This hunt detects adversary activity involving the deployment of ClearFake malware by correlating Azure Sentinel telemetry against a specific set of 32 known Indicators of Compromise (IOCs). Proactively hunting for these signatures is critical to identify early-stage infections and mitigate potential data exfiltration or lateral movement before the threat escalates within the cloud environment.
Malware Family: ClearFake Total IOCs: 32 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | rxyvhv1x[.]1xforward.cash | payload_delivery | 2026-07-04 | 100% |
| domain | 1xforward.cash | payload_delivery | 2026-07-04 | 100% |
| domain | gakvmew.tinybet.bio | payload_delivery | 2026-07-04 | 100% |
| domain | 1v2w5ogt.prozhe.shopping | payload_delivery | 2026-07-04 | 100% |
| domain | prozhe.shopping | payload_delivery | 2026-07-04 | 100% |
| domain | cgoucbv.thevallartasrestaurants.com | payload_delivery | 2026-07-04 | 100% |
| domain | xxjbypq.takbetkade.com | payload_delivery | 2026-07-04 | 100% |
| domain | wji9u2ff.fileecell.com | payload_delivery | 2026-07-04 | 100% |
| domain | fileecell.com | payload_delivery | 2026-07-04 | 100% |
| domain | oxepqya.btyek.autos | payload_delivery | 2026-07-04 | 100% |
| domain | sevffjdu.jozveyek.com | payload_delivery | 2026-07-04 | 100% |
| domain | jozveyek.com | payload_delivery | 2026-07-04 | 100% |
| domain | frfjuzh.btyek.cloud | payload_delivery | 2026-07-04 | 100% |
| domain | ms9datqz[.]953.games | payload_delivery | 2026-07-04 | 100% |
| domain | 953.games | payload_delivery | 2026-07-04 | 100% |
| domain | kwsgmru.btyek.click | payload_delivery | 2026-07-04 | 100% |
| domain | btyek.click | payload_delivery | 2026-07-04 | 100% |
| domain | 91qdl1ty[.]1xcart.cash | payload_delivery | 2026-07-04 | 100% |
| domain | 1xcart.cash | payload_delivery | 2026-07-04 | 100% |
| domain | iu41zeaj[.]1xgame.vip | payload_delivery | 2026-07-04 | 100% |
| domain | 1xgame.vip | payload_delivery | 2026-07-04 | 100% |
| domain | ceohdvj.bonos.promo | payload_delivery | 2026-07-04 | 100% |
| domain | vchbhqa.betbazi.net | payload_delivery | 2026-07-04 | 100% |
| domain | betbazi.net | payload_delivery | 2026-07-04 | 100% |
| domain | q3g84ost[.]22beet.pro | payload_delivery | 2026-07-04 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["rxyvhv1x.1xforward.cash", "1xforward.cash", "gakvmew.tinybet.bio", "1v2w5ogt.prozhe.shopping", "prozhe.shopping", "cgoucbv.thevallartasrestaurants.com", "xxjbypq.takbetkade.com", "wji9u2ff.fileecell.com", "fileecell.com", "oxepqya.btyek.autos", "sevffjdu.jozveyek.com", "jozveyek.com", "frfjuzh.btyek.cloud", "ms9datqz.953.games", "953.games", "kwsgmru.btyek.click", "btyek.click", "91qdl1ty.1xcart.cash", "1xcart.cash", "iu41zeaj.1xgame.vip", "1xgame.vip", "ceohdvj.bonos.promo", "vchbhqa.betbazi.net", "betbazi.net", "q3g84ost.22beet.pro", "22beet.pro", "gefpeqd.bet1xiraq.com", "feeykse.betbacklink.com", "fituwzg.yek.autos", "yek.autos", "cxs9e097.vip1xbet.org", "kmkyfcu.winnerbahis-tr.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule in an enterprise environment, including suggested filters and exclusions:
Endpoint Protection Signature Updates via WSUS/SCCM
MpCmdRun.exe, CfSvc.exe) and restrict the scope to the specific IP Address range of the WSUS or SCCM servers. Alternatively, exclude events where the parent process is a known update service.Scheduled Threat Intelligence Feed Synchronization Jobs
02:00 – 04:00 UTC). Additionally, exclude traffic originating from the specific hostname or IP of the Threat Intelligence ingestion server where the job is executed.Software Vulnerability Scanning and Patch Deployment