This hunt targets adversary behavior where attackers leverage ClearFake-tagged malicious URLs to deliver phishing payloads or command-and-control traffic that may evade standard signature-based defenses. Proactively hunting for these specific indicators in Azure Sentinel is critical because it enables the SOC team to identify early-stage compromise attempts and block high-fidelity threats before they propagate across the organization’s network.
Threat: ClearFake Total URLs: 24 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://nxyhlvha.fileboroo.com/ | offline | malware_download | 2026-07-15 |
hxxps://pcipjcar.fileboroo.com/ | offline | malware_download | 2026-07-15 |
hxxps://i6s46ndy.site-takhtenard-sharti-betland.com/?ublib=5a752451-e0a9-4b9c-b910-d8502e29bb72 | offline | malware_download | 2026-07-15 |
hxxps://litwpjrq.casinomhub.bet/ | offline | malware_download | 2026-07-15 |
hxxps://mgnj.behtarin-site-shartbandi-football.com/ | offline | malware_download | 2026-07-15 |
hxxps://j1xayyip.bordbett10.com/?ublib=3094be8c-ed41-4bd6-a4c3-05505d7eafd9 | offline | malware_download | 2026-07-15 |
hxxps://frqbuzgo.bingobet.bingo/ | offline | malware_download | 2026-07-15 |
hxxps://mpygi.jadoou.space/ | offline | malware_download | 2026-07-15 |
hxxps://ycrarqcd.bingobet.bingo/ | offline | malware_download | 2026-07-15 |
hxxps://078zq932.betyek.bio/?ublib=824a9ab2-0433-44f5-b514-ea52ff0c725a | offline | malware_download | 2026-07-15 |
hxxps://0rlxki7g.bordbett10.com/?ublib=6577db6d-a247-4385-a5b4-571e6630c79e | offline | malware_download | 2026-07-15 |
hxxps://vjs8k4dd.betyek.bio/?ublib=0b07568c-0ae1-4d6d-8f0e-6c04db7b4e22 | offline | malware_download | 2026-07-15 |
hxxps://brmzm.jadoou.space/d1a18065-4220-4288-9ef4-9d203819a90f | offline | malware_download | 2026-07-15 |
hxxps://cgzt.behtarin-site-shartbandi-football.com/0e888cff-0881-48cf-8970-eacb0f78c572 | offline | malware_download | 2026-07-15 |
hxxps://krdqfpte.bingobet.bingo/b6baa5eb-3eb7-4b19-bbdf-c78d3dbd0218 | offline | malware_download | 2026-07-15 |
hxxps://nkqj.behtarin-site-shartbandi-football.com/56455686-a6fc-454f-bbb1-109ce77de960 | offline | malware_download | 2026-07-15 |
hxxps://zxpimegb.bingobet.bingo/a5abf05c-0a9e-496d-bbf2-85959ed38cb5 | offline | malware_download | 2026-07-15 |
hxxps://xnshgwgf.bingobet.bingo/5b7a85e7-8610-4074-84a2-d4a225ee00f8 | offline | malware_download | 2026-07-15 |
hxxps://jw27s0al.site-takhtenard-sharti-betland.com/?ublib=af4dca3e-5adf-4abe-b28a-354aefc7078b | offline | malware_download | 2026-07-15 |
hxxps://hcnmjrat.bingobet.bingo/f08720b0-82af-4e74-99c0-1940e8258ec4 | offline | malware_download | 2026-07-15 |
hxxps://izehzccr.bet90forward.win/c390c01d-1161-4fb0-915e-6bf160003071 | offline | malware_download | 2026-07-15 |
hxxps://mhyp.bahigo90bet.com/82f7f408-5c5a-4908-ac83-04e3948263b5 | offline | malware_download | 2026-07-15 |
hxxps://wxxlppea.onjabet1.com/9060edc9-cce1-4910-a259-6552f4b3e19f | offline | malware_download | 2026-07-15 |
hxxps://pnsc.radioshartbandi.bet/bf5c32fe-8d24-4588-8525-a0c882a3bba2 | offline | malware_download | 2026-07-15 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["jw27s0al.site-takhtenard-sharti-betland.com", "0rlxki7g.bordbett10.com", "078zq932.betyek.bio", "i6s46ndy.site-takhtenard-sharti-betland.com", "mgnj.behtarin-site-shartbandi-football.com", "krdqfpte.bingobet.bingo", "vjs8k4dd.betyek.bio", "wxxlppea.onjabet1.com", "nkqj.behtarin-site-shartbandi-football.com", "mpygi.jadoou.space", "litwpjrq.casinomhub.bet", "frqbuzgo.bingobet.bingo", "hcnmjrat.bingobet.bingo", "pcipjcar.fileboroo.com", "zxpimegb.bingobet.bingo", "ycrarqcd.bingobet.bingo", "brmzm.jadoou.space", "nxyhlvha.fileboroo.com", "mhyp.bahigo90bet.com", "pnsc.radioshartbandi.bet", "xnshgwgf.bingobet.bingo", "cgzt.behtarin-site-shartbandi-football.com", "j1xayyip.bordbett10.com", "izehzccr.bet90forward.win"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["jw27s0al.site-takhtenard-sharti-betland.com", "0rlxki7g.bordbett10.com", "078zq932.betyek.bio", "i6s46ndy.site-takhtenard-sharti-betland.com", "mgnj.behtarin-site-shartbandi-football.com", "krdqfpte.bingobet.bingo", "vjs8k4dd.betyek.bio", "wxxlppea.onjabet1.com", "nkqj.behtarin-site-shartbandi-football.com", "mpygi.jadoou.space", "litwpjrq.casinomhub.bet", "frqbuzgo.bingobet.bingo", "hcnmjrat.bingobet.bingo", "pcipjcar.fileboroo.com", "zxpimegb.bingobet.bingo", "ycrarqcd.bingobet.bingo", "brmzm.jadoou.space", "nxyhlvha.fileboroo.com", "mhyp.bahigo90bet.com", "pnsc.radioshartbandi.bet", "xnshgwgf.bingobet.bingo", "cgzt.behtarin-site-shartbandi-football.com", "j1xayyip.bordbett10.com", "izehzccr.bet90forward.win"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the URLhaus: ClearFake Malicious URLs rule in an enterprise environment, along with suggested filters or exclusions:
IT Asset Management & Software Inventory Scans
10.x.x.x or the public IPs of the scanner appliances) OR filter by User-Agent strings containing keywords like “Lansweeper,” “SCCM,” or “SolarWinds.”Scheduled Software Update Checks
01:00–04:00 on weekdays) for specific Service Accounts used by these deployment tools, or exclude the destination domains associated with your primary software vendors.Third-Party Cloud Backup & Sync Operations