This hunt detects adversary activity linked to the ClearFake campaign by monitoring for specific indicators of compromise across network and endpoint telemetry within Azure Sentinel. Proactive hunting is essential due to the high severity of these IOCs, enabling the SOC team to identify early-stage intrusions and mitigate potential data exfiltration before broader impact occurs.
Malware Family: ClearFake Total IOCs: 41 IOC Types: domain, url, sha256_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | t4gd7ofi.retinaclier.com | payload_delivery | 2026-09-01 | 100% |
| domain | glyco--mute.com | payload_delivery | 2026-09-01 | 100% |
| domain | glyco-glycofree.com | payload_delivery | 2026-09-01 | 100% |
| url | hxxps://raw.githubusercontent.com/moonstone-lgtm/radugawolrd/refs/heads/main/wintar | payload_delivery | 2026-09-01 | 100% |
| url | hxxps://raw.githubusercontent.com/moonstone-lgtm/romana/refs/heads/main/lida486 | payload_delivery | 2026-09-01 | 100% |
| url | hxxps://raw.githubusercontent.com/moonstone-lgtm/romana/refs/heads/main/fds5412 | payload_delivery | 2026-09-01 | 100% |
| url | hxxps://raw.githubusercontent.com/snowplow-byte/coronawins/refs/heads/main/ladywin | payload_delivery | 2026-09-01 | 100% |
| domain | tkmpeinture.ch | payload_delivery | 2026-09-01 | 90% |
| domain | wrx8mbpe.en-trump-token.com | payload_delivery | 2026-09-01 | 100% |
| domain | szlqgs89.shop-nervealive.com | payload_delivery | 2026-09-01 | 100% |
| domain | shop-nervealive.com | payload_delivery | 2026-09-01 | 100% |
| domain | 8mpvpdgn.shop-lungexpandpro.us | payload_delivery | 2026-09-01 | 100% |
| domain | shop-lungexpandpro.us | payload_delivery | 2026-09-01 | 100% |
| domain | j1tkppsh.en-hero-up.com | payload_delivery | 2026-09-01 | 100% |
| domain | nyhj91bw.shop-neurovera.us | payload_delivery | 2026-09-01 | 100% |
| domain | shop-neurovera.us | payload_delivery | 2026-09-01 | 100% |
| domain | eulenhof.swiss | payload_delivery | 2026-09-01 | 90% |
| domain | chalet-araucaria.com | payload_delivery | 2026-09-01 | 90% |
| domain | wgx2w28e.chelseatbaldeagle.com | payload_delivery | 2026-09-01 | 100% |
| domain | chelseatbaldeagle.com | payload_delivery | 2026-09-01 | 100% |
| sha256_hash | fd0da8d49a6b2082d1704611e4006eeccad283a960a36292fa5324b6466f1c98 | payload | 2026-09-01 | 90% |
| sha256_hash | 0d178ef3b9bfe3209dc26d0c6e22536f890f09e32feef8f4a6953fb626553511 | payload | 2026-09-01 | 90% |
| sha256_hash | 0d765af312d12d61aa518279c186efa0808939fd32b98a003f9431652a166131 | payload | 2026-09-01 | 90% |
| sha256_hash | bf67638cb602e52981ecb98338e0296d642565f1a512b5f0224de69676830467 | payload | 2026-09-01 | 90% |
| sha256_hash | 3b6cb37e1308d272a539f17a73b0da83e74ec35fc8361950936c679711914344 | payload | 2026-09-01 | 90% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["t4gd7ofi.retinaclier.com", "glyco--mute.com", "glyco-glycofree.com", "tkmpeinture.ch", "wrx8mbpe.en-trump-token.com", "szlqgs89.shop-nervealive.com", "shop-nervealive.com", "8mpvpdgn.shop-lungexpandpro.us", "shop-lungexpandpro.us", "j1tkppsh.en-hero-up.com", "nyhj91bw.shop-neurovera.us", "shop-neurovera.us", "eulenhof.swiss", "chalet-araucaria.com", "wgx2w28e.chelseatbaldeagle.com", "chelseatbaldeagle.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - ClearFake
