This detection identifies adversary activity involving traffic to specific malicious URLs (tagged 195-177-94-111) that may indicate initial compromise or command-and-control communication from external threat intelligence feeds. A proactive hunt is essential in Azure Sentinel to validate these high-severity indicators against internal network logs, ensuring early identification of potential data exfiltration or lateral movement before broader impact occurs.
Threat: 195-177-94-111 Total URLs: 2 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://195.177.94.111/Bin/ScreenConnect.ClientSetup.exe | offline | malware_download | 2026-08-22 |
hxxps://195.177.94.111/bin/support.client.exe | offline | malware_download | 2026-08-22 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 195-177-94-111
let malicious_domains = dynamic(["195.177.94.111"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["195.177.94.111"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios and corresponding filters for the URLhaus: 195-177-94-111 Malicious URLs detection rule in an enterprise environment:
Scenario: Automated Patch Deployment via Vendor Repository
195.177.94.111. During nightly maintenance windows, the patching service initiates a high-volume connection to this IP to download metadata and binaries, triggering the rule due to the volume of requests rather than malicious intent.SCCM-PRIMARY01.corp.local) or Ansible controller hostnames where the destination IP is 195.177.94.111 and the user agent contains “System Center” or “Ansible”.Scenario: Scheduled Cloud Backup Agent Heartbeats
FILE-SRV-04) send periodic heartbeat and configuration sync requests every 15 minutes, which the detection logic flags as suspicious URL activity due to the specific tagging of the destination.VeeamTransport.exe or rubrik-agent.service and the destination IP is 195.177.94.111, specifically during non-business hours (02:00–06