This hunt targets adversary activity involving known indicators of compromise from the IClickFix threat intelligence feed to identify potential intrusions or lateral movement within the network. Proactively hunting for these 57 IOCs in Azure Sentinel is critical because it enables the SOC team to rapidly correlate high-severity alerts with external threat data, ensuring early detection and containment before attackers can establish persistence.
Malware Family: IClickFix Total IOCs: 57 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | elxxvvx.xyz | botnet_cc | 2026-07-07 | 100% |
| domain | peedprexz.xyz | botnet_cc | 2026-07-07 | 100% |
| domain | multisavcx.xyz | botnet_cc | 2026-07-07 | 100% |
| domain | adminpoipet.com | payload_delivery | 2026-07-07 | 100% |
| domain | alphaottplaayer.click | payload_delivery | 2026-07-07 | 100% |
| domain | amigored.com.co | payload_delivery | 2026-07-07 | 100% |
| domain | amper.pl | payload_delivery | 2026-07-07 | 100% |
| domain | asianhub.net | payload_delivery | 2026-07-07 | 100% |
| domain | bilmax.net | payload_delivery | 2026-07-07 | 100% |
| domain | bkexpertaz.com | payload_delivery | 2026-07-07 | 100% |
| domain | bridgecrossrealty.com | payload_delivery | 2026-07-07 | 100% |
| domain | cartecgroup.ci | payload_delivery | 2026-07-07 | 100% |
| domain | continentalauto.ci | payload_delivery | 2026-07-07 | 100% |
| domain | derbytrail.com | payload_delivery | 2026-07-07 | 100% |
| domain | dev-papyrus.com | payload_delivery | 2026-07-07 | 100% |
| domain | ecomstorenutra.shop | payload_delivery | 2026-07-07 | 100% |
| domain | enventureconsulting.com | payload_delivery | 2026-07-07 | 100% |
| domain | fcdd.ca | payload_delivery | 2026-07-07 | 100% |
| domain | fjn.ci | payload_delivery | 2026-07-07 | 100% |
| domain | forummassjezetek.com | payload_delivery | 2026-07-07 | 100% |
| domain | globalprosresearch.org | payload_delivery | 2026-07-07 | 100% |
| domain | hotelalmutlaq.com | payload_delivery | 2026-07-07 | 100% |
| domain | iftga.com | payload_delivery | 2026-07-07 | 100% |
| domain | ileadsbpo.com | payload_delivery | 2026-07-07 | 100% |
| domain | innovehosting.com | payload_delivery | 2026-07-07 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - IClickFix
let malicious_domains = dynamic(["elxxvvx.xyz", "peedprexz.xyz", "multisavcx.xyz", "adminpoipet.com", "alphaottplaayer.click", "amigored.com.co", "amper.pl", "asianhub.net", "bilmax.net", "bkexpertaz.com", "bridgecrossrealty.com", "cartecgroup.ci", "continentalauto.ci", "derbytrail.com", "dev-papyrus.com", "ecomstorenutra.shop", "enventureconsulting.com", "fcdd.ca", "fjn.ci", "forummassjezetek.com", "globalprosresearch.org", "hotelalmutlaq.com", "iftga.com", "ileadsbpo.com", "innovehosting.com", "japananimecase.com", "kreaturk.org", "kwirxprime.com", "matthewsmarineservices.com", "mhdgroup.ci", "mybehlimmigration.com", "nutrageni.store", "office-com.app", "oflander.com", "ogi.ci", "oneservice-com.app", "panel-sis.com", "pobieranie.amper.pl", "proburo-ci.com", "rising.com.tr", "risingglass.eu", "rose-tr.com", "sisa.ci", "sisteco.co", "stainfo-ci.com", "ste-iconiadatasearch.com", "texiumcoin.com", "thecarefirst.com", "third-party.com", "traceysolutionsltd.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: IClickFix IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scheduled Patch Management Scans
svc_tenable_scanner, LocalSystem running MsMpEng.exe) during defined maintenance windows (e.g., 02:00–04:00 UTC).IT Asset Discovery and Inventory Jobs
DiscoveryAgent.exe, swagent) communicating with internal management subnets, specifically filtering out events where the destination port corresponds to standard asset management protocols (e.g., WMI 135, SSH 22) rather than external threat intel feeds.**Third-Party SIEM/SOAR Enrichment