This detection identifies adversary command and control (C2) activity by flagging traffic to URLs dynamically classified as malicious by the URLhaus threat intelligence feed. Proactive hunting for these indicators in Azure Sentinel is critical because automated C2 monitoring allows the SOC team to rapidly isolate compromised endpoints before lateral movement or data exfiltration occurs.
Threat: c2-monitor-auto Total URLs: 2 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://91.92.242.236/files-129312398/files/file_2406cf76a7ca34ca.exe | offline | malware_download | 2026-08-02 |
hxxp://91.92.242.236/files-129312398/files/file_bbcbeb2966f48fd6.exe | offline | malware_download | 2026-08-02 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: c2-monitor-auto
let malicious_domains = dynamic(["91.92.242.236"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["91.92.242.236"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios and corresponding filters for the URLhaus: c2-monitor-auto Malicious URLs detection rule:
Scenario: Automated vulnerability scanning by enterprise security tools.
urlhaus-api domains or specific feed URLs tagged as “c2-monitor-auto”.10.50.10.0/24) and filter out user agents containing keywords like Nessus, QualysGuard, or Rapid7.Scenario: Scheduled backup and synchronization jobs accessing cloud repositories.
Veeam or Rubrik services, specifically targeting destination URLs ending in .cloud.vvmware.com or specific S3 bucket endpoints used by the backup infrastructure.Scenario: Admin-initiated patch management and software deployment workflows.