This hunt detects adversary behavior involving user or system interactions with specific malicious web endpoints identified by URLhaus under the signature 137-184-35-2, which often indicate early-stage phishing campaigns or command-and-control communications. The SOC team should proactively investigate these URLs in Azure Sentinel to validate potential lateral movement or data exfiltration attempts before they escalate into confirmed incidents.
Threat: 137-184-35-2 Total URLs: 2 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://137.184.35.2/Bin/ScreenConnect.ClientSetup.exe | offline | malware_download | 2026-07-14 |
hxxp://137.184.35.2/bin/support.client.exe | offline | malware_download | 2026-07-14 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: 137-184-35-2
let malicious_domains = dynamic(["137.184.35.2"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["137.184.35.2"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the URLhaus: 137-184-35-2 Malicious URLs detection rule in an enterprise environment, including suggested filters and exclusions:
Automated Vulnerability Scanning from Security Appliances
137-184-35-2 signature.Source_IP IN [Tenable_Scanner_Range]) or specific service accounts used by these tools (e.g., User_Agent CONTAINS "Nessus").Endpoint Protection Definition Updates
137-184-35-2 tag often corresponds to a specific malware family; EDRs may query these URLs during their scheduled daily update cycle (e.g., every morning at 06:00 UTC) to validate the integrity of new definition packages before deployment.Process_Name = "csagent.exe" or "SentinelOneService") and restrict the exclusion to business hours or scheduled maintenance windows where updates are expected.**IT