This hunt detects adversary activity linked to the ClearFake campaign by identifying network and host interactions matching its specific set of 70 Indicators of Compromise (IOCs). Proactive hunting for these signatures in Azure Sentinel is critical to rapidly identify early-stage infections or lateral movement before they escalate into full-blown incidents.
Malware Family: ClearFake Total IOCs: 70 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | eluk.hazzaratbet.com | payload_delivery | 2026-07-08 | 100% |
| domain | kdmr.hazzaratbet.com | payload_delivery | 2026-07-08 | 100% |
| domain | hvaujhmz.alhilal90.com | payload_delivery | 2026-07-08 | 100% |
| domain | qee052b3.irantop.bet | payload_delivery | 2026-07-08 | 100% |
| domain | a5ozej0l.irantop.bet | payload_delivery | 2026-07-08 | 100% |
| domain | bwup.catsandcarp.com | payload_delivery | 2026-07-08 | 100% |
| domain | 2766iljo.melbetiran.poker | payload_delivery | 2026-07-08 | 100% |
| domain | melbetiran.poker | payload_delivery | 2026-07-08 | 100% |
| domain | 3w6k8hlt.pinbahis.bet | payload_delivery | 2026-07-08 | 100% |
| domain | pinbahis.bet | payload_delivery | 2026-07-08 | 100% |
| domain | phcwqqkr[.]1xgermany.com | payload_delivery | 2026-07-08 | 100% |
| domain | ykgl.calvaryhospice.org | payload_delivery | 2026-07-08 | 100% |
| domain | errxxcnl.gamee.bet | payload_delivery | 2026-07-08 | 100% |
| domain | vj7eaayr.fa1xbet.vip | payload_delivery | 2026-07-08 | 100% |
| domain | gamee.bet | payload_delivery | 2026-07-08 | 100% |
| domain | kqbtsllu[.]1xgame.pro | payload_delivery | 2026-07-08 | 100% |
| domain | fa1xbet.vip | payload_delivery | 2026-07-08 | 100% |
| domain | obuf.betawarz.com | payload_delivery | 2026-07-08 | 100% |
| domain | football7.football | payload_delivery | 2026-07-08 | 100% |
| domain | football360.football | payload_delivery | 2026-07-08 | 100% |
| domain | fezk.polbaz.bet | payload_delivery | 2026-07-08 | 100% |
| domain | nqwr.polbaz.bet | payload_delivery | 2026-07-08 | 100% |
| domain | ironhausflow.mivonflowsrv.garden | botnet_cc | 2026-07-08 | 90% |
| domain | tiduflxx.farsi1xbet.shop | payload_delivery | 2026-07-08 | 100% |
| domain | farsi1xbet.shop | payload_delivery | 2026-07-08 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["eluk.hazzaratbet.com", "kdmr.hazzaratbet.com", "hvaujhmz.alhilal90.com", "qee052b3.irantop.bet", "a5ozej0l.irantop.bet", "bwup.catsandcarp.com", "2766iljo.melbetiran.poker", "melbetiran.poker", "3w6k8hlt.pinbahis.bet", "pinbahis.bet", "phcwqqkr.1xgermany.com", "ykgl.calvaryhospice.org", "errxxcnl.gamee.bet", "vj7eaayr.fa1xbet.vip", "gamee.bet", "kqbtsllu.1xgame.pro", "fa1xbet.vip", "obuf.betawarz.com", "football7.football", "football360.football", "fezk.polbaz.bet", "nqwr.polbaz.bet", "ironhausflow.mivonflowsrv.garden", "tiduflxx.farsi1xbet.shop", "farsi1xbet.shop", "srgq.icebet90.com", "kcyh.icebet90.com", "aeons-echo.org", "artisan-advertising.cc", "brain-game.cc", "celebration-internet.cc", "ed-security-buff.cc", "fast-node.com", "firewall-sentinel.cc", "flame-guard.cc", "islandepstain.cc", "lavande-rocket.cc", "pkg.vogueatelier.cc", "quartermaster-sec.cc", "solid-manage.com", "tikcettoread.com", "cmicrosoft1.click", "fd.gstats-api-contact.cc", "mgo.gstats-api-contact.cc", "a1ukh8ol.cialispi.com", "ecouvs23.cialispi.com", "rbthbhfo.backlinkbet.com", "jrfl.hazzaratbet.com", "mfrj.hazzaratbet.com", "yhqm.milioner.bet"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
Automated Vulnerability Scanning by Qualys/CrowdStrike
10.20.50.x) or filter events where the process name is qualysagent.exe or csfalcon.exe and the destination port is associated with the ThreatFox update endpoint.Endpoint Protection Policy Updates via Microsoft Defender for Endpoint
SYSTEM or Local Service and the parent process is MsMpEng.exe (Antimalware Service Executable) occurring during standard maintenance windows (e.g., 02:00 – 04:00 UTC).**Scheduled Threat Intelligence Ingestion by Splunk/SI