This detection rule identifies adversary activity involving the ValleyRAT remote access tool by monitoring for specific indicators of compromise such as malicious file hashes and network connections. Proactive hunting is essential in Azure Sentinel to rapidly detect early-stage infections and prevent potential data exfiltration or lateral movement before the threat escalates.
Malware Family: ValleyRAT Total IOCs: 34 IOC Types: url, domain, ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | akyv188.club | botnet_cc | 2026-08-03 | 100% |
| domain | auk218.club | botnet_cc | 2026-08-03 | 100% |
| domain | co777.club | botnet_cc | 2026-08-03 | 100% |
| domain | ljdnxz.cc | botnet_cc | 2026-08-03 | 100% |
| domain | rkdrlc.pw | botnet_cc | 2026-08-03 | 100% |
| domain | txpfproxy.vip | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://tdfhdser-1433552157.cos.ap-hongkong.myqcloud.com/20260729213603.zip | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://twilight-shadow-df0c.piecestrengthen3327.workers.dev/ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://withered-lake-8596.krzakanna172.workers.dev/ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://yfghrey-1433552157.cos.ap-hongkong.myqcloud.com/20260729074327.zip | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://mt-link.qdhuzf.cc/cl/a5UYfW_dao7L4uK02Y5e3T4RKwwLAq7x5FXAtyV8o3UJAUT_K5Ia0VIbWVrxBLXMNGzEK9WhhAhSQFoBqqCupKzzInKiHGMgGOcp1Yiigbo6JUPzwHm0YBF._JurP0LhKB4wt0m5H1gYc3aG149V2da397unkY11uVn30sF8DGJJMiZtmJS_UGZtI_JqupELrUzGNWj2gvSMSOq9_0IdaVJwLmuBiwllpHaogXqN4cKH--rCZGX49Rzqev4iXM--N6CY14rgI..iNc2Atg5k9g~~ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://mt-link.qdhuzf.cc/cl/rlLXIXSwv8IKS9aWzYqx.GteIY.dfPLTRPY013hMjghjIqNPZYu0[.]3GRfdJuvkQ6tE_bREwYxiJYCce5tvEnoE3KBUTwvCDTiu2bDHWXZs0x1W9uo0iVh[.]1QNGRtX1FCHw7RAGf7rgebqPkGAHTMO9PNVObFPz6ZweWWMF.A8WcBWExrFhKajHLSIXt2Nztt0U74bljpjJsEHOma6bAX63E8oWmZHpihcBw2sQ~~--2IJbf9QXryunJZJU--8Oh[.]0r5JKH3jZkGT7hZ3yQ~~ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://restless-wood-acdc.kubataffeltie470.workers.dev/ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://royal-breeze-dc21.piecestrengthen3327.workers.dev/ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://still-block-4945.kubukushi4609-fee.workers.dev/ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://sweet-thunder-52f5.yenthi893197.workers.dev/ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://kaiwyrey.eu.cc/d/6f025f85e3c0 | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://kaiwyrey.eu.cc/d/70878efbc582 | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://kaiwyrey.eu.cc/d/ac516096c285 | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://kaiwyrey.eu.cc/d/bdc9637e70c2 | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://lively-fog-72fd.piecestrengthen3327.workers.dev/ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://mt-link.hxnxajp.club/cl/1tI4_QY7DCeBkEln5kmk9jrSOzkvCGnqOfOF.bP_ka4kNqy51He4r8IRtwhlZ2I_O_2nU1KmVVSZh_zV7BAOwQDLryYzqpE8R_QSdcIQel3f70U7Skywz[.]3B98ZVFhCxcdZMSYEd7RUj5.hif56qVudA9TU0yYiHnpS9u9fRMFRUpUFU4WNZg58wPV.jZgunKFKSrVPKboquHgJkbIYtGq_rfPM[.]1ldbJbc~--NuCyngcfq.n1c[.]5q--k8naVtPRTZtZg9yGwu3P8g~~ | botnet_cc | 2026-08-03 | 100% |
| url | hxxps://mt-link.jiosjcjp.club/cl/XyTkjX7q1dAL2BGNTd9WS4rxd2jM6dRs81I6p9oIabEzdaoU.hKBV4joWBgjmpuG1R7lQFSw.ycTLHGORYhj2SUP3sFXpIV6xdCcBG0RXRfRL7UHgFuOXTo2My_iS7qkQfe3qQ9HI3LZ8Yxj6VNOgU8mxReAxoA9FexD3dTAKBOPLMZS2YwrHmsCeDNS3nLZL3Bu53l9rtzb6rmz2xWLsLH_YpqfyMFUI0e7Ac9xKG.C0r8~--qdLygJPqKgnky9Es--_CzsqbW_5cv2HhL6j7Dr3w~~ | botnet_cc | 2026-08-03 | 100% |
| url | hxxp://kaiwyrey.eu.cc/d/bdc9637e70c2 | botnet_cc | 2026-08-03 | 100% |
