ClickGrab Threat Analysis Report - 2026-05-11
Generated on 2026-05-11 01:57:06
Executive Summary
- Total sites analyzed: 100
- Sites with malicious content: 20
- Unique domains encountered: 1,125
- Total URLs extracted: 5,724
- PowerShell download attempts: 2
- Clipboard manipulation instances: 87
Domain Analysis
Most Frequently Encountered Domains
- www.maheshwaree.com: 320 occurrences
- 98.70.13.131: 309 occurrences
- fudgeshop.com.au: 265 occurrences
- picsera.com: 226 occurrences
- 18.176.47.246: 218 occurrences
- adturekorea.co.kr: 214 occurrences
- scillarodriguez.com: 196 occurrences
- www.ccera-icar.org: 178 occurrences
- senevie.com: 174 occurrences
- www.creatorssky.com: 156 occurrences
- devblog.ezeelogin.com: 132 occurrences
- www.dorper.com.au: 125 occurrences
- picsera.sirv.com: 121 occurrences
- 104.199.248.167: 71 occurrences
- sun1118.com: 54 occurrences
URL Pattern Analysis
reCAPTCHA imagery
8 occurrences across 5 distinct URLs
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png(2 times)https://www.google.com/recaptcha/api.js(2 times)https://2captcha.com/dist/web/assets/google-privacy-policy-Cb0CGVRT.svg(2 times)https://pizzabyte.com.au/smartdetection/deviceverification/CF/path/captcha(1 times)https://www.google.com/recaptcha/api.js?hl=&render=6Lf7uxYsAAAAANagtTWlY2ET8HF8nbfMf4-ePcWm(1 times)
Font resources
74 occurrences across 61 distinct URLs
https://fonts.gstatic.com(5 times)https://fonts.googleapis.com(4 times)https://18.176.47.246/wp-content/plugins/vk-post-author-display/vendor/vektor-inc/font-awesome-versions/src/font-awesome/css/all.min.css?ver=7.1.0(2 times)https://adturekorea.co.kr/js/font-awesome/css/font-awesome.min.css?ver=220620(2 times)https://use.fontawesome.com/releases/v5.6.3/css/all.css(2 times)- ...and 56 more distinct URLs
CDN hosted scripts
4 occurrences across 4 distinct URLs
https://cdn.jsdelivr.net/npm/three@0.167.0/build/three.module.js(1 times)https://cdn.jsdelivr.net/npm/three@0.167.0/examples/jsm/(1 times)https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1(1 times)https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.css?ver=1.8.1(1 times)
Google resources
57 occurrences across 37 distinct URLs
https://www.google.com/s2/favicons?sz=128&domain=${encodeURIComponent(11 times)https://fonts.googleapis.com(4 times)https://www.google(3 times)https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png(2 times)https://www.creatorssky.com/google-adsppc/(2 times)- ...and 32 more distinct URLs
Suspicious Keyword Analysis
Total Keywords Found: 483 (106 unique)
Keyword Categories
Social Engineering
44 unique keywords
Verification IDCAPTCHA VerificationCaptchaCheckboxVerify you are humancaptcha_questionCaptchaLoadingcaptcha_word_new_400950command not supported TTL expired Connection not allowed by SOCKSv5 server General SOCKSv5 server failure _q_emitPendingReadNotification _q_emitPendingWriteNotification _q_emitPendingConnectionNotification ��d��d�d��dP-d�d�d�d$�d�d0�d6�d�d�d��d��dpd�d�!d@�d�dp�dp-d@ d�d�-d &d0,d/d�d�d�d�d�dP�d�d d� d� d� d� dSocks5 host did not support authentication method. QSocks5SocketEnginePrivate::_q_controlSocketReadNotification: Unexpectedly received data while in state=%d and mode=%d Remote host closed connection### ��d��d�d<�d�d�d�d�)d$�d*�d0�d6�dCan not access socks5 bind data from different thread 1_q_controlSocketStateChanged(QAbstractSocket::SocketState) 1_q_controlSocketDisconnected() 1_q_controlSocketError(QAbstractSocket::SocketError) 1_q_controlSocketBytesWritten() 1_q_controlSocketReadNotification() 1_q_controlSocketConnected() 1_q_udpSocketReadNotification() QSocks5SocketEngine::connectToHost: in QTcpServer mode ) 8 c � � � � W I ) � � � � � QAbstractSocket hostFound() connected() disconnected() stateChanged(QAbstractSocket::SocketState) error(QAbstractSocket::SocketError) proxy,authenticator proxyAuthenticationRequired(QNetworkProxy,QAuthenticator*) connectionClosed() delayedCloseFinished() hostName,port,mode connectToHostImplementation(QString,quint16,OpenMode) hostName,port connectToHostImplementation(QString,quint16) disconnectFromHostImplementation() _q_connectToNextAddress() _q_startConnecting(QHostInfo) _q_abortConnectionAttempt() _q_testConnection() _q_forceDisconnect() �d�/dt�dt�dt�dt�dt�ddisconnectFromHostImplementation