This hunt targets adversary behavior involving the deployment of XMRIG cryptocurrency mining processes to identify potential resource hijacking or lateral movement within the Azure environment. Proactively hunting for these specific indicators in Azure Sentinel is critical because early detection of unauthorized mining activity can prevent significant performance degradation and reveal hidden persistence mechanisms before they escalate into a full-scale compromise.
Malware Family: XMRIG Total IOCs: 2 IOC Types: ip:port, sha256_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 107[.]175[.]89[.]136:9009 | payload_delivery | 2026-07-07 | 100% |
| sha256_hash | d1487fa8c36489e6e46c950484855b52d4bd3e5a6e86b9caffc7e9a3168a60f4 | payload | 2026-07-07 | 75% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - XMRIG
let malicious_ips = dynamic(["107.175.89.136"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["107.175.89.136"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for files matching known malicious hashes
// Source: ThreatFox - XMRIG
let malicious_hashes = dynamic(["d1487fa8c36489e6e46c950484855b52d4bd3e5a6e86b9caffc7e9a3168a60f4"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceFileEvents | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the ThreatFox: XMRIG IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
DevOps Container Orchestration (Kubernetes/Docker)
xmrig for resource monitoring or as a dependency within CI/CD pipelines. These containers often initiate network connections to XMRIG mining pools or update servers immediately upon startup, triggering the IOC match even though no actual crypto-mining malware is present on the host OS.containerd, dockerd) by filtering for parent process names containing “kubelet” or “docker,” and restrict detection to non-containerized workloads unless specific namespaces are flagged.IT Asset Management & Hardware Diagnostics
xmrig components to benchmark CPU/GPU performance during scheduled maintenance windows. These legitimate administrative tasks generate the specific IOCs associated with XMRIG when scanning idle workstations overnight.speccy.exe, hwmonitor64.exe) or restrict alerts to business hours only, as these diagnostic scans are typically scheduled outside of peak user activity times.Software Development & Compilation Environments
xmrig libraries for parallel compilation tasks. During large-scale code builds, these IDEs spawn child processes that match