This hunt detects adversary activity involving connections to known malicious URLs associated with the Amos threat campaign, which often leverage web-based delivery mechanisms to compromise endpoints. A SOC team should proactively hunt for these indicators in Azure Sentinel to identify early-stage lateral movement or initial access attempts before they escalate into broader incidents within the organization’s network.
Threat: Amos Total URLs: 8 Active URLs: 4
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://192.162.199.249/8jot5vdohds0imt4 | online | malware_download | 2026-08-12 |
hxxp://192.162.199.249/1vo6lm4y50k3ww0f | online | malware_download | 2026-08-12 |
hxxp://192.162.199.249/zeb8cgwmkkpvu7pc | online | malware_download | 2026-08-12 |
hxxp://192.162.199.249/1edjop4tlj2d | offline | malware_download | 2026-08-12 |
hxxp://192.162.199.249/8w6vq50fsu | offline | malware_download | 2026-08-12 |
hxxp://192.162.199.249/ezaenul9 | offline | malware_download | 2026-08-12 |
hxxp://192.162.199.249/y6b3fuzj0w6pt97e | online | malware_download | 2026-08-12 |
hxxp://192.162.199.249/tzb10mmujurn | offline | malware_download | 2026-08-12 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: Amos
let malicious_domains = dynamic(["192.162.199.249"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["192.162.199.249"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the URLhaus: Amos Malicious URLs detection rule in an enterprise environment, along with targeted filtering strategies:
Scenario: Automated Security Scanner Traffic
10.20.50.x) or filter out traffic where the User-Agent string contains keywords like “Nessus”, “Qualys”, or “Rapid7”.Scenario: Scheduled Backup and Replication Jobs
192.168.10.x) between 01:00 and 05:00 local time, or exclude specific destination domains known to be part of the backup infrastructure (e.g., *.veeam.com, *.rubrik.com).Scenario: Software Update Mechanisms