This hunt hypothesis targets adversary behavior where threat actors leverage known RedTail infrastructure to establish persistence or command-and-control channels within the network. Proactively hunting these specific 54 IOCs in Azure Sentinel is critical because early identification of RedTail-associated artifacts allows the SOC team to disrupt active campaigns before they escalate into broader compromises.
Malware Family: RedTail Total IOCs: 54 IOC Types: ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 104[.]207[.]59[.]23:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 109[.]24[.]152[.]219:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 109[.]9[.]42[.]77:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 115[.]84[.]114[.]228:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 120[.]79[.]220[.]198:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 135[.]181[.]34[.]178:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 128[.]79[.]9[.]232:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 140[.]238[.]153[.]39:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 157[.]245[.]241[.]172:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 159[.]65[.]143[.]47:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 159[.]148[.]58[.]10:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 159[.]65[.]91[.]36:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 172[.]86[.]90[.]30:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 178[.]128[.]215[.]119:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 18[.]97[.]26[.]66:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 180[.]232[.]31[.]158:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 184[.]105[.]247[.]195:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 185[.]214[.]96[.]148:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 185[.]214[.]96[.]151:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 185[.]214[.]96[.]157:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 185[.]231[.]252[.]243:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 185[.]247[.]137[.]143:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 185[.]247[.]137[.]193:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 185[.]247[.]137[.]210:2375 | payload_delivery | 2026-07-01 | 80% |
| ip:port | 185[.]9[.]251[.]81:2375 | payload_delivery | 2026-07-01 | 80% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - RedTail
let malicious_ips = dynamic(["172.86.90.30", "185.247.137.193", "185.214.96.148", "20.169.105.51", "185.214.96.157", "209.50.179.215", "109.24.152.219", "109.9.42.77", "216.26.241.217", "37.66.147.5", "195.184.76.170", "115.84.114.228", "209.99.188.240", "45.79.192.108", "140.238.153.39", "5.49.168.239", "52.165.81.253", "184.105.247.195", "20.64.105.155", "37.65.162.60", "159.65.143.47", "213.244.62.236", "45.148.10.119", "180.232.31.158", "104.207.59.23", "159.148.58.10", "209.50.185.18", "128.79.9.232", "195.96.139.54", "209.50.166.85", "37.24.77.70", "159.65.91.36", "185.231.252.243", "18.97.26.66", "185.9.251.81", "157.245.241.172", "47.238.136.107", "37.65.58.154", "45.3.54.189", "37.27.199.35", "185.247.137.210", "178.128.215.119", "185.247.137.143", "216.26.242.169", "135.181.34.178", "20.163.61.13", "31.16.230.158", "45.3.39.26", "120.79.220.198", "46.193.64.99"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["172.86.90.30", "185.247.137.193", "185.214.96.148", "20.169.105.51", "185.214.96.157", "209.50.179.215", "109.24.152.219", "109.9.42.77", "216.26.241.217", "37.66.147.5", "195.184.76.170", "115.84.114.228", "209.99.188.240", "45.79.192.108", "140.238.153.39", "5.49.168.239", "52.165.81.253", "184.105.247.195", "20.64.105.155", "37.65.162.60", "159.65.143.47", "213.244.62.236", "45.148.10.119", "180.232.31.158", "104.207.59.23", "159.148.58.10", "209.50.185.18", "128.79.9.232", "195.96.139.54", "209.50.166.85", "37.24.77.70", "159.65.91.36", "185.231.252.243", "18.97.26.66", "185.9.251.81", "157.245.241.172", "47.238.136.107", "37.65.58.154", "45.3.54.189", "37.27.199.35", "185.247.137.210", "178.128.215.119", "185.247.137.143", "216.26.242.169", "135.181.34.178", "20.163.61.13", "31.16.230.158", "45.3.39.26", "120.79.220.198", "46.193.64.99"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
Here are 3-5 specific false positive scenarios for the ThreatFox: RedTail IOCs detection rule in an enterprise environment, including suggested filters and exclusions:
Endpoint Management Software Updates
System account with executable paths matching C:\Program Files\Microsoft Configuration Manager\* or C:\Program Files (x86)\Ivanti\*. Additionally, filter out network traffic originating from specific internal IP ranges used by patch management servers during defined maintenance windows (e.g., 02:00–04:00 UTC).IT Admin Manual Investigation Tasks
@internal-admins or belongs to the “Security Operations” AD Security Group. Furthermore, filter out events occurring on workstations within the IT-Management-VLAN subnet.Automated Threat Intelligence Feeds Integration
Update-ThreatIntelligence.ps1) that ingests daily feeds