before sensitive assets are compromised.
Malware Family: Stealc Total IOCs: 2 IOC Types: ip:port, url
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 176[.]65[.]144[.]127:80 | botnet_cc | 2026-07-02 | 100% |
| url | hxxp://176[.]65[.]144[.]127/312b423bf6dd463f8d15.php | botnet_cc | 2026-07-02 | 75% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Stealc
let malicious_ips = dynamic(["176.65.144.127"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["176.65.144.127"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - Stealc
let malicious_urls = dynamic(["http://176.65.144.127/312b423bf6dd463f8d15.php"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: Stealc IOCs detection rule in an enterprise environment, along with suggested filters and exclusions:
Endpoint Protection Scanning of Quarantine Archives
C:\ProgramData\ThreatFox\Quarantine directory. When these agents extract and analyze archived malware samples containing Stealc artifacts for signature updates, they may trigger network connections to Stealc-associated IOCs (e.g., specific C2 domains) that are part of the sample’s embedded configuration rather than an active infection on the host.ProcessName containing “CrowdStrike”, “MsMpEng.exe”, or “SentinelOne” where the ParentProcessName is the EDR service itself, and the action is limited to file I/O or local network scanning rather than outbound C2 communication.Scheduled Threat Intelligence Feed Synchronization
SourceHost belonging to the “SIEM-Management” or “ThreatIntel-Sync” asset group. Additionally, filter for specific scheduled