I was searching for information about a domain for Dandelion Sprout's antimalware, and I came across these spammy results.
I think this is the second or third time I have seen this.

"links.hokaoneone.emailpowerreviews.com blocked by Anti ..." is clearly based on the GitHub issue I was researching this for: https://github.com/DandelionSprout/adfilt/issues/1226

Searching for "happy ghast harnesses float under the ghast" turns up a ton more of these websites.

So something is scraping the internet for random keywords in order to fill the search results with malicious websites.

Clicking on one of these domains redirects the user to a fake CAPTCHA asking the user to allow notifications (typical scam); in this case the domain is humanverify.co.in. uBlock Origin's ads list and EasyList both block earlier stages of the redirection. Subliminal messaging to use uBlock Origin.

I noticed the blogspot domain loaded a heavily obfuscated script from kettledroopingcontinuation.com.

Here is the URL: https://kettledroopingcontinuation[.]com/4d/be/e5/4dbee55e59fc95ea4356dbb197f2132c.js
And here is a copy of that script: https://gist.github.com/iam-py-test/375bc55e52d1cde68520fdc9afa85705

Searching for that domain returns a few interesting results:

I had never heard of ApateWeb, but searching for it turns up this report:

Unit 42 researchers discovered a large-scale campaign we call ApateWeb that uses a network of over 130,000 domains to deliver scareware, potentially unwanted programs (PUPs) and other scam pages. Among these PUPs, we have identified several adware programs including a rogue browser and different browser extensions.

https://unit42.paloaltonetworks.com/apateweb-scareware-pup-delivery-campaign/

kettledroopingcontinuation isn't mentioned in that report, and I haven't read it in depth, so I do not know if it aligns with what we are seeing here.

kettledroopingcontinuation.com - Malicious script host

The initial post is promoting shapescan[.]pt, which is supposedly the domain for ShapeScan. However, a lot of people report the domain redirecting them to malicious websites when using a mobile device. While I would not put a ton of faith in whatever "cursor" is, this does support this domain being malicious.

Cursor (code editor) - Wikipedia

@rusty__shackleford I knew it looked like AI generated text.
Seems like an odd choice to use for malware analysis, though.

@iampytest1

An odd choice indeed, I am disappointed in them for using it. Poor ethics, bad models and hallucinations aside: As someone still learning, I brushed shoulders with AI tools a few times, constantly reviewing myself I noticed it resulted in stunting my learning, dulled sharpness, and so I dumped them and haven't looked back. Saw you or someone else make the joke to swap "AI" with "stimulant" or "cocaine".

I would agree, don't do cocaine kids, you just *feel* like you're working fast.