This detection identifies adversary activity involving connections to specific malicious URLs (tagged 193-26-115-28) that may indicate initial access or command-and-control communications from compromised hosts. Proactively hunting for these indicators in Azure Sentinel is critical due to the high severity of the threat, allowing the SOC team to rapidly isolate affected systems and prevent potential data exfiltration or lateral movement before broader impact occurs.
Threat: 193-26-115-28 Total URLs: 2 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://193.26.115.28/Bin/ScreenConnect.ClientSetup.exe | offline | malware_download | 2026-08-17 |
hxxps://193.26.115.28/bin/support.client.exe | offline | malware_download | 2026-08-17 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 193-26-115-28
let malicious_domains = dynamic(["193.26.115.28"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["193.26.115.28"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios and corresponding mitigation strategies for the URLhaus: 193-26-115-28 Malicious URLs detection rule in a legitimate enterprise environment:
Scenario: Automated Security Scanning by EDR Agents
193.26.115.28 (or its associated subdomains) to fetch the latest malware signature updates, which triggers the rule despite being a trusted source.ProcessName matches C:\Program Files\CrowdStrike\csagent.exe (or equivalent EDR binary) and UserName is SYSTEM or a dedicated service account like svc-threat-intel.Scenario: Scheduled Cloud Backup Connectivity Checks
193.26.115.28 range, resulting in legitimate traffic that mimics malicious URL access patterns.ProcessPath contains `\Veeam\BackupService.exe