This hunt targets adversary behavior where threat actors leverage ClearFake-malicious URLs to execute phishing campaigns or deliver malware payloads through compromised web resources. Proactively hunting these specific indicators within Azure Sentinel is critical because early detection of these known malicious endpoints enables rapid containment before attackers can establish persistence or exfiltrate sensitive data from the organization’s cloud infrastructure.
Threat: ClearFake Total URLs: 24 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://u9gcj5sd.oxiidbet.com/?ublib=55a4e6f9-1eba-4151-bd42-9c01fa2b2c8a | offline | malware_download | 2026-07-05 |
hxxps://nazemud.ac90bet.net/1a2dfa37-1efd-4b97-9945-7e195dd16099 | offline | malware_download | 2026-07-05 |
hxxps://azxhmev.prozhe.net/fa296535-349e-4380-8e53-b05fe29b5396 | offline | malware_download | 2026-07-05 |
hxxps://zshaimrg.forwardbahis.com/b16b28f5-d99c-4809-bfb4-78897dd50d51 | offline | malware_download | 2026-07-05 |
hxxps://oemtklu.pabloobet.com/df769883-de99-4605-81da-08e182d5fa09 | offline | malware_download | 2026-07-05 |
hxxps://6l2yvway.fidoubet.com/?ublib=51c06ffc-d56f-4c77-bd3e-befc23213cc8 | offline | malware_download | 2026-07-05 |
hxxps://ojst23x0.site-enfejar-hotbet.com/?ublib=804cda12-7364-4208-90d7-15392b48c617 | offline | malware_download | 2026-07-05 |
hxxps://8bmmubit.site-enfejar-ba-zarib-bala.com/?ublib=560f8e55-8bd2-470b-84be-e3010f1e4aab | offline | malware_download | 2026-07-05 |
hxxps://njgpeig.onjabet.casino/51513efa-204c-4f4b-af74-1949847e293d | offline | malware_download | 2026-07-05 |
hxxps://mospyqp.ninjafruiet.casino/0dd75653-621b-49c0-997f-adb738326cd7 | offline | malware_download | 2026-07-05 |
hxxps://irf3md7c.casinobahis.app/?ublib=ed7de21b-ddc2-4b7f-8bb7-9426ad91080e | offline | malware_download | 2026-07-05 |
hxxps://qvmobjz.nextbahis.org/315d124b-352d-4ee0-ad6f-5f33db621dcc | offline | malware_download | 2026-07-05 |
hxxps://sfcrhzgd.btyek.shop/4cc045e2-8f3b-495b-a423-b7c54c56f7ba | offline | malware_download | 2026-07-05 |
hxxps://cldppqm.jetshart.net/2e4a62c3-c4d3-41bb-b7c0-70bac110cc8a | offline | malware_download | 2026-07-05 |
hxxps://jpdgawf.enfejar-site.bet/93236947-d382-49ca-a477-f3fff71fb8ee | offline | malware_download | 2026-07-05 |
hxxps://fbkhheg.bahisforward.com/ae82047f-19c2-4dad-9f87-c24acd731bda | offline | malware_download | 2026-07-05 |
hxxps://69gqzj0b.cartbahis.com/?ublib=4b8c809b-60ea-4854-b047-0282294be527 | offline | malware_download | 2026-07-05 |
hxxps://xcgifut.bahisdolar.com/d0ea5931-feda-4c1b-a635-b801b97acbac | offline | malware_download | 2026-07-05 |
hxxps://rbso1spv.hi-lo.bet/?ublib=e975a273-1662-420c-88c1-c148a8df7034 | offline | malware_download | 2026-07-05 |
hxxps://ibsovb64.bet1xiraq.com/?ublib=2c119b2d-279e-4756-ab26-50d4c6b67b64 | offline | malware_download | 2026-07-05 |
hxxps://ufdopmc.bahiscash.com/5cd6c481-2149-490d-b048-950c14d15d23 | offline | malware_download | 2026-07-05 |
hxxps://lcsywbam.btyek.christmas/adc2ab6a-88ab-4cf5-9095-1395059a67ad | offline | malware_download | 2026-07-05 |
