This hunt targets adversary behavior where threat actors leverage ClearFake-malicious URLs to deliver targeted phishing or drive-by download attacks against organizational endpoints. Proactively hunting these specific indicators in Azure Sentinel is critical because early detection of this known campaign allows security teams to block active infection vectors before they compromise sensitive data or escalate into broader lateral movement incidents.
Threat: ClearFake Total URLs: 26 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://nsbnqzdnv.pathfindersafrica.com/96efb0d6-e57f-4c82-bca9-aa42392dbaf5 | offline | malware_download | 2026-07-18 |
hxxps://p43qsij4.nextbahis.one/?ublib=b030b8fc-8b9c-4ad8-9b33-3554b0984efd | offline | malware_download | 2026-07-18 |
hxxps://jeekd.senorgyros.com/8ead5b91-652a-4381-a42a-f5b038d19333 | offline | malware_download | 2026-07-18 |
hxxps://vwpanxmoc.orlandosmuncy.com/9405a702-74fe-4399-a260-180bfc6ad07c | offline | malware_download | 2026-07-18 |
hxxps://yvzqh.hazaratbet.game/654d4f01-0b10-4a37-9bf7-0f776e4eaf1b | offline | malware_download | 2026-07-18 |
hxxps://jifyi.gamehazarat.com/7f36ec19-3fac-44af-99b2-c7951863f721 | offline | malware_download | 2026-07-18 |
hxxps://7uaho90m.myluxurykitchenandbath.com/?ublib=169aad7a-f72d-48b3-b94d-d5acc64eed7a | offline | malware_download | 2026-07-18 |
hxxps://kgptwmgqf.taktikkbet.com/ed043999-1b44-4f74-9567-af7f6a924982 | offline | malware_download | 2026-07-18 |
hxxps://lbtzq.funxbet.casino/43549fd6-7800-4c87-8705-fbe79cbd7c94 | offline | malware_download | 2026-07-18 |
hxxps://yblfhadfu.mango90bet.com/4c6146f1-11cd-4268-98cf-fe98a519d427 | offline | malware_download | 2026-07-18 |
hxxps://rmxohycah.sky7bet.casino/88cbdf70-e54d-4d15-80c8-6ea2692bdd6e | offline | malware_download | 2026-07-18 |
hxxps://heork.derbi.promo/e7b03feb-46d2-4e40-b088-c64649ad2433 | offline | malware_download | 2026-07-18 |
hxxps://8862moud.mikespizzafairfield.com/?ublib=248d863c-9953-4ba1-8311-357833fc01da | offline | malware_download | 2026-07-18 |
hxxps://uvxzsajar.lion1bet.com/50e0e0ee-0f02-40e1-a6c3-8e1fc242c721 | offline | malware_download | 2026-07-18 |
hxxps://mpuwd.deepspaceparker.com/83c48f54-3720-427b-a093-b64f5ffcd66d | offline | malware_download | 2026-07-18 |
hxxps://atqfb.calirayalake.com/e0b68956-6852-40f7-a9c0-212b646cc5a7 | offline | malware_download | 2026-07-18 |
hxxps://jppxuuhae.imagederm.com/ee204b50-ce64-4666-a796-d47c131311b7 | offline | malware_download | 2026-07-18 |
hxxps://5ipju606.venus90bet.com/?ublib=6bb30fc5-584e-4d29-9a05-0f20337df1c2 | offline | malware_download | 2026-07-18 |
hxxps://hdz7omr1.nextbahis.blog/?ublib=00d4f7ea-16b1-41d6-af41-493405c20829 | offline | malware_download | 2026-07-18 |
hxxps://i0bep9cj.medallionfoodsinctempura.com/?ublib=7c37f001-8260-46b0-bee9-82b217b2ec2e | offline | malware_download | 2026-07-18 |
hxxps://olyqj.luxurygoodscaree.com/72b6a9eb-5d43-42ca-bed2-c68c30e3680d | offline | malware_download | 2026-07-18 |
hxxps://dogfrpygx.hazzarat.com/22b404a4-79fa-424c-b6a7-0305e39e96f9 | offline | malware_download | 2026-07-18 |
hxxps://acvwd.lunapizzaco.com/c5f9bf04-f5ab-41ba-a2bc-57320785bb3a | offline | malware_download | 2026-07-18 |
hxxps://ubwzdjejr.fun777game.org/d60dfc8d-b516-4111-843c-585ebd2b04cf | offline | malware_download | 2026-07-18 |
hxxps://4j6m037n.mcbelize.com/?ublib=85f2c8d0-1468-4b04-aa1a-5a99b75ea8f6 | offline | malware_download | 2026-07-18 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["yblfhadfu.mango90bet.com", "tygnu.lokercorp.com", "p43qsij4.nextbahis.one", "lbtzq.funxbet.casino", "jeekd.senorgyros.com", "dogfrpygx.hazzarat.com", "i0bep9cj.medallionfoodsinctempura.com", "kgptwmgqf.taktikkbet.com", "vwpanxmoc.orlandosmuncy.com", "mpuwd.deepspaceparker.com", "nsbnqzdnv.pathfindersafrica.com", "acvwd.lunapizzaco.com", "4j6m037n.mcbelize.com", "atqfb.calirayalake.com", "rmxohycah.sky7bet.casino", "5ipju606.venus90bet.com", "hdz7omr1.nextbahis.blog", "8862moud.mikespizzafairfield.com", "yvzqh.hazaratbet.game", "7uaho90m.myluxurykitchenandbath.com", "olyqj.luxurygoodscaree.com", "jifyi.gamehazarat.com", "heork.derbi.promo", "uvxzsajar.lion1bet.com", "jppxuuhae.imagederm.com", "ubwzdjejr.fun777game.org"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["yblfhadfu.mango90bet.com", "tygnu.lokercorp.com", "p43qsij4.nextbahis.one", "lbtzq.funxbet.casino", "jeekd.senorgyros.com", "dogfrpygx.hazzarat.com", "i0bep9cj.medallionfoodsinctempura.com", "kgptwmgqf.taktikkbet.com", "vwpanxmoc.orlandosmuncy.com", "mpuwd.deepspaceparker.com", "nsbnqzdnv.pathfindersafrica.com", "acvwd.lunapizzaco.com", "4j6m037n.mcbelize.com", "atqfb.calirayalake.com", "rmxohycah.sky7bet.casino", "5ipju606.venus90bet.com", "hdz7omr1.nextbahis.blog", "8862moud.mikespizzafairfield.com", "yvzqh.hazaratbet.game", "7uaho90m.myluxurykitchenandbath.com", "olyqj.luxurygoodscaree.com", "jifyi.gamehazarat.com", "heork.derbi.promo", "uvxzsajar.lion1bet.com", "jppxuuhae.imagederm.com", "ubwzdjejr.fun777game.org"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule, tailored for a legitimate enterprise environment:
Software Update & Patch Management Scans
clearfake.net domain to verify signature databases, check for new threat intelligence feeds, or validate SSL certificate revocation lists. These background health checks often trigger the rule because the tool initiates an HTTP/HTTPS connection to a URL flagged by URLhaus as part of the ClearFake campaign.C:\Program Files\CrowdStrike\csagent.exe or Microsoft Defender Antivirus Service) combined with the destination domain *.clearfake.net. Additionally, exclude traffic originating from specific Service Accounts used by these management consoles.Automated Backup and Data Integrity Verification
01:30 – 04:00 daily) for traffic generated by backup service accounts (e.g., svc_backup_prod) targeting the specific URL paths associated with the ClearFake package