TF-1932722
high
📛 Threat Title
ClearFake: Domain name that delivers a malware payload tickett.bet
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: ClearFake. Confidence: 100. First seen: 2026-09-25 08:10:28 UTC. Last seen: 2026-09-25 08:10:34 UTC. Reporter: Gi7w0rm. Tags: 25September2026, ClearFake, Commandline, macOS.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
tickett.bet
VT 2 / 91
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
tickett.bet- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Gridinsoft | suspicious | suspicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | bet |
History
| Creation date | 2024-10-13 00:00 UTC |
| Last analysis | 2026-09-25 08:48 UTC |
| Last modified on VirusTotal | 2026-09-25 22:31 UTC |
| Last WHOIS update | 2024-10-13 00:00 UTC |
| WHOIS record date | 2025-10-13 00:00 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: ClearFake. Confidence: 100. First seen: 2026-09-25 08:10:28 UTC. Last seen: 2026-09-25 08:10:34 UTC. Reporter: Gi7w0rm. Tags: 25September2026, ClearFake, Commandline, macOS.
Remediations (10)
-
web:cybersecuritynews.com
ClearFake uses fake CAPTCHA prompts to spread malware that steals crypto and credentials while disabling endpoint protection.
-
web:darkwebinformer.com
⚠️ This IOC underscores the persistent activity of ClearFake malware operators, who continue to leverage compromised or newly registered domains to deliver JavaScript payloads under the guise of security or software update warnings.
-
web:izoologic.com
Payload retrieval and staging: Review outbound connections to newly registered domains , Cloudflare Pages, jsDelivr GitHub CDN paths, WebDAV paths, unfamiliar file-hosting locations, or domains associated with ClearFake delivery infrastructure.
-
web:securereading.com
Once delivered, ClearFake malware typically enables follow-on activity such as credential theft, redirection to scam content, or additional payload downloads. Because the delivery channel appears legitimate, many perimeter defenses fail to block access by default.
-
web:thehackernews.com
ClickFix accounted for 47% of Microsoft Defender Experts initial-access cases in 2025, while a Polygon contract rotated lure hosts.
-
web:threatfox.abuse.ch
ClearFake IOC: tickett.bet ( domain ) ThreatFox IOC Database You are viewing the ThreatFox database entry for domain tickett.bet .
-
web:www.ctm360.com
ClickFix is a rapidly evolving social engineering technique that tricks users into executing malicious commands through fake CAPTCHA checks, browser errors, verification prompts, and other seemingly legitimate instructions. Unlike traditional malware delivery, ClickFix often requires no software exploit—the user is manipulated into initiating the attack themselves. In ClickFix & Beyond ...
-
web:www.darktrace.com
Darktrace detected a potential ClearFake‑related incident involving signs of EtherHiding activity and interactions with blockchain‑based infrastructure. A single device showed repeated suspicious command‑line behavior, primarily involving Microsoft HTML Application Host. The activity occurred over the course of a day and indicated early‑stage attempts to load malicious content ...
-
web:www.packetlabs.net
A new ClearFake variant deceives victims with fake reCAPTCHA challenges and bypasses with smart-contract ABIs tricking users into running PowerShell malware . Learn how it works and how to defend.
-
web:www.silentpush.com
Executive Summary Silent Push Threat Analysts have discovered 2000+ unique domains that are affected by the ClickFix/ ClearFake fake browser update malware . Our team has constructed two Bulk Data Feeds that track affected domains in real time, using a Silent Push Web Scanner query that scans domain metadata for infected domains and IPs.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.