This hunt targets the presence of SmartApeSG indicators of compromise, which are associated with a high-severity threat actor likely leveraging these specific assets for initial access or lateral movement. Proactively hunting for these IOCs in Azure Sentinel allows the SOC to identify compromised endpoints or network artifacts before the adversary can establish a persistent foothold or escalate privileges within the environment.
Malware Family: SmartApeSG Total IOCs: 2 IOC Types: url, domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| url | hxxps://gorsegazette.co/profile/router-validator.js | payload_delivery | 2026-09-24 | 100% |
| domain | gorsegazette.co | payload_delivery | 2026-09-24 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - SmartApeSG
let malicious_domains = dynamic(["gorsegazette.co"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - SmartApeSG
let malicious_urls = dynamic(["https://gorsegazette.co/profile/router-validator.js"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
jenkins.exe, docker.exe, kubectl) or where the file path resides within standard build directories (e.g., C:\Jenkins\workspace\, /var/lib/docker/).FalconSensor.exe, SentinelOne.exe) or where the alert type is explicitly tagged as “Signature Match” rather than “Behavioral Anomaly.”10.20.30.0/24) and the destination is a known test host.