This hunt targets adversary behavior where compromised hosts initiate outbound connections to known malicious infrastructure hosted on IP 137.184.133.198, as identified by URLhaus threat intelligence feeds. Proactively hunting for these specific URLs in Azure Sentinel is critical because early detection of this high-severity indicator can prevent lateral movement and data exfiltration before the malware fully establishes its command-and-control channel.
Threat: 137-184-133-198 Total URLs: 2 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://137.184.133.198/Bin/ScreenConnect.ClientSetup.exe | offline | malware_download | 2026-07-14 |
hxxps://137.184.133.198/bin/support.client.exe | offline | malware_download | 2026-07-14 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 137-184-133-198
let malicious_domains = dynamic(["137.184.133.198"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["137.184.133.198"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are four specific false positive scenarios for the URLhaus: 137-184-133-198 Malicious URLs detection rule, tailored for a legitimate enterprise environment. These scenarios focus on common administrative workflows and automated maintenance tasks that interact with this IP range (often associated with Microsoft or major cloud infrastructure).
Microsoft Office 365 Proactive Threat Scanning
137-184-133-198. The rule triggers because the IP is flagged as “Malicious” in the global feed, but the traffic originates from a trusted internal service account performing routine hygiene checks rather than user-initiated browsing.svc-office-scanner@domain.local) or exclude traffic originating from the Office 365 management subnet (10.x.x.x/24) when accessing this IP during business hours (08:00–18:00).Scheduled Antivirus Definition Updates via WSUS
137-184-133-198 (a known Microsoft CDN node). The detection logic flags this connection because the URLhaus feed recently updated its reputation score for this IP due to a transient global alert, even though the enterprise’s internal WSUS server has already validated the content signature.