This detection identifies adversary activity where compromised hosts communicate with known botnet domains to establish command and control channels or exfiltrate data. A proactive hunt is essential in Azure Sentinel to rapidly isolate infected endpoints before they propagate lateral movement or disrupt critical infrastructure through coordinated botnet operations.
Threat: botnetdomain Total URLs: 26 Active URLs: 26
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://tractor.trees4sale.net/no_killer/x86 | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/dlr.mpsl | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/no_killer/arm | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/no_killer/mips | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/tvt/aarch64 | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/gigatex/mpsl | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/dlr.arm5 | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/dlr.arm7 | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/m | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/t | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/tvt/arm | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/tvt/arm7 | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/o | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/massload | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/dlr.x86 | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/no_killer/arm7 | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/gigatex/mips | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/no_killer/arm5 | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/gigatex/arm | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/mipsel | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/no_killer/mpsl | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/dlr.mips | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/gigatex/arm5 | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/dvr.sh | online | malware_download | 2026-07-26 |
hxxp://tractor.trees4sale.net/tplink.sh | online | malware_download | 2026-07-26 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: botnetdomain
let malicious_domains = dynamic(["tractor.trees4sale.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["tractor.trees4sale.net"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios and corresponding filters for the URLhaus: botnetdomain Malicious URLs detection rule in an enterprise environment:
Scheduled Endpoint Security Updates: Managed security agents (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint) often perform nightly or weekly definition updates by contacting vendor update servers. These domains are frequently flagged as “botnet” due to their high-volume traffic patterns and dynamic DNS usage.
*.crowdstrike.com, *.microsoft.com) and associated IP ranges to a whitelist exclusion in the EDR policy, scoped specifically to the “Update Service” process identity.Cloud Storage Synchronization Services: Enterprise file sync tools like OneDrive for Business or Google Drive for Desktop constantly poll cloud endpoints for change detection. These services often utilize shared CDN domains that URLhaus may misclassify as botnet infrastructure due to their global distribution and high connection counts.
OneDrive.exe, GoogleUpdate.exe) combined with destination ports 443, ensuring that traffic from known cloud storage domains is bypassed for this specific detection logic.Automated Backup and Disaster Recovery Jobs: Scheduled backup agents (such as Veeam Agent or Rubrik) initiate outbound connections to remote repositories or management consoles during off-hours. These recurring connections often hit public URLs that mimic botnet command-and-control (C2) behaviors, triggering the rule.
**Third-Party