← Back to SOC feed Coverage →

URLhaus: 32-bit Malicious URLs

ioc-hunt HIGH URLhaus
CommonSecurityLogDnsEvents
iocurlhaus
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at URLhaus →
Retrieved: 2026-06-05T11:00:00Z · Confidence: medium

Hunt Hypothesis

The hypothesis is that the detected URLs are likely used by adversaries to deliver 32-bit malware, which may bypass modern endpoint protections. SOC teams should proactively hunt for these URLs in Azure Sentinel to identify and mitigate potential compromise of 32-bit systems.

IOC Summary

Threat: 32-bit Total URLs: 37 Active URLs: 36

URLStatusThreatDate Added
hxxp://163.142.86.138:60944/iofflinemalware_download2026-06-05
hxxp://182.113.202.170:36412/ionlinemalware_download2026-06-05
hxxp://110.36.1.200:53411/ionlinemalware_download2026-06-05
hxxp://125.43.33.196:39064/bin.shonlinemalware_download2026-06-05
hxxp://123.14.32.97:42939/bin.shonlinemalware_download2026-06-05
hxxp://27.215.53.135:55865/ionlinemalware_download2026-06-05
hxxp://182.113.202.170:36412/bin.shonlinemalware_download2026-06-05
hxxp://123.11.77.199:53437/ionlinemalware_download2026-06-05
hxxp://123.11.77.199:53437/bin.shonlinemalware_download2026-06-05
hxxp://42.229.151.147:52080/bin.shonlinemalware_download2026-06-05
hxxp://39.78.182.101:34099/bin.shonlinemalware_download2026-06-05
hxxp://182.127.178.140:59972/ionlinemalware_download2026-06-05
hxxp://27.215.53.135:55865/bin.shonlinemalware_download2026-06-05
hxxp://27.220.114.3:48953/ionlinemalware_download2026-06-05
hxxp://182.119.71.160:55615/ionlinemalware_download2026-06-05
hxxp://39.78.182.101:34099/ionlinemalware_download2026-06-05
hxxp://182.127.178.140:59972/bin.shonlinemalware_download2026-06-05
hxxp://42.231.31.141:54460/bin.shonlinemalware_download2026-06-05
hxxp://125.45.156.130:59062/bin.shonlinemalware_download2026-06-05
hxxp://42.226.223.139:53794/ionlinemalware_download2026-06-05
hxxp://42.226.223.139:53794/bin.shonlinemalware_download2026-06-05
hxxp://182.112.14.59:38383/ionlinemalware_download2026-06-05
hxxp://27.204.197.147:39822/ionlinemalware_download2026-06-05
hxxp://175.146.244.185:50487/bin.shonlinemalware_download2026-06-05
hxxp://175.146.244.185:50487/ionlinemalware_download2026-06-05

KQL: Url Dns Hunt

// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 32-bit
let malicious_domains = dynamic(["222.141.26.232", "42.229.151.147", "182.127.178.140", "123.11.77.199", "182.119.71.160", "182.112.14.59", "39.78.182.101", "27.215.53.135", "182.113.202.170", "115.55.117.53", "42.231.31.141", "42.226.223.139", "125.43.33.196", "125.45.156.130", "110.36.1.200", "27.204.197.147", "123.14.32.97", "27.220.114.3", "112.248.103.32", "175.146.244.185"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc

KQL: Url Proxy Hunt

// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["222.141.26.232", "42.229.151.147", "182.127.178.140", "123.11.77.199", "182.119.71.160", "182.112.14.59", "39.78.182.101", "27.215.53.135", "182.113.202.170", "115.55.117.53", "42.231.31.141", "42.226.223.139", "125.43.33.196", "125.45.156.130", "110.36.1.200", "27.204.197.147", "123.14.32.97", "27.220.114.3", "112.248.103.32", "175.146.244.185"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Original source: https://urlhaus.abuse.ch/