The ThreatFox: ClearFake IOCs rule detects potential adversary activity associated with the ClearFake malware, leveraging known malicious indicators to identify compromised systems. SOC teams should proactively hunt for this behavior in Azure Sentinel to uncover early-stage attacks and prevent lateral movement and data exfiltration.
IOC Summary
Malware Family: ClearFake Total IOCs: 8 IOC Types: domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | yezqbe5v.tarahisystem.xyz | payload_delivery | 2026-06-21 | 100% |
| domain | xlp38wsp.yekiran.com | payload_delivery | 2026-06-21 | 100% |
| domain | s3zzh7np.sigaribetkade.com | payload_delivery | 2026-06-21 | 100% |
| domain | xfq2kf92.angizeshfarahani.store | payload_delivery | 2026-06-21 | 100% |
| domain | zamineravanshenasi.xyz | payload_delivery | 2026-06-21 | 100% |
| domain | bbzvqin8.zamineravan.xyz | payload_delivery | 2026-06-21 | 100% |
| domain | zamineravan.xyz | payload_delivery | 2026-06-21 | 100% |
| domain | g9lo26em.shartland.com | payload_delivery | 2026-06-21 | 100% |
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - ClearFake
let malicious_domains = dynamic(["yezqbe5v.tarahisystem.xyz", "xlp38wsp.yekiran.com", "s3zzh7np.sigaribetkade.com", "xfq2kf92.angizeshfarahani.store", "zamineravanshenasi.xyz", "bbzvqin8.zamineravan.xyz", "zamineravan.xyz", "g9lo26em.shartland.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
DnsEvents | Ensure this data connector is enabled |
Scenario: Legitimate system update using ClearFake tool
Filter/Exclusion: process.name != "ClearFake" or process.parent.name != "Windows Update"
Scenario: Scheduled job running ClearFake for malware analysis
Filter/Exclusion: process.name != "ClearFake" or process.parent.name != "Task Scheduler"
Scenario: Admin using ClearFake for forensic analysis
Filter/Exclusion: process.name != "ClearFake" or user.name != "admin"
Scenario: ClearFake used as part of a legitimate security toolchain (e.g., for sandboxing)
Filter/Exclusion: process.name != "ClearFake" or process.parent.name != "Sandboxed Environment"
Scenario: ClearFake being used in a red team exercise with approved tools
Filter/Exclusion: process.name != "ClearFake" or user.name != "redteam"