This detection identifies adversary activity where endpoints interact with five distinct ASCII-tagged malicious URLs identified by URLhaus, signaling potential command-and-control communication or phishing attempts. A proactive hunt is essential in Azure Sentinel to rapidly isolate compromised assets and prevent lateral movement before these known threats can exfiltrate sensitive data or deploy additional payloads.
Threat: ascii Total URLs: 5 Active URLs: 4
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://algi-english.4lima.at/wp-includes/rest-api/iwpmqoy/egilhta/qio1pek/KK3crypted.ps1 | online | malware_download | 2026-08-26 |
hxxps://algi-english.4lima.at/wp-includes/rest-api/iwpmqoy/egilhta/qio1pek/Millscrypted.ps1 | online | malware_download | 2026-08-26 |
hxxps://algi-english.4lima.at/wp-includes/rest-api/iwpmqoy/egilhta/qio1pek/crypted.ps1 | online | malware_download | 2026-08-26 |
hxxps://algi-english.4lima.at/wp-includes/rest-api/iwpmqoy/egilhta/qio1pek/E3crypted.ps1 | online | malware_download | 2026-08-26 |
hxxps://idylliccreations.net/gsew/crypted.ps1 | offline | malware_download | 2026-08-26 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ascii
let malicious_domains = dynamic(["algi-english.4lima.at"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["algi-english.4lima.at"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 3-5 specific false positive scenarios for the URLhaus: ascii Malicious URLs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Automated Security Tool Updates & Telemetry
https://urlhaus-api.abuse.ch/v1/url/) to fetch real-time threat intelligence feeds. These queries often contain ASCII-encoded URLs that match the rule’s signature but represent legitimate health checks rather than user-initiated malicious browsing.source_host or process_name. Exclude traffic originating from known security service executables (e.g., C:\Program Files\CrowdStrike\fs_qrte.exe, MsMpEng.exe) where the destination URL contains urlhaus-api.abuse.ch or similar threat intelligence endpoints.Scenario: Scheduled Backup and Reporting Jobs
process_name matches VeeamBackupService.exe and the event timestamp falls within the defined maintenance window (e.g., 02:00–04:00 UTC), or filter by destination domain if the URL points to a known internal reporting subdomain.