This hunt detects adversary behavior where endpoints communicate with known North Korean (DPRK) malicious infrastructure, indicating potential reconnaissance or command-and-control activity from state-sponsored threat actors. Proactively hunting for these specific URLs in Azure Sentinel is critical to identify early-stage DPRK campaigns and mitigate risks before they escalate into full-scale data exfiltration or lateral movement incidents.
Threat: DPRK Total URLs: 5 Active URLs: 4
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://srv335762319.host.ultaserver.net:45000/icons/106 | online | malware_download | 2026-07-21 |
hxxps://ezpz.link:45000/icons/106 | online | malware_download | 2026-07-21 |
hxxps://www.ezpz.link:45000/icons/106 | online | malware_download | 2026-07-21 |
hxxps://46.183.25.232:45000/icons/106 | online | malware_download | 2026-07-21 |
hxxp://46.183.25.232:45000/icons/106 | offline | malware_download | 2026-07-21 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: DPRK
let malicious_domains = dynamic(["srv335762319.host.ultaserver.net", "46.183.25.232", "ezpz.link", "www.ezpz.link"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["srv335762319.host.ultaserver.net", "46.183.25.232", "ezpz.link", "www.ezpz.link"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: DPRK Malicious URLs rule in an enterprise environment, including suggested filters and exclusions:
Scheduled Security Software Updates via Internal Proxy
svc-defender-update) connecting to known vendor IP ranges (e.g., *.crowdstrike.com, *.sentinelone.net). Additionally, filter out events occurring strictly between 01:30 and 03:30 UTC on weekdays.IT Admin Manual Research and Threat Intelligence Consumption
*.cisa.gov, *.recordedfuture.com) where the DPRK tag appears only on secondary resource links rather than the primary navigation.**Automated Compliance and