This hypothesis posits that adversaries are actively leveraging ELF-based malware delivery through compromised or newly registered domains identified by URLhaus to execute initial infection vectors within the network. Proactive hunting for these specific malicious URLs in Azure Sentinel is critical because early detection of ELF payloads can prevent lateral movement and data exfiltration before traditional endpoint signatures trigger alerts on the infected hosts.
Threat: elf Total URLs: 55 Active URLs: 55
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://wreath.rapidbranchzi.com/rebirth.arm7 | online | malware_download | 2026-07-14 |
hxxp://wreath.rapidbranchzi.com/rebirth.sh4 | online | malware_download | 2026-07-14 |
hxxp://wreath.rapidbranchzi.com/rebirth.ppc | online | malware_download | 2026-07-14 |
hxxp://wreath.rapidbranchzi.com/rebirth.m68k | online | malware_download | 2026-07-14 |
hxxp://wreath.rapidbranchzi.com/rebirth.arm6 | online | malware_download | 2026-07-14 |
hxxp://wreath.rapidbranchzi.com/rebirth.arm5 | online | malware_download | 2026-07-14 |
hxxp://wreath.rapidbranchzi.com/rebirth.arm | online | malware_download | 2026-07-14 |
hxxp://wreath.rapidbranchzi.com/rebirth.x86 | online | malware_download | 2026-07-14 |
hxxp://wreath.rapidbranchzi.com/rebirth.mips | online | malware_download | 2026-07-14 |
hxxp://wreath.rapidbranchzi.com/rebirth.mpsl | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/bot.aarch64 | online | malware_download | 2026-07-14 |
hxxp://organza.rapidbranchzi.com/hiddenbin/zombie.x86 | online | malware_download | 2026-07-14 |
hxxp://organza.rapidbranchzi.com/hiddenbin/zombie.i686 | online | malware_download | 2026-07-14 |
hxxp://organza.rapidbranchzi.com/hiddenbin/zombie.sh4 | online | malware_download | 2026-07-14 |
hxxp://zipper.rapidbranchzi.com/debug.dbg | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/main_aarch64 | online | malware_download | 2026-07-14 |
hxxp://organza.rapidbranchzi.com/hiddenbin/zombie.spc | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/bot.mipsel | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/main_arm7 | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/bot.mips | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/main_mpsl | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/main_mips | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/main_x64 | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/bot.x86_64 | online | malware_download | 2026-07-14 |
hxxp://gravy.rapidbranchzi.com/bot.arm | online | malware_download | 2026-07-14 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: elf
let malicious_domains = dynamic(["organza.rapidbranchzi.com", "wreath.rapidbranchzi.com", "gravy.rapidbranchzi.com", "zipper.rapidbranchzi.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["organza.rapidbranchzi.com", "wreath.rapidbranchzi.com", "gravy.rapidbranchzi.com", "zipper.rapidbranchzi.com"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: elf Malicious URLs detection rule in an enterprise environment, along with suggested filters or exclusions:
Security Information and Event Management (SIEM) Log Ingestion Jobs
SIEM-Forwarder service account or specific IP ranges of the logging infrastructure when accessing internal domains ending in .internal or .corp.Endpoint Detection and Response (EDR) Definition Updates
*.crowdstrike.com, *.sentinelone.net) and restrict the rule to only flag non-vendor IP ranges or exclude specific user agents identified as EDR update services.Software Deployment via Configuration Management Tools
.deb or .rpm files