The ThreatFox: ClearFake IOCs rule detects potential adversary activity linked to the ClearFake malware, which is associated with the distribution of malicious payloads and command-and-control infrastructure. SOC teams should proactively hunt for this behavior in Azure Sentinel to identify and mitigate advanced threats that could compromise network security.
IOC Summary
Malware Family: ClearFake Total IOCs: 33 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | clmkghe.bettime90.casino | payload_delivery | 2026-06-04 | 100% |
| domain | bettime90.casino | payload_delivery | 2026-06-04 | 100% |
| domain | kfvgvcb.betrophy90.com | payload_delivery | 2026-06-04 | 100% |
| domain | !z!.betrophy90.com | payload_delivery | 2026-06-04 | 100% |
| domain | swmzey[.]3sefr3.ir | payload_delivery | 2026-06-04 | 100% |
| domain | ffeqlui.betrayon.casino | payload_delivery | 2026-06-04 | 100% |
| domain | betrayon.casino | payload_delivery | 2026-06-04 | 100% |
| domain | t7gjz81d.bet360pro.bet | payload_delivery | 2026-06-04 | 100% |
| domain | ug5x33qq.bet360pro.bet | payload_delivery | 2026-06-04 | 100% |
| domain | cmzgymj.betobet90.com | payload_delivery | 2026-06-04 | 100% |
| domain | !z!.betobet90.com | payload_delivery | 2026-06-04 | 100% |
| domain | bkbopol.betlikegirisi.com | payload_delivery | 2026-06-04 | 100% |
| domain | !z!.betlikegirisi.com | payload_delivery | 2026-06-04 | 100% |
| domain | betlikegirisi.com | payload_delivery | 2026-06-04 | 100% |
| domain | zthnnrr.betistmobil.com | payload_delivery | 2026-06-04 | 100% |
| domain | !z!.betistmobil.com | payload_delivery | 2026-06-04 | 100% |
| domain | ty7zctpt.bet303casino.com | payload_delivery | 2026-06-04 | 100% |
| domain | 3z2a3kyo.bet303casino.com | payload_delivery | 2026-06-04 | 100% |
| domain | wezdgtt.betistcomgiris.com | payload_delivery | 2026-06-04 | 100% |
| domain | !z!.betistcomgiris.com | payload_delivery | 2026-06-04 | 100% |
| domain | betistcomgiris.com | payload_delivery | 2026-06-04 | 100% |
| domain | cxgbphg.betgopro.com | payload_delivery | 2026-06-04 | 100% |
| domain | !z!.betgopro.com | payload_delivery | 2026-06-04 | 100% |
| domain | bijmduj.betforward.now | payload_delivery | 2026-06-04 | 100% |
| domain | betforward.now | payload_delivery | 2026-06-04 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["clmkghe.bettime90.casino", "bettime90.casino", "kfvgvcb.betrophy90.com", "!z!.betrophy90.com", "swmzey.3sefr3.ir", "ffeqlui.betrayon.casino", "betrayon.casino", "t7gjz81d.bet360pro.bet", "ug5x33qq.bet360pro.bet", "cmzgymj.betobet90.com", "!z!.betobet90.com", "bkbopol.betlikegirisi.com", "!z!.betlikegirisi.com", "betlikegirisi.com", "zthnnrr.betistmobil.com", "!z!.betistmobil.com", "ty7zctpt.bet303casino.com", "3z2a3kyo.bet303casino.com", "wezdgtt.betistcomgiris.com", "!z!.betistcomgiris.com", "betistcomgiris.com", "cxgbphg.betgopro.com", "!z!.betgopro.com", "bijmduj.betforward.now", "betforward.now", "betfoot.bet", "!z!.betfoot.bet", "mcqkkmc.betfootbal90.com", "!z!.betfootbal90.com", "sfmbqki.betfa90.net", "!z!.betfa90.net", "gud6pt4u.bet212.casino", "bet212.casino"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Scenario: Legitimate system update using ClearFake-related tools
Description: A system administrator is performing a scheduled update that includes tools or scripts flagged by the ClearFake IOC list.
Filter/Exclusion: Exclude processes associated with known system update tools (e.g., Windows Update, WSUS, Chocolatey, or PowerShell scripts with known update tasks).
Scenario: Scheduled job running ClearFake-related scripts for compliance
Description: A compliance or security team runs a scheduled job that uses scripts or tools matching ClearFake IOCs to audit or remediate systems.
Filter/Exclusion: Exclude processes initiated by scheduled tasks with known compliance tools (e.g., Task Scheduler tasks named ComplianceAudit, SecurityScan, or PolicyCheck).
Scenario: Admin using ClearFake IOC list for threat hunting
Description: A SOC analyst manually queries or uses the ClearFake IOC list to hunt for threats, triggering the rule during investigation.
Filter/Exclusion: Exclude processes initiated by threat hunting tools (e.g., Splunk, ELK, Sigma, or OSQuery) or user actions with known hunting activities (e.g., powershell.exe with -Command arguments related to IOC lookups).
Scenario: Legitimate software installation using ClearFake-related artifacts
Description: A software deployment tool (e.g., Chocolatey, Ansible, or Puppet) installs a package that includes files or registry keys matching ClearFake IOCs.
Filter/Exclusion: Exclude processes associated with package managers or deployment tools (e.g., choco, ansible, puppet, or msiexec with known installation tasks).
Scenario: False positive from a third-party security tool integrating ClearFake data
Description: A third-party security tool (e.g., `