Account Tools - Phishing Kit Author

#AccountTools #phishing #phishingkit #SwiftMailer
There is a phishing kit being used to steal passwords from Yahoo, Outlook, and Gmail users. The kit may contain folders like

.zip\yinput
.zip\outlook
.zip\ginput
.zip\products
.zip\lib
.zip\classes\Swift
.zip\dependency_map



This folder ( .zip\classes\Swift ) indicates it uses the Swift Mailer ( SwiftMailer (c) 2004-2009 Chris Corbyn ) to send the malicious emails to the drop accounts.

The Phishing Kit Author calls themself "Account Tools"
Here are several related links to them (some still alive, some not)
- https://www.youtube.com/watch?v=2T1HJwkYn74
- http://rghost.net/55166139
- http://rghost.net/55166141
- http://rghost.net/55166140
- http://spamboard.su
- http://accounttools.cc

Their youtube page says
"Advanced Scam page for hacking any email and password, mailer, smtp, cpanel all tools"
"Deme Bin Published on May 14, 2014"
"All in one scampage, Yahoo, Gmail, Hotmail Hacking Special Mailer and more visit our"

Here are 2 examples of #phishingkit matching this Phishing Kit Author
example 1
found 5/23/2019
md5 aa4586a64637bc5cf4b9b91916eef3be
http://artisbycarolburns.co.uk/index/Y@FMT.zip
https://www.virustotal.com/#/file/6c84b2442ce3c00ed63e39f243f1dfddb1f8000cb7b741f693f3f5af45460f44/detection
screenshot: https://imgur.com/a/IEPgUsO


example 2
from 8/2018
md5 8d4c3f85ab9b00ea7b198fc1545c04b0
http://toperfection.co/aa/tire_update.zip
https://www.virustotal.com/#/file/137c8bfe24620c8416bff55cf4c0a9a044968d42fb2cb29f2fe7ddc2366d50fb/detection

These kits will usually contain a email address in the url and that email address will be used to determine in php code which sub-folder to redirect the user to (e.g. if the victim has a @yahoo.com email they get redirected to the "yinput" folder, if they have a @gmail.com email they get redirected to the "ginput" folder)

The sub-folder usually contains an "id.php" file that is the actual phishing page.

The folder may contain the following files
.country.inc.php (heavily obfuscated, defines helper functions like 'SendAttach, Swift, Email')
address.php (contains the #threatactoremail who purchased / downloaded the kit)
The folder may also contains file such as 
"FMT@YAHOO.txt" 
which will be used to record locally on the web server all the victim passwords


Scampage Demo and Tutorial: https://www.youtube.com/watch?v=2T1HJ...
Mailer Tutorial: https://www.youtube.com/watch?v=IHerw...
There was also a 
rename.php 
file that may log to the text file above and in both cases I saw contained a country timezone of Africa
date_default_timezone_set("Africa/Lagos");
The kit may also contain a READ ME.txt file which has this content

-----------------------------------
READ ME.TXT file in the kit
-----------------------------------
NOTE: DO NOT EDIT ANYTHING JUST CHANGE THE EMAIL IN "address.php" IF YOU TOUCH ANYTHING YOU MAY RUIN THE WHOLE SCRIPT
1. IN THIS TUTORIAL YOU WILL LEARN HOW THIS ALL IN ONE SCAMPAGE WORKS
IT USE ONE LINK, BUT REDIRECTS TO THE A SCAMPAGE RELATING TO THE EMAIL OF THE USER/PERSON YOU EMAIL TO.
E.G IF I USE http://scam-page.com/index.php?userid=#e-mail# as link in my message.
my mailer or sendblaster would change #e-mail# to user1@yahoo.com assuming that email is valid. so if your email list is 3 emails
1. you@yahoo.com
2. me@hotmail.com
3. them@gmail.com
4. others@163.com or anything@example.com
when each and everyone recieve the email: The mailer or script would change
#e-mail# to the person who receives the email so:
when you check your email the link will be http://scam-page.com/index.php?userid=you@yahoo.com
When I check my email it will be
http://scam-page.com/index.php?userid=me@hotmail.com
FINALLY:
WHEN USER CLICK THE LINK IN THE MESSAGE THE SCAM-PAGE WILL OPEN YAHOO SCAM PAGE IF THE USER IS USING YAHOO. SO YOU WILL BE DIRECTED TO YAHOO AND I WILL BE DIRECTED TO HOTMAIL BECAUSE MY EMAIL IS ME@HOTMAIL.COM AND YOU WILL BE YAHOO BECAUSE YOUR EMAIL IS YOU@YAHOO.COM
FOR MORE INFORMATION:
WATCH THE VIDEO ON YOUTUBE TO SEE DEMO:
For the mailer visit: http://accounttools.cc/smtp_mailer.zip
For another type of mailer no smtp: http://accounttools.cc/normal_mailer.zip
Scampage Demo and Tutorial: https://www.youtube.com/watch?v=2T1HJwkYn74
Mailer Tutorial: https://www.youtube.com/watch?v=IHerwW9VXog
For Scam page that works with it: visit http://accounttools.cc/source_update.zip



