← Back to SOC feed Coverage →

URLhaus: ClearFake Malicious URLs

ioc-hunt HIGH URLhaus
CommonSecurityLogDnsEvents
iocurlhaus
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at URLhaus →
Retrieved: 2026-07-08T11:00:00Z · Confidence: medium

Hunt Hypothesis

This hunt targets adversary behavior where attackers leverage ClearFake-malicious URLs to deliver targeted phishing payloads or command-and-control traffic designed to evade standard signature-based defenses. The SOC team should proactively investigate these specific indicators within Azure Sentinel to identify early-stage compromise attempts and validate the effectiveness of existing URL filtering policies against this known threat family.

IOC Summary

Threat: ClearFake Total URLs: 19 Active URLs: 0

URLStatusThreatDate Added
hxxps://toonhymp.barcelona11.com/77f467b3-2f80-4605-98e9-c9a7ad320f85offlinemalware_download2026-07-08
hxxps://eluk.hazzaratbet.com/66b34559-2dd8-472a-b900-17481638eb05offlinemalware_download2026-07-08
hxxps://hvaujhmz.alhilal90.com/053c7321-7980-41f5-ae96-c0de156094daofflinemalware_download2026-07-08
hxxps://qee052b3.irantop.bet/?ublib=387ccab7-95c0-4bd8-92e4-9265942c14d8offlinemalware_download2026-07-08
hxxps://bwup.catsandcarp.com/2af7d0f8-d488-4646-9d1e-ad290a2df45aofflinemalware_download2026-07-08
hxxps://2766iljo.melbetiran.poker/?ublib=105c4669-6188-45e1-9feb-ff87e61450e3offlinemalware_download2026-07-08
hxxps://3w6k8hlt.pinbahis.bet/?ublib=2c82e7ff-387f-43fe-bcd1-51c1395115f4offlinemalware_download2026-07-08
hxxps://phcwqqkr.1xgermany.com/d2b282f1-b951-4e49-8364-6d87897cc80fofflinemalware_download2026-07-08
hxxps://ykgl.calvaryhospice.org/5468cbb5-9b09-40a6-8515-0bdcdd62b0cbofflinemalware_download2026-07-08
hxxps://errxxcnl.gamee.bet/70738f5e-4f31-4119-b124-a45974b35888offlinemalware_download2026-07-08
hxxps://vj7eaayr.fa1xbet.vip/?ublib=7d3d7529-c27d-40be-b74a-3177bddd906dofflinemalware_download2026-07-08
hxxps://kqbtsllu.1xgame.pro/7df7b7fe-ab25-4c20-b375-43f1e4c1eb41offlinemalware_download2026-07-08
hxxps://obuf.betawarz.com/275fec36-f843-46b7-9adb-43ddeb837b10offlinemalware_download2026-07-08
hxxps://fezk.polbaz.bet/48d045e7-7562-43ed-a88a-ea1e6d5a6f9dofflinemalware_download2026-07-08
hxxps://tiduflxx.farsi1xbet.shop/8d25635e-11c6-43b3-9d66-4a95eb45e11cofflinemalware_download2026-07-08
hxxps://srgq.icebet90.com/5c2f6eef-2d2d-4cc8-b668-0d8549e18eb9offlinemalware_download2026-07-08
hxxps://a1ukh8ol.cialispi.com/?ublib=24b3d06c-8ce8-4099-940e-1d8af649555aofflinemalware_download2026-07-08
hxxps://rbthbhfo.backlinkbet.com/4f5e79ed-eafd-44ff-8f0d-09e1945855a9offlinemalware_download2026-07-08
hxxps://jrfl.hazzaratbet.com/c5a4f284-e088-4b11-8d91-48fedb48e0eaofflinemalware_download2026-07-08

KQL: Url Dns Hunt

// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["vj7eaayr.fa1xbet.vip", "errxxcnl.gamee.bet", "kqbtsllu.1xgame.pro", "3w6k8hlt.pinbahis.bet", "ykgl.calvaryhospice.org", "a1ukh8ol.cialispi.com", "bwup.catsandcarp.com", "jrfl.hazzaratbet.com", "obuf.betawarz.com", "phcwqqkr.1xgermany.com", "eluk.hazzaratbet.com", "fezk.polbaz.bet", "toonhymp.barcelona11.com", "qee052b3.irantop.bet", "hvaujhmz.alhilal90.com", "srgq.icebet90.com", "rbthbhfo.backlinkbet.com", "2766iljo.melbetiran.poker", "tiduflxx.farsi1xbet.shop"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc

KQL: Url Proxy Hunt

// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["vj7eaayr.fa1xbet.vip", "errxxcnl.gamee.bet", "kqbtsllu.1xgame.pro", "3w6k8hlt.pinbahis.bet", "ykgl.calvaryhospice.org", "a1ukh8ol.cialispi.com", "bwup.catsandcarp.com", "jrfl.hazzaratbet.com", "obuf.betawarz.com", "phcwqqkr.1xgermany.com", "eluk.hazzaratbet.com", "fezk.polbaz.bet", "toonhymp.barcelona11.com", "qee052b3.irantop.bet", "hvaujhmz.alhilal90.com", "srgq.icebet90.com", "rbthbhfo.backlinkbet.com", "2766iljo.melbetiran.poker", "tiduflxx.farsi1xbet.shop"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 4 specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule, tailored for a legitimate enterprise environment:

Original source: https://urlhaus.abuse.ch/