This hunt detects adversary behavior involving the exploitation of trusted “Bill Gates” branding to deliver malicious payloads via phishing or drive-by attacks using known compromised URLs. A SOC team should proactively hunt for this in Azure Sentinel because leveraging URLhaus intelligence allows for the immediate identification and containment of high-severity threats that mimic legitimate sources, thereby reducing the risk of initial access compromises.
Threat: BillGates Total URLs: 2 Active URLs: 2
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://194.59.30.63:56439/b/kswpad | online | malware_download | 2026-08-22 |
hxxp://194.59.30.63:56439/b/kal64 | online | malware_download | 2026-08-22 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: BillGates
let malicious_domains = dynamic(["194.59.30.63"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["194.59.30.63"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are the specific false positive scenarios and corresponding filters for the URLhaus: BillGates Malicious URLs detection rule in an enterprise environment:
Scenario 1: Scheduled Security Scans by EDR Agents
urlhaus.abuse.ch feed directly or via a proxy to fetch threat intelligence updates, triggering hits on the BillGates tagged URLs during these automated health checks.svc-crowdstrike, defender-agent) or filter by process name if the detection includes process metadata (e.g., process_name IN ('csfalcon.exe', 'MsMpEng.exe')).Scenario 2: Admin Manual Verification via Browser
SG-Security-Admins or IT-Ops, and restrict the filter to business hours (e.g., 08:00–18:00) if manual checks are primarily performed during workdays.Scenario 3: Automated Threat Intelligence Feeds Ingestion