This rule detects adversary activity involving specific Indicators of Compromise (IOCs) linked to the Remus threat actor, signaling potential reconnaissance or initial access attempts within the Azure Sentinel environment. Proactively hunting for these IOCs allows the SOC team to identify early-stage threats and mitigate risks before adversaries can establish persistence or expand their foothold in the network.
Malware Family: Remus Total IOCs: 2 IOC Types: url, domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| url | hxxp://texchub.biz:6520 | botnet_cc | 2026-07-27 | 75% |
| domain | texchub.biz | botnet_cc | 2026-07-27 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Remus
let malicious_domains = dynamic(["texchub.biz"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - Remus
let malicious_urls = dynamic(["http://texchub.biz:6520"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios and corresponding filters for the ThreatFox: Remus IOCs detection rule in an enterprise environment:
Scenario: Scheduled Antivirus or EDR Definition Updates
MsMpEng.exe, FalconSensorService) and restrict the rule to trigger only when the source IP is not within the known corporate update server subnet range.Scenario: Third-Party Backup Agent Connectivity
svc-veeam-agent, rubrik-backup) and limit detection to exclude connections destined for known backup vendor IP ranges listed in the enterprise allow-list.Scenario: Automated Compliance Scanning Jobs