This hunt targets adversary behavior involving the execution or access of known malicious web resources identified by URLhaus, specifically those associated with the IP range 91.92.42.50 which may indicate active command-and-control communication or phishing campaigns. Proactively hunting for these indicators in Azure Sentinel is critical to rapidly identify compromised endpoints and block lateral movement before attackers can establish persistence within the organization’s cloud infrastructure.
Threat: 91-92-42-50 Total URLs: 12 Active URLs: 12
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://91.92.42.50/byroom.mips | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.mpsl | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.x86 | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/top.sh | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.m68k | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.sh4 | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.spc | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.arm5 | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.arm7 | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.arm6 | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.arm | online | malware_download | 2026-07-17 |
hxxp://91.92.42.50/byroom.ppc | online | malware_download | 2026-07-17 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 91-92-42-50
let malicious_domains = dynamic(["91.92.42.50"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["91.92.42.50"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: 91-92-42-50 Malicious URLs detection rule, including suggested filters and exclusions tailored for a legitimate enterprise environment:
Automated Security Scanner Probing
91-92-42-50 IP range during routine discovery scans.svc_qualys_agent) or specific asset groups tagged as “Vulnerability Scanners.”Endpoint Protection Cloud Updates
91-92-42-50 IP range to download signature definitions, threat intelligence feeds, or configuration patches from the vendor’s cloud infrastructure, which may be flagged as “Malicious” by URLhaus due to high-volume traffic patterns.C:\Program Files\CrowdStrike\fsa.exe) communicating over standard update ports (443, 80) during defined maintenance windows.IT Admin Manual Verification & Troubleshooting