← Back to SOC feed Coverage →

URLhaus: ClearFake Malicious URLs

ioc-hunt HIGH URLhaus
CommonSecurityLogDnsEvents
iocurlhaus
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at URLhaus →
Retrieved: 2026-07-17T11:00:00Z · Confidence: medium

Hunt Hypothesis

This hunt targets adversary behavior where attackers leverage ClearFake-tagged malicious URLs to deliver phishing payloads or command-and-control traffic that may bypass standard allow-lists due to their recent registration or reputation status. Proactively hunting for these specific indicators in Azure Sentinel is critical because the high severity of ClearFake threats suggests a sophisticated campaign capable of evading initial perimeter defenses, requiring immediate investigation to prevent lateral movement and data exfiltration.

IOC Summary

Threat: ClearFake Total URLs: 15 Active URLs: 0

URLStatusThreatDate Added
hxxps://wtkxprzu.funxbet.casino/16ea8481-3c31-4731-94a3-6cd4deb7745bofflinemalware_download2026-07-17
hxxps://hzdmfcatc.sky7bet.casino/a4c342e5-03b8-4ed5-96c8-2442dae29d40offlinemalware_download2026-07-17
hxxps://vzsagfrw.derbi.football/a02b928d-c48d-4e91-a56e-b2f83f3a22a2offlinemalware_download2026-07-17
hxxps://dvc734k1.hazaratbet.game/?ublib=72cb809a-c116-4cc8-986e-8a84d448199aofflinemalware_download2026-07-17
hxxps://3x6v81kc.varzeshlife.ir/?ublib=9b8815ae-acf4-431e-a447-43d509809dc9offlinemalware_download2026-07-17
hxxps://lhozmsokb.nextbahis.coupons/e8c2bba0-5bd1-43e4-93be-564b396e1fd1offlinemalware_download2026-07-17
hxxps://eogwp3fe.site-shartbandi-pasor.online/?ublib=bcad3ea3-4741-4fee-ac5c-0afe561e6974offlinemalware_download2026-07-17
hxxps://pygnidup.gem90bet.com/f7acb2d0-d33a-4993-90b2-f65f68273383offlinemalware_download2026-07-17
hxxps://dsdvsvqgy.jetbet.download/3132a032-1ae9-46a0-8ace-28746947f5e8offlinemalware_download2026-07-17
hxxps://dlylkjaji.jetboro.fun/510aa0a0-d2cb-44e8-9f88-ff17a8893c33offlinemalware_download2026-07-17
hxxps://bgtnaqoc.fileboroo.com/8d0ecdf8-756a-421f-ba9b-d9bb001ac817offlinemalware_download2026-07-17
hxxps://aefauhqwk.irani-music.com/52d561b5-b166-4aca-a561-96ee624363fcofflinemalware_download2026-07-17
hxxps://iodz0i3f.behtarin-site-shartbandi-football.com/?ublib=e866450f-8093-4490-baff-a1bd8c740acbofflinemalware_download2026-07-17
hxxps://arvujwijm.irani-music.com/a892a6a3-4cfe-4227-bf44-35269c9f0eeeofflinemalware_download2026-07-17
hxxps://itwynsuh.enfejartime.com/ad836539-a545-496d-a687-fa356ae76372offlinemalware_download2026-07-17

KQL: Url Dns Hunt

// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["pygnidup.gem90bet.com", "bgtnaqoc.fileboroo.com", "lhozmsokb.nextbahis.coupons", "dsdvsvqgy.jetbet.download", "dlylkjaji.jetboro.fun", "3x6v81kc.varzeshlife.ir", "itwynsuh.enfejartime.com", "aefauhqwk.irani-music.com", "vzsagfrw.derbi.football", "wtkxprzu.funxbet.casino", "dvc734k1.hazaratbet.game", "hzdmfcatc.sky7bet.casino", "eogwp3fe.site-shartbandi-pasor.online", "arvujwijm.irani-music.com", "iodz0i3f.behtarin-site-shartbandi-football.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc

KQL: Url Proxy Hunt

// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["pygnidup.gem90bet.com", "bgtnaqoc.fileboroo.com", "lhozmsokb.nextbahis.coupons", "dsdvsvqgy.jetbet.download", "dlylkjaji.jetboro.fun", "3x6v81kc.varzeshlife.ir", "itwynsuh.enfejartime.com", "aefauhqwk.irani-music.com", "vzsagfrw.derbi.football", "wtkxprzu.funxbet.casino", "dvc734k1.hazaratbet.game", "hzdmfcatc.sky7bet.casino", "eogwp3fe.site-shartbandi-pasor.online", "arvujwijm.irani-music.com", "iodz0i3f.behtarin-site-shartbandi-football.com"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 4 specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule, tailored for a legitimate enterprise environment:

Original source: https://urlhaus.abuse.ch/