Threat Intelligence Report
100
Total Sites Analyzed
31
Malicious Sites
31.0% detection rate
10
PowerShell Commands
63
Clipboard Hijacks
543
Avg Threat Score
Attack Pattern Analysis
11
High Risk Commands
393
Base64 Encoded
0
Obfuscated JS
32
Inline JS Redirects
6
External JS Chains
23
Redirect Follows
Top Indicators/Keywords
robot (6)
hidden (6)
failed_to_retrieve (4)
Robot (4)
captcha (2)
CAPTCHA Verification (2)
Verification ID (2)
Ray ID (2)
I am not a robot (2)
You will observe (2)
CAPTCHA (2)
CAPTCHA-verificatie-ID (2)
Verification (2)
verification (2)
verification-id (2)
Malicious Sites Detected
Click on a site to view detailed analysishttp://192.155.93.247:3101/
1025 indicators detected
Score: 8528
6
base64
3
suspicious keywords
🔍 Suspicious Keywords 3
robot
Robot
hidden
🌐 Extracted URLs 190
https://gmpg.org/xfn/11
https://yoast.com/wordpress/plugins/seo/
https://www.ccera-icar.org/
https://www.ccera-icar.org/
https://www.ccera-icar.org/wp-content/uploads/2022/08/Frame-3.png
https://3.18.128.17/
791 indicators detected
Score: 6077
Redirect Chain
5
base64
3
redirect chains
3
redirect follows
3
suspicious keywords
🔍 Suspicious Keywords 3
robot
Robot
hidden
🌐 Extracted URLs 63
https://gmpg.org/xfn/11
https://3.18.128.17/feed/
https://3.18.128.17/comments/feed/
https://api.w.org/
https://3.18.128.17/wp-json/
🔁 External JavaScript Redirect Chains
Showing first 2 of 3 chains (truncated for performance)
Script: https://3.18.128.17/wp-content/plugins/wpvr/public/js/video.js?ver=1
Type: script_src
Destination (first appearance): https://vjs.zencdn.net/vttjs/0.14.1/vtt.min.js
d in
var script = document.createElement('script');
script.src = this.options_['vtt.js'] || 'https://vjs.zencdn.net/vttjs/0.14.1/vtt.min.js';
script.onload = function () {
/**
* Fired …Script: https://3.18.128.17/wp-content/plugins/wpvr/public/lib/videojs-vr/videojs-vr.js?ver=1
Type: base64_payload
Destination (first appearance): https://www.w3.org/2000/svg
<?xml version="1.0" encoding="UTF-8" standalone="no"?> <svg width="198px" height="240px" viewBox="0 0 198 240" version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:sketch="http://www.bohemiancodi…
🛰️ Redirect Follower Findings (3)
Source: external_js
Method: script_src
d in
var script = document.createElement('script');
script.src = this.options_['vtt.js'] || 'https://vjs.zencdn.net/vttjs/0.14.1/vtt.min.js';
script.onload = function () {
/**
* Fired …Status: ok
/* videojs-vtt.js - v0.14.1 (https://github.com/gkatsev/vtt.js) built on 10-04-2018 */
!function(a){if("object"==typeof exports&&"undefined"!=typeof module)module.exports=a();else if("function"==typeof define&&define.amd)define([],a);else{var b;b="undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self?self:this,b.vttjs=a()}}(function(){return function a(b,c,d){function e(g,h){if(!c[g]){if(!b[g]){var i="function"==typeof require&&require;if(!h&&i)return i(g,!0... [truncated]Source: external_js
Method: base64_payload
Original: http://www.w3.org/2000/svg
Final: https://www.w3.org/2000/svg
Chain: http://www.w3.org/2000/svg
<?xml version="1.0" encoding="UTF-8" standalone="no"?> <svg width="198px" height="240px" viewBox="0 0 198 240" version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:sketch="http://www.bohemiancodi…
Status: ok
<!DOCTYPE html><html lang="en-US"><head><title>Just a moment...</title><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=Edge"><meta name="robots" content="noindex,nofollow"><meta name="viewport" content="width=device-width,initial-scale=1"><meta http-equiv="content-security-policy" content="default-src 'none'; script-src 'nonce-ZKKyWhwxhG40PCZRrxiHux' 'unsafe-eval' https://challenges.cloudflare.com; script-s... [truncated]
Source: external_js
Method: base64_payload
Original: http://www.videolan.org/x264.html
Chain: http://www.videolan.org/x264.html