additional potential examples of this phishing kit author
http://phishtank.net/phish_detail.php?phish_id=5972671 ( groutpro[.]com[.]au )
https://www.phishtank.com/phish_detail.php?phish_id=5905669 ( supersoca[.]com )
https://urlscan.io/result/6517b93d-3b89-450f-a2ef-e57c626d49cd/ ( prenocisca-kocar[.]si )


Comments

  1. Clearing of Gmail information from the account is only done in case of the fix of some glitch or error for that the user should open the device settings application after that the user should click the option “APPS and notifications” further should click “Gmail” and should then go to “storage” after that the user should click the option “clear data” if required then for more information the user should take help from the Gmail experts.
    Gmail Help UK

    ReplyDelete
  2. ****Contact Me****
    *ICQ :748957107
    *Gmail :taimoorh944@gmail.com
    *Telegram :@James307


    SELLING Fresh and valid USA ssn fullz
    99% connectivity with quality
    *If you have any trust issue before any deal you may get few to test
    *Every leads are well checked and available 24 hours
    *Fully cooperate with clients
    *Any invalid info found will be replaced
    *Good credit score above 700 every fullz
    *Payment (BTC&Paypal)
    *Fullz will be available according to demand i.e (format,specific state,specific zip code & specifc name etc..)

    *Format of Fullz/leads/profiles
    °First & last Name
    °SSN
    °DOB
    °(DRIVING LICENSE NUMBER)
    °ADDRESS
    (ZIP CODE,STATE,CITY)
    °PHONE NUMBER
    °EMAIL ADDRESS
    °Relative Details
    °Employment status
    °Previous Address


    $2 for each fullz/lead
    (Price can be negotiable if order in bulk)


    OTHER SERVICES ProvIDING

    *(Dead Fullz)
    *(Email leads with Password)

    *(Dumps track 1 & 2 with pin and without pin)

    *Hacking Tutorials
    *Smtp Linux

    *Contact soon!
    *Hope for a long term Business
    *Thank You!

    ****Contact Me****
    *ICQ :748957107
    *Gmail :taimoorh944@gmail.com
    *Telegram :@James307

    ReplyDelete
  3. Update April 20, 2021 => Sell CVV/Passport/Fullz/eGift
    Hi guys!
    Call me Jack...
    Update April 20, 2021 <12:01 PM>
    LIST CREDIT CARD AND GIFT CARD

    ***** CREDIT CARD
    USA (Best Seller)
    UNITED KINGDOM (Best Seller)
    AUSTRALIA
    CANADA
    FRANCE
    GERMANY
    CHILE
    TAIWAN
    SPAIN
    JAPAN
    ITALY
    BRAZIL

    ***** GIFT CARD
    AMAZON (Best Seller)
    ITUNES (Best Seller)
    BESTBUY
    STARBUCK
    EBAY
    XBOX (Best Seller)
    WALMART
    TARGET

    ***** DEAD FULLZ INFORMATION
    US/UK FULLZ RANDOM BANK
    US/UK FULLZ WITH ALL BANK (CHASE, HSBC, BARCLAYS, etc...)
    VALID PASSPORT - DRIVER'S LICENSE - NATIONAL INSURANCE NUMBER - SSN - DOB
    UPDATED NEW YORK, COLORADO, CALIFORNIA, TEXAS, RHODE ISLAND, ILLINOIS (DRIVER'S LICENSE, SSN, DOB)