| url | hxxp://withered-lake-8596.krzakanna172.workers.dev/ | botnet_cc | 2026-08-03 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - ValleyRAT
let malicious_ips = dynamic(["192.140.175.92"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["192.140.175.92"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ValleyRAT
let malicious_domains = dynamic(["akyv188.club", "auk218.club", "co777.club", "ljdnxz.cc", "rkdrlc.pw", "txpfproxy.vip"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - ValleyRAT
let malicious_urls = dynamic(["https://tdfhdser-1433552157.cos.ap-hongkong.myqcloud.com/20260729213603.zip", "https://twilight-shadow-df0c.piecestrengthen3327.workers.dev/", "https://withered-lake-8596.krzakanna172.workers.dev/", "https://yfghrey-1433552157.cos.ap-hongkong.myqcloud.com/20260729074327.zip", "https://mt-link.qdhuzf.cc/cl/a5UYfW_dao7L4uK02Y5e3T4RKwwLAq7x5FXAtyV8o3UJAUT_K5Ia0VIbWVrxBLXMNGzEK9WhhAhSQFoBqqCupKzzInKiHGMgGOcp1Yiigbo6JUPzwHm0YBF._JurP0LhKB4wt0m5H1gYc3aG149V2da397unkY11uVn30sF8DGJJMiZtmJS_UGZtI_JqupELrUzGNWj2gvSMSOq9_0IdaVJwLmuBiwllpHaogXqN4cKH--rCZGX49Rzqev4iXM--N6CY14rgI..iNc2Atg5k9g~~", "https://mt-link.qdhuzf.cc/cl/rlLXIXSwv8IKS9aWzYqx.GteIY.dfPLTRPY013hMjghjIqNPZYu0.3GRfdJuvkQ6tE_bREwYxiJYCce5tvEnoE3KBUTwvCDTiu2bDHWXZs0x1W9uo0iVh.1QNGRtX1FCHw7RAGf7rgebqPkGAHTMO9PNVObFPz6ZweWWMF.A8WcBWExrFhKajHLSIXt2Nztt0U74bljpjJsEHOma6bAX63E8oWmZHpihcBw2sQ~~--2IJbf9QXryunJZJU--8Oh.0r5JKH3jZkGT7hZ3yQ~~", "https://restless-wood-acdc.kubataffeltie470.workers.dev/", "https://royal-breeze-dc21.piecestrengthen3327.workers.dev/", "https://still-block-4945.kubukushi4609-fee.workers.dev/", "https://sweet-thunder-52f5.yenthi893197.workers.dev/", "https://kaiwyrey.eu.cc/d/6f025f85e3c0", "https://kaiwyrey.eu.cc/d/70878efbc582", "https://kaiwyrey.eu.cc/d/ac516096c285", "https://kaiwyrey.eu.cc/d/bdc9637e70c2", "https://lively-fog-72fd.piecestrengthen3327.workers.dev/", "https://mt-link.hxnxajp.club/cl/1tI4_QY7DCeBkEln5kmk9jrSOzkvCGnqOfOF.bP_ka4kNqy51He4r8IRtwhlZ2I_O_2nU1KmVVSZh_zV7BAOwQDLryYzqpE8R_QSdcIQel3f70U7Skywz.3B98ZVFhCxcdZMSYEd7RUj5.hif56qVudA9TU0yYiHnpS9u9fRMFRUpUFU4WNZg58wPV.jZgunKFKSrVPKboquHgJkbIYtGq_rfPM.1ldbJbc~--NuCyngcfq.n1c.5q--k8naVtPRTZtZg9yGwu3P8g~~", "https://mt-link.jiosjcjp.club/cl/XyTkjX7q1dAL2BGNTd9WS4rxd2jM6dRs81I6p9oIabEzdaoU.hKBV4joWBgjmpuG1R7lQFSw.ycTLHGORYhj2SUP3sFXpIV6xdCcBG0RXRfRL7UHgFuOXTo2My_iS7qkQfe3qQ9HI3LZ8Yxj6VNOgU8mxReAxoA9FexD3dTAKBOPLMZS2YwrHmsCeDNS3nLZL3Bu53l9rtzb6rmz2xWLsLH_YpqfyMFUI0e7Ac9xKG.C0r8~--qdLygJPqKgnky9Es--_CzsqbW_5cv2HhL6j7Dr3w~~", "http://kaiwyrey.eu.cc/d/bdc9637e70c2", "http://withered-lake-8596.krzakanna172.workers.dev/", "https://autumn-mountain-e855.erinbraumbachlianebl.workers.dev/", "https://divine-shape-b4fb.erinbraumbachlianebl.workers.dev/", "https://fragrant-shape-bd43.kucantoojd641.workers.dev/", "https://frosty-tooth-517b.erinbraumbachlianebl.workers.dev/", "https://icy-mountain-13d6.hazukashi4816.workers.dev/", "http://autumn-mountain-e855.erinbraumbachlianebl.workers.dev/", "http://icy-mountain-13d6.hazukashi4816.workers.dev/"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are the documented false positive scenarios and corresponding exclusions for the ThreatFox: ValleyRAT IOCs detection rule:
Scenario: Scheduled Backup or Antivirus Scans Triggering Hash Matches
VeeamAgent.exe, DefenderService.exe, or CrowdStrike.exe AND the event source falls within the defined maintenance window (e.g., 02:00–04:00 local time).Scenario: Admin Deployment of Internal Patching Tools
10.x.x.x management subnets) where the destination is an approved internal repository server. Additionally, exclude processes spawned by ccmexec.exe or ansible-runner running under the domain account DOMAIN\DeployAdmin.Scenario: Legitimate Remote Support Sessions