This hunt targets adversary behavior where threat actors leverage ClearFake-malicious URLs to deliver targeted phishing payloads or command-and-control communications that evade standard signature-based defenses. Proactively hunting for these specific indicators within Azure Sentinel is critical because early detection of ClearFake activity allows the SOC team to isolate compromised endpoints and block malicious traffic before lateral movement occurs across the cloud environment.
Threat: ClearFake Total URLs: 12 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://owhzzucu.jadoou.cyou/?ublib=22ff5e31-98ca-4762-9c5c-70c36de7fe56 | offline | malware_download | 2026-07-12 |
hxxps://zbplgmhe.bet90forward.win/5b259190-a06b-4b6a-a92c-2632aa5c1431 | offline | malware_download | 2026-07-12 |
hxxps://elng.jadoou.baby/883cb613-5b0b-4410-8696-5ef2ba6535c9 | offline | malware_download | 2026-07-12 |
hxxps://mjbpgp3k.jadoou.cfd/?ublib=f4e25355-7f92-4829-9607-bf2c2b9d748e | offline | malware_download | 2026-07-12 |
hxxps://fibvhxte.bekabet.casino/44830036-ce23-46ab-a71c-f2f19094f716 | offline | malware_download | 2026-07-12 |
hxxps://tgjg.jadoou.autos/a9c55ebf-3bc9-4e5b-87bf-59904e3bdb15 | offline | malware_download | 2026-07-12 |
hxxps://rgklgdmw.jadoobet.click/?ublib=39b6c84b-94e1-47a4-9b57-885788854487 | offline | malware_download | 2026-07-12 |
hxxps://acthwqwn.behtarin-site-shartbandi.com/21e8f421-57c5-470b-80e7-7191fece8290 | offline | malware_download | 2026-07-12 |
hxxps://9h5e0vbd.jadoou.club/?ublib=8c7d8c1b-d43a-4676-baac-132ed6648164 | offline | malware_download | 2026-07-12 |
hxxps://omwf.jadoou.art/3fdbe0c1-4fe2-478f-ad6c-b1efed486439 | offline | malware_download | 2026-07-12 |
hxxps://xmgonqda.jadoobet.xyz/02fd6dad-2527-4251-b2c9-648e0dc3f04d | offline | malware_download | 2026-07-12 |
hxxps://tetz.site-shartbandi-khareji.com/dca18a52-f5bc-4110-a48b-8f22b5049993 | offline | malware_download | 2026-07-12 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["acthwqwn.behtarin-site-shartbandi.com", "mjbpgp3k.jadoou.cfd", "omwf.jadoou.art", "elng.jadoou.baby", "rgklgdmw.jadoobet.click", "fibvhxte.bekabet.casino", "tetz.site-shartbandi-khareji.com", "owhzzucu.jadoou.cyou", "zbplgmhe.bet90forward.win", "xmgonqda.jadoobet.xyz", "9h5e0vbd.jadoou.club", "tgjg.jadoou.autos"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["acthwqwn.behtarin-site-shartbandi.com", "mjbpgp3k.jadoou.cfd", "omwf.jadoou.art", "elng.jadoou.baby", "rgklgdmw.jadoobet.click", "fibvhxte.bekabet.casino", "tetz.site-shartbandi-khareji.com", "owhzzucu.jadoou.cyou", "zbplgmhe.bet90forward.win", "xmgonqda.jadoobet.xyz", "9h5e0vbd.jadoou.club", "tgjg.jadoou.autos"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule in an enterprise environment, along with suggested filters or exclusions:
Automated Software Update Checks by Endpoint Protection Agents
ClearFake threat intelligence feed to cross-reference their local signature databases. These background processes generate high-volume GET requests to specific ClearFake URLs, which may be flagged as “malicious” by the rule if the URL’s reputation score is borderline or if the request pattern mimics a browser session rather than an API call.svc-crowdstrike-updater, msdefender-agent) and restrict the rule to trigger only on interactive user sessions (User-Agent containing “Chrome”, “Edge”, or “Firefox”) rather than system-level HTTP clients.Scheduled Vulnerability Scans by Internal Security Tools
01:00–05:00 UTC) or whitelist the specific IP addresses of internal vulnerability scanners and their associated proxy gateways.**Third-Party