ClickGrab Threat Analysis Report - 2026-05-20
Generated on 2026-05-20 02:03:52
Executive Summary
- Total sites analyzed: 100
- Sites with malicious content: 22
- Unique domains encountered: 2,335
- Total URLs extracted: 9,281
- PowerShell download attempts: 2
- Clipboard manipulation instances: 101
Domain Analysis
Most Frequently Encountered Domains
- bharatnamkeens.com: 405 occurrences
- baovechuyennghiep.baovengayvadem.com: 348 occurrences
- www.maheshwaree.com: 320 occurrences
- 98.70.13.131: 309 occurrences
- fudgeshop.com.au: 265 occurrences
- picsera.com: 226 occurrences
- 18.176.47.246: 218 occurrences
- adturekorea.co.kr: 214 occurrences
- scillarodriguez.com: 199 occurrences
- www.ccera-icar.org: 178 occurrences
- www.evodigital.com.au: 156 occurrences
- www.creatorssky.com: 156 occurrences
- devblog.ezeelogin.com: 126 occurrences
- www.dorper.com.au: 125 occurrences
- picsera.sirv.com: 121 occurrences
URL Pattern Analysis
reCAPTCHA imagery
11 occurrences across 8 distinct URLs
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png(2 times)https://www.google.com/recaptcha/api.js(2 times)https://2captcha.com/dist/web/assets/google-privacy-policy-Cb0CGVRT.svg(2 times)https://pizzabyte.com.au/smartdetection/deviceverification/CF/path/captcha(1 times)https://www.google.com/recaptcha/api.js?hl=&render=6Lf7uxYsAAAAANagtTWlY2ET8HF8nbfMf4-ePcWm(1 times)- ...and 3 more distinct URLs
Font resources
70 occurrences across 60 distinct URLs
https://fonts.gstatic.com(4 times)https://18.176.47.246/wp-content/plugins/vk-post-author-display/vendor/vektor-inc/font-awesome-versions/src/font-awesome/css/all.min.css?ver=7.1.0(2 times)https://adturekorea.co.kr/js/font-awesome/css/font-awesome.min.css?ver=220620(2 times)https://use.fontawesome.com/releases/v5.6.3/css/all.css(2 times)https://adturekorea.co.kr/theme/FT_WEB20/css/icofont.min.css(2 times)- ...and 55 more distinct URLs
CDN hosted scripts
10 occurrences across 10 distinct URLs
https://cdn.jsdelivr.net/npm/three@0.167.0/build/three.module.js(1 times)https://cdn.jsdelivr.net/npm/three@0.167.0/examples/jsm/(1 times)https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1(1 times)https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.css?ver=6.8.5(1 times)https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js?ver=6.0.8(1 times)- ...and 5 more distinct URLs
Google resources
123 occurrences across 68 distinct URLs
https://bharatnamkeens.com/wp-content/plugins/widget-google-reviews/assets/img/guest.png(32 times)https://www.google.com/s2/favicons?sz=128&domain=${encodeURIComponent(13 times)https://www.googletagmanager.com/gtm.js?id=(4 times)https://www.google(3 times)https://fonts.googleapis.com(2 times)- ...and 63 more distinct URLs
Suspicious Keyword Analysis
Total Keywords Found: 530 (113 unique)
Keyword Categories
Social Engineering
46 unique keywords
exec /i https://pizzabyte.com.au/smartdetection/deviceverification/CF/path/captcha";Verification Hashverification_dataCommand line: [2]Removing applicationsRemoving filesRemoving foldersFile: [1], Section: [2], Key: [3], Value: [4]Removing INI file entriesRemoving ODBC componentsRemoving system registry valuesKey: [1], Name: [2]Removing shortcutsFile: [1], Folder: [2]Registering modulesRemoving backup filesRollbackRemoving moved filesRollbackCleanupInitializing ODBC directoriesStarting servicesStopping servicesUnpublishing Qualified ComponentsUnpublishing product informationThe wizard was interrupted before [ProductName] could be completely installed.UnmoveFilesUnpublishing product featuresUnregister class serversCreating IIS Virtual Roots...UnpublishProductAppId: [1]{{, AppType: [2]}}Unregistering COM+ Applications and ComponentsUnregistering extension serversUnregistering fontsUnregistering MIME infoUnregistering program identifiersUnregistering type librariesWriting INI file valuesKey: [1], Name: [2], Value: [3]Writing system registry valuesAdvertising applicationRemoving IIS Virtual Roots...caCreateVRoots{&TahomaBold10}Welcome to the InstallShield Wizard for [ProductName]caRemoveVRoots1ISCHECKFORPRODUCTUPDATESAllUsersApplicationUsersNoAgreeToLicenseChange_IsMaintenanceCloseRestartRestartManagerOptionTypicalSetupType_IsSetupTypeMinDisplay_IsBitmapDlg{3B59CBE2-36D2-452F-B123-685CEEEB7456}[1]ALLUSERSARPPRODUCTICON.exeARPPRODUCTICON30DWUSINTERVALCE8B87EF8EFC67DF99ACF778AEBB978FDEEB808FFEAB07BFCEBC872FEE9BD088CECCA08FC9ACDWUSLINKTahoma8DefaultUIFontInstallShield for Windows InstallerDialogCaptionMinimalDisplayNameCustomThe InstallShield(R) Wizard will create a server image of [ProductName] at a specified network location. To continue, click Next.DisplayNameMinimalCosting COM+ application: [1]DisplayNameTypicalSetupErrorErrorDialog100INSTALLLEVEL0ISVROOT_PORT_NOInstalling COM+ application: [1]IS_COMPLUS_PROGRESSTEXT_COSTUninstalling COM+ application: [1]IS_COMPLUS_PROGRESSTEXT_INSTALLA newer version of this application is already installed on this computer. If you wish to install this version, please uninstall the newer version first. Click OK to exit the wizard.IS_COMPLUS_PROGRESSTEXT_UNINSTALLReplacing %s with %s in %s...IS_PREVENT_DOWNGRADE_EXITCosting XML files...IS_PROGMSG_TEXTFILECHANGS_REPLACECreating XML file %s...IS_PROGMSG_XML_COSTINGPerforming XML file changes...IS_PROGMSG_XML_CREATE_FILERemoving XML file %s...IS_PROGMSG_XML_FILESRolling back XML file changes...IS_PROGMSG_XML_REMOVE_FILEUpdating XML file %s...IS_PROGMSG_XML_ROLLBACK_FILESYour Company NameIS_PROGMSG_XML_UPDATE_FILEIS_SQLSERVER_AUTHENTICATIONsaIS_SQLSERVER_USERNAMEARInstallChoiceCreating application pool %sManufacturer12345<###-%%%%%%%>@@@@@PIDTemplateCreating application Pools...PROGMSG_IIS_CREATEAPPPOOLCreating IIS virtual directory %sPROGMSG_IIS_CREATEAPPPOOLSCreating IIS virtual directories...PROGMSG_IIS_CREATEVROOTCreating web service extensionPROGMSG_IIS_CREATEVROOTSCreating web service extensions...PROGMSG_IIS_CREATEWEBSERVICEEXTENSIONCreating IIS website %sPROGMSG_IIS_CREATEWEBSERVICEEXTENSIONSCreating IIS websites...PROGMSG_IIS_CREATEWEBSITEExtracting information for IIS virtual directories...PROGMSG_IIS_CREATEWEBSITESExtracted information for IIS virtual directories...PROGMSG_IIS_EXTRACTRemoving application po ! " $ 0 / &