This hunt targets adversary behavior where attackers leverage ClearFake-tagged malicious URLs to deliver targeted payloads or conduct phishing campaigns against user endpoints. Proactively hunting for these specific indicators within Azure Sentinel is critical to rapidly identify and isolate compromised assets before they can establish persistence or exfiltrate sensitive data.
Threat: ClearFake Total URLs: 13 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://txwd.borrender.com/5c1b4fb5-8786-4c71-ba6c-9144253c5d95 | offline | malware_download | 2026-07-19 |
hxxps://znnop.frisbeeburgerllc.com/95671f7c-f2f5-42fa-b18b-04611bec7913 | offline | malware_download | 2026-07-19 |
hxxps://gwcs.bolesfarms.com/d0376c85-7693-477c-90a0-f5aa8ba10847 | offline | malware_download | 2026-07-19 |
hxxps://g5sy0m2g.calirayalake.com/?ublib=fd83772a-43fa-4861-8355-a259be9721a9 | offline | malware_download | 2026-07-19 |
hxxps://ystr.bittersweetkennel.com/58f140ad-e33d-4f57-a949-540bf2c98aae | offline | malware_download | 2026-07-19 |
hxxps://zuibs.jetbet.download/b9bfd8cd-e410-48f8-a457-fa272d2aa9f3 | offline | malware_download | 2026-07-19 |
hxxps://bzeg.bikertlane.com/34a038b6-b6ed-454b-817e-22730ead4dbc | offline | malware_download | 2026-07-19 |
hxxps://m4jpiubh.royaldoorsspringdale.com/?ublib=85b3fe11-4a50-432f-8b23-ac138e4f85e4 | offline | malware_download | 2026-07-19 |
hxxps://4yl6u62i.pdfbama.com/?ublib=fd9f4cee-541f-49bf-8dc2-b8a07559cc06 | offline | malware_download | 2026-07-19 |
hxxps://otcgf.christorem.com/dbb18cc6-cebb-446b-8ce8-3f7ba6e70600 | offline | malware_download | 2026-07-19 |
hxxps://dlvk.nextbahis.one/ad2e4456-58e2-49b0-844a-b6ffccd6b59a | offline | malware_download | 2026-07-19 |
hxxps://ht326ul6.hazaratbet.bet/?ublib=ebf13cc2-cdc0-4ecf-90fb-36448cb22623 | offline | malware_download | 2026-07-19 |
hxxps://lqcah.cheaperthan-dirt.com/23be72bc-0ade-4140-8f87-a3bc07414e4e | offline | malware_download | 2026-07-19 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["g5sy0m2g.calirayalake.com", "ht326ul6.hazaratbet.bet", "lqcah.cheaperthan-dirt.com", "txwd.borrender.com", "gwcs.bolesfarms.com", "bzeg.bikertlane.com", "4yl6u62i.pdfbama.com", "otcgf.christorem.com", "m4jpiubh.royaldoorsspringdale.com", "znnop.frisbeeburgerllc.com", "zuibs.jetbet.download", "ystr.bittersweetkennel.com", "dlvk.nextbahis.one"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["g5sy0m2g.calirayalake.com", "ht326ul6.hazaratbet.bet", "lqcah.cheaperthan-dirt.com", "txwd.borrender.com", "gwcs.bolesfarms.com", "bzeg.bikertlane.com", "4yl6u62i.pdfbama.com", "otcgf.christorem.com", "m4jpiubh.royaldoorsspringdale.com", "znnop.frisbeeburgerllc.com", "zuibs.jetbet.download", "ystr.bittersweetkennel.com", "dlvk.nextbahis.one"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule, tailored for an enterprise environment:
Endpoint Management Patching Cycles
*.ccm.microsoft.com, *.ivanti.net) where the destination port is 443 and the user agent matches the enterprise patching tool signature.Third-Party SaaS Integration Webhooks
api.partner.com/v2/sync) and restrict the rule to only flag traffic where the HTTP method is not GET or where the response code is not 200 OK.Digital Rights Management (DRM) License Validation