IronToll PhaaS: C2 IPs, kit fingerprint, and lure-domain hunt
Detects network activity and HTTP traffic associated with the Iron Man System kit, specifically targeting hardcoded C2 infrastructure (IP-based) and lure domain patterns involving specific brand tokens combined with disposable TLDs.
Microsoft Sentinel (KQL)