QAbstractSocket::SocketError( QAbstractSocket::ProxyProtocolError QAbstractSocket::ProxyNotFoundError QAbstractSocket::ProxyConnectionTimeoutError QAbstractSocket::ProxyConnectionClosedError QAbstractSocket::ProxyConnectionRefusedError QAbstractSocket::UnknownSocketError QAbstractSocket::ProxyAuthenticationRequiredError QAbstractSocket::UnfinishedSocketOperationError QAbstractSocket::UnsupportedSocketOperationError QAbstractSocket::SocketAddressNotAvailableError QAbstractSocket::AddressInUseError QAbstractSocket::NetworkError QAbstractSocket::DatagramTooLargeError QAbstractSocket::SocketTimeoutError QAbstractSocket::SocketResourceError QAbstractSocket::SocketAccessError QAbstractSocket::HostNotFoundError QAbstractSocket::RemoteHostClosedError QAbstractSocket::ConnectionRefusedError QAbstractSocket::SocketState( QAbstractSocket::ClosingState QAbstractSocket::ListeningState QAbstractSocket::BoundState QAbstractSocket::ConnectedState QAbstractSocket::ConnectingState QAbstractSocket::HostLookupState QAbstractSocket::UnconnectedState connectToHostImplementation quint16 OpenMode h�d�:d5d gd�hd�d�d�d$�d�d0�d6�d��dT�dp@dZ�d�d�d�?dl�d�;d�;d�<d�kd@mdpdd 0d�LdOperation on socket is not supported ,�d�Gd�pd qdd�Xd Hd��dPHd��d��d��dlocalhost. Socket is not connected 1_q_abortConnectionAttempt() 1_q_forceDisconnect() QAbstractSocketPrivate::_q_startConnecting() received hostInfo for wrong lookup ID %d expected %d QAbstractSocket::connectToHost() called when already looking up or connecting/connected to "%s" 1_q_startConnecting(QHostInfo) QAbstractSocket::waitForBytesWritten() is not allowed in UnconnectedState QAbstractSocket::waitForDisconnected() is not allowed in UnconnectedState ��d�Gd�pd qdd�Xd Hd@�dPHd��d��d��d ��dp�d�d��d qd�d�d�d$�d*�d0�d6�d��dT�dp@dZ�d�d�d�?dl�d�;d�;d�<d�kd@mdpdd 0d�Ld�d�Gd�pd qdd�Xd Hd�dPHd��d��d��dt�d��d��d��d0sd�d�d�d$�d�d0�d6�d��dT�dp@dZ�d�d�d�?dl�d�;d�;d�<d�kd@mdpdd 0d�LdQUdpSocket::hasPendingDatagrams() called on a QUdpSocket when not in QUdpSocket::BoundState �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} �} ~ QUdpSocket::pendingDatagramSize() called on a QUdpSocket when not in QUdpSocket::BoundState QUdpSocket::readDatagram() called on a QUdpSocket when not in QUdpSocket::BoundState QTcpServer newConnection() QTcpServer::setSocketDescriptor() called when already listening 8 d��d��dddd�hd��d@�dL d |d�{d0|d��d�d�d�d$�d�d0�d6�d�d �d��dQTcpServer::listen() called when already listening 5 ) g [ � � � � QLocalSocket connected() disconnected() socketError error(QLocalSocket::LocalSocketError) socketState stateChanged(QLocalSocket::LocalSocketState) _q_notified() _q_canWrite() _q_pipeClosed() _q_emitReadyRead() � d��d�d��d�d�d�d�d$�d�d0�d6�d��dT�dp�dZ�d�d�df�dl�d0�dP�dp�d��d��d��d��d �dQLocalSocket::SocketError( QLocalSocket::UnknownSocketError QLocalSocket::UnsupportedSocketOperationError QLocalSocket::ConnectionError QLocalSocket::DatagramTooLargeError QLocalSocket::SocketTimeoutError QLocalSocket::SocketResourceError QLocalSocket::SocketAccessError QLocalSocket::ServerNotFoundError QLocalSocket::PeerClosedError QLocalSocket::ConnectionRefusedError QLocalSocket::SocketState( QLocalSocket::ClosingState QLocalSocket::ConnectedState QLocalSocket::ConnectingState QLocalSocket::UnconnectedState QLocalServer newConnection() _q_onNewConnection() %1: Name error QLocalServer::listen QLocalServer::listen() called when already listening � d@�d8 d��dЗd��d@�d�d�d�d$�d*�d0�d6�d�d��d��dQTcpSocketAPI: WinSock v2.0 initialization failed. 2activated(HANDLE) 1_q_notified() � d��d��d��d��d��d�d�d$�d�d0�d6�d%1: Unknown error %2 %1: Invalid name %1: Connection error 1_q_emitReadyRead() 1_q_pipeClosed() 2canWrite() 1_q_canWrite() � d��d��d��d�d�d�d�d$�d�d0�d6�d��dQLocalSocket::waitForDisconnected isn't supported for write only pipes. X d��d��d��d��dQLocalSocketPrivate::completeAsyncRead QLocalSocketPrivate::startAsyncRead QLocalSocket::waitForReadyRead WaitForSingleObject failed with error code %d. \.\pipe\ QLocalSocket::connectToServer %1: %2 QLocalServerPrivate::addListener 1_q_onNewConnection() QLocalServerPrivate::_q_onNewConnection ;