This hunt targets the presence of known botnet command-and-control (C2) infrastructure by identifying traffic to 47 malicious URLs associated with botnet domains. Proactively hunting for these indicators in Azure Sentinel allows the SOC to detect compromised endpoints or lateral movement attempts before the botnet can fully establish persistence or execute its payload.
Threat: botnetdomain Total URLs: 47 Active URLs: 42
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://iloveboats.st:8081/titan.ppc | online | malware_download | 2026-09-07 |
hxxp://quietsurfwi.help:8081/titan.mips | online | malware_download | 2026-09-07 |
hxxp://quietsurfwi.help:8081/titan.mipsel | online | malware_download | 2026-09-07 |
hxxp://www.iloveboats.st:8081/titan.ppc440 | online | malware_download | 2026-09-07 |
hxxp://quietsurfwi.help:8081/titan.ppc440 | online | malware_download | 2026-09-07 |
hxxp://iloveboats.st:8081/bash.sh | offline | malware_download | 2026-09-07 |
hxxp://mail.quietsurfwi.help:8081/titan.arm7 | online | malware_download | 2026-09-07 |
hxxp://iloveboats.st:8081/titan.m68k | online | malware_download | 2026-09-07 |
hxxp://www.iloveboats.st:8081/titan.sh4 | online | malware_download | 2026-09-07 |
hxxp://www.iloveboats.st:8081/titan.arm4l | online | malware_download | 2026-09-07 |
hxxp://quietsurfwi.help:8081/titan.x32 | offline | malware_download | 2026-09-07 |
hxxp://iloveboats.st:8081/titan.x64-test | online | malware_download | 2026-09-07 |
hxxp://mail.quietsurfwi.help:8081/titan.ppc440 | online | malware_download | 2026-09-07 |
hxxp://www.iloveboats.st:8081/titan.x64-test | online | malware_download | 2026-09-07 |
hxxp://mail.quietsurfwi.help:8081/titan.arm5 | online | malware_download | 2026-09-07 |
hxxp://quietsurfwi.help:8081/titan.x64-test | online | malware_download | 2026-09-07 |
hxxp://www.iloveboats.st:8081/titan.mips | online | malware_download | 2026-09-07 |
hxxp://www.iloveboats.st:8081/bash.sh | offline | malware_download | 2026-09-07 |
hxxp://www.iloveboats.st:8081/titan.mipsel | online | malware_download | 2026-09-07 |
hxxp://quietsurfwi.help:8081/titan.arm4tl | offline | malware_download | 2026-09-07 |
hxxp://mail.quietsurfwi.help:8081/titan.m68k | online | malware_download | 2026-09-07 |
hxxp://mail.quietsurfwi.help:8081/titan.arm6 | online | malware_download | 2026-09-07 |
hxxp://quietsurfwi.help:8081/titan.arm6 | online | malware_download | 2026-09-07 |
hxxp://iloveboats.st:8081/titan.arm6 | online | malware_download | 2026-09-07 |
hxxp://mail.quietsurfwi.help:8081/titan.arm4l | online | malware_download | 2026-09-07 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: botnetdomain
let malicious_domains = dynamic(["quietsurfwi.help", "mail.quietsurfwi.help", "iloveboats.st", "www.iloveboats.st"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["quietsurfwi.help", "mail.quietsurfwi.help", "iloveboats.st", "www.iloveboats.st"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
http://botnet-domain.com/health) to verify outbound connectivity.
api-gateway-service account and the destination port is 80 or 443, specifically for the known URL path /health or /ping.ci-runner-pool subnet where the User-Agent contains Jenkins or GitLab-Runner and the HTTP method is GET.Chrome or Edge and the request path matches /telemetry or /metrics, provided the source IP is within the corporate user VLAN range.db-failover-service process where the