This rule detects adversaries leveraging automated feeds from URLhaus to identify and block malicious command-and-control (C2) endpoints that may evade static signature-based defenses. A SOC team should proactively hunt for these indicators in Azure Sentinel because C2 channels are frequently used as the initial foothold for lateral movement and data exfiltration, requiring real-time visibility beyond passive alerting.
Threat: c2-monitor-auto Total URLs: 2 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://91.92.242.236/files-129312398/files/file_5f93378efbf927ff.exe | offline | malware_download | 2026-08-29 |
hxxp://91.92.242.236/files-129312398/files/file_fe068c2e35dc5fe2.exe | offline | malware_download | 2026-08-29 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: c2-monitor-auto
let malicious_domains = dynamic(["91.92.242.236"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["91.92.242.236"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the URLhaus: c2-monitor-auto Malicious URLs detection rule, including targeted filters and exclusions:
Scheduled Security Scanner Updates
https://urlhaus-api.abusix.com endpoint.svc-security-updater) and restrict the exclusion to the specific destination IP range of the URLhaus API or the vendor’s update server.IT Admin Manual Threat Research
https://urlhaus.abusix.com) via their corporate browser (e.g., Google Chrome Enterprise) to review hash details and download sample reports. The rule interprets this legitimate browsing activity as a potential C2 beacon because the URL contains known malicious indicators within its structure.SOC-Analysts or Security-Admins when accessing the domain urlhaus.abusix.com, regardless of the specific path or query parameters.Cloud Backup and Synchronization Jobs