This hunt targets adversary behavior where malicious actors deploy the CrossRAT remote access trojan to establish persistent footholds and exfiltrate sensitive data via its known indicators of compromise. Proactively hunting for these specific IOCs in Azure Sentinel is critical because early detection of CrossRAT activity allows the SOC team to rapidly isolate compromised endpoints before lateral movement occurs, mitigating the high risk associated with this sophisticated threat actor.
Malware Family: CrossRAT Total IOCs: 9 IOC Types: sha1_hash, md5_hash, sha256_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha1_hash | 093ac47b4dcac8fa8d3487b73be98fea003513bc | payload | 2026-07-02 | 95% |
| md5_hash | 668012498421c76b8a9d344ce6acfc67 | payload | 2026-07-02 | 95% |
| sha1_hash | d307f448f00cb89fee296eb1144ef414905902f3 | payload | 2026-07-02 | 95% |
| md5_hash | f9158f928bff45d130cc27d4ae20aee8 | payload | 2026-07-02 | 95% |
| sha256_hash | 9a6475f5c793000640b312a5d5a9b18edf9d570cb2b86204dc9b7101ce5b4fdb | payload | 2026-07-02 | 95% |
| sha256_hash | 193863103749d8b2f536cef7bbac7e9691f96742962c5aea4e9f6604db0c4aa7 | payload | 2026-07-02 | 95% |
| sha256_hash | 02727498170edcb29c041a632172eda8b43c89f7235346b03b174b3e5985bb38 | payload | 2026-07-02 | 95% |
| sha1_hash | e8a104ec01ee0fa1c25022eb13ae28150485f212 | payload | 2026-07-02 | 95% |
| md5_hash | 683c7276bbdc7df8740788e245a461d5 | payload | 2026-07-02 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - CrossRAT
let malicious_hashes = dynamic(["093ac47b4dcac8fa8d3487b73be98fea003513bc", "668012498421c76b8a9d344ce6acfc67", "d307f448f00cb89fee296eb1144ef414905902f3", "f9158f928bff45d130cc27d4ae20aee8", "9a6475f5c793000640b312a5d5a9b18edf9d570cb2b86204dc9b7101ce5b4fdb", "193863103749d8b2f536cef7bbac7e9691f96742962c5aea4e9f6604db0c4aa7", "02727498170edcb29c041a632172eda8b43c89f7235346b03b174b3e5985bb38", "e8a104ec01ee0fa1c25022eb13ae28150485f212", "683c7276bbdc7df8740788e245a461d5"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: CrossRAT IOCs detection rule, along with suggested filters and exclusions tailored for an enterprise environment:
Endpoint Protection Scanning of Quarantine Archives
C:\Program Files\CrowdStrike\fsa.exe or MsMpEng.exe) combined with a specific User Context (e.g., NT AUTHORITY\SYSTEM). Additionally, filter out traffic originating from known internal scanning subnets.IT Asset Management and Software Inventory Jobs
IvantiAgent.exe, ccmexec.exe) and the Destination Port is standard web traffic (80/443). Ensure the exclusion applies specifically to recurring scheduled job windows (e.g., 02:00–04:00 UTC daily).Threat Intelligence Feed Synchronization by SIEM/SOAR Platforms