This rule detects the presence of known indicators of compromise associated with the Unknown Stealer malware, a threat actor that typically deploys information-stealing payloads to exfiltrate sensitive data such as credentials and browser sessions. Proactively hunting for these IOCs in Azure Sentinel allows the SOC team to identify compromised endpoints before the adversary achieves full persistence or data exfiltration, thereby reducing the overall dwell time and impact of the intrusion.
Malware Family: Unknown Stealer Total IOCs: 24 IOC Types: url
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| url | hxxps://tanamvsepox.info/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://tldsapi.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://xlamedioz.rest/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://petyshiniyvidar.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://rifjfiriei44.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://rrrrrrrfffff.club/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://russianaltushkawantdickinside.club/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://sadqwdghq.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://stukachab.club/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://kakjemnenadoeloetodelat.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://kekkekesgkdf.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://ksakdakd1k.club/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://mnemvsepox.info/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://myufix.club/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://orkaleroorkalalelo.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://daemqllad.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://dgqweg.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://dojaekrt.cc/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://dojaekrt.forum/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://dojaekrt.trade/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://bizstash.club/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://boloshoy-huy-negra.com/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://bomboclat.rest/ | botnet_cc | 2026-09-23 | 25% |
| url | hxxps://booblik.rest/ | botnet_cc | 2026-09-23 | 25% |
// Hunt for access to known malicious URLs
// Source: ThreatFox - Unknown Stealer
let malicious_urls = dynamic(["https://tanamvsepox.info/", "https://tldsapi.com/", "https://xlamedioz.rest/", "https://petyshiniyvidar.com/", "https://rifjfiriei44.com/", "https://rrrrrrrfffff.club/", "https://russianaltushkawantdickinside.club/", "https://sadqwdghq.com/", "https://stukachab.club/", "https://kakjemnenadoeloetodelat.com/", "https://kekkekesgkdf.com/", "https://ksakdakd1k.club/", "https://mnemvsepox.info/", "https://myufix.club/", "https://orkaleroorkalalelo.com/", "https://daemqllad.com/", "https://dgqweg.com/", "https://dojaekrt.cc/", "https://dojaekrt.forum/", "https://dojaekrt.trade/", "https://bizstash.club/", "https://boloshoy-huy-negra.com/", "https://bomboclat.rest/", "https://booblik.rest/"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
UrlClickEvents | Ensure this data connector is enabled |
Scenario: Enterprise backup agents (e.g., Veeam, Commvault, or Rubrik) or disk imaging tools (e.g., Acronis, Clonezilla) perform deep file system scans or memory dumps that may match generic “stealer” IOCs such as specific file hashes, unusual process trees (e.g., powershell.exe spawning cmd.exe for disk operations), or known library injections used for efficient data transfer.
VeeamBackupSvc.exe, commvaultagent.exe) or where the process path resides in standard backup installation directories (e.g., C:\Program Files\Veeam\, C:\Program Files\Commvault\).Scenario: IT support or helpdesk staff use remote administration tools (e.g., TeamViewer, AnyDesk, or Citrix Receiver) to troubleshoot user machines. These tools often inject helper processes or execute scripts from temporary directories (%TEMP%, %APPDATA%) to perform diagnostics, which can mimic the behavior of infostealers that hide in user profiles or temp folders.
TeamViewer, AnyDesk, Citrix) or where the process is launched by a known remote desktop client executable (e.g., tvnss.exe, anydesk.exe, CSC.exe).Scenario: Automated software deployment or patching tools (e.g., SCCM, PDQ Deploy, or Chocolatey) install or update applications by extracting files to temporary locations and executing installers or configuration scripts. Some installers use PowerShell or VBScript to modify registry keys or copy files to system directories, which may trigger IOCs related to “unknown” stealer behaviors if the