This hypothesis targets the presence of ClearFake IOCs, which are known indicators associated with the ClearFake malware family that often leverages browser extensions to exfiltrate sensitive data. Proactively hunting for these specific indicators in Azure Sentinel allows the SOC team to identify compromised endpoints or user sessions before the adversary can establish persistence or escalate privileges within the tenant.
Malware Family: ClearFake Total IOCs: 13 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | r6qobdol.laken.store | payload_delivery | 2026-09-14 | 100% |
| domain | laken.store | payload_delivery | 2026-09-14 | 100% |
| domain | cu8d1374.us-eng-zensulin.com | payload_delivery | 2026-09-14 | 100% |
| domain | juhgjnjm.api24.store | payload_delivery | 2026-09-14 | 100% |
| domain | cvf9a6ez.alvare.store | payload_delivery | 2026-09-14 | 100% |
| domain | lgtbun4a.niaa.store | payload_delivery | 2026-09-14 | 100% |
| domain | www.credissimmo.fr | payload_delivery | 2026-09-14 | 90% |
| domain | www.viralabperu.com | payload_delivery | 2026-09-14 | 90% |
| domain | edilbertocosta.com | payload_delivery | 2026-09-14 | 90% |
| domain | 52uj2wm2[.]7flex.store | payload_delivery | 2026-09-14 | 100% |
| domain | bkbmall.in | payload_delivery | 2026-09-14 | 90% |
| domain | www.werde-medium.com | payload_delivery | 2026-09-14 | 90% |
| domain | beit-shoresh.ch | payload_delivery | 2026-09-14 | 90% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["r6qobdol.laken.store", "laken.store", "cu8d1374.us-eng-zensulin.com", "juhgjnjm.api24.store", "cvf9a6ez.alvare.store", "lgtbun4a.niaa.store", "www.credissimmo.fr", "www.viralabperu.com", "edilbertocosta.com", "52uj2wm2.7flex.store", "bkbmall.in", "www.werde-medium.com", "beit-shoresh.ch"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
SecurityOps or IR-Team security group, and the destination asset is a SIEM/EDR management console or a designated “test” subnet.python.exe, curl.exe, wget.exe) and the destination is the internal Threat Intelligence Platform (TIP) or a specific IOC storage server (e.g., ioc-db-01.corp.local).jenkins-01, github-actions-runner), and the destination is the configuration management server or a specific “security-config” share.