This hunt targets adversary behavior involving initial access or command-and-control activities through known 32-bit malicious web endpoints identified by URLhaus. Proactively hunting for these specific indicators in Azure Sentinel is critical to rapidly detect and contain potential infections before they escalate into broader lateral movement within the organization’s network.
Threat: 32-bit Total URLs: 47 Active URLs: 39
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://122.243.151.244:35817/i | online | malware_download | 2026-07-11 |
hxxp://110.36.15.1:47461/i | online | malware_download | 2026-07-11 |
hxxp://119.179.239.23:37650/bin.sh | online | malware_download | 2026-07-11 |
hxxp://39.90.185.248:48598/i | online | malware_download | 2026-07-11 |
hxxp://182.127.0.185:44672/i | online | malware_download | 2026-07-11 |
hxxp://157.66.146.183:48011/i | online | malware_download | 2026-07-11 |
hxxp://196.189.198.193:44465/i | online | malware_download | 2026-07-11 |
hxxp://157.66.146.183:48011/bin.sh | online | malware_download | 2026-07-11 |
hxxp://123.10.153.185:55114/i | online | malware_download | 2026-07-11 |
hxxp://1.61.201.77:37817/i | online | malware_download | 2026-07-11 |
hxxp://110.36.15.1:47461/bin.sh | online | malware_download | 2026-07-11 |
hxxp://123.10.153.185:55114/bin.sh | online | malware_download | 2026-07-11 |
hxxp://101.22.41.112:47649/i | online | malware_download | 2026-07-11 |
hxxp://162.255.251.91:36557/i | online | malware_download | 2026-07-11 |
hxxp://119.99.250.219:43060/i | online | malware_download | 2026-07-11 |
hxxp://219.156.99.10:45205/i | online | malware_download | 2026-07-11 |
hxxp://162.255.251.91:36557/bin.sh | offline | malware_download | 2026-07-11 |
hxxp://27.207.225.43:40906/i | online | malware_download | 2026-07-11 |
hxxp://109.226.203.246:38639/i | online | malware_download | 2026-07-11 |
hxxp://61.52.172.124:42236/i | online | malware_download | 2026-07-11 |
hxxp://61.52.172.124:42236/bin.sh | online | malware_download | 2026-07-11 |
hxxp://219.156.99.10:45205/bin.sh | online | malware_download | 2026-07-11 |
hxxp://115.52.177.97:60804/i | online | malware_download | 2026-07-11 |
hxxp://27.207.225.43:40906/bin.sh | online | malware_download | 2026-07-11 |
hxxp://27.215.95.48:60918/i | online | malware_download | 2026-07-11 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 32-bit
let malicious_domains = dynamic(["157.66.146.183", "182.127.0.185", "110.36.15.1", "119.99.250.219", "39.90.185.248", "61.52.172.124", "109.226.203.246", "219.156.99.10", "27.202.235.64", "42.230.35.67", "1.61.201.77", "122.243.151.244", "27.207.225.43", "101.22.41.112", "27.215.95.48", "119.179.239.23", "196.189.198.193", "123.10.153.185", "101.109.81.222", "162.255.251.91", "115.52.177.97", "175.146.241.30"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["157.66.146.183", "182.127.0.185", "110.36.15.1", "119.99.250.219", "39.90.185.248", "61.52.172.124", "109.226.203.246", "219.156.99.10", "27.202.235.64", "42.230.35.67", "1.61.201.77", "122.243.151.244", "27.207.225.43", "101.22.41.112", "27.215.95.48", "119.179.239.23", "196.189.198.193", "123.10.153.185", "101.109.81.222", "162.255.251.91", "115.52.177.97", "175.146.241.30"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: 32-bit Malicious URLs detection rule, tailored for an enterprise environment where legacy 32-bit applications and administrative workflows are common:
Legacy Software License Validation (e.g., Adobe Creative Suite or Oracle Client)
Adobe.exe, javaw.exe) connecting to known vendor domains (e.g., *.adobe.com, *.oracle.com). Alternatively, whitelist the specific URL patterns associated with license validation endpoints.Automated Patch Management Scans (e.g., SCCM or WSUS Clients)
SYSTEM or specific service accounts (e.g., NT AUTHORITY\SCCM) during maintenance windows. Filter based on the User-Agent header containing keywords like “Microsoft-Update” or “ConfigMgrClient”.Internal Admin Dashboard Access via Legacy Browsers