This hunt detects adversary activity linked to the ClearFake campaign by identifying matches against a curated set of 23 specific indicators of compromise within Azure Sentinel logs. Proactively hunting for these signals is critical due to the high severity of ClearFake’s known tactics, enabling the SOC team to rapidly identify and contain potential infections before they escalate into broader incidents.
Malware Family: ClearFake Total IOCs: 23 IOC Types: domain, url
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | tsnjsimoo.en-us-en-eloncode.com | payload_delivery | 2026-08-25 | 100% |
| domain | en-us-en-eloncode.com | payload_delivery | 2026-08-25 | 100% |
| domain | ue0xfkgn.en-trumplapelpin.com | payload_delivery | 2026-08-25 | 100% |
| domain | en-trumplapelpin.com | payload_delivery | 2026-08-25 | 100% |
| domain | pretuniflex.ca | payload_delivery | 2026-08-25 | 90% |
| domain | 2hc0b19k.en-us-en-darkreset.com | payload_delivery | 2026-08-25 | 100% |
| domain | en-us-en-darkreset.com | payload_delivery | 2026-08-25 | 100% |
| domain | mysticinteriors.com.mt | payload_delivery | 2026-08-25 | 90% |
| domain | fan[.]369bbqsifangonline.com | botnet_cc | 2026-08-25 | 100% |
| domain | faplasg.ch | payload_delivery | 2026-08-25 | 90% |
| domain | d2qbo0u3.en-us-eng-geniusbrainsignal.com | payload_delivery | 2026-08-25 | 100% |
| domain | toad.ampwin123.com | botnet_cc | 2026-08-25 | 90% |
| domain | theatre-du-chateau.ch | payload_delivery | 2026-08-25 | 90% |
| url | hxxps://cdn.jsdelivr.net/gh/marye4562/df64gre7j/yd98gh3s | payload_delivery | 2026-08-25 | 100% |
| domain | lausannoir.ch | payload_delivery | 2026-08-25 | 90% |
| domain | mariage-adeline-loris.ch | payload_delivery | 2026-08-25 | 90% |
| domain | macaronvanille.ch | payload_delivery | 2026-08-25 | 90% |
| domain | ayuztxyw.en-en-usa-memorylift.com | payload_delivery | 2026-08-25 | 100% |
| domain | dv1q7cal.eng-usa-nervealive.com | payload_delivery | 2026-08-25 | 100% |
| domain | anup-nastik.ch | payload_delivery | 2026-08-25 | 90% |
| domain | rwj46i7as3h4.en-heroup.us | payload_delivery | 2026-08-25 | 100% |
| domain | hut.yourbodybydesign.me | botnet_cc | 2026-08-25 | 100% |
| domain | dock.yourbodybydesign.me | botnet_cc | 2026-08-25 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["tsnjsimoo.en-us-en-eloncode.com", "en-us-en-eloncode.com", "ue0xfkgn.en-trumplapelpin.com", "en-trumplapelpin.com", "pretuniflex.ca", "2hc0b19k.en-us-en-darkreset.com", "en-us-en-darkreset.com", "mysticinteriors.com.mt", "fan.369bbqsifangonline.com", "faplasg.ch", "d2qbo0u3.en-us-eng-geniusbrainsignal.com", "toad.ampwin123.com", "theatre-du-chateau.ch", "lausannoir.ch", "mariage-adeline-loris.ch", "macaronvanille.ch", "ayuztxyw.en-en-usa-memorylift.com", "dv1q7cal.eng-usa-nervealive.com", "anup-nastik.ch", "rwj46i7as3h4.en-heroup.us", "hut.yourbodybydesign.me", "dock.yourbodybydesign.me"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - ClearFake
let malicious_urls = dynamic(["https://cdn.jsdelivr.net/gh/marye4562/df64gre7j/yd98gh3s"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule, including suggested filters and exclusions:
Scenario: Scheduled Antivirus Definition Updates via ClearFake Repository
10.20.50.x) where the destination port is restricted to standard update ports (443, 8080). Additionally, exclude file hashes that match the known “ClearFake Update Agent” version hash stored in the asset inventory.Scenario: Admin-Driven Endpoint Remediation Scripts
powershell.exe spawning curl.exe) that match the rule’s IOCs during business hours.ccmexec.exe (SCCM agent) or Task Scheduler (svchost.exe with specific service name). Exclude events occurring within the defined maintenance window (e.g., 02:00 – 04:00 local time) for these specific admin accounts.Scenario: Third-Party SIEM Integration and Log Forwarding