This hunt targets adversaries leveraging known 32-bit malicious web resources to deliver payloads or establish command-and-control channels within the Azure environment. Proactively searching for these specific URL signatures in Azure Sentinel is critical because they represent a high-confidence indicator of compromise that may bypass initial perimeter defenses and require immediate containment before lateral movement occurs.
Threat: 32-bit Total URLs: 62 Active URLs: 61
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://115.55.8.197:54012/i | online | malware_download | 2026-07-03 |
hxxp://115.49.4.59:52130/bin.sh | online | malware_download | 2026-07-03 |
hxxp://182.121.170.194:45501/bin.sh | online | malware_download | 2026-07-03 |
hxxp://105.225.64.238:54357/i | online | malware_download | 2026-07-03 |
hxxp://42.229.200.225:60685/i | online | malware_download | 2026-07-03 |
hxxp://120.84.215.46:34093/i | online | malware_download | 2026-07-03 |
hxxp://115.51.104.177:51026/i | online | malware_download | 2026-07-03 |
hxxp://42.224.51.147:36172/i | online | malware_download | 2026-07-03 |
hxxp://39.79.15.194:37416/bin.sh | online | malware_download | 2026-07-03 |
hxxp://115.55.8.197:54012/bin.sh | online | malware_download | 2026-07-03 |
hxxp://115.50.93.34:37693/i | online | malware_download | 2026-07-03 |
hxxp://125.44.243.245:44944/i | online | malware_download | 2026-07-03 |
hxxp://42.224.51.147:36172/bin.sh | online | malware_download | 2026-07-03 |
hxxp://42.229.200.225:60685/bin.sh | online | malware_download | 2026-07-03 |
hxxp://222.220.145.105:51630/i | online | malware_download | 2026-07-03 |
hxxp://105.224.71.15:54389/bin.sh | online | malware_download | 2026-07-03 |
hxxp://115.52.16.242:37666/bin.sh | online | malware_download | 2026-07-03 |
hxxp://115.50.93.34:37693/bin.sh | online | malware_download | 2026-07-03 |
hxxp://125.44.243.245:44944/bin.sh | online | malware_download | 2026-07-03 |
hxxp://110.37.91.29:45945/bin.sh | online | malware_download | 2026-07-03 |
hxxp://222.220.145.105:51630/bin.sh | online | malware_download | 2026-07-03 |
hxxp://110.85.111.205:41787/i | online | malware_download | 2026-07-03 |
hxxp://171.37.127.210:41472/i | online | malware_download | 2026-07-03 |
hxxp://212.164.115.235:33213/bin.sh | online | malware_download | 2026-07-03 |
hxxp://110.39.230.2:52121/i | online | malware_download | 2026-07-03 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 32-bit
let malicious_domains = dynamic(["110.39.230.2", "120.84.215.46", "39.79.15.194", "42.229.200.225", "105.224.71.15", "105.225.64.238", "115.55.8.197", "222.220.145.105", "205.250.173.210", "115.52.16.242", "110.85.111.205", "110.37.39.129", "42.224.51.147", "115.50.93.34", "125.44.243.245", "110.37.91.29", "212.164.115.235", "182.121.170.194", "115.51.104.177", "115.49.4.59", "171.37.127.210"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["110.39.230.2", "120.84.215.46", "39.79.15.194", "42.229.200.225", "105.224.71.15", "105.225.64.238", "115.55.8.197", "222.220.145.105", "205.250.173.210", "115.52.16.242", "110.85.111.205", "110.37.39.129", "42.224.51.147", "115.50.93.34", "125.44.243.245", "110.37.91.29", "212.164.115.235", "182.121.170.194", "115.51.104.177", "115.49.4.59", "171.37.127.210"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: 32-bit Malicious URLs detection rule in an enterprise environment, along with suggested filters and exclusions:
Legacy Patch Management Scans by SCCM/MECM
Microsoft-ConfigurationManager or SCCM-Agent.Automated Vulnerability Scans via Qualys or Tenable
urlhaus.abuse.ch (or the specific URLhaus subdomain), ensuring the traffic is marked as Scheduled-Job in the asset inventory.Third-Party SIEM Log Forwarding via Splunk Universal Forwarder