This detection identifies adversaries leveraging newly registered malicious domains from the URLhaus threat intelligence feed to deliver initial payloads or command-and-control traffic via web browsers. A proactive hunt is essential in Azure Sentinel because these emerging URLs often lack historical reputation data, allowing attackers to bypass traditional static allow-lists and evade early-stage compromise indicators before broader signature updates are deployed.
Threat: opendir Total URLs: 2 Active URLs: 2
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://94.154.43.37/bins/ipmiv2.xml | online | malware_download | 2026-07-22 |
hxxp://94.154.43.164/peak.sh | online | malware_download | 2026-07-22 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: opendir
let malicious_domains = dynamic(["94.154.43.164", "94.154.43.37"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["94.154.43.164", "94.154.43.37"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 3-5 specific false positive scenarios for the URLhaus: opendir Malicious URLs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Automated Software Update Scans by Endpoint Protection Agents
opendir API to check for the latest threat intelligence feeds and signature updates. These agents often initiate HTTP/HTTPS requests that match the rule’s logic but are part of a standard maintenance routine rather than user-initiated browsing.C:\Program Files\CrowdStrike\csfalcon.exe or MsMpEng.exe) and restrict the rule to exclude traffic originating from known Service Accounts (e.g., svc-updates, defender-service).Scenario: Scheduled Backup and Inventory Jobs
opendir URL to validate asset metadata or check for new software releases, generating traffic that mimics a malicious web request but is purely administrative.10.10.40.0/24).Scenario: CI/CD Pipeline Artifact Retrieval