This hunt targets adversary behavior where attackers leverage ClearFake-malicious URLs to deliver targeted phishing payloads or command-and-control traffic designed to evade standard signature-based defenses. The SOC team should proactively investigate these specific indicators within Azure Sentinel to identify early-stage compromise attempts and validate the effectiveness of existing URL filtering policies against this known threat family.
Threat: ClearFake Total URLs: 19 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://toonhymp.barcelona11.com/77f467b3-2f80-4605-98e9-c9a7ad320f85 | offline | malware_download | 2026-07-08 |
hxxps://eluk.hazzaratbet.com/66b34559-2dd8-472a-b900-17481638eb05 | offline | malware_download | 2026-07-08 |
hxxps://hvaujhmz.alhilal90.com/053c7321-7980-41f5-ae96-c0de156094da | offline | malware_download | 2026-07-08 |
hxxps://qee052b3.irantop.bet/?ublib=387ccab7-95c0-4bd8-92e4-9265942c14d8 | offline | malware_download | 2026-07-08 |
hxxps://bwup.catsandcarp.com/2af7d0f8-d488-4646-9d1e-ad290a2df45a | offline | malware_download | 2026-07-08 |
hxxps://2766iljo.melbetiran.poker/?ublib=105c4669-6188-45e1-9feb-ff87e61450e3 | offline | malware_download | 2026-07-08 |
hxxps://3w6k8hlt.pinbahis.bet/?ublib=2c82e7ff-387f-43fe-bcd1-51c1395115f4 | offline | malware_download | 2026-07-08 |
hxxps://phcwqqkr.1xgermany.com/d2b282f1-b951-4e49-8364-6d87897cc80f | offline | malware_download | 2026-07-08 |
hxxps://ykgl.calvaryhospice.org/5468cbb5-9b09-40a6-8515-0bdcdd62b0cb | offline | malware_download | 2026-07-08 |
hxxps://errxxcnl.gamee.bet/70738f5e-4f31-4119-b124-a45974b35888 | offline | malware_download | 2026-07-08 |
hxxps://vj7eaayr.fa1xbet.vip/?ublib=7d3d7529-c27d-40be-b74a-3177bddd906d | offline | malware_download | 2026-07-08 |
hxxps://kqbtsllu.1xgame.pro/7df7b7fe-ab25-4c20-b375-43f1e4c1eb41 | offline | malware_download | 2026-07-08 |
hxxps://obuf.betawarz.com/275fec36-f843-46b7-9adb-43ddeb837b10 | offline | malware_download | 2026-07-08 |
hxxps://fezk.polbaz.bet/48d045e7-7562-43ed-a88a-ea1e6d5a6f9d | offline | malware_download | 2026-07-08 |
hxxps://tiduflxx.farsi1xbet.shop/8d25635e-11c6-43b3-9d66-4a95eb45e11c | offline | malware_download | 2026-07-08 |
hxxps://srgq.icebet90.com/5c2f6eef-2d2d-4cc8-b668-0d8549e18eb9 | offline | malware_download | 2026-07-08 |
hxxps://a1ukh8ol.cialispi.com/?ublib=24b3d06c-8ce8-4099-940e-1d8af649555a | offline | malware_download | 2026-07-08 |
hxxps://rbthbhfo.backlinkbet.com/4f5e79ed-eafd-44ff-8f0d-09e1945855a9 | offline | malware_download | 2026-07-08 |
hxxps://jrfl.hazzaratbet.com/c5a4f284-e088-4b11-8d91-48fedb48e0ea | offline | malware_download | 2026-07-08 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["vj7eaayr.fa1xbet.vip", "errxxcnl.gamee.bet", "kqbtsllu.1xgame.pro", "3w6k8hlt.pinbahis.bet", "ykgl.calvaryhospice.org", "a1ukh8ol.cialispi.com", "bwup.catsandcarp.com", "jrfl.hazzaratbet.com", "obuf.betawarz.com", "phcwqqkr.1xgermany.com", "eluk.hazzaratbet.com", "fezk.polbaz.bet", "toonhymp.barcelona11.com", "qee052b3.irantop.bet", "hvaujhmz.alhilal90.com", "srgq.icebet90.com", "rbthbhfo.backlinkbet.com", "2766iljo.melbetiran.poker", "tiduflxx.farsi1xbet.shop"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["vj7eaayr.fa1xbet.vip", "errxxcnl.gamee.bet", "kqbtsllu.1xgame.pro", "3w6k8hlt.pinbahis.bet", "ykgl.calvaryhospice.org", "a1ukh8ol.cialispi.com", "bwup.catsandcarp.com", "jrfl.hazzaratbet.com", "obuf.betawarz.com", "phcwqqkr.1xgermany.com", "eluk.hazzaratbet.com", "fezk.polbaz.bet", "toonhymp.barcelona11.com", "qee052b3.irantop.bet", "hvaujhmz.alhilal90.com", "srgq.icebet90.com", "rbthbhfo.backlinkbet.com", "2766iljo.melbetiran.poker", "tiduflxx.farsi1xbet.shop"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule, tailored for a legitimate enterprise environment:
Endpoint Security Agent Updates via Cloud Repository
svc-crowdstrike, defender-agent) targeting known update domains (e.g., *.crowdstrike.com, *.microsoftonline.com).Scheduled Third-Party Backup Verification Jobs
*.amazonaws.com, *.core.windows.net) during the defined maintenance window (e.g., 02:00 – 04:00 UTC).ITSM Ticketing System Integration Webhooks *