← Back to SOC feed Coverage →

URLhaus: ClearFake Malicious URLs

ioc-hunt HIGH URLhaus
CommonSecurityLogDnsEvents
iocurlhaus
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at URLhaus →
Retrieved: 2026-07-01T23:00:00Z · Confidence: medium

Hunt Hypothesis

This hunt targets adversary behavior where attackers leverage ClearFake-malicious URLs to deliver phishing payloads or command-and-control traffic that may evade standard signature-based defenses. Proactively hunting for these specific indicators within Azure Sentinel is critical because it enables the SOC team to identify early-stage compromise attempts and validate endpoint exposure before widespread infection occurs.

IOC Summary

Threat: ClearFake Total URLs: 12 Active URLs: 0

URLStatusThreatDate Added
hxxps://8pxyyjso.doobix.pro/?ublib=2a59e2df-fdea-4f99-844f-e4b4a244d394offlinemalware_download2026-07-01
hxxps://zthayuyp.1x303.casino/?ublib=b9b94899-24e9-44bb-aa25-a842760bd4a5offlinemalware_download2026-07-01
hxxps://i0gxyl9q.betaffiliate.marketing/?ublib=84186b88-51bf-4d6c-9eee-ad796fb31ecdofflinemalware_download2026-07-01
hxxps://phcbmap.vip1xbet.net/3ba097aa-2c3d-423f-b757-ac32580b80b2offlinemalware_download2026-07-01
hxxps://uamhqvjx.abresanishahri.store/10129262-2452-481f-bb8f-392907e90f17offlinemalware_download2026-07-01
hxxps://lwflkiar.betsoor.live/460da77f-1d92-4cf2-b5d3-fe7fcca31370offlinemalware_download2026-07-01
hxxps://jpopdwg.vip1xbet.net/887e4755-f7b8-4f69-9917-73976e7e3ea5offlinemalware_download2026-07-01
hxxps://7ipg23zj.bet808.poker/?ublib=76959cda-9e5e-497a-9f75-e1b8f95ded46offlinemalware_download2026-07-01
hxxps://69x4o4j5.bet808.casino/?ublib=56156c61-4a81-460f-8ef6-b2a8da140228offlinemalware_download2026-07-01
hxxps://xwnfpj7t.betrein.pro/?ublib=b3d51f5c-b226-4a07-b9a6-43a851fd6025offlinemalware_download2026-07-01
hxxps://esjvtzn6.aloo.bet/?ublib=a571ff30-9c75-45c3-a2d3-babc9f0d9c52offlinemalware_download2026-07-01
hxxps://91vkuxv1.enf90.net/?ublib=79226b16-10a2-475f-84d9-cb02e3f4a875offlinemalware_download2026-07-01

KQL: Url Dns Hunt

// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["uamhqvjx.abresanishahri.store", "esjvtzn6.aloo.bet", "91vkuxv1.enf90.net", "lwflkiar.betsoor.live", "69x4o4j5.bet808.casino", "xwnfpj7t.betrein.pro", "7ipg23zj.bet808.poker", "zthayuyp.1x303.casino", "8pxyyjso.doobix.pro", "phcbmap.vip1xbet.net", "i0gxyl9q.betaffiliate.marketing", "jpopdwg.vip1xbet.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc

KQL: Url Proxy Hunt

// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["uamhqvjx.abresanishahri.store", "esjvtzn6.aloo.bet", "91vkuxv1.enf90.net", "lwflkiar.betsoor.live", "69x4o4j5.bet808.casino", "xwnfpj7t.betrein.pro", "7ipg23zj.bet808.poker", "zthayuyp.1x303.casino", "8pxyyjso.doobix.pro", "phcbmap.vip1xbet.net", "i0gxyl9q.betaffiliate.marketing", "jpopdwg.vip1xbet.net"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 4 specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule, including targeted filters and exclusions:

Original source: https://urlhaus.abuse.ch/