← Back to SOC feed Coverage →

URLhaus: 150-40-127-145 Malicious URLs

ioc-hunt HIGH URLhaus
CommonSecurityLogDnsEvents
iocurlhaus
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at URLhaus →
Retrieved: 2026-09-09T23:00:00Z · Confidence: medium

Hunt Hypothesis

This hypothesis targets adversaries leveraging the IP address 150.40.127.145 to host malicious URLs, a common tactic for delivering payloads or establishing command-and-control channels. Proactively hunting for these indicators in Azure Sentinel allows the SOC to identify compromised assets or active exfiltration attempts before they escalate into a full breach.

IOC Summary

Threat: 150-40-127-145 Total URLs: 17 Active URLs: 2

URLStatusThreatDate Added
hxxp://150.40.127.145/sora.shofflinemalware_download2026-09-09
hxxp://150.40.127.145/gpon443offlinemalware_download2026-09-09
hxxp://150.40.127.145/yarnofflinemalware_download2026-09-09
hxxp://150.40.127.145/awsofflinemalware_download2026-09-09
hxxp://150.40.127.145/zyxelofflinemalware_download2026-09-09
hxxp://150.40.127.145/zteonlinemalware_download2026-09-09
hxxp://150.40.127.145/hnapofflinemalware_download2026-09-09
hxxp://150.40.127.145/goaheadofflinemalware_download2026-09-09
hxxp://150.40.127.145/jawsofflinemalware_download2026-09-09
hxxp://150.40.127.145/thinkphpofflinemalware_download2026-09-09
hxxp://150.40.127.145/payofflinemalware_download2026-09-09
hxxp://150.40.127.145/realtekofflinemalware_download2026-09-09
hxxp://150.40.127.145/huaweionlinemalware_download2026-09-09
hxxp://150.40.127.145/binofflinemalware_download2026-09-09
hxxp://150.40.127.145/bins/sora.armofflinemalware_download2026-09-09
hxxp://150.40.127.145/pulseofflinemalware_download2026-09-09
hxxp://150.40.127.145/lgofflinemalware_download2026-09-09

KQL: Url Dns Hunt

// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 150-40-127-145
let malicious_domains = dynamic(["150.40.127.145"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc

KQL: Url Proxy Hunt

// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["150.40.127.145"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Original source: https://urlhaus.abuse.ch/