    ***** DUMPS WITH PIN + CLONE CARD

    CONTACT ME TO BUY:
    ICQ NUMBER: 678924920
    TELEGRAM: @jackhieu or Link https://t.me/jackhieu (Recommend)
    WHATSAPP: +84774511893
    GMAIL: (ICQ678924920@GMAIL . COM)

    FOLLOW WEBSITE:
    https : / / sellcvvicq678924920 . blogspot . com (Clear space)


    THANK YOUR TIME!

    Tag:
    sell info ssn dob dl, Sell Info Fullz Company
    I Sell Info use it to do PUA and SBA
    Sell Info Fullz SBA
    cvv for sale,
    track 2 dumps, selling dumps cvv fullz,
    track 1 track 2 dumps, buy cc dumps,
    selling dumps with pin,
    dump cvv, track 1&2 dumps with pin,
    cc dumps free, track 1 and track 2 dumps,
    dump cc, fresh dumps, free cvv dumps, track 2 dumps for sale
    Black Market Stolen Credit Card Information cvv fullz dumps, buy cvv dumps verified seller,
    buy dumps online, buy fresh Dumps, credit card cvv information for sale, cvv fullz dumps,
    cvv2 shop, free dead fullz 2021, free fullz 2021, free fullz info, Fresh fullz, fullz shop,
    Legit Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,git Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,

    ReplyDelete
  4. Update April 28, 2021 => Sell CVV/Passport/Fullz/eGift
    Hi guys!
    Call me Jack...
    Update April 28, 2021 <11:36 AM>
    LIST CREDIT CARD AND GIFT CARD

    ***** CREDIT CARD
    USA (Best Seller)
    UNITED KINGDOM (Best Seller)
    AUSTRALIA
    CANADA
    FRANCE
    GERMANY
    CHILE
    TAIWAN
    SPAIN
    JAPAN
    ITALY
    BRAZIL

    ***** GIFT CARD
    AMAZON (Best Seller)
    ITUNES (Best Seller)
    BESTBUY
    STARBUCK
    EBAY
    XBOX (Best Seller)
    WALMART
    TARGET

    ***** DEAD FULLZ INFORMATION
    US/UK FULLZ RANDOM BANK
    US/UK FULLZ WITH ALL BANK (CHASE, HSBC, BARCLAYS, etc...)
    VALID PASSPORT - DRIVER'S LICENSE - NATIONAL INSURANCE NUMBER - SSN - DOB
    UPDATED NEW YORK, COLORADO, CALIFORNIA, TEXAS, RHODE ISLAND, ILLINOIS (DRIVER'S LICENSE, SSN, DOB)

    ***** DUMPS WITH PIN + CLONE CARD

    CONTACT ME TO BUY:
    ICQ NUMBER: 678924920
    TELEGRAM: @jackhieu or Link https://t.me/jackhieu (Recommend)
    WHATSAPP: +84774511893
    GMAIL: (ICQ678924920@GMAIL . COM)

    FOLLOW WEBSITE:
    https : / / sellcvvicq678924920 . blogspot . com (Clear space)


    THANK YOUR TIME!

    Tag:
    sell info ssn dob dl, Sell Info Fullz Company
    I Sell Info use it to do PUA and SBA
    Sell Info Fullz SBA
    cvv for sale,
    track 2 dumps, selling dumps cvv fullz,
    track 1 track 2 dumps, buy cc dumps,
    selling dumps with pin,
    dump cvv, track 1&2 dumps with pin,
    cc dumps free, track 1 and track 2 dumps,
    dump cc, fresh dumps, free cvv dumps, track 2 dumps for sale
    Black Market Stolen Credit Card Information cvv fullz dumps, buy cvv dumps verified seller,
    buy dumps online, buy fresh Dumps, credit card cvv information for sale, cvv fullz dumps,
    cvv2 shop, free dead fullz 2021, free fullz 2021, free fullz info, Fresh fullz, fullz shop,
    Legit Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,git Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,


