This hunt targets adversary activity involving known Indicators of Compromise (IOCs) linked to the Socks5 Systemz infrastructure, which often serves as a command and control channel for sophisticated threat actors. Proactively hunting these specific IOCs within Azure Sentinel is critical to identify early-stage lateral movement or data exfiltration attempts before they escalate into confirmed incidents.
Malware Family: Socks5 Systemz Total IOCs: 3 IOC Types: sha256_hash, md5_hash, sha1_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha1_hash | 89eec27c0af96d4932891f02c0a7988b05526012 | payload | 2026-06-27 | 95% |
| md5_hash | 52c76d9b7366f34a1fad3b5b0527e24f | payload | 2026-06-27 | 95% |
| sha256_hash | 716612c11982500cca51970f822ddffb5a4b3aa84fda3cb30ffab6daa94f5248 | payload | 2026-06-27 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Socks5 Systemz
let malicious_hashes = dynamic(["89eec27c0af96d4932891f02c0a7988b05526012", "52c76d9b7366f34a1fad3b5b0527e24f", "716612c11982500cca51970f822ddffb5a4b3aa84fda3cb30ffab6daa94f5248"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: Socks5 Systemz IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
Scheduled Vulnerability Scanning Jobs
10.20.50.x) or specific hostnames containing “scanner” or “vuln”. Additionally, restrict the alert to business hours if scans are scheduled during off-peak times but still trigger during maintenance windows.Endpoint Protection Policy Updates
ProcessName is “CrowdStrikeService.exe” or “MsMpEng.exe” connecting to the Socks5 Systemz IP range.IT Administration and Patch Management Workflows