This detection rule identifies potential botnet command-and-control activity by flagging traffic to a curated set of 52 known malicious domains associated with active botnets. A proactive hunt is essential in Azure Sentinel to rapidly isolate compromised endpoints and disrupt botnet propagation before adversaries can establish persistent footholds or initiate lateral movement within the network.
Threat: botnetdomain Total URLs: 52 Active URLs: 49
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://www.93-152-221-234.plesk.page/arm64 | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/run.sh | offline | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/x86 | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/mips | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/mips64le | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/aarch64 | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/ppc64 | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/armv6l | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/i686 | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/x86_64 | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/armv7l | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/armv5l | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/mips64 | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/mipsel | online | malware_download | 2026-09-01 |
hxxp://pingu.ltd/run.sh | offline | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/amd64 | online | malware_download | 2026-09-01 |
hxxp://www.93-152-221-234.plesk.page/ppc64le | online | malware_download | 2026-09-01 |
hxxp://pingu.ltd/ppc64 | online | malware_download | 2026-09-01 |
hxxp://delii.icu/ppc64le | online | malware_download | 2026-09-01 |
hxxp://trusting-golick.93-152-221-234.plesk.page/i686 | online | malware_download | 2026-09-01 |
hxxp://pingu.ltd/armv5l | online | malware_download | 2026-09-01 |
hxxp://delii.icu/arm64 | online | malware_download | 2026-09-01 |
hxxp://trusting-golick.93-152-221-234.plesk.page/arm64 | online | malware_download | 2026-09-01 |
hxxp://pingu.ltd/ppc64le | online | malware_download | 2026-09-01 |
hxxp://delii.icu/armv5l | online | malware_download | 2026-09-01 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: botnetdomain
let malicious_domains = dynamic(["www.93-152-221-234.plesk.page", "trusting-golick.93-152-221-234.plesk.page", "delii.icu", "pingu.ltd"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["www.93-152-221-234.plesk.page", "trusting-golick.93-152-221-234.plesk.page", "delii.icu", "pingu.ltd"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the URLhaus: botnetdomain Malicious URLs rule, including tailored filters and exclusions suitable for an enterprise environment:
Scenario: Scheduled Antivirus Definition Updates via Cloud Repositories
*.update.microsoft.com, *.falcon.crowdstrike.com, or *.dl.avast.com. Additionally, filter based on the process name MpCmdRun.exe (Microsoft) or FalconService.exe to ensure only legitimate updater processes trigger these connections.Scenario: Automated SaaS Data Sync and Backup Jobs
Veeam.Backup.Service.exe, RubrikAgent.exe) and exclude traffic destined for specific IP ranges or subdomains associated with major cloud providers like *.amazonaws.com or *.azureedge.net when accessed by these specific services.Scenario: Legitimate Third-Party Analytics and Telemetry Services