This detection rule identifies adversary behavior where ClearFake malware establishes initial access and executes data exfiltration activities using known Indicators of Compromise (IOCs). A SOC team should proactively hunt for these specific IOCs in Azure Sentinel to rapidly detect early-stage infections and prevent sensitive data loss before the threat escalates.
Malware Family: ClearFake Total IOCs: 29 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | elsfpng.classicpontiac.org | payload_delivery | 2026-07-31 | 100% |
| domain | classicpontiac.org | payload_delivery | 2026-07-31 | 100% |
| domain | bxzpts.aurinebeverly.com | payload_delivery | 2026-07-31 | 100% |
| domain | videogeo.ru | payload_delivery | 2026-07-31 | 50% |
| domain | chestnutstanza.top | botnet_cc | 2026-07-31 | 50% |
| domain | aurinebeverly.com | payload_delivery | 2026-07-31 | 100% |
| domain | consumersupporthelpline.co.uk | payload_delivery | 2026-07-31 | 100% |
| domain | 0lt9m77b.roundtheclockcare.net | payload_delivery | 2026-07-31 | 100% |
| domain | frenlvq.citycompanies-dev.net | payload_delivery | 2026-07-31 | 100% |
| domain | citycompanies-dev.net | payload_delivery | 2026-07-31 | 100% |
| domain | oboizw.atriplejranch.com | payload_delivery | 2026-07-31 | 100% |
| domain | atriplejranch.com | payload_delivery | 2026-07-31 | 100% |
| domain | 6oybqhpt.coachandkitchen.com | payload_delivery | 2026-07-31 | 100% |
| domain | coachandkitchen.com | payload_delivery | 2026-07-31 | 100% |
| domain | nqgikft.chevyrepairhuntingtonbeach.com | payload_delivery | 2026-07-31 | 100% |
| domain | chevyrepairhuntingtonbeach.com | payload_delivery | 2026-07-31 | 100% |
| domain | dhatfu.apmlandscaping.com | payload_delivery | 2026-07-31 | 100% |
| domain | apmlandscaping.com | payload_delivery | 2026-07-31 | 100% |
| domain | iwffn03j.eastonfootandanklecenter.com | payload_delivery | 2026-07-31 | 100% |
| domain | eastonfootandanklecenter.com | payload_delivery | 2026-07-31 | 100% |
| domain | lbsmduw.certifiedairbalanceinlosangelesca.com | payload_delivery | 2026-07-31 | 100% |
| domain | certifiedairbalanceinlosangelesca.com | payload_delivery | 2026-07-31 | 100% |
| domain | zsupeg.angelnailsphenix.com | payload_delivery | 2026-07-31 | 100% |
| domain | angelnailsphenix.com | payload_delivery | 2026-07-31 | 100% |
| domain | mrdughl.cannesresidencia.com | payload_delivery | 2026-07-31 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["elsfpng.classicpontiac.org", "classicpontiac.org", "bxzpts.aurinebeverly.com", "videogeo.ru", "chestnutstanza.top", "aurinebeverly.com", "consumersupporthelpline.co.uk", "0lt9m77b.roundtheclockcare.net", "frenlvq.citycompanies-dev.net", "citycompanies-dev.net", "oboizw.atriplejranch.com", "atriplejranch.com", "6oybqhpt.coachandkitchen.com", "coachandkitchen.com", "nqgikft.chevyrepairhuntingtonbeach.com", "chevyrepairhuntingtonbeach.com", "dhatfu.apmlandscaping.com", "apmlandscaping.com", "iwffn03j.eastonfootandanklecenter.com", "eastonfootandanklecenter.com", "lbsmduw.certifiedairbalanceinlosangelesca.com", "certifiedairbalanceinlosangelesca.com", "zsupeg.angelnailsphenix.com", "angelnailsphenix.com", "mrdughl.cannesresidencia.com", "cannesresidencia.com", "kvetkoms.smallshopsandwhatknot.com", "dfojjm.angebagnia.com", "angebagnia.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: ClearFake IOCs rule, tailored for a legitimate enterprise environment:
Scenario: Antivirus Endpoint Scanning of Large Archives
ProcessName matches known AV engines (MsMpEng.exe, FalconSensorService.exe) and FileName ends with .zip or .7z. Additionally, apply a threshold filter to ignore events where the total data volume transferred in a single session is less than 50MB.Scenario: Scheduled Backup Jobs via Cloud Sync Tools
Scheduled Task Name (e.g., “VeeamBackup”, “OneDriveSync”) and restrict detection to exclude traffic destined for known corporate cloud storage CIDR blocks or specific SaaS URLs (e.g., *.office365.com, *.veeam.com).Scenario: Software Deployment via Configuration Management Tools