← Back to SOC feed Coverage →

ThreatFox: IClickFix IOCs

ioc-hunt HIGH ThreatFox
DnsEventsUrlClickEvents
iocjs-iclickfixthreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-08-06T23:00:00Z · Confidence: high

Hunt Hypothesis

This hunt detects adversary activity involving known indicators of compromise (IOCs) from the ThreatFox intelligence feed specifically linked to the IClickFix ecosystem. A SOC team should proactively search for these signals in Azure Sentinel to identify potential lateral movement or data exfiltration attempts that may evade standard rule-based detections.

IOC Summary

Malware Family: IClickFix Total IOCs: 25 IOC Types: domain, url

TypeValueThreat TypeFirst SeenConfidence
domainpblmedic.compayload_delivery2026-08-06100%
domaindirtynightmare92.icupayload_delivery2026-08-06100%
domainatomento10.icupayload_delivery2026-08-06100%
domainfrontalback91.icupayload_delivery2026-08-06100%
domainhubcert.com.brpayload_delivery2026-08-06100%
domainsiege-close.combotnet_cc2026-08-06100%
urlhxxps://siege-close.com/x9i32md/w1/la02botnet_cc2026-08-06100%
domaincmaelevadores.compayload_delivery2026-08-06100%
domainelenaargandona.compayload_delivery2026-08-06100%
domainemsaluminium.frpayload_delivery2026-08-06100%
domainencofradosamazon.compayload_delivery2026-08-06100%
domainhelpdesk.pushit.itpayload_delivery2026-08-06100%
domainjoao-martins.compayload_delivery2026-08-06100%
domainkarmactive.compayload_delivery2026-08-06100%
domainlibella-wordpress.awebi-lab.compayload_delivery2026-08-06100%
domainmail.encofradosamazon.compayload_delivery2026-08-06100%
domainvamoscurtiromelhor.com.brpayload_delivery2026-08-06100%
domainwww.museoshaghenbeck.mxpayload_delivery2026-08-06100%
domainburministr5123.icupayload_delivery2026-08-06100%
domainbutterbread1122.icupayload_delivery2026-08-06100%
domainelizium999.digitalpayload_delivery2026-08-06100%
domainfaircloud512421.buzzpayload_delivery2026-08-06100%
domainfochinal5123.lifepayload_delivery2026-08-06100%
domainkorichniuu122.icupayload_delivery2026-08-06100%
domaintrokkypi512122.icupayload_delivery2026-08-06100%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - IClickFix
let malicious_domains = dynamic(["pblmedic.com", "dirtynightmare92.icu", "atomento10.icu", "frontalback91.icu", "hubcert.com.br", "siege-close.com", "cmaelevadores.com", "elenaargandona.com", "emsaluminium.fr", "encofradosamazon.com", "helpdesk.pushit.it", "joao-martins.com", "karmactive.com", "libella-wordpress.awebi-lab.com", "mail.encofradosamazon.com", "vamoscurtiromelhor.com.br", "www.museoshaghenbeck.mx", "burministr5123.icu", "butterbread1122.icu", "elizium999.digital", "faircloud512421.buzz", "fochinal5123.life", "korichniuu122.icu", "trokkypi512122.icu"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

KQL: Url Hunt

// Hunt for access to known malicious URLs
// Source: ThreatFox - IClickFix
let malicious_urls = dynamic(["https://siege-close.com/x9i32md/w1/la02"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled
UrlClickEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 4 specific false positive scenarios and corresponding exclusion strategies for the ThreatFox: IClickFix IOCs detection rule:

Original source: https://threatfox.abuse.ch/browse/malware/js.iclickfix/