← Back to SOC feed Coverage →

URLhaus: ClearFake Malicious URLs

ioc-hunt HIGH URLhaus
CommonSecurityLogDnsEvents
iocurlhaus
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at URLhaus →
Retrieved: 2026-07-15T11:00:00Z · Confidence: medium

Hunt Hypothesis

This hunt targets adversary behavior where attackers leverage ClearFake-tagged malicious URLs to deliver phishing payloads or command-and-control traffic that may evade standard signature-based defenses. Proactively hunting for these specific indicators in Azure Sentinel is critical because it enables the SOC team to identify early-stage compromise attempts and block high-fidelity threats before they propagate across the organization’s network.

IOC Summary

Threat: ClearFake Total URLs: 24 Active URLs: 0

URLStatusThreatDate Added
hxxps://nxyhlvha.fileboroo.com/offlinemalware_download2026-07-15
hxxps://pcipjcar.fileboroo.com/offlinemalware_download2026-07-15
hxxps://i6s46ndy.site-takhtenard-sharti-betland.com/?ublib=5a752451-e0a9-4b9c-b910-d8502e29bb72offlinemalware_download2026-07-15
hxxps://litwpjrq.casinomhub.bet/offlinemalware_download2026-07-15
hxxps://mgnj.behtarin-site-shartbandi-football.com/offlinemalware_download2026-07-15
hxxps://j1xayyip.bordbett10.com/?ublib=3094be8c-ed41-4bd6-a4c3-05505d7eafd9offlinemalware_download2026-07-15
hxxps://frqbuzgo.bingobet.bingo/offlinemalware_download2026-07-15
hxxps://mpygi.jadoou.space/offlinemalware_download2026-07-15
hxxps://ycrarqcd.bingobet.bingo/offlinemalware_download2026-07-15
hxxps://078zq932.betyek.bio/?ublib=824a9ab2-0433-44f5-b514-ea52ff0c725aofflinemalware_download2026-07-15
hxxps://0rlxki7g.bordbett10.com/?ublib=6577db6d-a247-4385-a5b4-571e6630c79eofflinemalware_download2026-07-15
hxxps://vjs8k4dd.betyek.bio/?ublib=0b07568c-0ae1-4d6d-8f0e-6c04db7b4e22offlinemalware_download2026-07-15
hxxps://brmzm.jadoou.space/d1a18065-4220-4288-9ef4-9d203819a90fofflinemalware_download2026-07-15
hxxps://cgzt.behtarin-site-shartbandi-football.com/0e888cff-0881-48cf-8970-eacb0f78c572offlinemalware_download2026-07-15
hxxps://krdqfpte.bingobet.bingo/b6baa5eb-3eb7-4b19-bbdf-c78d3dbd0218offlinemalware_download2026-07-15
hxxps://nkqj.behtarin-site-shartbandi-football.com/56455686-a6fc-454f-bbb1-109ce77de960offlinemalware_download2026-07-15
hxxps://zxpimegb.bingobet.bingo/a5abf05c-0a9e-496d-bbf2-85959ed38cb5offlinemalware_download2026-07-15
hxxps://xnshgwgf.bingobet.bingo/5b7a85e7-8610-4074-84a2-d4a225ee00f8offlinemalware_download2026-07-15
hxxps://jw27s0al.site-takhtenard-sharti-betland.com/?ublib=af4dca3e-5adf-4abe-b28a-354aefc7078bofflinemalware_download2026-07-15
hxxps://hcnmjrat.bingobet.bingo/f08720b0-82af-4e74-99c0-1940e8258ec4offlinemalware_download2026-07-15
hxxps://izehzccr.bet90forward.win/c390c01d-1161-4fb0-915e-6bf160003071offlinemalware_download2026-07-15
hxxps://mhyp.bahigo90bet.com/82f7f408-5c5a-4908-ac83-04e3948263b5offlinemalware_download2026-07-15
hxxps://wxxlppea.onjabet1.com/9060edc9-cce1-4910-a259-6552f4b3e19fofflinemalware_download2026-07-15
hxxps://pnsc.radioshartbandi.bet/bf5c32fe-8d24-4588-8525-a0c882a3bba2offlinemalware_download2026-07-15

KQL: Url Dns Hunt

// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["jw27s0al.site-takhtenard-sharti-betland.com", "0rlxki7g.bordbett10.com", "078zq932.betyek.bio", "i6s46ndy.site-takhtenard-sharti-betland.com", "mgnj.behtarin-site-shartbandi-football.com", "krdqfpte.bingobet.bingo", "vjs8k4dd.betyek.bio", "wxxlppea.onjabet1.com", "nkqj.behtarin-site-shartbandi-football.com", "mpygi.jadoou.space", "litwpjrq.casinomhub.bet", "frqbuzgo.bingobet.bingo", "hcnmjrat.bingobet.bingo", "pcipjcar.fileboroo.com", "zxpimegb.bingobet.bingo", "ycrarqcd.bingobet.bingo", "brmzm.jadoou.space", "nxyhlvha.fileboroo.com", "mhyp.bahigo90bet.com", "pnsc.radioshartbandi.bet", "xnshgwgf.bingobet.bingo", "cgzt.behtarin-site-shartbandi-football.com", "j1xayyip.bordbett10.com", "izehzccr.bet90forward.win"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc

KQL: Url Proxy Hunt

// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["jw27s0al.site-takhtenard-sharti-betland.com", "0rlxki7g.bordbett10.com", "078zq932.betyek.bio", "i6s46ndy.site-takhtenard-sharti-betland.com", "mgnj.behtarin-site-shartbandi-football.com", "krdqfpte.bingobet.bingo", "vjs8k4dd.betyek.bio", "wxxlppea.onjabet1.com", "nkqj.behtarin-site-shartbandi-football.com", "mpygi.jadoou.space", "litwpjrq.casinomhub.bet", "frqbuzgo.bingobet.bingo", "hcnmjrat.bingobet.bingo", "pcipjcar.fileboroo.com", "zxpimegb.bingobet.bingo", "ycrarqcd.bingobet.bingo", "brmzm.jadoou.space", "nxyhlvha.fileboroo.com", "mhyp.bahigo90bet.com", "pnsc.radioshartbandi.bet", "xnshgwgf.bingobet.bingo", "cgzt.behtarin-site-shartbandi-football.com", "j1xayyip.bordbett10.com", "izehzccr.bet90forward.win"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 5 specific false positive scenarios for the URLhaus: ClearFake Malicious URLs rule in an enterprise environment, along with suggested filters or exclusions:

Original source: https://urlhaus.abuse.ch/