This hunt targets adversary behavior where threat actors leverage ClearFake-tagged malicious URLs to deliver phishing payloads or drive-by downloads that compromise user endpoints within the Azure environment. Proactively hunting for these specific indicators in Azure Sentinel is critical because early detection of this known malware family allows the SOC team to isolate affected assets and block command-and-control communications before lateral movement occurs.
Threat: ClearFake Total URLs: 14 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://cdn.jsdelivr.net/gh/roadvillnet/doh-dot-edge-ns@8550fa1/cluste | offline | malware_download | 2026-06-30 |
hxxps://zi6uvzi9.btyek.beauty/?ublib=31d873f0-7010-4688-834b-f92e0ed39993 | offline | malware_download | 2026-06-30 |
hxxps://0oj9pa7x.1xbetlogin.co/?ublib=7c4ce8f7-5081-4730-a783-030262ed3a24 | offline | malware_download | 2026-06-30 |
hxxps://c28vzpro.bet808.app/?ublib=8062c589-4b7a-4c85-8c87-689b40d563f0 | offline | malware_download | 2026-06-30 |
hxxps://cess.digishart.news/b1ad7276-9078-4de0-9bf4-896dfffa2264 | offline | malware_download | 2026-06-30 |
hxxps://cdn.jsdelivr.net/gh/Roody2643/pipeline-runner@d29c24b/com | offline | malware_download | 2026-06-30 |
hxxps://vxg18bmc.btyek.baby/?ublib=09437f79-6180-46d7-9f17-a55540c48989 | offline | malware_download | 2026-06-30 |
hxxps://fpqatzfu.btyek.autos/?ublib=9482a6f9-eb87-4122-a0b8-0b114fcaf4f1 | offline | malware_download | 2026-06-30 |
hxxps://1ozso11s.blackjackonlineplay83.com/?ublib=1d952190-a9a4-4f7f-9ca2-9622167aad6a | offline | malware_download | 2026-06-30 |
hxxps://35iozqs1.bet1bonus.com/?ublib=bba1610e-9190-468e-87d6-db8679e1c0af | offline | malware_download | 2026-06-30 |
hxxps://j1yidzep.boombasket.bet/?ublib=c68069ac-e965-4a12-b582-7a865b656c6a | offline | malware_download | 2026-06-30 |
hxxps://cdn.jsdelivr.net/gh/Roody2643/enterprise-identity-gateway@cbf22ee/protected | offline | malware_download | 2026-06-30 |
hxxps://lancer.shartboro.xyz/f599839a-06d8-4cd1-a1f9-e53d806052af | offline | malware_download | 2026-06-30 |
hxxps://wt51peii.boomball.bet/?ublib=cbdb21c8-e4d7-4519-b396-ae3ae8a8b34e | offline | malware_download | 2026-06-30 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["lancer.shartboro.xyz", "j1yidzep.boombasket.bet", "zi6uvzi9.btyek.beauty", "vxg18bmc.btyek.baby", "35iozqs1.bet1bonus.com", "0oj9pa7x.1xbetlogin.co", "cess.digishart.news", "wt51peii.boomball.bet", "1ozso11s.blackjackonlineplay83.com", "cdn.jsdelivr.net", "fpqatzfu.btyek.autos", "c28vzpro.bet808.app"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["lancer.shartboro.xyz", "j1yidzep.boombasket.bet", "zi6uvzi9.btyek.beauty", "vxg18bmc.btyek.baby", "35iozqs1.bet1bonus.com", "0oj9pa7x.1xbetlogin.co", "cess.digishart.news", "wt51peii.boomball.bet", "1ozso11s.blackjackonlineplay83.com", "cdn.jsdelivr.net", "fpqatzfu.btyek.autos", "c28vzpro.bet808.app"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule in an enterprise environment, along with suggested filters and exclusions:
Automated Software Update Checks by Patch Management Tools
Hostnames containing 'SCCM-Update' or IP Ranges of Patch Servers) and filter for specific HTTP status codes (200 OK) where the User-Agent string matches known patch management tools.Scheduled Compliance Scans by Security Information Systems
02:00 - 04:00 UTC) for specific Destination URLs associated with trusted vendor domains, or exclude traffic originating from the Service Account used by these scanning agents.Cloud Identity and Access Management (IAM) Token Refreshes