This hunt detects adversary activity consistent with the ClearFake malware campaign by identifying network connections and file artifacts matching its specific set of 56 Indicators of Compromise (IOCs). Proactively hunting for these signals in Azure Sentinel is critical to rapidly identify early-stage infections and prevent lateral movement before the threat escalates into a full-scale breach.
Malware Family: ClearFake Total IOCs: 56 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | wtkxprzu.funxbet.casino | payload_delivery | 2026-07-17 | 100% |
| domain | hzdmfcatc.sky7bet.casino | payload_delivery | 2026-07-17 | 100% |
| domain | vzsagfrw.derbi.football | payload_delivery | 2026-07-17 | 100% |
| domain | dvc734k1.hazaratbet.game | payload_delivery | 2026-07-17 | 100% |
| domain | 3x6v81kc.varzeshlife.ir | payload_delivery | 2026-07-17 | 100% |
| domain | lhozmsokb.nextbahis.coupons | payload_delivery | 2026-07-17 | 100% |
| domain | eogwp3fe.site-shartbandi-pasor.online | payload_delivery | 2026-07-17 | 100% |
| domain | pygnidup.gem90bet.com | payload_delivery | 2026-07-17 | 100% |
| domain | dsdvsvqgy.jetbet.download | payload_delivery | 2026-07-17 | 100% |
| domain | dlylkjaji.jetboro.fun | payload_delivery | 2026-07-17 | 100% |
| domain | bgtnaqoc.fileboroo.com | payload_delivery | 2026-07-17 | 100% |
| domain | aefauhqwk.irani-music.com | payload_delivery | 2026-07-17 | 100% |
| domain | iodz0i3f.behtarin-site-shartbandi-football.com | payload_delivery | 2026-07-17 | 100% |
| domain | arvujwijm.irani-music.com | payload_delivery | 2026-07-17 | 100% |
| domain | itwynsuh.enfejartime.com | payload_delivery | 2026-07-17 | 100% |
| domain | scjzlqeyk.hazzarat.world | payload_delivery | 2026-07-17 | 100% |
| domain | suwqmlyd.efbetfarsi.com | payload_delivery | 2026-07-17 | 100% |
| domain | 6j7gyyz9.barkerautoms.com | payload_delivery | 2026-07-17 | 100% |
| domain | wexltdqtf.hazzarat.com | payload_delivery | 2026-07-17 | 100% |
| domain | los16zn2.celebritiesadda.com | payload_delivery | 2026-07-17 | 100% |
| domain | dy6t0cul.hazarat.now | payload_delivery | 2026-07-17 | 100% |
| domain | ggitkzzn.derbi.promo | payload_delivery | 2026-07-17 | 100% |
| domain | nruyvebwd.taktikkbet.com | payload_delivery | 2026-07-17 | 100% |
| domain | ovbeoktk.coop-fresh.com | payload_delivery | 2026-07-17 | 100% |
| domain | jorjsrfgd.lion1bet.com | payload_delivery | 2026-07-17 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["wtkxprzu.funxbet.casino", "hzdmfcatc.sky7bet.casino", "vzsagfrw.derbi.football", "dvc734k1.hazaratbet.game", "3x6v81kc.varzeshlife.ir", "lhozmsokb.nextbahis.coupons", "eogwp3fe.site-shartbandi-pasor.online", "pygnidup.gem90bet.com", "dsdvsvqgy.jetbet.download", "dlylkjaji.jetboro.fun", "bgtnaqoc.fileboroo.com", "aefauhqwk.irani-music.com", "iodz0i3f.behtarin-site-shartbandi-football.com", "arvujwijm.irani-music.com", "itwynsuh.enfejartime.com", "scjzlqeyk.hazzarat.world", "suwqmlyd.efbetfarsi.com", "6j7gyyz9.barkerautoms.com", "wexltdqtf.hazzarat.com", "los16zn2.celebritiesadda.com", "dy6t0cul.hazarat.now", "ggitkzzn.derbi.promo", "nruyvebwd.taktikkbet.com", "ovbeoktk.coop-fresh.com", "jorjsrfgd.lion1bet.com", "u5dn1e6x.bazisangkaqazgeychidancepoli.com", "chsxhscsh.tampabayspin.com", "vkvmygpg.betbuf90.com", "rdusnlyzh.sky7bet.casino", "iqgxtjfc.hazzarat.world", "a1h9t4pt.venus90bet.com", "dvzzqxef.gamehazarat.com", "g3b4hjbg.calculadoracomisiones.com", "wig5l9be.calirayalake.com", "zdgfs8pf.cacharreriamilenio.com", "ahxpqhqnc.nextbahis.coupons", "bkgtqeai.derbi.football", "eprqnfyeb.hazzarat.com", "zetkskre.funxbet.casino", "eqodjhwk.enfejartime.com", "drkynxdcu.gem90bet.com", "gardoone-shans-pool.com", "9zzh7dnw.coop-fresh.com", "coop-fresh.com", "edhabqne.taktikkbet.com", "tjcmwnljp.fileboroo.com", "arpumupr.site-shartbandi-pasor.online", "xyoyfdeyf.efbetfarsi.com", "pzsbygor.radioshartbandi.bet", "r4iuquzx.cookeatrun.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule, tailored for an enterprise environment where legitimate activities may mimic the behavior of the 56 associated Indicators of Compromise (IOCs):
Endpoint Protection Scanning & Quarantine Operations
CROWDSTRIE-FALCON-MGR) and specific service accounts (e.g., svc-defender-updates). Additionally, filter out file hashes that match the “Known Good” signature database of your internal AV policy.Scheduled Patch Management and Software Distribution
ccmexec.exe, jamfagentd) running under the context of the `