← Back to SOC feed Coverage →

ThreatFox: IClickFix IOCs

ioc-hunt HIGH ThreatFox
DnsEvents
iocjs-iclickfixthreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-07-31T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt detects adversary activity by monitoring for network connections and process executions matching the specific indicators of compromise (IOCs) associated with the IClickFix threat landscape. A SOC team should proactively hunt for these signals in Azure Sentinel to rapidly identify potential compromises from this high-severity campaign before they escalate into broader incidents within the organization’s cloud environment.

IOC Summary

Malware Family: IClickFix Total IOCs: 121 IOC Types: domain

TypeValueThreat TypeFirst SeenConfidence
domaindth.travelpayload_delivery2026-07-31100%
domainecosweetbaby.espayload_delivery2026-07-31100%
domaincooperacionescolar.orgpayload_delivery2026-07-31100%
domaincscreate.compayload_delivery2026-07-31100%
domaind-privacy.depayload_delivery2026-07-31100%
domaincodeman.nzpayload_delivery2026-07-31100%
domaincodeman.rupayload_delivery2026-07-31100%
domainluma-film.depayload_delivery2026-07-31100%
domainlunasnailsbeauty.compayload_delivery2026-07-31100%
domainluneoulautre.bepayload_delivery2026-07-31100%
domainluxeaminos.ispayload_delivery2026-07-31100%
domainlvidrado.com.brpayload_delivery2026-07-31100%
domainlongtrantrui.compayload_delivery2026-07-31100%
domainlotaautomotive.compayload_delivery2026-07-31100%
domainlowandhigh.xyzpayload_delivery2026-07-31100%
domainlpointiers.compayload_delivery2026-07-31100%
domainlsc-canfranc.espayload_delivery2026-07-31100%
domainltchelmond.nlpayload_delivery2026-07-31100%
domainlubospospisil.czpayload_delivery2026-07-31100%
domainluciebalit.frpayload_delivery2026-07-31100%
domainlucienbordes.compayload_delivery2026-07-31100%
domainlukechisholm.com.aupayload_delivery2026-07-31100%
domainkik-kreuzlingen.chpayload_delivery2026-07-31100%
domainkoolyom.frpayload_delivery2026-07-31100%
domaingokayaknow.compayload_delivery2026-07-31100%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - IClickFix
let malicious_domains = dynamic(["dth.travel", "ecosweetbaby.es", "cooperacionescolar.org", "cscreate.com", "d-privacy.de", "codeman.nz", "codeman.ru", "luma-film.de", "lunasnailsbeauty.com", "luneoulautre.be", "luxeaminos.is", "lvidrado.com.br", "longtrantrui.com", "lotaautomotive.com", "lowandhigh.xyz", "lpointiers.com", "lsc-canfranc.es", "ltchelmond.nl", "lubospospisil.cz", "luciebalit.fr", "lucienbordes.com", "lukechisholm.com.au", "kik-kreuzlingen.ch", "koolyom.fr", "gokayaknow.com", "recbf.fr", "reciclarpelobrasil.com.br", "recyclablellc.com", "q3creative.com", "qinov8.com", "qtts.ipcms.fr", "quarryoaks.ca", "quickquartz.ca", "quinnebogfishingclub.com", "radioelmiradordelgallo.cl", "radiolauncion.net", "rado-design.at", "raheemsoft.com", "rainfond.com", "raspberrypiforschools.com", "rcssolar.co.il", "rcssolar.com", "rebuildingtogetherdca.org", "primebuilderswallc.com", "prinmor.co.za", "printtex.pl", "probsts.com", "producegood.com", "proindivisosgestionpropiedades.com", "promosalutgirona.org"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 5 specific false positive scenarios and their corresponding filters/exclusions for the ThreatFox: IClickFix IOCs detection rule:

Original source: https://threatfox.abuse.ch/browse/malware/js.iclickfix/