www.group-ib.com
172.67.69.208AS13335 · US- Content Inspectionsuspicious
- Browser Analysisclean
- Network & Hostingclean
- Threat Intelligenceclean
- Related Infrastructureclean
- Domain Intelligenceunknown
- TLS Fingerprintunknown
Be careful — warning signs found
AutomatedIts form submits what you type to a different website than the one you are on. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.
What to do
Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.
"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.
Findings
Strongest firstOur Content Inspection engine downloaded the file this URL serves and analyzed it. The payload shows traits commonly seen in malware. Treat it as unsafe until verified.
Success
SHA-256 599a96471d35c485d6a8ca1d21ec2b303d17568529d958eded8a5b8928ad70cd
The page dynamically injected scripts from other domains. This is extremely common on legitimate sites (CDNs, analytics, asset domains) and is shown for context only.
Analyst noteNoisy by itself — a CDN/asset domain (e.g. a brand's own *.githubassets.com) is normal. Only meaningful if the source domain is unrelated/suspicious.
Infrastructure
- IP
- 172.67.69.208CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
- TLS
- CN=WE1, O=Google Trust Services, C=US · expires Nov 23, 2026
WHOIS
- Registrar
- GoDaddy.com, LLC
- Created
- Oct 2, 2008
- Expires
- Oct 2, 2027
- Nameservers
- dora.ns.cloudflare.comtom.ns.cloudflare.com
Hashes & fingerprints
Page capture
LiveTitle “ClickFix Attack: How ClickFix Malware Scam Works | Group-IB”
Engines
7 · time to verdictPage
- HTTP
- 200 · Completed
- Title
- ClickFix Attack: How ClickFix Malware Scam Works | Group-IB
- Load
- 9.63 s · 221 requests