This hunt targets adversary behavior where malicious processes execute known Venus Stealer indicators to exfiltrate sensitive credentials and browser data from endpoints. Proactively hunting these specific IOCs within Azure Sentinel is critical to rapidly identify early-stage infections before they compromise high-value assets or establish persistent footholds in the environment.
Malware Family: Venus Stealer Total IOCs: 33 IOC Types: md5_hash, sha1_hash, sha256_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha256_hash | b8006c2a5a511648876a967f55bae95ccb5515ff0436e7855ce5d2ecc7dd407f | payload | 2026-07-18 | 95% |
| sha1_hash | 044b9e2eba3cb9c410aff01e350676b2405c930e | payload | 2026-07-18 | 95% |
| md5_hash | 52709e9850a742eea194b78fcb9a5528 | payload | 2026-07-18 | 95% |
| sha256_hash | cdc0d27aee64dbcc4b67a3a6cdde4c7f32065144d8fbb6ada691143456e7d756 | payload | 2026-07-18 | 95% |
| sha1_hash | d13ff91e9a6fc4c6fb02a2e1e766d18859f84641 | payload | 2026-07-18 | 95% |
| md5_hash | 43cb4e27e723dad9476b5907e60f7f44 | payload | 2026-07-18 | 95% |
| sha256_hash | ccce59754ac625d60cda648debe4a3021b70a30bc8b85d9a7d5612b1b64ef52a | payload | 2026-07-18 | 95% |
| sha1_hash | 718574faa7708402d748edd30bc9deac049abad0 | payload | 2026-07-18 | 95% |
| md5_hash | 1b344651227f8909c586256a6e7541a2 | payload | 2026-07-18 | 95% |
| sha256_hash | 235f91d8d4634d2af5a9a504420d624496f11af6ffc8a98adea083121b88ab1e | payload | 2026-07-18 | 95% |
| sha1_hash | cdb870a8ea5056f88d548e2bd8c6b7a2004f452f | payload | 2026-07-18 | 95% |
| md5_hash | 7b1c118968b9261ad00231a7fc8180ad | payload | 2026-07-18 | 95% |
| sha256_hash | f3feecf1f6fb2fec70747006dbb8a09b73dfeb8f54946a4d701c13fd71d4600c | payload | 2026-07-18 | 95% |
| sha1_hash | 33297bdf9799e478a11ad7215d5342cc9afe5c5e | payload | 2026-07-18 | 95% |
| md5_hash | ed4861335d1a898ce5b42d2bb1ab98f6 | payload | 2026-07-18 | 95% |
| md5_hash | 8b41af0eb62a9152cc69899f82472db9 | payload | 2026-07-18 | 95% |
| sha256_hash | 5d16539260e3c23da6f5fee3ba39104fde4f68d4226a9957b1c7e35b4a9c1cd4 | payload | 2026-07-18 | 95% |
| sha1_hash | 4080d4e71549072b27b24b5cb902d2d2cdb05da5 | payload | 2026-07-18 | 95% |
| md5_hash | bc4a779062e33deafacd023552b70b70 | payload | 2026-07-18 | 95% |
| md5_hash | 14bb9ecf6b180317899ee49c68008b63 | payload | 2026-07-18 | 95% |
| sha256_hash | a82cd50cbc1beec0bb4d774c248d3daa58f858fa4bddc99b314874cb9914eaca | payload | 2026-07-18 | 95% |
| sha1_hash | 51ac02e4dd3ba3ae244f0830166dbdaf6cdefe56 | payload | 2026-07-18 | 95% |
| md5_hash | fc85c6ec73bec24c13e3c845b01f517c | payload | 2026-07-18 | 95% |
| sha256_hash | 64a3a21cb92d06b12229c7788f6578dc71a3a61cd8658c53fa9cafe051b11b2e | payload | 2026-07-18 | 95% |
| sha1_hash | 0301c109feb04625b760b29cc34fceadd8c62e6f | payload | 2026-07-18 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Venus Stealer
let malicious_hashes = dynamic(["b8006c2a5a511648876a967f55bae95ccb5515ff0436e7855ce5d2ecc7dd407f", "044b9e2eba3cb9c410aff01e350676b2405c930e", "52709e9850a742eea194b78fcb9a5528", "cdc0d27aee64dbcc4b67a3a6cdde4c7f32065144d8fbb6ada691143456e7d756", "d13ff91e9a6fc4c6fb02a2e1e766d18859f84641", "43cb4e27e723dad9476b5907e60f7f44", "ccce59754ac625d60cda648debe4a3021b70a30bc8b85d9a7d5612b1b64ef52a", "718574faa7708402d748edd30bc9deac049abad0", "1b344651227f8909c586256a6e7541a2", "235f91d8d4634d2af5a9a504420d624496f11af6ffc8a98adea083121b88ab1e", "cdb870a8ea5056f88d548e2bd8c6b7a2004f452f", "7b1c118968b9261ad00231a7fc8180ad", "f3feecf1f6fb2fec70747006dbb8a09b73dfeb8f54946a4d701c13fd71d4600c", "33297bdf9799e478a11ad7215d5342cc9afe5c5e", "ed4861335d1a898ce5b42d2bb1ab98f6", "8b41af0eb62a9152cc69899f82472db9", "5d16539260e3c23da6f5fee3ba39104fde4f68d4226a9957b1c7e35b4a9c1cd4", "4080d4e71549072b27b24b5cb902d2d2cdb05da5", "bc4a779062e33deafacd023552b70b70", "14bb9ecf6b180317899ee49c68008b63", "a82cd50cbc1beec0bb4d774c248d3daa58f858fa4bddc99b314874cb9914eaca", "51ac02e4dd3ba3ae244f0830166dbdaf6cdefe56", "fc85c6ec73bec24c13e3c845b01f517c", "64a3a21cb92d06b12229c7788f6578dc71a3a61cd8658c53fa9cafe051b11b2e", "0301c109feb04625b760b29cc34fceadd8c62e6f", "f409be3647f3a4b0b01e59213a1ef5d9", "72c5cec904df799ee47952dba0d830fccd58e49c4810db5261e85747d4495713", "c2cea49d2daec034380b762d47dea91725311948", "1352fc1e651300138b7f5cd431dac11935e54639f8c8b3f87fa9ea6937e6a07a", "3145629198744f73861f58763e0396f728039972", "9264d342f207b8a9233c393b864c26617385071283b030ec6b6976069d91a587", "50cba914311bba28c423bbc11d499b429b1b64ff", "8ab0732a85899cb205f645e969d0b4b8"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: Venus Stealer IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Endpoint Security Scanning of Quarantine Archives
C:\Quarantine directory. This directory often contains archived versions of previously detected malware samples, including historical Venus Stealer variants that were already remediated but not yet purged from the archive. The scanner’s file integrity check triggers the IOCs within these static archives.Quarantine, C:\ProgramData\Antivirus\Archive, or specific vendor quarantine folders (e.g., C:\Windows\System32\config\AppEventLog for Defender) from the detection logic, provided the process initiating the scan is a known security agent.IT Asset Management and Software Inventory Scans
C:\Dev\Staging folders for regression testing purposes.ccmexec.exe, LansweeperAgent.exe) and restrict the detection scope to exclude paths under C:\Dev, D:\Staging, or any directory explicitly tagged with a “Test” or “Development” security tag in the asset management database.Backup and Disaster Recovery Verification Jobs