This hunt targets adversary behavior where attackers leverage ClearFake-malicious URLs to deliver phishing payloads or command-and-control traffic that may evade standard signature-based defenses. Proactively hunting for these specific indicators within Azure Sentinel is critical because it enables the SOC team to identify early-stage compromise attempts and validate endpoint exposure before widespread infection occurs.
Threat: ClearFake Total URLs: 12 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://8pxyyjso.doobix.pro/?ublib=2a59e2df-fdea-4f99-844f-e4b4a244d394 | offline | malware_download | 2026-07-01 |
hxxps://zthayuyp.1x303.casino/?ublib=b9b94899-24e9-44bb-aa25-a842760bd4a5 | offline | malware_download | 2026-07-01 |
hxxps://i0gxyl9q.betaffiliate.marketing/?ublib=84186b88-51bf-4d6c-9eee-ad796fb31ecd | offline | malware_download | 2026-07-01 |
hxxps://phcbmap.vip1xbet.net/3ba097aa-2c3d-423f-b757-ac32580b80b2 | offline | malware_download | 2026-07-01 |
hxxps://uamhqvjx.abresanishahri.store/10129262-2452-481f-bb8f-392907e90f17 | offline | malware_download | 2026-07-01 |
hxxps://lwflkiar.betsoor.live/460da77f-1d92-4cf2-b5d3-fe7fcca31370 | offline | malware_download | 2026-07-01 |
hxxps://jpopdwg.vip1xbet.net/887e4755-f7b8-4f69-9917-73976e7e3ea5 | offline | malware_download | 2026-07-01 |
hxxps://7ipg23zj.bet808.poker/?ublib=76959cda-9e5e-497a-9f75-e1b8f95ded46 | offline | malware_download | 2026-07-01 |
hxxps://69x4o4j5.bet808.casino/?ublib=56156c61-4a81-460f-8ef6-b2a8da140228 | offline | malware_download | 2026-07-01 |
hxxps://xwnfpj7t.betrein.pro/?ublib=b3d51f5c-b226-4a07-b9a6-43a851fd6025 | offline | malware_download | 2026-07-01 |
hxxps://esjvtzn6.aloo.bet/?ublib=a571ff30-9c75-45c3-a2d3-babc9f0d9c52 | offline | malware_download | 2026-07-01 |
hxxps://91vkuxv1.enf90.net/?ublib=79226b16-10a2-475f-84d9-cb02e3f4a875 | offline | malware_download | 2026-07-01 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["uamhqvjx.abresanishahri.store", "esjvtzn6.aloo.bet", "91vkuxv1.enf90.net", "lwflkiar.betsoor.live", "69x4o4j5.bet808.casino", "xwnfpj7t.betrein.pro", "7ipg23zj.bet808.poker", "zthayuyp.1x303.casino", "8pxyyjso.doobix.pro", "phcbmap.vip1xbet.net", "i0gxyl9q.betaffiliate.marketing", "jpopdwg.vip1xbet.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["uamhqvjx.abresanishahri.store", "esjvtzn6.aloo.bet", "91vkuxv1.enf90.net", "lwflkiar.betsoor.live", "69x4o4j5.bet808.casino", "xwnfpj7t.betrein.pro", "7ipg23zj.bet808.poker", "zthayuyp.1x303.casino", "8pxyyjso.doobix.pro", "phcbmap.vip1xbet.net", "i0gxyl9q.betaffiliate.marketing", "jpopdwg.vip1xbet.net"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule, including targeted filters and exclusions:
Automated Software Update Scans by Antivirus Agents
svc-antivirus-updater) and destination ports associated with update protocols (TCP 443) where the User-Agent string contains “CrowdStrike” or “Microsoft Defender”.Scheduled Backup Repository Verification
IT Admin Manual Remediation and Patch Testing