← Back to SOC feed Coverage →

ThreatFox: KongTuke IOCs

ioc-hunt HIGH ThreatFox
DnsEvents
iocjs-kongtukethreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-07-26T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt detects adversary activity by correlating Azure Sentinel logs against a curated set of 50 Indicators of Compromise (IOCs) specific to the KongTuke threat actor. Proactively hunting for these IOCs is critical to identify early-stage compromises and mitigate potential lateral movement before the adversary establishes persistence within the environment.

IOC Summary

Malware Family: KongTuke Total IOCs: 50 IOC Types: domain

TypeValueThreat TypeFirst SeenConfidence
domainsouls-of-wildlife.chbotnet_cc2026-07-2650%
domaintestspsychotechniques974.rebotnet_cc2026-07-2650%
domaintoppansecurity.combotnet_cc2026-07-2650%
domaintraditionalafricanmarket.combotnet_cc2026-07-2650%
domainuhnjfoundation.orgbotnet_cc2026-07-2650%
domainverifyaiinitiative.combotnet_cc2026-07-2650%
domainvimjes.edu.inbotnet_cc2026-07-2650%
domainvisiononfire.co.zabotnet_cc2026-07-2650%
domainwamproperties.combotnet_cc2026-07-2650%
domainwarhawgs.orgbotnet_cc2026-07-2650%
domainwww.jolivet.asso.frbotnet_cc2026-07-2650%
domainwww.lacompaniahostal.combotnet_cc2026-07-2650%
domainwww.lowbudgetmovers.netbotnet_cc2026-07-2650%
domainwww.ridderkerkfm.nlbotnet_cc2026-07-2650%
domainwww.slidingdesk.combotnet_cc2026-07-2650%
domainwww.zfederal.combotnet_cc2026-07-2650%
domainzainbeauty-sa.combotnet_cc2026-07-2650%
domainzensostudio.combotnet_cc2026-07-2650%
domain304771.eu15.myftpupload.combotnet_cc2026-07-2650%
domainactivistsediblesolutions.combotnet_cc2026-07-2650%
domainalambiodiversitasindonesia.or.idbotnet_cc2026-07-2650%
domainamadadopai.com.brbotnet_cc2026-07-2650%
domainandressadinizbeauty.com.brbotnet_cc2026-07-2650%
domainandroscogginpal.combotnet_cc2026-07-2650%
domainaxletrees.combotnet_cc2026-07-2650%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - KongTuke
let malicious_domains = dynamic(["souls-of-wildlife.ch", "testspsychotechniques974.re", "toppansecurity.com", "traditionalafricanmarket.com", "uhnjfoundation.org", "verifyaiinitiative.com", "vimjes.edu.in", "visiononfire.co.za", "wamproperties.com", "warhawgs.org", "www.jolivet.asso.fr", "www.lacompaniahostal.com", "www.lowbudgetmovers.net", "www.ridderkerkfm.nl", "www.slidingdesk.com", "www.zfederal.com", "zainbeauty-sa.com", "zensostudio.com", "304771.eu15.myftpupload.com", "activistsediblesolutions.com", "alambiodiversitasindonesia.or.id", "amadadopai.com.br", "andressadinizbeauty.com.br", "androscogginpal.com", "axletrees.com", "baztechalarm.net", "shyariinhindi.com", "bookdayz.com", "rossomazara.com", "royalaigle.fr", "purikurniaayuvilla.com", "praxis-uruska.de", "primosgourmetcatering.com", "pmmoldpro.com", "oceanemarine.com", "libretto.awebi-lab.com", "makhaniwelfare.com", "ktco-co.ir", "guardiansunlimited.org", "haba.com.vn", "gov.flstudios.website", "genesis-mfg.ae", "frigor-refrigerationoils.com", "findyourrootshairacademy.com", "devcon.cd", "entertainment.zincgroup.com", "cozinca.com.br", "darkslateblue-gnu-453682.hostingersite.com", "1stclassmovingtn.com", "americanjackets.us"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 4 specific false positive scenarios for the ThreatFox: KongTuke IOCs detection rule, tailored for an enterprise environment:

Original source: https://threatfox.abuse.ch/browse/malware/js.kongtuke/