This hunt detects adversary activity by correlating network and endpoint telemetry against a curated set of 14 Indicators of Compromise (IOCs) specific to the Aisuru threat actor. Proactively hunting for these IOCs in Azure Sentinel is critical to identify early-stage intrusions from this known actor, enabling rapid containment before lateral movement or data exfiltration occurs.
Malware Family: Aisuru Total IOCs: 14 IOC Types: ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 167[.]172[.]71[.]69:8080 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 137[.]184[.]70[.]190:8001 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 103[.]214[.]146[.]46:8443 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 206[.]189[.]81[.]41:9034 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 206[.]189[.]81[.]41:8443 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 167[.]99[.]64[.]180:8443 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 47[.]107[.]224[.]89:34567 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 167[.]99[.]64[.]180:8080 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 167[.]172[.]71[.]69:8443 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 143[.]198[.]206[.]191:8443 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 206[.]189[.]81[.]41:8080 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 137[.]184[.]199[.]120:34567 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 178[.]128[.]22[.]21:8443 | botnet_cc | 2026-08-01 | 100% |
| ip:port | 167[.]99[.]64[.]180:9034 | botnet_cc | 2026-08-01 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Aisuru
let malicious_ips = dynamic(["137.184.199.120", "167.99.64.180", "137.184.70.190", "167.172.71.69", "178.128.22.21", "206.189.81.41", "47.107.224.89", "143.198.206.191", "103.214.146.46"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["137.184.199.120", "167.99.64.180", "137.184.70.190", "167.172.71.69", "178.128.22.21", "206.189.81.41", "47.107.224.89", "143.198.206.191", "103.214.146.46"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
Scenario: Legitimate Endpoint Protection Updates via Microsoft Defender for Endpoint
MsMpEng.exe) downloads and verifies signature definitions or engine updates that contain file hashes matching the Aisuru IOC set. This often occurs during scheduled nightly update windows where the AV client pulls new threat intelligence feeds from the cloud.ImageName containing MsMpEng.exe OR MsSense.exe when the parent process is ServiceHost.exe running under the SYSTEM account, specifically during the defined maintenance window (e.g., 02:00–04:00 local time).Scenario: Scheduled Third-Party Backup Agent Scans
VeeamTransportService.exe (or commvault_agent.exe) and the file path resides within known backup directories (e.g., C:\Program Files\Veeam\Backup\...).Scenario: Automated Software Deployment via SCCM/Intune