#AccountTools #phishing #phishingkit #SwiftMailer
There is a phishing kit being used to steal passwords from Yahoo, Outlook, and Gmail users. The kit may contain folders like
.zip\yinput
.zip\outlook
.zip\ginput
.zip\products
.zip\lib
.zip\classes\Swift
.zip\dependency_map
This folder ( .zip\classes\Swift ) indicates it uses the Swift Mailer ( SwiftMailer (c) 2004-2009 Chris Corbyn ) to send the malicious emails to the drop accounts.
The Phishing Kit Author calls themself "Account Tools"
Here are several related links to them (some still alive, some not)
- https://www.youtube.com/watch?v=2T1HJwkYn74
- http://rghost.net/55166139
- http://rghost.net/55166141
- http://rghost.net/55166140
- http://spamboard.su
- http://accounttools.cc
Their youtube page says
"Advanced Scam page for hacking any email and password, mailer, smtp, cpanel all tools"
"Deme Bin Published on May 14, 2014"
"All in one scampage, Yahoo, Gmail, Hotmail Hacking Special Mailer and more visit our"
Here are 2 examples of #phishingkit matching this Phishing Kit Author
example 1
found 5/23/2019
md5 aa4586a64637bc5cf4b9b91916eef3be
http://artisbycarolburns.co.uk/index/Y@FMT.zip
https://www.virustotal.com/#/file/6c84b2442ce3c00ed63e39f243f1dfddb1f8000cb7b741f693f3f5af45460f44/detection
screenshot: https://imgur.com/a/IEPgUsO
example 2
from 8/2018
md5 8d4c3f85ab9b00ea7b198fc1545c04b0
http://toperfection.co/aa/tire_update.zip
https://www.virustotal.com/#/file/137c8bfe24620c8416bff55cf4c0a9a044968d42fb2cb29f2fe7ddc2366d50fb/detection
These kits will usually contain a email address in the url and that email address will be used to determine in php code which sub-folder to redirect the user to (e.g. if the victim has a @yahoo.com email they get redirected to the "yinput" folder, if they have a @gmail.com email they get redirected to the "ginput" folder)
The sub-folder usually contains an "id.php" file that is the actual phishing page.
The folder may contain the following files
.country.inc.php (heavily obfuscated, defines helper functions like 'SendAttach, Swift, Email')
address.php (contains the #threatactoremail who purchased / downloaded the kit)
The folder may also contains file such as
"FMT@YAHOO.txt"
which will be used to record locally on the web server all the victim passwords
Scampage Demo and Tutorial: https://www.youtube.com/watch?v=2T1HJ...
Mailer Tutorial: https://www.youtube.com/watch?v=IHerw...
There was also a
rename.php
file that may log to the text file above and in both cases I saw contained a country timezone of Africa
date_default_timezone_set("Africa/Lagos");
The kit may also contain a READ ME.txt file which has this content
-----------------------------------
READ ME.TXT file in the kit
-----------------------------------
NOTE: DO NOT EDIT ANYTHING JUST CHANGE THE EMAIL IN "address.php" IF YOU TOUCH ANYTHING YOU MAY RUIN THE WHOLE SCRIPT
1. IN THIS TUTORIAL YOU WILL LEARN HOW THIS ALL IN ONE SCAMPAGE WORKS
IT USE ONE LINK, BUT REDIRECTS TO THE A SCAMPAGE RELATING TO THE EMAIL OF THE USER/PERSON YOU EMAIL TO.
E.G IF I USE http://scam-page.com/index.php?userid=#e-mail# as link in my message.
