This hunt targets adversary behavior where attackers leverage known 32-bit malicious URLs to deliver payloads or redirect users to compromised web resources within the Azure environment. Proactively hunting for these specific URL patterns in Azure Sentinel is critical because they represent a high-severity vector that may bypass standard perimeter defenses, requiring immediate investigation to prevent lateral movement and data exfiltration.
Threat: 32-bit Total URLs: 61 Active URLs: 60
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://123.5.168.10:36741/bin.sh | online | malware_download | 2026-07-01 |
hxxp://123.14.221.183:52277/i | online | malware_download | 2026-07-01 |
hxxp://123.14.221.183:52277/bin.sh | online | malware_download | 2026-07-01 |
hxxp://119.179.208.110:34766/i | online | malware_download | 2026-07-01 |
hxxp://27.44.144.253:43603/i | online | malware_download | 2026-07-01 |
hxxp://125.44.42.45:53083/bin.sh | online | malware_download | 2026-07-01 |
hxxp://119.179.208.110:34766/bin.sh | online | malware_download | 2026-07-01 |
hxxp://123.14.93.231:50448/bin.sh | online | malware_download | 2026-07-01 |
hxxp://105.184.182.42:54111/i | online | malware_download | 2026-07-01 |
hxxp://27.44.145.224:36350/i | online | malware_download | 2026-07-01 |
hxxp://182.127.38.188:36121/bin.sh | online | malware_download | 2026-07-01 |
hxxp://42.231.250.215:59905/i | online | malware_download | 2026-07-01 |
hxxp://27.37.229.70:60470/i | online | malware_download | 2026-07-01 |
hxxp://219.155.251.103:43616/i | online | malware_download | 2026-07-01 |
hxxp://105.184.182.42:54111/bin.sh | online | malware_download | 2026-07-01 |
hxxp://125.44.244.56:44944/bin.sh | online | malware_download | 2026-07-01 |
hxxp://182.113.248.145:35518/i | online | malware_download | 2026-07-01 |
hxxp://115.48.27.166:55311/i | online | malware_download | 2026-07-01 |
hxxp://42.85.135.133:46174/i | online | malware_download | 2026-07-01 |
hxxp://219.155.251.103:43616/bin.sh | online | malware_download | 2026-07-01 |
hxxp://220.249.175.20:58631/bin.sh | online | malware_download | 2026-07-01 |
hxxp://123.10.15.235:48416/bin.sh | online | malware_download | 2026-07-01 |
hxxp://115.48.27.166:55311/bin.sh | online | malware_download | 2026-07-01 |
hxxp://110.36.19.101:43670/i | online | malware_download | 2026-07-01 |
hxxp://110.36.19.101:43670/bin.sh | online | malware_download | 2026-07-01 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 32-bit
let malicious_domains = dynamic(["42.85.135.133", "42.231.250.215", "115.48.27.166", "125.44.244.56", "27.37.229.70", "123.10.15.235", "115.55.52.84", "27.44.145.224", "110.36.19.101", "125.44.42.45", "115.52.176.66", "219.155.251.103", "42.231.46.107", "123.5.168.10", "182.113.248.145", "105.184.182.42", "119.179.208.110", "182.127.38.188", "220.249.175.20", "123.14.93.231", "123.14.221.183", "125.41.8.228", "27.44.144.253"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["42.85.135.133", "42.231.250.215", "115.48.27.166", "125.44.244.56", "27.37.229.70", "123.10.15.235", "115.55.52.84", "27.44.145.224", "110.36.19.101", "125.44.42.45", "115.52.176.66", "219.155.251.103", "42.231.46.107", "123.5.168.10", "182.113.248.145", "105.184.182.42", "119.179.208.110", "182.127.38.188", "220.249.175.20", "123.14.93.231", "123.14.221.183", "125.41.8.228", "27.44.144.253"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are four specific false positive scenarios for the URLhaus: 32-bit Malicious URLs detection rule, tailored for an enterprise environment:
Legacy Patch Management Scans via WSUS or SCCM
10.x.x.x) or specific service accounts (e.g., svc_sccm_agent) accessing Microsoft domains (*.microsoft.com, *.update.microsoft.com).Automated Software Inventory and Compliance Audits
*.adobe.com, *.oracle.com) initiated by the audit agent process.Third-Party Cloud Backup Agents on Legacy Hardware