let malicious_urls = dynamic(["https://raw.githubusercontent.com/moonstone-lgtm/radugawolrd/refs/heads/main/wintar", "https://raw.githubusercontent.com/moonstone-lgtm/romana/refs/heads/main/lida486", "https://raw.githubusercontent.com/moonstone-lgtm/romana/refs/heads/main/fds5412", "https://raw.githubusercontent.com/snowplow-byte/coronawins/refs/heads/main/ladywin"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
// Hunt for files matching known malicious hashes
// Source: ThreatFox - ClearFake
let malicious_hashes = dynamic(["fd0da8d49a6b2082d1704611e4006eeccad283a960a36292fa5324b6466f1c98", "0d178ef3b9bfe3209dc26d0c6e22536f890f09e32feef8f4a6953fb626553511", "0d765af312d12d61aa518279c186efa0808939fd32b98a003f9431652a166131", "bf67638cb602e52981ecb98338e0296d642565f1a512b5f0224de69676830467", "3b6cb37e1308d272a539f17a73b0da83e74ec35fc8361950936c679711914344", "b8389f99db47eef8df5a119b0a405bc8036d55228840896042fe2547a189cc84", "d48b3261262e7d4ef3a9a2f2f0bcaf20ef866c71ba8ec860faa37a40cca66625", "2c632225d9c340a519249066b3ad28d41b90b0323557afc649e54ef49fa90e81", "6669388a05e514f07e77095dae05a45918a6f10988dda7f9d5aed3fb07513f41", "06b75afa6f460179da9d8dbb15ff105910d3244277a7b3a9fe459a33d4580999", "6de97f30eeedf7677c8c97bad32a6566b3b50c8efc611f371e44f588731d7aaf", "8e5826352a64fea7c6ecc9408f175bb6dca9543111c7b9b3d3a61cdc8fac959b", "0f38e3f484884bd7c85d0b070b1d820f59271543928079c43d0c77c2fbd51929", "1d7a7c178076dddee6ea1a67423d3318c1e01d96a331d3f355ff6b1867d634a3", "f67de1b7e7ca36727bd4c1e127ed4f516a0193ac8fc41693353558455e686c99", "7ef30865cb0f0adc81fce00afa2bc7aa4112ff8b1f6c5357b00a0f9e687db464", "f61bcd49872e452e245d60425e2637c47092211faf94c24e14cb13e870a25aed", "07d9b155b52542204c047cc28fd69c0f06c67432d5a3fc3d3b9fa632f0f4ffcc", "21ea6d2a589f017ad32a70de58ce07c4abbea65918ec7d9d13df8687c03dcad4", "83340582a4d5d32cb602edc03210cdb103457c4ce777b3bd43d096febf4cff04", "d23b15822d46d5adcd503a7a7ec37f3cda13675a067a28f28fa4449c07593f1c"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are the false positive scenarios and corresponding filters for the ThreatFox: ClearFake IOCs detection rule:
Scenario: The Enterprise Security Operations Center (SOC) team manually imports a new batch of threat intelligence feeds into the SIEM using Splunk Add-on for Threat Intelligence, which includes the 41 ClearFake indicators as part of a routine quarterly update.
source_app is “splunk_ta_threat_intel” and the action_type equals “feed_import”, or filter out alerts generated by the specific service account used for feed ingestion (e.g., user_name = svc_ti_ingestion).Scenario: An automated Microsoft Defender for Endpoint scheduled task runs nightly to perform a custom threat scan, which queries the internal threat library containing the ClearFake IOC set to validate endpoint protection signatures.
process_name is “DefenderService.exe” and the scheduled_task_name matches “NightlyThreatLibrarySync”, provided the event timestamp falls within the maintenance window (e.g., 02:00–04:00 UTC).Scenario: The DevOps team executes a Jenkins pipeline for the “Security-Validation” stage, which triggers an automated script to verify network traffic against known IOCs using Python’s requests library, inadvertently matching the ClearFake hash signatures during the test phase.
source_ip in range 10.50.20.0/24) where the process_command_line contains “jenkins-build” and the user_agent string includes “Jenkins-Client”.