← Back to SOC feed Coverage →

ThreatFox: vSkimmer IOCs

ioc-hunt HIGH ThreatFox
DnsEvents
iocthreatfoxwin-vskimmer
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-09-26T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt targets the presence of nine specific IOCs linked to the vSkimmer malware, a high-severity threat known for injecting malicious code into web pages to steal sensitive user data. Proactively hunting for these indicators in Azure Sentinel allows the SOC to identify compromised assets or lateral movement attempts before the malware can successfully exfiltrate credentials or financial information.

IOC Summary

Malware Family: vSkimmer Total IOCs: 9 IOC Types: domain

TypeValueThreat TypeFirst SeenConfidence
domainwww.bookson7thave.compayload_delivery2026-09-2650%
domainwww.fosterbooks.co.ukpayload_delivery2026-09-2650%
domainwww.gibsonbooks.compayload_delivery2026-09-2650%
domainwww.lectioz.compayload_delivery2026-09-2650%
domainwww.literarycatbooks.compayload_delivery2026-09-2650%
domainwww.mostlyusefulfictions.compayload_delivery2026-09-2650%
domainwww.roundtablebooks.compayload_delivery2026-09-2650%
domainwww.thebooktique.orgpayload_delivery2026-09-2650%
domainwww.vintage-books.compayload_delivery2026-09-2650%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - vSkimmer
let malicious_domains = dynamic(["www.bookson7thave.com", "www.fosterbooks.co.uk", "www.gibsonbooks.com", "www.lectioz.com", "www.literarycatbooks.com", "www.mostlyusefulfictions.com", "www.roundtablebooks.com", "www.thebooktique.org", "www.vintage-books.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Original source: https://threatfox.abuse.ch/browse/malware/win.vskimmer/