hxxps://nfpljmg.bahiscart.com/cd15335c-4143-4cba-a880-3d4babbcccd5 | offline | malware_download | 2026-07-05 |
hxxps://0681dt20.bahisgame.com/?ublib=e9fbc6e5-2ba7-4559-8049-bbac13f8ab3d | offline | malware_download | 2026-07-05 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["sfcrhzgd.btyek.shop", "lcsywbam.btyek.christmas", "u9gcj5sd.oxiidbet.com", "oemtklu.pabloobet.com", "69gqzj0b.cartbahis.com", "qvmobjz.nextbahis.org", "rbso1spv.hi-lo.bet", "ibsovb64.bet1xiraq.com", "mospyqp.ninjafruiet.casino", "cldppqm.jetshart.net", "ufdopmc.bahiscash.com", "njgpeig.onjabet.casino", "nfpljmg.bahiscart.com", "irf3md7c.casinobahis.app", "nazemud.ac90bet.net", "fbkhheg.bahisforward.com", "6l2yvway.fidoubet.com", "jpdgawf.enfejar-site.bet", "8bmmubit.site-enfejar-ba-zarib-bala.com", "azxhmev.prozhe.net", "0681dt20.bahisgame.com", "xcgifut.bahisdolar.com", "zshaimrg.forwardbahis.com", "ojst23x0.site-enfejar-hotbet.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["sfcrhzgd.btyek.shop", "lcsywbam.btyek.christmas", "u9gcj5sd.oxiidbet.com", "oemtklu.pabloobet.com", "69gqzj0b.cartbahis.com", "qvmobjz.nextbahis.org", "rbso1spv.hi-lo.bet", "ibsovb64.bet1xiraq.com", "mospyqp.ninjafruiet.casino", "cldppqm.jetshart.net", "ufdopmc.bahiscash.com", "njgpeig.onjabet.casino", "nfpljmg.bahiscart.com", "irf3md7c.casinobahis.app", "nazemud.ac90bet.net", "fbkhheg.bahisforward.com", "6l2yvway.fidoubet.com", "jpdgawf.enfejar-site.bet", "8bmmubit.site-enfejar-ba-zarib-bala.com", "azxhmev.prozhe.net", "0681dt20.bahisgame.com", "xcgifut.bahisdolar.com", "zshaimrg.forwardbahis.com", "ojst23x0.site-enfejar-hotbet.com"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule, tailored for an enterprise environment:
IT Asset Management Scans via Lansweeper or SCCM
LanSweepAgent.exe or ccmexec.exe) that query internal asset management portals. If these portals host dynamic content or use third-party widgets hosted on domains recently flagged by URLhaus as “ClearFake” (often due to rapid certificate changes or shared IP infrastructure), the scanner’s HTTP requests will trigger alerts despite being benign administrative tasks.svc-lansweeper, DOMAIN\SCCM-Service) and restrict the rule scope to exclude internal DNS suffixes (e.g., .internal.corp.local) or specific IP ranges used by asset discovery tools.Automated Patch Deployment via Microsoft Endpoint Configuration Manager
Wuauserv service on client endpoints initiates connections to software update repositories and vendor portals (e.g., Adobe, Java, or Chrome update servers). If a vendor’s update server IP has been recently rotated or flagged by URLhaus as part of a “ClearFake” campaign due to a previous transient issue, the legitimate download of patch manifests will generate high-volume false positives.*.update.microsoft.com, dl.google.com) when initiated by the Windows Update service (svchost.exe with Wuauserv session), or implement a “cool-down” period where alerts are suppressed for 48 hours after a new URL is added to the ClearFake list.**Third-