This hunt detects adversary activity by correlating network and endpoint telemetry against five specific Indicators of Compromise (IOCs) linked to the Aisuru threat actor. Proactively hunting for these IOCs in Azure Sentinel allows the SOC team to identify early-stage intrusions associated with this campaign before they escalate into broader compromises.
Malware Family: Aisuru Total IOCs: 5 IOC Types: ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 91[.]208[.]162[.]129:34567 | botnet_cc | 2026-08-05 | 100% |
| ip:port | 137[.]184[.]70[.]190:9034 | botnet_cc | 2026-08-05 | 100% |
| ip:port | 167[.]99[.]64[.]180:34567 | botnet_cc | 2026-08-05 | 100% |
| ip:port | 137[.]184[.]70[.]190:34567 | botnet_cc | 2026-08-05 | 100% |
| ip:port | 137[.]184[.]199[.]120:9034 | botnet_cc | 2026-08-05 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Aisuru
let malicious_ips = dynamic(["91.208.162.129", "167.99.64.180", "137.184.70.190", "137.184.199.120"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["91.208.162.129", "167.99.64.180", "137.184.70.190", "137.184.199.120"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
Here are 3-5 specific false positive scenarios for the ThreatFox: Aisuru IOCs detection rule, along with suggested filters and exclusions tailored for an enterprise environment:
Endpoint Protection Scans by Crowdstrike or Microsoft Defender
ProcessName containing “C-Host.exe” (CrowdStrike) or “MsMpEng.exe” (Defender). Additionally, exclude alerts where the SourceIP belongs to the internal IP range of the Security Operations Center (SOC) jump hosts if they are known to host these EDR agents.Scheduled Backup Jobs via Veeam or Commvault
SRV-BKP-01). Alternatively, exclude processes where the CommandLine contains keywords like “vbr.exe” or “commvault.cmd”.