This hunt targets adversary activity linked to the ClearFake malware campaign by correlating network and endpoint telemetry against a curated set of 68 specific Indicators of Compromise (IOCs). Proactively hunting for these signatures in Azure Sentinel is critical to rapidly identify early-stage infections and prevent lateral movement before the threat escalates across the organization’s cloud infrastructure.
Malware Family: ClearFake Total IOCs: 68 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | ark-crestos.eightyen1arge.garden | botnet_cc | 2026-07-19 | 90% |
| domain | znnop.frisbeeburgerllc.com | payload_delivery | 2026-07-19 | 100% |
| domain | frisbeeburgerllc.com | payload_delivery | 2026-07-19 | 100% |
| domain | gwcs.bolesfarms.com | payload_delivery | 2026-07-19 | 100% |
| domain | g5sy0m2g.calirayalake.com | payload_delivery | 2026-07-19 | 100% |
| domain | bolesfarms.com | payload_delivery | 2026-07-19 | 100% |
| domain | ystr.bittersweetkennel.com | payload_delivery | 2026-07-19 | 100% |
| domain | bittersweetkennel.com | payload_delivery | 2026-07-19 | 100% |
| domain | jackpot168.de.com | payload_delivery | 2026-07-19 | 100% |
| domain | zuibs.jetbet.download | payload_delivery | 2026-07-19 | 100% |
| domain | coolriverpizzaca.com | payload_delivery | 2026-07-19 | 100% |
| domain | nextbahis.app | payload_delivery | 2026-07-19 | 100% |
| domain | trivaleal9.eightyen1arge.garden | botnet_cc | 2026-07-19 | 90% |
| domain | markol.pro | botnet_cc | 2026-07-19 | 90% |
| domain | bzeg.bikertlane.com | payload_delivery | 2026-07-19 | 100% |
| domain | m4jpiubh.royaldoorsspringdale.com | payload_delivery | 2026-07-19 | 100% |
| domain | bikertlane.com | payload_delivery | 2026-07-19 | 100% |
| domain | royaldoorsspringdale.com | payload_delivery | 2026-07-19 | 100% |
| domain | 4yl6u62i.pdfbama.com | payload_delivery | 2026-07-19 | 100% |
| domain | otcgf.christorem.com | payload_delivery | 2026-07-19 | 100% |
| domain | christorem.com | payload_delivery | 2026-07-19 | 100% |
| domain | dlvk.nextbahis.one | payload_delivery | 2026-07-19 | 100% |
| domain | ht326ul6.hazaratbet.bet | payload_delivery | 2026-07-19 | 100% |
| domain | lqcah.cheaperthan-dirt.com | payload_delivery | 2026-07-19 | 100% |
| domain | cheaperthan-dirt.com | payload_delivery | 2026-07-19 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["ark-crestos.eightyen1arge.garden", "znnop.frisbeeburgerllc.com", "frisbeeburgerllc.com", "gwcs.bolesfarms.com", "g5sy0m2g.calirayalake.com", "bolesfarms.com", "ystr.bittersweetkennel.com", "bittersweetkennel.com", "jackpot168.de.com", "zuibs.jetbet.download", "coolriverpizzaca.com", "nextbahis.app", "trivaleal9.eightyen1arge.garden", "markol.pro", "bzeg.bikertlane.com", "m4jpiubh.royaldoorsspringdale.com", "bikertlane.com", "royaldoorsspringdale.com", "4yl6u62i.pdfbama.com", "otcgf.christorem.com", "christorem.com", "dlvk.nextbahis.one", "ht326ul6.hazaratbet.bet", "lqcah.cheaperthan-dirt.com", "cheaperthan-dirt.com", "olotu.cardanaircraft.org", "cardanaircraft.org", "xexop.burritodelight.com", "qjhi.taktikkbet.com", "ybntipf1.ramenizakaya-himeji.com", "burritodelight.com", "bvxbg.buildableconcepts.com", "buildableconcepts.com", "tomi.socialclub112.com", "vcjh.shimiaodaoflushing.com", "wsfls.hazaratbet.game", "6ytetbzh.quickandcleanfetish.com", "amse.senorgyros.com", "hcrty.funxbet.casino", "ru4xmcs2.onjabet1.com", "uina.noodlesbymomi.com", "yxzsj.derbi.promo", "zugaztieta.com", "vftudd2r.gamehazarat.bet", "twincitytattoos.com", "a2wk5fd0.purity-pharmaceuticals.net", "purity-pharmaceuticals.net", "sultanoffc.com", "sultan88.xyz", "hszy.nextbahis.blog"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios and corresponding exclusions for the ThreatFox: ClearFake IOCs detection rule in an enterprise environment:
Endpoint Security Agent Updates via Microsoft Endpoint Configuration Manager (MECM/SCCM)
ccmexec.exe) downloads and installs new definition packs containing the specific 68 IOCs flagged by ThreatFox (e.g., updated hash signatures or configuration manifests) across thousands of workstations simultaneously.443 and the user agent contains “Microsoft-SoftwareUpdate” or the process name matches ccmexec.exe.Automated Backup Jobs Using Veeam Backup & Replication
vbrservice.exe) performs a read-heavy scan of the repository directory, generating network connections to external ThreatFox update servers to validate the integrity of the 68 IOCs before archiving them to tape or cloud storage.443/80, specifically filtering out events where the process name is vbrservice.exe or VeeamAgent.exe.IT Admin Manual Remediation via PowerShell Scripts
ClearFake_Sync.ps1) on a jump host to manually synchronize threat intelligence feeds. This script uses the Invoke-WebRequest cmdlet to pull the latest IOC list from