← Back to SOC feed Coverage →

ThreatFox: MetaStealer IOCs

ioc-hunt HIGH ThreatFox
DnsEvents
infostealeriocthreatfoxwin-metastealer
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-07-16T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt hypothesis targets adversary behavior where malicious actors deploy MetaStealer to exfiltrate sensitive credentials and system data by matching network traffic against a curated set of 128 known Indicators of Compromise (IOCs). Proactively hunting for these specific IOCs in Azure Sentinel is critical because it enables the SOC team to rapidly identify early-stage infections across the cloud environment before the stealer establishes persistence or expands its lateral movement.

IOC Summary

Malware Family: MetaStealer Total IOCs: 128 IOC Types: domain

TypeValueThreat TypeFirst SeenConfidence
domainyyowcsswsesksomi.xyzbotnet_cc2026-07-16100%
domainyyqewussumqweisi.xyzbotnet_cc2026-07-16100%
domainyyqisgekkgammukq.xyzbotnet_cc2026-07-16100%
domainyyqkageayymeoses.xyzbotnet_cc2026-07-16100%
domainyyqokiuoyqkuwiog.xyzbotnet_cc2026-07-16100%
domainyywesmeciecsmksk.xyzbotnet_cc2026-07-16100%
domainyquagqysgcsuceqs.xyzbotnet_cc2026-07-16100%
domainyqukwqcwqgceousm.xyzbotnet_cc2026-07-16100%
domainyqusqqumoekaqaoq.xyzbotnet_cc2026-07-16100%
domainyqwqkcaiaeemoouq.xyzbotnet_cc2026-07-16100%
domainyqwysiuoiyomosec.xyzbotnet_cc2026-07-16100%
domainyqyoccyuaoysckmm.xyzbotnet_cc2026-07-16100%
domainyqyueyuoukmsmqem.xyzbotnet_cc2026-07-16100%
domainyyaqcymcosceugwu.xyzbotnet_cc2026-07-16100%
domainyyaygggumsoywcwk.xyzbotnet_cc2026-07-16100%
domainyyeckmeayawguoim.xyzbotnet_cc2026-07-16100%
domainyyeoguuueeoaggwi.xyzbotnet_cc2026-07-16100%
domainyygiiasyoqkgsqee.xyzbotnet_cc2026-07-16100%
domainyyigcsagquigikkq.xyzbotnet_cc2026-07-16100%
domainyyiicoewgysyayam.xyzbotnet_cc2026-07-16100%
domainyqaaywumkgiuoegk.xyzbotnet_cc2026-07-16100%
domainyqagqiuauqoyuwkw.xyzbotnet_cc2026-07-16100%
domainyqaiqmaygauogoyk.xyzbotnet_cc2026-07-16100%
domainyqckmsmisoycykgc.xyzbotnet_cc2026-07-16100%
domainyqeaqqsiqwgaoyws.xyzbotnet_cc2026-07-16100%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - MetaStealer
let malicious_domains = dynamic(["yyowcsswsesksomi.xyz", "yyqewussumqweisi.xyz", "yyqisgekkgammukq.xyz", "yyqkageayymeoses.xyz", "yyqokiuoyqkuwiog.xyz", "yywesmeciecsmksk.xyz", "yquagqysgcsuceqs.xyz", "yqukwqcwqgceousm.xyz", "yqusqqumoekaqaoq.xyz", "yqwqkcaiaeemoouq.xyz", "yqwysiuoiyomosec.xyz", "yqyoccyuaoysckmm.xyz", "yqyueyuoukmsmqem.xyz", "yyaqcymcosceugwu.xyz", "yyaygggumsoywcwk.xyz", "yyeckmeayawguoim.xyz", "yyeoguuueeoaggwi.xyz", "yygiiasyoqkgsqee.xyz", "yyigcsagquigikkq.xyz", "yyiicoewgysyayam.xyz", "yqaaywumkgiuoegk.xyz", "yqagqiuauqoyuwkw.xyz", "yqaiqmaygauogoyk.xyz", "yqckmsmisoycykgc.xyz", "yqeaqqsiqwgaoyws.xyz", "yqegkgwweowiowmw.xyz", "yqiiwqcuyquwcmse.xyz", "yqkquakgsccocsqg.xyz", "yqkyggoocksesowc.xyz", "yqmaimewwksoksue.xyz", "yqmcoeokqwwmmaea.xyz", "yqqccumwacwqowuo.xyz", "yqqioagmmsciwquq.xyz", "yqsacwmwiwukwuig.xyz", "yqsciwsaaeeucqaa.xyz", "ykoqymcuwwwggkqw.xyz", "ykqegysecaamkage.xyz", "ykqeoegaiwmekyiy.xyz", "ykqwogyoeasiaugw.xyz", "ykugyiiicguawywq.xyz", "ykuiqqumgamwwgia.xyz", "ykuqogqmoqmgsyow.xyz", "ykwgeqoaawkkemos.xyz", "ykwmoukgikemiauc.xyz", "ykwosqoemowmuqyu.xyz", "ykyieuyoesksuqiw.xyz", "ykyiieuemcesiuwe.xyz", "ykyoiggwuoyeskkw.xyz", "yoigusekcwamuoqe.xyz", "yeyaqmgqcmwukkmi.xyz"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 4 specific false positive scenarios for the ThreatFox: MetaStealer IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:

Original source: https://threatfox.abuse.ch/browse/malware/win.metastealer/