This hunt targets adversary activity linked to the ClearFake campaign by correlating network and endpoint telemetry against a curated set of 36 specific Indicators of Compromise (IOCs). Proactively searching for these signals in Azure Sentinel is critical because ClearFake’s high-severity footprint often indicates sophisticated initial access or lateral movement that may evade standard signature-based detections.
Malware Family: ClearFake Total IOCs: 36 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | gbbzsnq[.]1xgame.cash | payload_delivery | 2026-07-02 | 100% |
| domain | 1xgame.cash | payload_delivery | 2026-07-02 | 100% |
| domain | ejjfjm2l.vip1xbet.net | payload_delivery | 2026-07-02 | 100% |
| domain | pmaumei[.]1xgame.bet | payload_delivery | 2026-07-02 | 100% |
| domain | 1xgame.bet | payload_delivery | 2026-07-02 | 100% |
| domain | tearmbdo.bet1forward.com | payload_delivery | 2026-07-02 | 100% |
| domain | qlrjloxh.jozve.one | payload_delivery | 2026-07-02 | 100% |
| domain | jozve.one | payload_delivery | 2026-07-02 | 100% |
| domain | gold-land-8.vortex-sys.in.net | botnet_cc | 2026-07-02 | 90% |
| domain | betwinner.bet | payload_delivery | 2026-07-02 | 100% |
| domain | flhrpdn.yekbetkade.com | payload_delivery | 2026-07-02 | 100% |
| domain | yekbetkade.com | payload_delivery | 2026-07-02 | 100% |
| domain | rfedpuuc.falsafekonkour.site | payload_delivery | 2026-07-02 | 100% |
| domain | noir-5.vortex-sys.in.net | botnet_cc | 2026-07-02 | 90% |
| domain | lbftpzh.takbetkade.com | payload_delivery | 2026-07-02 | 100% |
| domain | mlvgwjn[.]1xforward.pro | payload_delivery | 2026-07-02 | 100% |
| domain | 1xforward.pro | payload_delivery | 2026-07-02 | 100% |
| domain | 926ikjry.euroyek.bio | payload_delivery | 2026-07-02 | 100% |
| domain | id10ixg6[.]1x1bet.cash | payload_delivery | 2026-07-02 | 100% |
| domain | 1x1bet.cash | payload_delivery | 2026-07-02 | 100% |
| domain | aqjyrpm[.]1xforward.org | payload_delivery | 2026-07-02 | 100% |
| domain | 1xforward.org | payload_delivery | 2026-07-02 | 100% |
| domain | fsaxdfy0.hit4.bet | payload_delivery | 2026-07-02 | 100% |
| domain | hit4.bet | payload_delivery | 2026-07-02 | 100% |
| domain | fast-zeit-2.vortex-sys.in.net | botnet_cc | 2026-07-02 | 90% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["gbbzsnq.1xgame.cash", "1xgame.cash", "ejjfjm2l.vip1xbet.net", "pmaumei.1xgame.bet", "1xgame.bet", "tearmbdo.bet1forward.com", "qlrjloxh.jozve.one", "jozve.one", "gold-land-8.vortex-sys.in.net", "betwinner.bet", "flhrpdn.yekbetkade.com", "yekbetkade.com", "rfedpuuc.falsafekonkour.site", "noir-5.vortex-sys.in.net", "lbftpzh.takbetkade.com", "mlvgwjn.1xforward.pro", "1xforward.pro", "926ikjry.euroyek.bio", "id10ixg6.1x1bet.cash", "1x1bet.cash", "aqjyrpm.1xforward.org", "1xforward.org", "fsaxdfy0.hit4.bet", "hit4.bet", "fast-zeit-2.vortex-sys.in.net", "uusqctu.eurojet.pro", "eurojet.pro", "v1rsowak.xbetone.com", "dedzwcx.enfejarbahis.com", "lsyhgfl.enfejarbahis.com", "enfejarbahis.com", "fmpdxnv.enfejar.poker", "lseczri.enfejar.poker", "gejrdcu.enfejar.poker", "pnz8cbiq.vip1xbet.org", "gold-star-4m.public-shoot.in.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scheduled Vulnerability Scans via Tenable Nessus
SVR-NESSUS-01) which actively queries external threat intelligence feeds to update its local database. During this synchronization, the scanner connects to known ClearFake IOCs (IP addresses and domains) to validate signature updates, triggering the hunt package.10.20.50.0/24) communicating with the identified ClearFake IOC list during business hours (08:00–18:00).Endpoint Protection Policy Updates via CrowdStrike Falcon
Cortex.exe or FalconSensorService when connecting to the ClearFake domain list, provided the connection is initiated from the standard workstation VLAN (VLAN-100).IT Admin Manual Investigation via Splunk SOAR Playbook