This hunt targets adversary activity linked to the ClearFake malware by correlating network and endpoint telemetry against a specific set of 18 known Indicators of Compromise (IOCs). Proactively hunting for these signatures in Azure Sentinel is critical to identify early-stage infections or lateral movement attempts before they escalate into widespread data exfiltration events.
Malware Family: ClearFake Total IOCs: 18 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | adsbln3.xyz | payload_delivery | 2026-07-16 | 100% |
| domain | eastbwxa.funxbet.casino | payload_delivery | 2026-07-16 | 100% |
| domain | j112srgz.bahigo90bet.com | payload_delivery | 2026-07-16 | 100% |
| domain | ftcfotjnd.adsbln2.xyz | payload_delivery | 2026-07-16 | 100% |
| domain | adsbln2.xyz | payload_delivery | 2026-07-16 | 100% |
| domain | rzecbgjw.enfejartime.com | payload_delivery | 2026-07-16 | 100% |
| domain | iygfxiad.efcasino.bet | payload_delivery | 2026-07-16 | 100% |
| domain | zwydarcig.adsbln1.xyz | payload_delivery | 2026-07-16 | 100% |
| domain | cdmke7zf.sky7bet.casino | payload_delivery | 2026-07-16 | 100% |
| domain | x78boe03.lion1bet.com | payload_delivery | 2026-07-16 | 100% |
| domain | cfplyjmq.efcasino.bet | payload_delivery | 2026-07-16 | 100% |
| domain | jii17zh7.yekbetyek.com | payload_delivery | 2026-07-16 | 100% |
| domain | isbbetvcj.adsbln1.xyz | payload_delivery | 2026-07-16 | 100% |
| domain | mzzetrvqf.jadoou.space | payload_delivery | 2026-07-16 | 100% |
| domain | xhbmcyyao.adsbln1.xyz | payload_delivery | 2026-07-16 | 100% |
| domain | adsbln1.xyz | payload_delivery | 2026-07-16 | 100% |
| domain | tufxszft.efcasino.bet | payload_delivery | 2026-07-16 | 100% |
| domain | mukmnvwls[.]101motorsports.net | payload_delivery | 2026-07-16 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["adsbln3.xyz", "eastbwxa.funxbet.casino", "j112srgz.bahigo90bet.com", "ftcfotjnd.adsbln2.xyz", "adsbln2.xyz", "rzecbgjw.enfejartime.com", "iygfxiad.efcasino.bet", "zwydarcig.adsbln1.xyz", "cdmke7zf.sky7bet.casino", "x78boe03.lion1bet.com", "cfplyjmq.efcasino.bet", "jii17zh7.yekbetyek.com", "isbbetvcj.adsbln1.xyz", "mzzetrvqf.jadoou.space", "xhbmcyyao.adsbln1.xyz", "adsbln1.xyz", "tufxszft.efcasino.bet", "mukmnvwls.101motorsports.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Endpoint Protection Policy Updates via Microsoft Defender for Endpoint
MsMpEng.exe (Microsoft Antimalware) service on thousands of endpoints, which establishes outbound connections to Microsoft’s cloud infrastructure. If ClearFake IOCs overlap with Microsoft’s IP ranges or domains used for telemetry, this mass deployment will generate high-volume alerts.Source Process Name is MsMpEng.exe and the Destination Port is standard HTTPS (443) or specific Microsoft update ports, provided the destination IP belongs to the known “Microsoft Azure” ASN.Scheduled Software Deployment via SCCM/MECM
ccmexec.exe) downloads installers and manifests from an internal software distribution point that mirrors external repositories containing ClearFake signatures. The rule triggers because the download traffic matches the IOCs associated with ClearFake’s update servers.Source Host is part of the “Engineering” AD OU and the Process Command Line contains keywords like /install, /update, or references to the internal SCCM server FQDN, specifically during the maintenance window (e.g., 02:00–04:00 UTC).Third-Party Cloud Backup Synchronization