This detection identifies adversary behavior where endpoints access newly identified malicious URLs classified with the ELF (Executable and Linkable Format) signature, indicating potential delivery of Linux-based malware or command-and-control traffic. The SOC team should proactively hunt for these indicators in Azure Sentinel to rapidly isolate compromised workloads before they establish persistence or exfiltrate sensitive data within cloud-native environments.
Threat: elf Total URLs: 27 Active URLs: 8
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://31.77.227.10/bins/manji.arm7 | online | malware_download | 2026-07-19 |
hxxp://94.154.43.42/skiddy.x86 | online | malware_download | 2026-07-19 |
hxxp://94.154.43.42/skiddy.x86_64 | online | malware_download | 2026-07-19 |
hxxp://129.121.110.105/0GE | online | malware_download | 2026-07-19 |
hxxp://129.121.110.105/c3cS | online | malware_download | 2026-07-19 |
hxxp://129.121.110.105/rU0 | online | malware_download | 2026-07-19 |
hxxp://129.121.110.105/43Ob | online | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.m68k | offline | malware_download | 2026-07-19 |
hxxp://160.119.69.4/z/post/noroot.php | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.armv5l | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.armv7l | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.armv4l | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.i686 | offline | malware_download | 2026-07-19 |
hxxp://129.121.110.105/iHO | offline | malware_download | 2026-07-19 |
hxxp://129.121.110.105/Fz0 | online | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.mipsel | offline | malware_download | 2026-07-19 |
hxxp://129.121.110.105/KIB | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.x86 | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.powerpc | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.x86_64 | offline | malware_download | 2026-07-19 |
hxxp://129.121.110.105/W5y | offline | malware_download | 2026-07-19 |
hxxp://129.121.110.105/irSl | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.armv6l | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.arm | offline | malware_download | 2026-07-19 |
hxxp://217.60.195.187:8080/bot.i586 | offline | malware_download | 2026-07-19 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: elf
let malicious_domains = dynamic(["94.154.43.42", "31.77.227.10", "129.121.110.105"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["94.154.43.42", "31.77.227.10", "129.121.110.105"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: elf Malicious URLs detection rule in an enterprise environment, along with suggested filters or exclusions:
Antivirus Signature Updates via Microsoft Update Services
elf signature in URLhaus due to their executable nature and high traffic volume, triggering alerts despite being benign.10.x.x.x, 192.168.x.x) destined for Microsoft’s official update domains (*.update.microsoft.com, go.microsoft.com) or specific whitelisted CDN IPs used by your AV vendor.Software Deployment via Chocolatey or SCCM
.exe or .msi containing ELF components) from the organization’s internal software repository or trusted public sources. The detection logic flags these high-volume downloads as potential threats because they are categorized under the elf tag.*.artifactory.internal, *.choco.org) and restrict the alert scope to exclude traffic from known deployment service accounts or specific “Software Distribution” subnets during maintenance windows.Endpoint Protection Agent Communication