This hunt targets adversary behavior involving initial access or command-and-control communications through a specific cluster of 17 known malicious URLs associated with IP 85-11-167-178. Proactively hunting for these indicators in Azure Sentinel is critical to identify early-stage infections and prevent lateral movement before the threat escalates into a broader compromise.
Threat: 85-11-167-178 Total URLs: 17 Active URLs: 11
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://85.11.167.178/manji.x86 | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.sh4 | offline | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.spc | offline | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.ppc | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.ppc440 | offline | malware_download | 2026-07-17 |
hxxp://85.11.167.178/ohshit.sh | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.arm4 | offline | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.i486 | offline | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.dbg | offline | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.m68k | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.arm5 | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.arm7 | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.i686 | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.mpsl | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.mips | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/manji.arm6 | online | malware_download | 2026-07-17 |
hxxp://85.11.167.178/Services.apk | online | malware_download | 2026-07-17 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 85-11-167-178
let malicious_domains = dynamic(["85.11.167.178"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["85.11.167.178"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the URLhaus: 85-11-167-178 Malicious URLs detection rule, tailored for an enterprise environment:
Automated Security Scanner Health Checks
85-11-167-178 (or a subdomain thereof) for signature updates, this traffic may be flagged as malicious despite being part of a scheduled maintenance window.Tenable.Nessus or QualysAgent. Alternatively, exclude traffic occurring during defined maintenance windows (e.g., 02:00–04:00 UTC daily).Software Deployment & Patch Management Agents
85-11-167-178 for distributing these payloads, legitimate bulk downloads by thousands of endpoints during patch cycles will trigger this rule./updates, /packages, /deploy) and the Source Host Group matches ”