This hypothesis targets the presence of known Mirai botnet command-and-control (C2) URLs in network traffic, indicating potential IoT or server compromise by a widespread malware family. Proactively hunting for these indicators in Azure Sentinel allows the SOC to identify infected assets early, preventing lateral movement and ensuring rapid containment of this high-severity threat.
Threat: mirai Total URLs: 31 Active URLs: 31
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://172.233.43.198/bins/xnxnxnxnxnxnxnxnloongarch64xnxn | online | malware_download | 2026-09-09 |
hxxp://172.233.43.198/bins/xnxnxnxnxnxnxnxnsh2xnxn | online | malware_download | 2026-09-09 |
hxxp://172.233.43.198/bins/xnxnxnxnxnxnxnxnmipsxnxn | online | malware_download | 2026-09-09 |
hxxp://172.233.43.198/bins/xnxnxnxnxnxnxnxnmicroblazexnxn | online | malware_download | 2026-09-09 |
hxxp://172.233.43.198/bins/xnxnxnxnxnxnxnxnor1kxnxn | online | malware_download | 2026-09-09 |
hxxp://172.233.43.198/bins/xnxnxnxnxnxnxnxnriscv64xnxn | online | malware_download | 2026-09-09 |
hxxp://172.233.43.198/bins/xnxnxnxnxnxnxnxnsh4xnxn | online | malware_download | 2026-09-09 |
hxxp://172.233.43.198/bins/xnxnxnxnxnxnxnxnm68kxnxn | online | malware_download | 2026-09-09 |
hxxp://36.68.93.208:57750/i | online | malware_download | 2026-09-09 |
hxxp://58.22.210.127:46509/i | online | malware_download | 2026-09-09 |
hxxp://58.22.210.127:46509/bin.sh | online | malware_download | 2026-09-09 |
hxxp://38.58.200.25:40355/i | online | malware_download | 2026-09-09 |
hxxp://221.3.87.188:42241/i | online | malware_download | 2026-09-09 |
hxxp://196.189.69.192:45951/i | online | malware_download | 2026-09-09 |
hxxp://180.191.49.27:47666/bin.sh | online | malware_download | 2026-09-09 |
hxxp://119.73.59.113:60742/bin.sh | online | malware_download | 2026-09-09 |
hxxp://114.198.242.174:38879/bin.sh | online | malware_download | 2026-09-09 |
hxxp://124.158.191.121:35084/i | online | malware_download | 2026-09-09 |
hxxp://120.28.215.116:56895/bin.sh | online | malware_download | 2026-09-09 |
hxxp://221.3.87.188:42241/bin.sh | online | malware_download | 2026-09-09 |
hxxp://216.126.86.93:35535/i | online | malware_download | 2026-09-09 |
hxxp://175.31.228.93:43869/i | online | malware_download | 2026-09-09 |
hxxp://124.158.191.121:35084/bin.sh | online | malware_download | 2026-09-09 |
hxxp://120.28.215.36:39145/i | online | malware_download | 2026-09-09 |
hxxp://210.208.110.172:46277/bin.sh | online | malware_download | 2026-09-09 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: mirai
let malicious_domains = dynamic(["38.58.200.25", "120.28.215.36", "221.3.87.188", "172.233.43.198", "120.28.215.116", "124.6.165.86", "124.158.191.121", "175.31.228.93", "115.59.231.52", "114.198.242.174", "120.28.219.231", "216.126.86.93", "58.22.210.127", "119.73.59.113", "196.189.69.192", "210.208.110.172", "210.208.110.20", "180.191.49.27", "36.68.93.208"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["38.58.200.25", "120.28.215.36", "221.3.87.188", "172.233.43.198", "120.28.215.116", "124.6.165.86", "124.158.191.121", "175.31.228.93", "115.59.231.52", "114.198.242.174", "120.28.219.231", "216.126.86.93", "58.22.210.127", "119.73.59.113", "196.189.69.192", "210.208.110.172", "210.208.110.20", "180.191.49.27", "36.68.93.208"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
cron or Windows Task Scheduler).
svc_nessus, qualys_agent) and verify the timestamp aligns with the scheduled scan window.docker build or kubectl apply operations in the CI/CD pipeline (e.g., Jenkins, GitHub Actions).
jenkins-master, github-runner-01) where the user context is a non-interactive service account.