This hunt detects adversary activity involving the specific Indicators of Compromise (IOCs) linked to the ClearFake campaign, which is known for targeting financial and enterprise sectors through sophisticated phishing and malware delivery. Proactively hunting for these 72 IOCs in Azure Sentinel allows the SOC team to identify early-stage infections or lateral movement attempts before they escalate into significant data breaches or operational disruptions.
Malware Family: ClearFake Total IOCs: 72 IOC Types: sha256_hash, domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | jtgj.interventionalpainmanagement.net | payload_delivery | 2026-07-24 | 100% |
| domain | getamericanglass.com | botnet_cc | 2026-07-24 | 90% |
| domain | interventionalpainmanagement.net | payload_delivery | 2026-07-24 | 100% |
| domain | bcmsc.deckico.bet | botnet_cc | 2026-07-24 | 90% |
| domain | cfuuzz.deckico.bet | botnet_cc | 2026-07-24 | 90% |
| domain | gentletouchchiropracticclinicauroracol.com | botnet_cc | 2026-07-24 | 90% |
| domain | 79ccfm8.deckico.bet | botnet_cc | 2026-07-24 | 90% |
| domain | ifnj.intellectualgroupie.com | payload_delivery | 2026-07-24 | 100% |
| domain | intellectualgroupie.com | payload_delivery | 2026-07-24 | 100% |
| domain | stabimodule.deckico.bet | botnet_cc | 2026-07-24 | 90% |
| domain | geigersjobs.com | botnet_cc | 2026-07-24 | 90% |
| domain | uocqxlqf.sendrat.bet | botnet_cc | 2026-07-24 | 90% |
| domain | pijw.inspirationflorida.com | payload_delivery | 2026-07-24 | 100% |
| domain | inspirationflorida.com | payload_delivery | 2026-07-24 | 100% |
| domain | cinemacast.sendrat.bet | botnet_cc | 2026-07-24 | 90% |
| domain | dyn-lithum.th0rniva.garden | botnet_cc | 2026-07-24 | 90% |
| domain | infinity-spc.com | botnet_cc | 2026-07-24 | 90% |
| domain | gabriellekwilson.com | botnet_cc | 2026-07-24 | 90% |
| domain | vitalamb.reptbot.bet | botnet_cc | 2026-07-24 | 90% |
| domain | 4tom-pulse.reptbot.bet | botnet_cc | 2026-07-24 | 90% |
| domain | chammaautosales.com | botnet_cc | 2026-07-24 | 90% |
| domain | upkx.infinityjoespizzaclearwater.com | payload_delivery | 2026-07-24 | 100% |
| domain | gigaping.online | botnet_cc | 2026-07-24 | 75% |
| domain | xcot.id-kkslot777.com | payload_delivery | 2026-07-24 | 100% |
| domain | gypd.id-kkslot777.com | payload_delivery | 2026-07-24 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["jtgj.interventionalpainmanagement.net", "getamericanglass.com", "interventionalpainmanagement.net", "bcmsc.deckico.bet", "cfuuzz.deckico.bet", "gentletouchchiropracticclinicauroracol.com", "79ccfm8.deckico.bet", "ifnj.intellectualgroupie.com", "intellectualgroupie.com", "stabimodule.deckico.bet", "geigersjobs.com", "uocqxlqf.sendrat.bet", "pijw.inspirationflorida.com", "inspirationflorida.com", "cinemacast.sendrat.bet", "dyn-lithum.th0rniva.garden", "infinity-spc.com", "gabriellekwilson.com", "vitalamb.reptbot.bet", "4tom-pulse.reptbot.bet", "chammaautosales.com", "upkx.infinityjoespizzaclearwater.com", "gigaping.online", "xcot.id-kkslot777.com", "gypd.id-kkslot777.com", "id-kkslot777.com", "tkwt.doubledavespizzatx.com", "doubledavespizzatx.com", "farmacia-bienestar.com", "cdcila.net", "shzc.fourseasonsmansion.com", "fourseasonsmansion.com", "42nmto8h.thebrandus.com", "ardi.fourseasondumpling.com", "fourseasondumpling.com", "ybqher3f.btcbullcoin.org", "hucx.fortworthfarm.com", "fortworthfarm.com", "backupper.info", "sdanc.trave1.bet", "eugen-x.com", "cedarember.lunave5.bet", "yjpo.footstepsdaycare.com", "dynflux4or.lunave5.bet", "footstepsdaycare.com", "portcho.lunave5.bet", "levyvo.lunave5.bet", "eritreancenter.org", "glacie-palet.oppo5it.bet", "umpt.focus-logistics.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for files matching known malicious hashes
// Source: ThreatFox - ClearFake
let malicious_hashes = dynamic(["217aa6561129b2ca5958da9dde6223908ddbfc978b2b92946cda9e2e35998931", "ca5daa545c6b467afe5d17602cddce924e56e2b90ecc56ccee4be17d2cc07125", "833f110b8ec1d51b1d56795bc9049d4cda5b1447a546209856cac9355612abb4"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Scenario: Scheduled Antivirus Definition Updates
MsMpEng.exe (for Defender) or Symantec Antivirus Service, combined with an exclusion for traffic originating from known vendor update servers (e.g., *.update.microsoft.com or specific Symantec CDN IPs).Scenario: Managed Backup and Archiving Jobs
VeeamAgent.exe or CommServe.exe. Alternatively, exclude the specific destination IP ranges used by the organization’s primary cloud storage provider.Scenario: Third-Party SaaS Integration Services