This hunt detects adversary activity by correlating Azure Sentinel logs against a curated set of 50 Indicators of Compromise (IOCs) specific to the KongTuke threat actor. Proactively hunting for these IOCs is critical to identify early-stage compromises and mitigate potential lateral movement before the adversary establishes persistence within the environment.
Malware Family: KongTuke Total IOCs: 50 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | souls-of-wildlife.ch | botnet_cc | 2026-07-26 | 50% |
| domain | testspsychotechniques974.re | botnet_cc | 2026-07-26 | 50% |
| domain | toppansecurity.com | botnet_cc | 2026-07-26 | 50% |
| domain | traditionalafricanmarket.com | botnet_cc | 2026-07-26 | 50% |
| domain | uhnjfoundation.org | botnet_cc | 2026-07-26 | 50% |
| domain | verifyaiinitiative.com | botnet_cc | 2026-07-26 | 50% |
| domain | vimjes.edu.in | botnet_cc | 2026-07-26 | 50% |
| domain | visiononfire.co.za | botnet_cc | 2026-07-26 | 50% |
| domain | wamproperties.com | botnet_cc | 2026-07-26 | 50% |
| domain | warhawgs.org | botnet_cc | 2026-07-26 | 50% |
| domain | www.jolivet.asso.fr | botnet_cc | 2026-07-26 | 50% |
| domain | www.lacompaniahostal.com | botnet_cc | 2026-07-26 | 50% |
| domain | www.lowbudgetmovers.net | botnet_cc | 2026-07-26 | 50% |
| domain | www.ridderkerkfm.nl | botnet_cc | 2026-07-26 | 50% |
| domain | www.slidingdesk.com | botnet_cc | 2026-07-26 | 50% |
| domain | www.zfederal.com | botnet_cc | 2026-07-26 | 50% |
| domain | zainbeauty-sa.com | botnet_cc | 2026-07-26 | 50% |
| domain | zensostudio.com | botnet_cc | 2026-07-26 | 50% |
| domain | 304771.eu15.myftpupload.com | botnet_cc | 2026-07-26 | 50% |
| domain | activistsediblesolutions.com | botnet_cc | 2026-07-26 | 50% |
| domain | alambiodiversitasindonesia.or.id | botnet_cc | 2026-07-26 | 50% |
| domain | amadadopai.com.br | botnet_cc | 2026-07-26 | 50% |
| domain | andressadinizbeauty.com.br | botnet_cc | 2026-07-26 | 50% |
| domain | androscogginpal.com | botnet_cc | 2026-07-26 | 50% |
| domain | axletrees.com | botnet_cc | 2026-07-26 | 50% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - KongTuke
let malicious_domains = dynamic(["souls-of-wildlife.ch", "testspsychotechniques974.re", "toppansecurity.com", "traditionalafricanmarket.com", "uhnjfoundation.org", "verifyaiinitiative.com", "vimjes.edu.in", "visiononfire.co.za", "wamproperties.com", "warhawgs.org", "www.jolivet.asso.fr", "www.lacompaniahostal.com", "www.lowbudgetmovers.net", "www.ridderkerkfm.nl", "www.slidingdesk.com", "www.zfederal.com", "zainbeauty-sa.com", "zensostudio.com", "304771.eu15.myftpupload.com", "activistsediblesolutions.com", "alambiodiversitasindonesia.or.id", "amadadopai.com.br", "andressadinizbeauty.com.br", "androscogginpal.com", "axletrees.com", "baztechalarm.net", "shyariinhindi.com", "bookdayz.com", "rossomazara.com", "royalaigle.fr", "purikurniaayuvilla.com", "praxis-uruska.de", "primosgourmetcatering.com", "pmmoldpro.com", "oceanemarine.com", "libretto.awebi-lab.com", "makhaniwelfare.com", "ktco-co.ir", "guardiansunlimited.org", "haba.com.vn", "gov.flstudios.website", "genesis-mfg.ae", "frigor-refrigerationoils.com", "findyourrootshairacademy.com", "devcon.cd", "entertainment.zincgroup.com", "cozinca.com.br", "darkslateblue-gnu-453682.hostingersite.com", "1stclassmovingtn.com", "americanjackets.us"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: KongTuke IOCs detection rule, tailored for an enterprise environment:
Scenario: Automated Vulnerability Scanning by Qualys or Tenable
svc_qualys, tenable_agent) or specific scanner IP ranges (e.g., 192.168.10.50-60). Add a condition to ignore events where the parent process is qualyscloudagent.exe or nessuscli.Scenario: Scheduled EDR Policy Updates via CrowdStrike Falcon
FalconSensorService.exe (or equivalent EDR daemon) and the event type is “Policy Update” or “Signature Refresh.” Filter out alerts generated during the defined maintenance window (e.g., 02:00–04:00 UTC).Scenario: Admin-Initiated Threat Intelligence Feed Import