my mailer or sendblaster would change #e-mail# to user1@yahoo.com assuming that email is valid. so if your email list is 3 emails
1. you@yahoo.com
2. me@hotmail.com
3. them@gmail.com
4. others@163.com or anything@example.com
when each and everyone recieve the email: The mailer or script would change
#e-mail# to the person who receives the email so:
when you check your email the link will be http://scam-page.com/index.php?userid=you@yahoo.com
When I check my email it will be
http://scam-page.com/index.php?userid=me@hotmail.com
FINALLY:
WHEN USER CLICK THE LINK IN THE MESSAGE THE SCAM-PAGE WILL OPEN YAHOO SCAM PAGE IF THE USER IS USING YAHOO. SO YOU WILL BE DIRECTED TO YAHOO AND I WILL BE DIRECTED TO HOTMAIL BECAUSE MY EMAIL IS ME@HOTMAIL.COM AND YOU WILL BE YAHOO BECAUSE YOUR EMAIL IS YOU@YAHOO.COM
FOR MORE INFORMATION:
WATCH THE VIDEO ON YOUTUBE TO SEE DEMO:
For the mailer visit: http://accounttools.cc/smtp_mailer.zip
For another type of mailer no smtp: http://accounttools.cc/normal_mailer.zip
Scampage Demo and Tutorial: https://www.youtube.com/watch?v=2T1HJwkYn74
Mailer Tutorial: https://www.youtube.com/watch?v=IHerwW9VXog
For Scam page that works with it: visit http://accounttools.cc/source_update.zip
additional potential examples of this phishing kit author
http://phishtank.net/phish_detail.php?phish_id=5972671 ( groutpro[.]com[.]au )
https://www.phishtank.com/phish_detail.php?phish_id=5905669 ( supersoca[.]com )
https://urlscan.io/result/6517b93d-3b89-450f-a2ef-e57c626d49cd/ ( prenocisca-kocar[.]si )
Clearing of Gmail information from the account is only done in case of the fix of some glitch or error for that the user should open the device settings application after that the user should click the option “APPS and notifications” further should click “Gmail” and should then go to “storage” after that the user should click the option “clear data” if required then for more information the user should take help from the Gmail experts.
ReplyDeleteGmail Help UK
****Contact Me****
ReplyDelete*ICQ :748957107
*Gmail :taimoorh944@gmail.com
*Telegram :@James307
SELLING Fresh and valid USA ssn fullz
99% connectivity with quality
*If you have any trust issue before any deal you may get few to test
*Every leads are well checked and available 24 hours
*Fully cooperate with clients
*Any invalid info found will be replaced
*Good credit score above 700 every fullz
*Payment (BTC&Paypal)
*Fullz will be available according to demand i.e (format,specific state,specific zip code & specifc name etc..)
*Format of Fullz/leads/profiles
°First & last Name
°SSN
°DOB
°(DRIVING LICENSE NUMBER)
°ADDRESS
(ZIP CODE,STATE,CITY)
°PHONE NUMBER
°EMAIL ADDRESS
°Relative Details
°Employment status
°Previous Address
$2 for each fullz/lead
(Price can be negotiable if order in bulk)
OTHER SERVICES ProvIDING
*(Dead Fullz)
*(Email leads with Password)
*(Dumps track 1 & 2 with pin and without pin)
*Hacking Tutorials
*Smtp Linux
*Contact soon!
*Hope for a long term Business
*Thank You!
****Contact Me****
*ICQ :748957107
*Gmail :taimoorh944@gmail.com
*Telegram :@James307
Update April 20, 2021 => Sell CVV/Passport/Fullz/eGift
ReplyDeleteHi guys!
Call me Jack...
Update April 20, 2021 <12:01 PM>
LIST CREDIT CARD AND GIFT CARD
***** CREDIT CARD
USA (Best Seller)
UNITED KINGDOM (Best Seller)
AUSTRALIA
CANADA
FRANCE
GERMANY
CHILE
TAIWAN
SPAIN
JAPAN
ITALY
BRAZIL
***** GIFT CARD
AMAZON (Best Seller)
ITUNES (Best Seller)
BESTBUY
STARBUCK
EBAY
XBOX (Best Seller)
WALMART
TARGET
***** DEAD FULLZ INFORMATION
US/UK FULLZ RANDOM BANK
US/UK FULLZ WITH ALL BANK (CHASE, HSBC, BARCLAYS, etc...)
VALID PASSPORT - DRIVER'S LICENSE - NATIONAL INSURANCE NUMBER - SSN - DOB
UPDATED NEW YORK, COLORADO, CALIFORNIA, TEXAS, RHODE ISLAND, ILLINOIS (DRIVER'S LICENSE, SSN, DOB)
***** DUMPS WITH PIN + CLONE CARD
CONTACT ME TO BUY:
ICQ NUMBER: 678924920
TELEGRAM: @jackhieu or Link https://t.me/jackhieu (Recommend)
WHATSAPP: +84774511893
GMAIL: (ICQ678924920@GMAIL . COM)
FOLLOW WEBSITE:
https : / / sellcvvicq678924920 . blogspot . com (Clear space)
THANK YOUR TIME!
