← Back to SOC feed Coverage →

ThreatFox: ClearFake IOCs

ioc-hunt HIGH ThreatFox
DnsEvents
iocjs-clearfakethreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-08-06T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt detects adversary activity linked to the ClearFake campaign by cross-referencing Azure Sentinel logs against a curated set of 101 specific Indicators of Compromise (IOCs). Proactively hunting for these IOCs is critical because it enables the SOC team to identify early-stage infections and lateral movement attempts before they escalate into significant data breaches.

IOC Summary

Malware Family: ClearFake Total IOCs: 101 IOC Types: domain

TypeValueThreat TypeFirst SeenConfidence
domainqxowqwa.theriveroaks1603.compayload_delivery2026-08-06100%
domaintheriveroaks1603.compayload_delivery2026-08-06100%
domainn7u8r9di.romeroautodetails.compayload_delivery2026-08-06100%
domainoqavsq.sunvalleysurf.compayload_delivery2026-08-06100%
domainsunvalleysurf.compayload_delivery2026-08-06100%
domainrgiisgy.thelovebugsband.compayload_delivery2026-08-06100%
domainthelovebugsband.compayload_delivery2026-08-06100%
domaincheeseloversmenu.compayload_delivery2026-08-0690%
domaincherokeeenterprise.netpayload_delivery2026-08-0690%
domainclqidi.sunluckchineserestaurant.compayload_delivery2026-08-06100%
domainsunluckchineserestaurant.compayload_delivery2026-08-06100%
domainxrafxsq.thefenceguysinc.compayload_delivery2026-08-06100%
domainthefenceguysinc.compayload_delivery2026-08-06100%
domainc6ta3e1a.remenacevintage.compayload_delivery2026-08-06100%
domainrtvzcs.sultan88.livepayload_delivery2026-08-06100%
domainsultan88.livepayload_delivery2026-08-06100%
domainngzhdgm.thecharcuteriebeach.compayload_delivery2026-08-06100%
domain022kgyq9.eachway-multiplier.compayload_delivery2026-08-06100%
domainthecharcuteriebeach.compayload_delivery2026-08-06100%
domainisqacg.streamsurge.sitepayload_delivery2026-08-06100%
domainstreamsurge.sitepayload_delivery2026-08-06100%
domainsribcag.starfishdancestudio.compayload_delivery2026-08-06100%
domainstarfishdancestudio.compayload_delivery2026-08-06100%
domainzyzdto.storia-riferimenti.orgpayload_delivery2026-08-06100%
domainwcsfgwq.springsconstruction.netpayload_delivery2026-08-06100%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["qxowqwa.theriveroaks1603.com", "theriveroaks1603.com", "n7u8r9di.romeroautodetails.com", "oqavsq.sunvalleysurf.com", "sunvalleysurf.com", "rgiisgy.thelovebugsband.com", "thelovebugsband.com", "cheeseloversmenu.com", "cherokeeenterprise.net", "clqidi.sunluckchineserestaurant.com", "sunluckchineserestaurant.com", "xrafxsq.thefenceguysinc.com", "thefenceguysinc.com", "c6ta3e1a.remenacevintage.com", "rtvzcs.sultan88.live", "sultan88.live", "ngzhdgm.thecharcuteriebeach.com", "022kgyq9.eachway-multiplier.com", "thecharcuteriebeach.com", "isqacg.streamsurge.site", "streamsurge.site", "sribcag.starfishdancestudio.com", "starfishdancestudio.com", "zyzdto.storia-riferimenti.org", "wcsfgwq.springsconstruction.net", "storia-riferimenti.org", "springsconstruction.net", "hxbvznvv.naolemedia.com", "sz3f5zti.reconciliationintl.com", "qsfmut.storageinridgecrest.com", "storageinridgecrest.com", "kpwogzd.spotlightstudioofdance.com", "spotlightstudioofdance.com", "oiewpbg.spirosnet.com", "dexvfy.sivasumutemlak.com", "xxhgrvi.specialtypopupevents.com", "specialtypopupevents.com", "berg-lifesciences.com", "schaffhauserbuchwoche.ch", "lagerraum-mieten-luzern.ch", "bangtanlab.net", "athycal.com", "avp-int.com", "askgeoffrey.ai", "balaentpr.com", "azvalleycontractors.com", "barakahhousing.com.bd", "autopowerssre.com", "voyagesetc.fr", "beryll-immobilien.ch"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 4 specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:

Original source: https://threatfox.abuse.ch/browse/malware/js.clearfake/