s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1852756 high

📛 Threat Title

ClearFake: Domain name that delivers a malware payload aefauhqwk.irani-music.com

Category: ClearFake Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: ClearFake. Confidence: 100. First seen: 2026-07-17 07:50:14 UTC. Reporter: anonymous. Tags: ClearFake, win-0x0cd5, Windows.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain aefauhqwk.irani-music.com UrlVoid 3 / 35

IOC database

Type
domain
Value
aefauhqwk.irani-music.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain name that delivers a malware payload attributed to ClearFake

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: ClearFake. Confidence: 100. First seen: 2026-07-17 07:50:14 UTC. Reporter: anonymous. Tags: ClearFake, win-0x0cd5, Windows.

Remediations (10)

  • web:darkwebinformer.com

    A domain -based indicator has been identified delivering ClearFake JavaScript malware . The domain is flagged for phishing and payload delivery activity and is associated with malicious script injection campaigns designed to trick users into interacting with fraudulent browser updates or phishing pages.

  • web:expel.com

    ClearFake is a malware campaign which displays fake CAPTCHA challenges across hundreds of hacked websites. The fake CAPTCHA challenges use social engineering to lure visitors into installing malware . Recently, the campaign has adopted much more evasive tactics such as leveraging Proxy Execution to run PowerShell commands via a trusted Window ...

  • web:thehackernews.com

    ClearFake malware infects 9,300+ websites, using fake reCAPTCHA and Web3 tactics to spread Lumma and Vidar Stealers, exposing 200,000+ users.

  • web:threatfox.abuse.ch

    ClearFake IOC: aefauhqwk.irani-music.com ( domain ) You are viewing the ThreatFox database entry for domain aefauhqwk.irani-music.com .

  • web:www.bridewell.com

    ClearFake is a relatively new, malicious JavaScript framework that was first identified in July 2023 by security researcher Randy McEoin.

  • web:www.darktrace.com

    Darktrace detected a potential ClearFake‑related incident involving signs of EtherHiding activity and interactions with blockchain‑based infrastructure. A single device showed repeated suspicious command‑line behavior, primarily involving Microsoft HTML Application Host. The activity occurred over the course of a day and indicated early‑stage attempts to load malicious content ...

  • web:www.kroll.com

    CLEARFAKE is the term used to describe the malicious in-browser JavaScript framework deployed on compromised webpages as part of drive-by compromise campaigns to deliver information stealers. It has the potential to impact all sectors. Read More.

  • web:www.kroll.com

    Although this article has highlighted the rapid evolution of CLEARFAKE delivery to victims across multiple sectors, there are also common themes throughout to assist in detection and mitigation strategies for this threat.

  • web:www.linkedin.com

    A sophisticated evolution of the ClearFake malware campaign has emerged, deploying advanced evasion techniques that abuse legitimate Windows components to bypass endpoint detection systems. The ...

  • web:www.threatdown.com

    ClearFake , tested on June 3, 2024 Distribution (Compromised site->fake error->copy/paste PowerShell) ClearFake is a malware campaign using social engineering first discovered by Randy McEoin. It is one of the many "fake browser updates" inspired by OG SocGholish which leverages compromised websites to target potential victims.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.