This hunt targets adversary activity linked to the ClearFake malware family by correlating Azure Sentinel logs against a curated set of 40 specific Indicators of Compromise (IOCs). Proactively hunting for these signatures is critical because ClearFake’s high-severity threat profile demands early detection to prevent lateral movement and data exfiltration before automated alerts trigger.
Malware Family: ClearFake Total IOCs: 40 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | oxqniwv[.]1xpin.vip | payload_delivery | 2026-07-03 | 100% |
| domain | 1xpin.vip | payload_delivery | 2026-07-03 | 100% |
| domain | qxguiws[.]1xpin.org | payload_delivery | 2026-07-03 | 100% |
| domain | 1xpin.org | payload_delivery | 2026-07-03 | 100% |
| domain | w9x1nvom.sizzleasianfood.com | payload_delivery | 2026-07-03 | 100% |
| domain | jds4p0yc.betbacklink.com | payload_delivery | 2026-07-03 | 100% |
| domain | dhur9q3h[.]1x303.casino | payload_delivery | 2026-07-03 | 100% |
| domain | sizzleasianfood.com | payload_delivery | 2026-07-03 | 100% |
| domain | pastiadajalan.pro | payload_delivery | 2026-07-03 | 100% |
| domain | bet808.bet | payload_delivery | 2026-07-03 | 100% |
| domain | ao046xe5[.]1xbeet.xyz | payload_delivery | 2026-07-03 | 100% |
| domain | 1xbeet.xyz | payload_delivery | 2026-07-03 | 100% |
| domain | prozhe.download | payload_delivery | 2026-07-03 | 100% |
| domain | vlmtl3yv.jozvedownload.com | payload_delivery | 2026-07-03 | 100% |
| domain | jozvedownload.com | payload_delivery | 2026-07-03 | 100% |
| domain | prozhe.computer | payload_delivery | 2026-07-03 | 100% |
| domain | prozhe24.com | payload_delivery | 2026-07-03 | 100% |
| domain | podcast.actor | payload_delivery | 2026-07-03 | 100% |
| domain | pasoor.net | payload_delivery | 2026-07-03 | 100% |
| domain | fnd9555t.ligabfa.com | payload_delivery | 2026-07-03 | 100% |
| domain | ligabfa.com | payload_delivery | 2026-07-03 | 100% |
| domain | estekhdam.download | payload_delivery | 2026-07-03 | 100% |
| domain | digish.art | payload_delivery | 2026-07-03 | 100% |
| domain | chizbet.com | payload_delivery | 2026-07-03 | 100% |
| domain | 1xpin.cash | payload_delivery | 2026-07-03 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["oxqniwv.1xpin.vip", "1xpin.vip", "qxguiws.1xpin.org", "1xpin.org", "w9x1nvom.sizzleasianfood.com", "jds4p0yc.betbacklink.com", "dhur9q3h.1x303.casino", "sizzleasianfood.com", "pastiadajalan.pro", "bet808.bet", "ao046xe5.1xbeet.xyz", "1xbeet.xyz", "prozhe.download", "vlmtl3yv.jozvedownload.com", "jozvedownload.com", "prozhe.computer", "prozhe24.com", "podcast.actor", "pasoor.net", "fnd9555t.ligabfa.com", "ligabfa.com", "estekhdam.download", "digish.art", "chizbet.com", "1xpin.cash", "jozve.vip", "bet1kick.com", "1xmorocco.com", "jozvepro.pro", "bc90game.com", "1xjet.net", "kitabmenang.pro", "jozvepro.com", "1xfa.casino", "hondamobiltangerang.com", "jozve.online", "betball90kade.com", "evhg599x.lemongrassasiangrill.com", "adoswjr.calvaryhospice.org", "lemongrassasiangrill.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule, tailored for an enterprise environment where legitimate traffic to these 40 IOCs is common:
Endpoint Protection Policy Updates via CrowdStrike Falcon or SentinelOne
svc-falcon-updater or SentinelOne-Service) and restrict the alert scope to exclude the specific destination ports used by these vendors (typically 80, 443, and vendor-specific high ports like 1620).Automated Vulnerability Scans via Qualys Cloud Agent or Tenable Nessus
10.50.20.0/24) or filter by the specific process names of the scanning agents (qualys-cloud-agent.exe, Tenable Nessus Agent.exe) when communicating with the ClearFake IOCs during defined maintenance windows (e.g., 02:00–06:00 UTC).Software Deployment and Patch Management via Microsoft SCCM or Ivanti