    VERIFIED SELLER BY ADMIN

    ReplyDelete
  5. Update May 3, 2021 => SELL FULLZ/DL/SSN/DOB/DUMPS
    Hi guys!
    Call me Jack...
    Update May 3, 2021 <10:39 AM>
    LIST CREDIT CARD AND GIFT CARD

    ***** CREDIT CARD
    USA (Best Seller)
    UNITED KINGDOM (Best Seller)
    AUSTRALIA
    CANADA
    FRANCE
    GERMANY
    CHILE
    TAIWAN
    SPAIN
    JAPAN
    ITALY
    BRAZIL

    ***** GIFT CARD
    AMAZON (Best Seller)
    ITUNES (Best Seller)
    BESTBUY
    STARBUCK
    EBAY
    XBOX (Best Seller)
    WALMART
    TARGET

    ***** DEAD FULLZ INFORMATION
    US/UK FULLZ RANDOM BANK
    US/UK FULLZ WITH ALL BANK (CHASE, HSBC, BARCLAYS, etc...)
    VALID PASSPORT - DRIVER'S LICENSE - NATIONAL INSURANCE NUMBER - SSN - DOB
    UPDATED NEW YORK, COLORADO, CALIFORNIA, TEXAS, RHODE ISLAND, ILLINOIS (DRIVER'S LICENSE, SSN, DOB)

    ***** DUMPS WITH PIN + CLONE CARD

    CONTACT ME TO BUY:
    ICQ NUMBER: 678924920
    TELEGRAM: @jackhieu or Link https://t.me/jackhieu (Recommend)
    WHATSAPP: +84774511893
    GMAIL: (ICQ678924920@GMAIL . COM)

    FOLLOW WEBSITE:
    https : / / sellcvvicq678924920 . blogspot . com (Clear space)


    THANK YOUR TIME!

    Tag:
    sell info ssn dob dl, Sell Info Fullz Company
    I Sell Info use it to do PUA and SBA
    Sell Info Fullz SBA
    cvv for sale,
    track 2 dumps, selling dumps cvv fullz,
    track 1 track 2 dumps, buy cc dumps,
    selling dumps with pin,
    dump cvv, track 1&2 dumps with pin,
    cc dumps free, track 1 and track 2 dumps,
    dump cc, fresh dumps, free cvv dumps, track 2 dumps for sale
    Black Market Stolen Credit Card Information cvv fullz dumps, buy cvv dumps verified seller,
    buy dumps online, buy fresh Dumps, credit card cvv information for sale, cvv fullz dumps,
    cvv2 shop, free dead fullz 2021, free fullz 2021, free fullz info, Fresh fullz, fullz shop,
    Legit Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,git Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,


    VERIFIED SELLER BY ADMIN

    ReplyDelete
  6. FRESH&VALID SPAMMED USA DATABASE/FULLZ/LEADS

    ****Contact****
    *ICQ :748957107
    *Gmail :fullzvendor111@gmail.com
    *Telegram :@James307
    *Skype : Jamesvince$
    <><><><><><><>
    USA SSN FULLZ WITH ALL PERSONAL DATA+DL NUMBER
    -FULLZ FOR PUA & SBA
    -FULLZ FOR TAX REFUND
    $2 for each fullz/lead with DL num
    $1 for each SSN+DOB
    $5 for each with Premium info
    ID's Photos For any state (back & front)
    (Price can be negotiable if order in bulk)
    <><><><><><><><><><><>
    +High quality and connectivity
    +If you have any trust issue before any deal you may get few to test
    +Every leads are well checked and available 24 hours
    +Fully cooperate with clients
    +Any invalid info found will be replaced
    +Payment Method(BTC,USDT,ETH,LTC & PAYPAL)
    +Fullz available according to demand too i.e (format,specific state,specific zip code & specifc name etc..)
    <><><><><><><><><><>
    +US cc Fullz
    +(Dead Fullz)
    +(Email leads with Password)
    +(Dumps track 1 & 2 with pin and without pin)
    +Hacking & Carding Tutorials
    +Smtp Linux
    +Safe Sock
    +Server I.P's
    +HQ Emails with passwords
    <><><><><><><><>
    *Let's do a long term business with good profit
    *Contact for more details & deal

    ReplyDelete

Post a Comment

Popular Posts