This hunt targets adversary behavior involving initial access or command and control via ClearFake phishing campaigns that leverage a specific set of 19 known malicious URLs. Proactively hunting for these indicators in Azure Sentinel is critical to detect early-stage compromise attempts before they escalate into broader lateral movement or data exfiltration incidents.
Threat: ClearFake Total URLs: 19 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://zxx1gpmw.pars90.download/?ublib=064f99d4-76a2-4eea-9e0e-56421ee3d280 | offline | malware_download | 2026-07-13 |
hxxps://ovcvaphj.jadoou.cfd/1db42ea1-b1e4-4362-a6a2-401372c0a395 | offline | malware_download | 2026-07-13 |
hxxps://zxco.madgal.life/616c555d-6508-42f9-a266-2ba19cdef127 | offline | malware_download | 2026-07-13 |
hxxps://5ufm19dl.pdfbama.com/?ublib=f0a96d5f-e04e-4681-a5c9-ba9d89fd9085 | offline | malware_download | 2026-07-13 |
hxxps://qcancmnq.jadoou.store/4d64f004-5d6b-4488-aebe-70eb2a743f52 | offline | malware_download | 2026-07-13 |
hxxps://vfld.jadoou.my/57f4b136-b251-4f84-9cde-a704fd972d86 | offline | malware_download | 2026-07-13 |
hxxps://zjyozhki.jadoou.space/47db3ff9-a24b-4fcc-8a59-e2aff502acaf | offline | malware_download | 2026-07-13 |
hxxps://gcyp.jadoou.monster/063f81aa-2266-4040-a7e0-a4272a0022cc | offline | malware_download | 2026-07-13 |
hxxps://cacbvgql.jadoou.skin/11ef4ad0-d374-4c42-b3de-78edbed055bb | offline | malware_download | 2026-07-13 |
hxxps://fahv2h6l.kimimaro-trance.com/?ublib=c8d50516-54c8-4b87-a3b1-0428854f1042 | offline | malware_download | 2026-07-13 |
hxxps://tkhf.jadoou.mom/60a3f216-d234-4ead-9e65-8daadeb9cd58 | offline | malware_download | 2026-07-13 |
hxxps://frqljktr.jadoou.site/b8a7601f-d076-4287-b05f-0d4b7b21e27e | offline | malware_download | 2026-07-13 |
hxxps://byagqv8a.fileboroo.com/?ublib=24901cc9-f3c6-4c2f-8e81-2458d20e816d | offline | malware_download | 2026-07-13 |
hxxps://mlbn.jadoou.makeup/d9a04cde-d015-470b-a51f-75ab154a1462 | offline | malware_download | 2026-07-13 |
hxxps://sth4xz5f.pacificcrestforaging.com/?ublib=24006556-f831-4f6e-ac02-922fcafa7d3f | offline | malware_download | 2026-07-13 |
hxxps://knihrdel.jadoou.shop/1f9c07a6-6ceb-4e3b-a4c9-70e2cb0bfa38 | offline | malware_download | 2026-07-13 |
hxxps://xc1y2oam.jetbet.download/?ublib=2a0a4211-ae80-4d54-a77e-c5e04e044848 | offline | malware_download | 2026-07-13 |
hxxps://ahkx.jadoou.lol/5c479e97-397b-4074-a7e4-d80c37dd6be7 | offline | malware_download | 2026-07-13 |
hxxps://pqxhifiu.jadoou.sbs/3f80625e-0815-4bcf-aad9-fe261f52fc51 | offline | malware_download | 2026-07-13 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["xc1y2oam.jetbet.download", "5ufm19dl.pdfbama.com", "cacbvgql.jadoou.skin", "byagqv8a.fileboroo.com", "frqljktr.jadoou.site", "tkhf.jadoou.mom", "fahv2h6l.kimimaro-trance.com", "gcyp.jadoou.monster", "zxx1gpmw.pars90.download", "ovcvaphj.jadoou.cfd", "knihrdel.jadoou.shop", "sth4xz5f.pacificcrestforaging.com", "ahkx.jadoou.lol", "zxco.madgal.life", "mlbn.jadoou.makeup", "vfld.jadoou.my", "qcancmnq.jadoou.store", "zjyozhki.jadoou.space", "pqxhifiu.jadoou.sbs"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["xc1y2oam.jetbet.download", "5ufm19dl.pdfbama.com", "cacbvgql.jadoou.skin", "byagqv8a.fileboroo.com", "frqljktr.jadoou.site", "tkhf.jadoou.mom", "fahv2h6l.kimimaro-trance.com", "gcyp.jadoou.monster", "zxx1gpmw.pars90.download", "ovcvaphj.jadoou.cfd", "knihrdel.jadoou.shop", "sth4xz5f.pacificcrestforaging.com", "ahkx.jadoou.lol", "zxco.madgal.life", "mlbn.jadoou.makeup", "vfld.jadoou.my", "qcancmnq.jadoou.store", "zjyozhki.jadoou.space", "pqxhifiu.jadoou.sbs"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule in an enterprise environment, along with suggested filters or exclusions:
Legacy Patch Management Scans
svc-patch-agent) and exclude destination IPs belonging to major vendor update domains (e.g., *.update.microsoft.com, *.adobe.com) from triggering this rule during scheduled maintenance windows (02:00–04:00 UTC).Cloud Identity Federation Redirects
login.microsoftonline.com or sso.okta.com) that utilize dynamic path parameters. URLhaus may misidentify these legitimate, high-traffic federation endpoints as ClearFake due to their complex query strings and shared IP ranges with active threat campaigns./oauth2, /saml, /login) when the user agent matches enterprise browsers (Chrome Enterprise, Edge) rather than generic scripts.Automated Compliance Reporting Jobs