This hunt targets adversary behavior where threat actors leverage known 32-bit malicious URLs to deliver payloads or establish command-and-control channels within the network. Proactively hunting for these specific indicators in Azure Sentinel is critical because early detection of these high-severity threats allows the SOC team to block compromised endpoints before they execute lateral movement or data exfiltration campaigns.
Threat: 32-bit Total URLs: 55 Active URLs: 49
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://202.1.26.69:37695/i | online | malware_download | 2026-07-05 |
hxxp://117.208.46.126:33920/i | online | malware_download | 2026-07-05 |
hxxp://38.21.70.189:46846/bin.sh | online | malware_download | 2026-07-05 |
hxxp://117.208.46.126:33920/bin.sh | online | malware_download | 2026-07-05 |
hxxp://182.119.182.78:59445/bin.sh | online | malware_download | 2026-07-05 |
hxxp://202.1.26.69:37695/bin.sh | online | malware_download | 2026-07-05 |
hxxp://59.180.168.190:45133/i | online | malware_download | 2026-07-05 |
hxxp://112.255.27.172:53031/bin.sh | online | malware_download | 2026-07-05 |
hxxp://222.139.127.61:46244/i | online | malware_download | 2026-07-05 |
hxxp://125.27.11.15:43282/i | online | malware_download | 2026-07-05 |
hxxp://175.166.11.195:60468/i | online | malware_download | 2026-07-05 |
hxxp://123.10.225.140:53465/i | online | malware_download | 2026-07-05 |
hxxp://59.96.138.50:46384/i | online | malware_download | 2026-07-05 |
hxxp://59.180.168.190:45133/bin.sh | online | malware_download | 2026-07-05 |
hxxp://222.139.127.61:46244/bin.sh | online | malware_download | 2026-07-05 |
hxxp://125.27.11.15:43282/bin.sh | online | malware_download | 2026-07-05 |
hxxp://123.8.152.122:39204/bin.sh | online | malware_download | 2026-07-05 |
hxxp://219.139.228.9:37295/i | online | malware_download | 2026-07-05 |
hxxp://98.252.87.232:56188/bin.sh | online | malware_download | 2026-07-05 |
hxxp://119.185.140.136:34637/i | online | malware_download | 2026-07-05 |
hxxp://42.239.229.103:57521/bin.sh | online | malware_download | 2026-07-05 |
hxxp://219.139.228.9:37295/bin.sh | online | malware_download | 2026-07-05 |
hxxp://113.215.223.222:37449/i | online | malware_download | 2026-07-05 |
hxxp://113.201.215.46:33942/bin.sh | online | malware_download | 2026-07-05 |
hxxp://59.96.138.50:46384/bin.sh | online | malware_download | 2026-07-05 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 32-bit
let malicious_domains = dynamic(["38.21.70.189", "125.27.11.15", "113.201.215.46", "61.53.88.18", "182.119.182.78", "113.215.223.222", "202.1.26.69", "115.58.152.142", "219.139.228.9", "42.239.229.103", "59.180.168.190", "123.8.152.122", "190.109.227.246", "119.185.140.136", "112.255.27.172", "117.208.46.126", "123.10.225.140", "42.239.147.11", "98.252.87.232", "175.166.11.195", "222.139.127.61", "59.96.138.50"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["38.21.70.189", "125.27.11.15", "113.201.215.46", "61.53.88.18", "182.119.182.78", "113.215.223.222", "202.1.26.69", "115.58.152.142", "219.139.228.9", "42.239.229.103", "59.180.168.190", "123.8.152.122", "190.109.227.246", "119.185.140.136", "112.255.27.172", "117.208.46.126", "123.10.225.140", "42.239.147.11", "98.252.87.232", "175.166.11.195", "222.139.127.61", "59.96.138.50"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: 32-bit Malicious URLs detection rule in an enterprise environment, along with recommended filters or exclusions:
Legacy Application Patching via Windows Update Agents
wuauserv.exe or a specific vendor agent (like Microsoft System Center Configuration Manager (SCCM)) connects to the Microsoft Update Content Delivery Network. URLhaus may flag these update endpoints as “32-bit Malicious” due to shared IP reputation with known malware distribution networks, even though the traffic is legitimate patching activity.wuauclt.exe, ccmexec.exe (SCCM), or update-agent.exe when connecting to Microsoft-owned domains (*.windows.com, *.microsoft.com) and specific IP ranges associated with the organization’s approved update servers.Automated Browser-Based Reporting Jobs
chrome.exe and firefox.exe when the process path indicates a non-user context (e.g., running under the SYSTEM or a specific service account like svc-reporting) and the destination URL is whitelisted in