This hunt targets adversary activity involving PureRAT remote access trojan indicators to identify potential command-and-control communications and lateral movement within the network. Proactively searching for these specific IOCs in Azure Sentinel is critical because PureRAT’s ability to execute arbitrary commands and exfiltrate data requires early detection before it establishes persistence on compromised endpoints.
Malware Family: PureRAT Total IOCs: 9 IOC Types: md5_hash, sha256_hash, sha1_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha1_hash | 097e7d7db52c47e763663991962b99f4920a3a5b | payload | 2026-07-14 | 95% |
| md5_hash | 96643dad566ec23b8917bd08cd0bb575 | payload | 2026-07-14 | 95% |
| sha256_hash | 68e91f0bde5d4c602eefa5e8057d65cf5a4af17021215736de2359fb4d577ce0 | payload | 2026-07-14 | 95% |
| md5_hash | 12be7a6c060a27bbed222ab8181ba592 | payload | 2026-07-14 | 95% |
| md5_hash | 3509393b29d79798b259223623bca4e5 | payload | 2026-07-14 | 95% |
| sha256_hash | e30c4e9e950ee26b0480a07c5a5128167a76b64dfac40ae06a0bb070a80838a9 | payload | 2026-07-14 | 95% |
| sha1_hash | cf918f6f67e2f0eaf5aa329280199a0c4adc9f37 | payload | 2026-07-14 | 95% |
| sha256_hash | 825f8963d55e53cad341401c2f235523b2f9e87b503f83019fdac5f9f2714088 | payload | 2026-07-14 | 95% |
| sha1_hash | 3b004549daf62319f3bd68dbe423c50acf3203be | payload | 2026-07-14 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - PureRAT
let malicious_hashes = dynamic(["097e7d7db52c47e763663991962b99f4920a3a5b", "96643dad566ec23b8917bd08cd0bb575", "68e91f0bde5d4c602eefa5e8057d65cf5a4af17021215736de2359fb4d577ce0", "12be7a6c060a27bbed222ab8181ba592", "3509393b29d79798b259223623bca4e5", "e30c4e9e950ee26b0480a07c5a5128167a76b64dfac40ae06a0bb070a80838a9", "cf918f6f67e2f0eaf5aa329280199a0c4adc9f37", "825f8963d55e53cad341401c2f235523b2f9e87b503f83019fdac5f9f2714088", "3b004549daf62319f3bd68dbe423c50acf3203be"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: PureRAT IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
Endpoint Management Software Updates
10.x.x.x for internal SCCM servers) and whitelist specific file hashes associated with the vendor’s signed installers in the detection logic.Software Deployment via Configuration Management
svc_ansible, chef-client) and filter out connections to internal artifact repository domains that are not part of the public threat intelligence feed.Scheduled Backup and Data Synchronization Jobs