← Back to SOC feed Coverage →

ThreatFox: ClearFake IOCs

ioc-hunt HIGH ThreatFox
DnsEvents
iocjs-clearfakethreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-07-16T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt targets adversary activity linked to the ClearFake malware by correlating network and endpoint telemetry against a specific set of 18 known Indicators of Compromise (IOCs). Proactively hunting for these signatures in Azure Sentinel is critical to identify early-stage infections or lateral movement attempts before they escalate into widespread data exfiltration events.

IOC Summary

Malware Family: ClearFake Total IOCs: 18 IOC Types: domain

TypeValueThreat TypeFirst SeenConfidence
domainadsbln3.xyzpayload_delivery2026-07-16100%
domaineastbwxa.funxbet.casinopayload_delivery2026-07-16100%
domainj112srgz.bahigo90bet.compayload_delivery2026-07-16100%
domainftcfotjnd.adsbln2.xyzpayload_delivery2026-07-16100%
domainadsbln2.xyzpayload_delivery2026-07-16100%
domainrzecbgjw.enfejartime.compayload_delivery2026-07-16100%
domainiygfxiad.efcasino.betpayload_delivery2026-07-16100%
domainzwydarcig.adsbln1.xyzpayload_delivery2026-07-16100%
domaincdmke7zf.sky7bet.casinopayload_delivery2026-07-16100%
domainx78boe03.lion1bet.compayload_delivery2026-07-16100%
domaincfplyjmq.efcasino.betpayload_delivery2026-07-16100%
domainjii17zh7.yekbetyek.compayload_delivery2026-07-16100%
domainisbbetvcj.adsbln1.xyzpayload_delivery2026-07-16100%
domainmzzetrvqf.jadoou.spacepayload_delivery2026-07-16100%
domainxhbmcyyao.adsbln1.xyzpayload_delivery2026-07-16100%
domainadsbln1.xyzpayload_delivery2026-07-16100%
domaintufxszft.efcasino.betpayload_delivery2026-07-16100%
domainmukmnvwls[.]101motorsports.netpayload_delivery2026-07-16100%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["adsbln3.xyz", "eastbwxa.funxbet.casino", "j112srgz.bahigo90bet.com", "ftcfotjnd.adsbln2.xyz", "adsbln2.xyz", "rzecbgjw.enfejartime.com", "iygfxiad.efcasino.bet", "zwydarcig.adsbln1.xyz", "cdmke7zf.sky7bet.casino", "x78boe03.lion1bet.com", "cfplyjmq.efcasino.bet", "jii17zh7.yekbetyek.com", "isbbetvcj.adsbln1.xyz", "mzzetrvqf.jadoou.space", "xhbmcyyao.adsbln1.xyz", "adsbln1.xyz", "tufxszft.efcasino.bet", "mukmnvwls.101motorsports.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 5 specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:

Original source: https://threatfox.abuse.ch/browse/malware/js.clearfake/