Indicators of Compromise (IOCs) serve as essential forensic markers in pinpointing security breaches. They encompass various elements such as file hashes, dubious IP addresses, domain names, URLs, specific email addresses, irregular file names, registry modifications, unexpected processes, and abnormal network traffic patterns. These indicators are instrumental in recognizing malicious activities and are vital for the swift detection and response to cybersecurity threats.
The ANY.RUN Threat Intelligence (TI) lookup service provides comprehensive threat data derived from the analysis of millions of malware and phishing samples. This information is continuously refreshed by a global network of cybersecurity experts who contribute to a shared database. Security professionals can access this extensive database, which spans 2 TB, and use more than 40 parameters and wildcards to pinpoint specific threats. The service delivers rapid results, each linked to a detailed sandbox analysis session for thorough investigation.
The platform facilitates the creation and integration of YARA rules into security systems via API, enabling security experts to identify active threats, generate accurate Indicators of Compromise (IOCs), and anticipate and thwart future attacks.
TI Lookup now includes IOCs extracted from malware configurations, with contributions from reverse-engineered malware samples covering 79 malware families. It effectively identifies potential command-and-control (C2) domains related to Remcos malware using the “malconf” tag. For instance, a search query combining “threatName:’remcos’” and “domainName:”” reveals over 250 domains found in sandbox environments that contain Remcos.
By prioritizing results with the “malconf” label, analysts can highlight domains extracted directly from malware configurations, which increases the chances of identifying active command-and-control infrastructure used in Remcos attacks.
Investigators can use IOCs from sandboxed AsyncRAT samples to uncover further malicious activities. If a sandbox report indicates an IP address within the AsyncRAT configuration, analysts can utilize TI Lookup for deeper investigation. For example, a search query with the destination IP field set to the extracted IP (e.g., “destinationIP: 37(.)120.233.226”) provides valuable insights into the IP’s potential maliciousness, including historical sightings in malware samples, connections to known malicious actors, and associated domain names. This information helps determine the IP’s involvement in the AsyncRAT campaign and identify broader threats.
TI Lookup identified 55 analysis sessions linked to the malicious IP. By reviewing these sessions, analysts can extract hash sums and other IOCs related to the malware, facilitating the identification of the malware family and uncovering additional threats by correlating related events, files, destination ports, and sandbox sessions associated with the indicator.
Additionally, ANY.RUN demonstrates how to analyze a Vidar URL using TI Lookup within its sandbox environment. By extracting a URL from Vidar’s configuration during a sandbox analysis, a TI Lookup query can be constructed using the “url:” search operator. For instance, searching with the query “url: https(:)//t.me/armad2a”” helps identify indicators associated with the URL. The results may reveal additional samples with similar indicators, offering insights into the broader threat landscape.
ANY.RUN’s investigation further suggests a connection between Vidar and PrivateLoader, indicating that Vidar might frequently be delivered via this downloader tool.
The ANY.RUN sandbox provides an interactive malware analysis environment, allowing users to safely interact with files and links to investigate the extent of each threat. The service automatically detects and records all activities across network traffic, registry, file system, and processes, and extracts relevant indicators of compromise.



