This rule detects adversaries leveraging malicious Microsoft Store URLs to execute payloads or establish footholds, a tactic that often bypasses traditional perimeter defenses by exploiting trusted application distribution channels. Proactively hunting for these specific URLhaus entries in Azure Sentinel allows the SOC to identify compromised endpoints or users interacting with these high-severity threats before they progress to lateral movement or data exfiltration.
Threat: msstore Total URLs: 2 Active URLs: 1
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://adpayworks.b-cdn.net/download/1.1.2/AdPayWorks.exe | offline | malware_download | 2026-09-11 |
hxxps://raw.githubusercontent.com/HartayKirjonrw/sa4/refs/heads/main/Signature%20Nib.exe | online | malware_download | 2026-09-11 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: msstore
let malicious_domains = dynamic(["raw.githubusercontent.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["raw.githubusercontent.com"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
msstore:// or related Microsoft Store URLs for activation or configuration.
IntuneAgent.exe, CCMAgent.exe, or MsiExec.exe and the user account belongs to a service or admin group (e.g., DOMAIN\svc-intune or DOMAIN\admins).dotnet.exe, msbuild.exe, or VisualStudioCode.exe on machines tagged as “Dev” or “Test” in your CMDB.svchost.exe with the service name WaaSMedicSvc (Windows Update Medication Service) or Store service, or where the command line contains arguments like /update or /clean.store.microsoft.com) and clicking “Install” may trigger local protocol handlers that resolve to msstore URLs, especially if the Store app is not fully installed or is in a transitional state.