← Back to SOC feed Coverage →

ThreatFox: ClearFake IOCs

ioc-hunt HIGH ThreatFox
DnsEvents
iocjs-clearfakethreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-08-19T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt detects adversary activity involving the specific indicators of compromise (IOCs) linked to the ClearFake campaign, which is known for deploying sophisticated malware and phishing operations. A SOC team should proactively search for these IOCs in Azure Sentinel to identify early-stage infections or lateral movement attempts that may have bypassed standard automated detection rules.

IOC Summary

Malware Family: ClearFake Total IOCs: 15 IOC Types: domain

TypeValueThreat TypeFirst SeenConfidence
domaintagsmarketing.compayload_delivery2026-08-1990%
domainthewelchstreetjournal.compayload_delivery2026-08-1990%
domaintragroup.co.zapayload_delivery2026-08-1990%
domainedamame-sushi.chpayload_delivery2026-08-1990%
domain22nbxu1y.eng-usa-goldalign.compayload_delivery2026-08-19100%
domain2evjlhkn.app8k.xyzpayload_delivery2026-08-19100%
domainslotcash.sitepayload_delivery2026-08-1990%
domainatanackovic.chpayload_delivery2026-08-1990%
domainburnpeak.us.compayload_delivery2026-08-19100%
domainburnpeakofficialsite.compayload_delivery2026-08-19100%
domainpedzes.chpayload_delivery2026-08-1990%
domaingolfmontreux.chpayload_delivery2026-08-1990%
domainametiqbanking.chpayload_delivery2026-08-1990%
domainimroos.chpayload_delivery2026-08-1990%
domainj7sd6wjs.en-theslimsplitsmethod.compayload_delivery2026-08-19100%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["tagsmarketing.com", "thewelchstreetjournal.com", "tragroup.co.za", "edamame-sushi.ch", "22nbxu1y.eng-usa-goldalign.com", "2evjlhkn.app8k.xyz", "slotcash.site", "atanackovic.ch", "burnpeak.us.com", "burnpeakofficialsite.com", "pedzes.ch", "golfmontreux.ch", "ametiqbanking.ch", "imroos.ch", "j7sd6wjs.en-theslimsplitsmethod.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Original source: https://threatfox.abuse.ch/browse/malware/js.clearfake/