This hunt targets adversary behavior involving the execution of malicious artifacts linked to the ClearFake campaign by correlating network and endpoint telemetry against a curated set of 53 specific Indicators of Compromise (IOCs). Proactively hunting for these IOCs in Azure Sentinel is critical because ClearFake’s high-severity threat profile suggests active exploitation attempts that require immediate identification and containment before lateral movement occurs.
Malware Family: ClearFake Total IOCs: 53 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | broadwaylotterytickets.com | payload_delivery | 2026-07-20 | 100% |
| domain | okv4iaii.contempoconstructiontx.com | payload_delivery | 2026-07-20 | 100% |
| domain | fgsnlppf.jadoou.lat | payload_delivery | 2026-07-20 | 100% |
| domain | contempoconstructiontx.com | payload_delivery | 2026-07-20 | 100% |
| domain | tgbft.countertops-dfw.com | payload_delivery | 2026-07-20 | 100% |
| domain | giwl.highkickstkd.com | payload_delivery | 2026-07-20 | 100% |
| domain | highkickstkd.com | payload_delivery | 2026-07-20 | 100% |
| domain | countertops-dfw.com | payload_delivery | 2026-07-20 | 100% |
| domain | 3efofny3.cielohillsevents.com | payload_delivery | 2026-07-20 | 100% |
| domain | cielohillsevents.com | payload_delivery | 2026-07-20 | 100% |
| domain | hpnohznb.site-takhtenard-sharti-betland.com | payload_delivery | 2026-07-20 | 100% |
| domain | u9p8kb56.crvbl.com | payload_delivery | 2026-07-20 | 100% |
| domain | wnq8bmsb.derbi.promo | payload_delivery | 2026-07-20 | 100% |
| domain | crvbl.com | payload_delivery | 2026-07-20 | 100% |
| domain | f9e2ff2h.site-asli-bedon-filter-1xbet.com | payload_delivery | 2026-07-20 | 100% |
| domain | apexstorm6link.solavern.garden | botnet_cc | 2026-07-20 | 90% |
| domain | neogateway9hub.solavern.garden | botnet_cc | 2026-07-20 | 90% |
| domain | ddsr.hieliao-app.com | payload_delivery | 2026-07-20 | 100% |
| domain | lightsiteview1.solavern.garden | botnet_cc | 2026-07-20 | 90% |
| domain | cnxst.jardins-do-mar.com | payload_delivery | 2026-07-20 | 100% |
| domain | hieliao-app.com | payload_delivery | 2026-07-20 | 100% |
| domain | jardins-do-mar.com | payload_delivery | 2026-07-20 | 100% |
| domain | ryr4q9kj.playantwatch.com | payload_delivery | 2026-07-20 | 100% |
| domain | vividmeshflow.solavern.garden | botnet_cc | 2026-07-20 | 90% |
| domain | boldlogicgate4.mistbriar.garden | botnet_cc | 2026-07-20 | 90% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["broadwaylotterytickets.com", "okv4iaii.contempoconstructiontx.com", "fgsnlppf.jadoou.lat", "contempoconstructiontx.com", "tgbft.countertops-dfw.com", "giwl.highkickstkd.com", "highkickstkd.com", "countertops-dfw.com", "3efofny3.cielohillsevents.com", "cielohillsevents.com", "hpnohznb.site-takhtenard-sharti-betland.com", "u9p8kb56.crvbl.com", "wnq8bmsb.derbi.promo", "crvbl.com", "f9e2ff2h.site-asli-bedon-filter-1xbet.com", "apexstorm6link.solavern.garden", "neogateway9hub.solavern.garden", "ddsr.hieliao-app.com", "lightsiteview1.solavern.garden", "cnxst.jardins-do-mar.com", "hieliao-app.com", "jardins-do-mar.com", "ryr4q9kj.playantwatch.com", "vividmeshflow.solavern.garden", "boldlogicgate4.mistbriar.garden", "cyki.hayleymarienorman.com", "jsthk.jademckenzieco.com", "swift7tasknet.mistbriar.garden", "hayleymarienorman.com", "jademckenzieco.com", "twyd6y14.elizabethspizzadenton.com", "01ejjpa2.behtarin-site-shartbandi.com", "pkspm.informatik-ai.com", "todn.hansikaenterprises.com", "hansikaenterprises.com", "informatik-ai.com", "oqtr.haleywoodportfolio.com", "tztgw.impactpromotionsclt.com", "haleywoodportfolio.com", "impactpromotionsclt.com", "primeglow2unit.mistbriar.garden", "signalwestport.mistbriar.garden", "t13ecldw.calculadoracomisiones.com", "proxyfastzone.lunavera.garden", "brightnode9sys.lunavera.garden", "llttu.hurtigegevinster.com", "rbnz.hairbyniki.com", "hairbyniki.com", "hurtigegevinster.com", "trendscanview.lunavera.garden"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: ClearFake IOCs detection rule in an enterprise environment, along with suggested filters and exclusions:
Endpoint Protection Policy Updates via Microsoft Defender for Endpoint
MsMpEng (Microsoft Antimalware) service to download and execute multiple scripts and binaries that match ClearFake’s known IOCs, specifically during the initial deployment window where network traffic spikes.C:\Program Files\Windows Defender\* directory and filter out events where the parent process is MsMpEng.exe or SenseService.exe. Additionally, exclude alerts occurring during known maintenance windows (e.g., Sunday 02:00–04:00 UTC).Scheduled Software Inventory Scans using SCCM/MECM
SmsAgentHost.exe process, which executes several discovery scripts to enumerate installed applications. These scripts often utilize standard libraries or temporary executables that share hash signatures with ClearFake’s IOCs.SmsAgentHost.exe and the command line arguments contain keywords like /Inventory, /Discovery, or specific SCCM task sequence IDs (e.g., TaskSequenceID=...).Automated Patch Management Deployments via Ivanti or ManageEngine
IvAgent.exe or EndpointManagerService) downloads