This hunt targets adversary behavior where threat actors leverage ClearFake-signed malicious URLs to deliver payloads that may bypass standard signature-based defenses due to their trusted appearance. Proactively hunting for these specific indicators in Azure Sentinel is critical because it enables the SOC team to identify and isolate compromised endpoints before they execute sophisticated supply chain or phishing attacks that exploit the credibility of valid certificates.
Threat: ClearFake Total URLs: 11 Active URLs: 0
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://frhphph.1xsomalia.com/f9d47e9f-1e00-48ba-870a-16342d35da74 | offline | malware_download | 2026-07-03 |
hxxps://oxqniwv.1xpin.vip/edcc3c22-d58e-4305-b72b-69493006207f | offline | malware_download | 2026-07-03 |
hxxps://qxguiws.1xpin.org/28b5e66a-f135-4665-b0ee-04dac7a9b654 | offline | malware_download | 2026-07-03 |
hxxps://w9x1nvom.sizzleasianfood.com/?ublib=c3d185d4-8bb1-4ee7-9118-3a5f3dc55199 | offline | malware_download | 2026-07-03 |
hxxps://jds4p0yc.betbacklink.com/?ublib=14de31c2-1df3-413d-8515-65ac9a31f290 | offline | malware_download | 2026-07-03 |
hxxps://dhur9q3h.1x303.casino/?ublib=00b08813-0c36-46f8-b24d-e0024332ea57 | offline | malware_download | 2026-07-03 |
hxxps://ao046xe5.1xbeet.xyz/?ublib=0550d70c-6683-4bf7-825d-d12f153c2d7e | offline | malware_download | 2026-07-03 |
hxxps://vlmtl3yv.jozvedownload.com/?ublib=fe77ff2e-5b89-43f9-876a-60bd8fa92a25 | offline | malware_download | 2026-07-03 |
hxxps://fnd9555t.ligabfa.com/?ublib=a5761cd7-be72-4803-b8d7-9bc0ec15b75b | offline | malware_download | 2026-07-03 |
hxxps://evhg599x.lemongrassasiangrill.com/?ublib=7310e1df-da6b-4277-934f-16f541d56837 | offline | malware_download | 2026-07-03 |
hxxps://adoswjr.calvaryhospice.org/42978f33-ddfe-49ee-a0dd-941c38341157 | offline | malware_download | 2026-07-03 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: ClearFake
let malicious_domains = dynamic(["w9x1nvom.sizzleasianfood.com", "oxqniwv.1xpin.vip", "vlmtl3yv.jozvedownload.com", "jds4p0yc.betbacklink.com", "qxguiws.1xpin.org", "dhur9q3h.1x303.casino", "fnd9555t.ligabfa.com", "adoswjr.calvaryhospice.org", "ao046xe5.1xbeet.xyz", "evhg599x.lemongrassasiangrill.com", "frhphph.1xsomalia.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["w9x1nvom.sizzleasianfood.com", "oxqniwv.1xpin.vip", "vlmtl3yv.jozvedownload.com", "jds4p0yc.betbacklink.com", "qxguiws.1xpin.org", "dhur9q3h.1x303.casino", "fnd9555t.ligabfa.com", "adoswjr.calvaryhospice.org", "ao046xe5.1xbeet.xyz", "evhg599x.lemongrassasiangrill.com", "frhphph.1xsomalia.com"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: ClearFake Malicious URLs detection rule in an enterprise environment, along with suggested filters or exclusions:
Scheduled Software Update Scans by Endpoint Protection Agents
Source_Host_Group = "EP_Agents" AND Process_Name = "CrowdStrikeService").Automated Vulnerability Assessment Scans
Source_IP_Range = "10.20.50.0/24" AND Destination_Port = 443).IT Admin Manual Threat Intelligence Research