This hunt targets adversaries leveraging known 32-bit malicious web resources to deliver payloads or establish command-and-control channels within the Azure environment. Proactively hunting these specific URL patterns in Azure Sentinel is critical because it enables the early identification of compromised hosts attempting to communicate with established threat infrastructure before lateral movement occurs.
Threat: 32-bit Total URLs: 42 Active URLs: 38
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://222.136.23.106:45812/bin.sh | online | malware_download | 2026-07-10 |
hxxp://182.126.99.164:43603/bin.sh | online | malware_download | 2026-07-10 |
hxxp://110.36.91.33:48724/bin.sh | online | malware_download | 2026-07-10 |
hxxp://221.3.122.78:42109/bin.sh | online | malware_download | 2026-07-10 |
hxxp://222.137.85.38:51752/i | online | malware_download | 2026-07-10 |
hxxp://222.137.85.38:51752/bin.sh | online | malware_download | 2026-07-10 |
hxxp://45.5.138.3:59029/bin.sh | online | malware_download | 2026-07-10 |
hxxp://105.187.33.138:33631/i | online | malware_download | 2026-07-09 |
hxxp://182.123.211.0:55917/i | online | malware_download | 2026-07-09 |
hxxp://105.187.33.138:33631/bin.sh | online | malware_download | 2026-07-09 |
hxxp://115.195.212.157:57971/i | online | malware_download | 2026-07-09 |
hxxp://222.137.23.22:54815/i | online | malware_download | 2026-07-09 |
hxxp://182.123.211.0:55917/bin.sh | online | malware_download | 2026-07-09 |
hxxp://222.137.23.22:54815/bin.sh | online | malware_download | 2026-07-09 |
hxxp://42.226.220.88:59642/i | online | malware_download | 2026-07-09 |
hxxp://115.195.212.157:57971/bin.sh | online | malware_download | 2026-07-09 |
hxxp://39.64.9.139:43526/bin.sh | online | malware_download | 2026-07-09 |
hxxp://182.115.74.126:34759/bin.sh | online | malware_download | 2026-07-09 |
hxxp://42.237.59.190:37182/bin.sh | online | malware_download | 2026-07-09 |
hxxp://27.215.127.151:60783/bin.sh | online | malware_download | 2026-07-09 |
hxxp://117.253.62.162:59112/i | online | malware_download | 2026-07-09 |
hxxp://115.55.199.160:48900/i | online | malware_download | 2026-07-09 |
hxxp://84.22.221.124:4908/bin.sh | online | malware_download | 2026-07-09 |
hxxp://115.55.59.63:52041/bin.sh | online | malware_download | 2026-07-09 |
hxxp://105.186.220.123:43043/bin.sh | offline | malware_download | 2026-07-09 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 32-bit
let malicious_domains = dynamic(["222.136.23.106", "115.55.199.160", "119.109.212.35", "124.131.186.170", "182.123.211.0", "222.137.23.22", "219.154.173.110", "222.137.85.38", "45.5.138.3", "117.253.62.162", "84.22.221.124", "119.14.97.112", "182.126.99.164", "39.64.9.139", "42.226.220.88", "115.55.59.63", "27.215.127.151", "221.3.122.78", "110.36.91.33", "105.187.33.138", "115.195.212.157", "42.237.59.190", "182.115.74.126"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["222.136.23.106", "115.55.199.160", "119.109.212.35", "124.131.186.170", "182.123.211.0", "222.137.23.22", "219.154.173.110", "222.137.85.38", "45.5.138.3", "117.253.62.162", "84.22.221.124", "119.14.97.112", "182.126.99.164", "39.64.9.139", "42.226.220.88", "115.55.59.63", "27.215.127.151", "221.3.122.78", "110.36.91.33", "105.187.33.138", "115.195.212.157", "42.237.59.190", "182.115.74.126"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are four specific false positive scenarios for the URLhaus: 32-bit Malicious URLs detection rule, tailored for an enterprise environment using Hunt packages and 32-bit legacy applications:
Legacy Accounting Software Auto-Updates
updates.quickbooks.com or specific SAP patch repositories). URLhaus may flag these internal or vendor-specific endpoints as “malicious” due to shared IP reputation scores with known 32-bit malware families, even though the traffic is legitimate business logic.QBUpdate.exe and SAPBusinessOne.exe (or their specific service accounts) when accessing URLs containing keywords like /api/v1/health, /update/check, or the vendor’s primary domain suffix, provided the HTTP response code is 200 OK.32-bit Browser Plugin Telemetry
telemetry.mcafees.com or update.symantec.com). URLhaus might classify these high-volume, automated 32-bit client connections as suspicious due to the “malicious URL” tag often associated with browser exploit kits.mfevtp.exe, Symantec Endpoint Protection Agent) targeting known vendor update domains, specifically filtering for User