The ThreatFox: ClearFake IOCs rule detects potential adversary activity linked to the ClearFake threat group, which is associated with the distribution of malicious software and phishing campaigns. SOC teams should proactively hunt for these IOCs in Azure Sentinel to identify and mitigate early-stage attacks that could compromise organizational assets.
IOC Summary
Malware Family: ClearFake Total IOCs: 33 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | bcfaxrtc.logic-compass.digital | payload_delivery | 2026-05-26 | 100% |
| domain | mzegv1ui.logic-compass.digital | payload_delivery | 2026-05-26 | 100% |
| domain | julya.bmz.hu | payload_delivery | 2026-05-26 | 100% |
| domain | nwree.bmz.hu | payload_delivery | 2026-05-26 | 100% |
| domain | boovs.anniethaispa.hu | payload_delivery | 2026-05-26 | 100% |
| domain | anniethaispa.hu | payload_delivery | 2026-05-26 | 100% |
| domain | vmpyw.almasiklima.hu | payload_delivery | 2026-05-26 | 100% |
| domain | uvbdg.almasiklima.hu | payload_delivery | 2026-05-26 | 100% |
| domain | fuluz.akonyvelod.hu | payload_delivery | 2026-05-26 | 100% |
| domain | vwbtp.akonyvelod.hu | payload_delivery | 2026-05-26 | 100% |
| domain | ilgte.aivallalkozok.hu | payload_delivery | 2026-05-26 | 100% |
| domain | ahume.aivallalkozok.hu | payload_delivery | 2026-05-26 | 100% |
| domain | eqgwn.aivallalkozo.hu | payload_delivery | 2026-05-26 | 100% |
| domain | qqxmr.aivallalkozo.hu | payload_delivery | 2026-05-26 | 100% |
| domain | abmjl.bertifolia.hu | payload_delivery | 2026-05-26 | 100% |
| domain | fhptw.bertifolia.hu | payload_delivery | 2026-05-26 | 100% |
| domain | ptnza.bni-ai.com | payload_delivery | 2026-05-26 | 100% |
| domain | tfaph.bni-ai.com | payload_delivery | 2026-05-26 | 100% |
| domain | neypx.bmz.hu | payload_delivery | 2026-05-26 | 100% |
| domain | ibmqr.bmz.hu | payload_delivery | 2026-05-26 | 100% |
| domain | miqhc.bmiroda.hu | payload_delivery | 2026-05-26 | 100% |
| domain | pdyer.bmiroda.hu | payload_delivery | 2026-05-26 | 100% |
| domain | bczth.bertifolia.hu | payload_delivery | 2026-05-26 | 100% |
| domain | albze.bertifolia.hu | payload_delivery | 2026-05-26 | 100% |
| domain | zcrop.bernoe.hu | payload_delivery | 2026-05-26 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["bcfaxrtc.logic-compass.digital", "mzegv1ui.logic-compass.digital", "julya.bmz.hu", "nwree.bmz.hu", "boovs.anniethaispa.hu", "anniethaispa.hu", "vmpyw.almasiklima.hu", "uvbdg.almasiklima.hu", "fuluz.akonyvelod.hu", "vwbtp.akonyvelod.hu", "ilgte.aivallalkozok.hu", "ahume.aivallalkozok.hu", "eqgwn.aivallalkozo.hu", "qqxmr.aivallalkozo.hu", "abmjl.bertifolia.hu", "fhptw.bertifolia.hu", "ptnza.bni-ai.com", "tfaph.bni-ai.com", "neypx.bmz.hu", "ibmqr.bmz.hu", "miqhc.bmiroda.hu", "pdyer.bmiroda.hu", "bczth.bertifolia.hu", "albze.bertifolia.hu", "zcrop.bernoe.hu", "wjldm.bernoe.hu", "vrifp.bergertetokft.hu", "lpnvi.bergertetokft.hu", "aklze.bercibutor.hu", "uqcaa.bercibutor.hu", "odqtx.bbglobalbau.hu", "ljfzn.bbglobalbau.hu", "bbglobalbau.hu"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Scenario: Legitimate System Update via Windows Update
Description: A system update from Microsoft’s Windows Update may include files or registry keys that match the ClearFake IOC list due to similar naming or hash collisions.
Filter/Exclusion: Check the file path and source against known Windows Update directories (e.g., C:\Windows\Temp\, C:\Windows\SoftwareDistribution\) and verify the file’s digital signature using sigcheck or certutil.
Scenario: Scheduled Job for Log Management (e.g., Splunk or ELK)
Description: A scheduled job that generates temporary files or logs in a known IOC directory (e.g., /var/log/ or C:\ProgramData\) may trigger the rule due to file names or paths.
Filter/Exclusion: Filter by file path containing /var/log/ or C:\ProgramData\ and check the file owner or process parent to ensure it’s a legitimate log management tool (e.g., splunkd.exe, logstash.exe).
Scenario: Admin Task for Software Deployment (e.g., SCCM or Group Policy)
Description: A software deployment task using SCCM or Group Policy may create temporary files or registry entries that match ClearFake IOCs.
Filter/Exclusion: Filter by process name (ccmexec.exe, gpupdate.exe) and check the file path against SCCM deployment directories (e.g., C:\Windows\Temp\SCCM\). Verify the file’s digital signature.
Scenario: Legitimate Antivirus or EDR Scan (e.g., CrowdStrike, CrowdStrike Falcon)
Description: A security tool like CrowdStrike may generate temporary files or use known hashes that appear in the ClearFake IOC list.
Filter/Exclusion: Filter by process name (falcon.exe, `