The ThreatFox: ClearFake IOCs rule detects potential adversary activity linked to the ClearFake malware, which is associated with credential theft and lateral movement. SOC teams should proactively hunt for this behavior in Azure Sentinel to identify and mitigate early-stage attacks that could compromise sensitive data and network integrity.
IOC Summary
Malware Family: ClearFake Total IOCs: 25 IOC Types: domain, url
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | gorgbetkade.com | payload_delivery | 2026-06-17 | 100% |
| domain | h0cbv92p.golfbetkade.com | payload_delivery | 2026-06-17 | 100% |
| domain | golfbetkade.com | payload_delivery | 2026-06-17 | 100% |
| domain | h2vkq89b.angizeshfarahani.store | payload_delivery | 2026-06-17 | 100% |
| domain | fazbetkade.com | payload_delivery | 2026-06-17 | 100% |
| domain | enfejwin.com | payload_delivery | 2026-06-17 | 100% |
| domain | 1ycpksxw.hugugmadani6.xyz | payload_delivery | 2026-06-17 | 100% |
| domain | j7n7i2dx.enfej.win | payload_delivery | 2026-06-17 | 100% |
| url | hxxps://cdn.jsdelivr.net/gh/vitiapig/lang-28/robot | payload_delivery | 2026-06-17 | 100% |
| domain | zaminshenasi.shop | payload_delivery | 2026-06-17 | 100% |
| url | hxxps://cdn.jsdelivr.net/gh/vitiapig/api-bd7dff3f-84b7-4bbb-a8e1-7be98555d879/js | payload_delivery | 2026-06-17 | 100% |
| domain | 429jq7cf.ravanshenasi.xyz | payload_delivery | 2026-06-17 | 100% |
| domain | bvsfuyvu.leaguejazire.com | payload_delivery | 2026-06-17 | 100% |
| domain | ugygn.shartmag.bet | payload_delivery | 2026-06-17 | 100% |
| domain | uwso33yr.riyazinikokar.xyz | payload_delivery | 2026-06-17 | 100% |
| domain | cjbbdtba.maharatmodiran.xyz | payload_delivery | 2026-06-17 | 100% |
| domain | vprhcxyu.masirpayambari.xyz | payload_delivery | 2026-06-17 | 100% |
| domain | qgkzqew.azmoonzare.online | payload_delivery | 2026-06-17 | 100% |
| domain | zyiirlrr.tarikhravannovin.shop | payload_delivery | 2026-06-17 | 100% |
| domain | nc45aae1.tractor11.com | payload_delivery | 2026-06-17 | 100% |
| domain | ysulmnsc.sanjeshravani.shop | payload_delivery | 2026-06-17 | 100% |
| domain | jwouoops.sakhtemandade.shop | payload_delivery | 2026-06-17 | 100% |
| domain | hzvho.shartbandifootballkade.online | payload_delivery | 2026-06-17 | 100% |
| domain | pvxvwrfu.sadreislam.xyz | payload_delivery | 2026-06-17 | 100% |
| domain | bchvsotq.questionsmotor.xyz | payload_delivery | 2026-06-17 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["gorgbetkade.com", "h0cbv92p.golfbetkade.com", "golfbetkade.com", "h2vkq89b.angizeshfarahani.store", "fazbetkade.com", "enfejwin.com", "1ycpksxw.hugugmadani6.xyz", "j7n7i2dx.enfej.win", "zaminshenasi.shop", "429jq7cf.ravanshenasi.xyz", "bvsfuyvu.leaguejazire.com", "ugygn.shartmag.bet", "uwso33yr.riyazinikokar.xyz", "cjbbdtba.maharatmodiran.xyz", "vprhcxyu.masirpayambari.xyz", "qgkzqew.azmoonzare.online", "zyiirlrr.tarikhravannovin.shop", "nc45aae1.tractor11.com", "ysulmnsc.sanjeshravani.shop", "jwouoops.sakhtemandade.shop", "hzvho.shartbandifootballkade.online", "pvxvwrfu.sadreislam.xyz", "bchvsotq.questionsmotor.xyz"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - ClearFake
let malicious_urls = dynamic(["https://cdn.jsdelivr.net/gh/vitiapig/lang-28/robot", "https://cdn.jsdelivr.net/gh/vitiapig/api-bd7dff3f-84b7-4bbb-a8e1-7be98555d879/js"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Scenario: Legitimate system update using ClearFake as part of a security tool deployment
Filter/Exclusion: process.name != "ClearFake" or process.parent.name != "Windows Update"
Scenario: Scheduled job running ClearFake for malware analysis in a sandboxed environment
Filter/Exclusion: process.parent.name == "sandboxed_environment" or process.directory contains "sandbox"
Scenario: Admin task using ClearFake to analyze a suspicious file during incident response
Filter/Exclusion: process.user contains "admin_user" and process.command_line contains "analyze"
Scenario: ClearFake used as part of a legitimate threat intelligence tool for IOC collection
Filter/Exclusion: process.name == "ThreatIntelCollector" or process.command_line contains "collect_iocs"
Scenario: ClearFake being used in a penetration test environment to simulate IOC behavior
Filter/Exclusion: process.directory contains "pen_test_env" or process.parent.name == "Metasploit"