Coruna/attacker-server IOC sweep: hashes, IP and domains
This rule performs a multi-source correlation (network, DNS, file, and process telemetry) to detect artifacts associated with the Coruna campaign. It looks for known malicious file hashes (SHA1), C2 IP addresses, and specific domain/URL patterns in process command lines and network connections.
Microsoft Sentinel (KQL)

