← Back to SOC feed Coverage →

ThreatFox: ClearFake IOCs

ioc-hunt HIGH ThreatFox
DnsEvents
iocjs-clearfakethreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-07-03T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt targets adversary activity linked to the ClearFake malware family by correlating Azure Sentinel logs against a curated set of 40 specific Indicators of Compromise (IOCs). Proactively hunting for these signatures is critical because ClearFake’s high-severity threat profile demands early detection to prevent lateral movement and data exfiltration before automated alerts trigger.

IOC Summary

Malware Family: ClearFake Total IOCs: 40 IOC Types: domain

TypeValueThreat TypeFirst SeenConfidence
domainoxqniwv[.]1xpin.vippayload_delivery2026-07-03100%
domain1xpin.vippayload_delivery2026-07-03100%
domainqxguiws[.]1xpin.orgpayload_delivery2026-07-03100%
domain1xpin.orgpayload_delivery2026-07-03100%
domainw9x1nvom.sizzleasianfood.compayload_delivery2026-07-03100%
domainjds4p0yc.betbacklink.compayload_delivery2026-07-03100%
domaindhur9q3h[.]1x303.casinopayload_delivery2026-07-03100%
domainsizzleasianfood.compayload_delivery2026-07-03100%
domainpastiadajalan.propayload_delivery2026-07-03100%
domainbet808.betpayload_delivery2026-07-03100%
domainao046xe5[.]1xbeet.xyzpayload_delivery2026-07-03100%
domain1xbeet.xyzpayload_delivery2026-07-03100%
domainprozhe.downloadpayload_delivery2026-07-03100%
domainvlmtl3yv.jozvedownload.compayload_delivery2026-07-03100%
domainjozvedownload.compayload_delivery2026-07-03100%
domainprozhe.computerpayload_delivery2026-07-03100%
domainprozhe24.compayload_delivery2026-07-03100%
domainpodcast.actorpayload_delivery2026-07-03100%
domainpasoor.netpayload_delivery2026-07-03100%
domainfnd9555t.ligabfa.compayload_delivery2026-07-03100%
domainligabfa.compayload_delivery2026-07-03100%
domainestekhdam.downloadpayload_delivery2026-07-03100%
domaindigish.artpayload_delivery2026-07-03100%
domainchizbet.compayload_delivery2026-07-03100%
domain1xpin.cashpayload_delivery2026-07-03100%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["oxqniwv.1xpin.vip", "1xpin.vip", "qxguiws.1xpin.org", "1xpin.org", "w9x1nvom.sizzleasianfood.com", "jds4p0yc.betbacklink.com", "dhur9q3h.1x303.casino", "sizzleasianfood.com", "pastiadajalan.pro", "bet808.bet", "ao046xe5.1xbeet.xyz", "1xbeet.xyz", "prozhe.download", "vlmtl3yv.jozvedownload.com", "jozvedownload.com", "prozhe.computer", "prozhe24.com", "podcast.actor", "pasoor.net", "fnd9555t.ligabfa.com", "ligabfa.com", "estekhdam.download", "digish.art", "chizbet.com", "1xpin.cash", "jozve.vip", "bet1kick.com", "1xmorocco.com", "jozvepro.pro", "bc90game.com", "1xjet.net", "kitabmenang.pro", "jozvepro.com", "1xfa.casino", "hondamobiltangerang.com", "jozve.online", "betball90kade.com", "evhg599x.lemongrassasiangrill.com", "adoswjr.calvaryhospice.org", "lemongrassasiangrill.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule, tailored for an enterprise environment where legitimate traffic to these 40 IOCs is common:

Original source: https://threatfox.abuse.ch/browse/malware/js.clearfake/