Tag:
sell info ssn dob dl, Sell Info Fullz Company
I Sell Info use it to do PUA and SBA
Sell Info Fullz SBA
cvv for sale,
track 2 dumps, selling dumps cvv fullz,
track 1 track 2 dumps, buy cc dumps,
selling dumps with pin,
dump cvv, track 1&2 dumps with pin,
cc dumps free, track 1 and track 2 dumps,
dump cc, fresh dumps, free cvv dumps, track 2 dumps for sale
Black Market Stolen Credit Card Information cvv fullz dumps, buy cvv dumps verified seller,
buy dumps online, buy fresh Dumps, credit card cvv information for sale, cvv fullz dumps,
cvv2 shop, free dead fullz 2021, free fullz 2021, free fullz info, Fresh fullz, fullz shop,
Legit Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,git Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,
Update April 28, 2021 => Sell CVV/Passport/Fullz/eGift
ReplyDeleteHi guys!
Call me Jack...
Update April 28, 2021 <11:36 AM>
LIST CREDIT CARD AND GIFT CARD
***** CREDIT CARD
USA (Best Seller)
UNITED KINGDOM (Best Seller)
AUSTRALIA
CANADA
FRANCE
GERMANY
CHILE
TAIWAN
SPAIN
JAPAN
ITALY
BRAZIL
***** GIFT CARD
AMAZON (Best Seller)
ITUNES (Best Seller)
BESTBUY
STARBUCK
EBAY
XBOX (Best Seller)
WALMART
TARGET
***** DEAD FULLZ INFORMATION
US/UK FULLZ RANDOM BANK
US/UK FULLZ WITH ALL BANK (CHASE, HSBC, BARCLAYS, etc...)
VALID PASSPORT - DRIVER'S LICENSE - NATIONAL INSURANCE NUMBER - SSN - DOB
UPDATED NEW YORK, COLORADO, CALIFORNIA, TEXAS, RHODE ISLAND, ILLINOIS (DRIVER'S LICENSE, SSN, DOB)
***** DUMPS WITH PIN + CLONE CARD
CONTACT ME TO BUY:
ICQ NUMBER: 678924920
TELEGRAM: @jackhieu or Link https://t.me/jackhieu (Recommend)
WHATSAPP: +84774511893
GMAIL: (ICQ678924920@GMAIL . COM)
FOLLOW WEBSITE:
https : / / sellcvvicq678924920 . blogspot . com (Clear space)
THANK YOUR TIME!
Tag:
sell info ssn dob dl, Sell Info Fullz Company
I Sell Info use it to do PUA and SBA
Sell Info Fullz SBA
cvv for sale,
track 2 dumps, selling dumps cvv fullz,
track 1 track 2 dumps, buy cc dumps,
selling dumps with pin,
dump cvv, track 1&2 dumps with pin,
cc dumps free, track 1 and track 2 dumps,
dump cc, fresh dumps, free cvv dumps, track 2 dumps for sale
Black Market Stolen Credit Card Information cvv fullz dumps, buy cvv dumps verified seller,
buy dumps online, buy fresh Dumps, credit card cvv information for sale, cvv fullz dumps,
cvv2 shop, free dead fullz 2021, free fullz 2021, free fullz info, Fresh fullz, fullz shop,
Legit Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,git Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,
VERIFIED SELLER BY ADMIN
Update May 3, 2021 => SELL FULLZ/DL/SSN/DOB/DUMPS
ReplyDeleteHi guys!
Call me Jack...
Update May 3, 2021 <10:39 AM>
LIST CREDIT CARD AND GIFT CARD
***** CREDIT CARD
USA (Best Seller)
UNITED KINGDOM (Best Seller)
AUSTRALIA
CANADA
FRANCE
GERMANY
CHILE
TAIWAN
SPAIN
JAPAN
ITALY
BRAZIL
***** GIFT CARD
AMAZON (Best Seller)
ITUNES (Best Seller)
BESTBUY
STARBUCK
EBAY
XBOX (Best Seller)
WALMART
TARGET
***** DEAD FULLZ INFORMATION
US/UK FULLZ RANDOM BANK
US/UK FULLZ WITH ALL BANK (CHASE, HSBC, BARCLAYS, etc...)
VALID PASSPORT - DRIVER'S LICENSE - NATIONAL INSURANCE NUMBER - SSN - DOB
UPDATED NEW YORK, COLORADO, CALIFORNIA, TEXAS, RHODE ISLAND, ILLINOIS (DRIVER'S LICENSE, SSN, DOB)
***** DUMPS WITH PIN + CLONE CARD
CONTACT ME TO BUY:
ICQ NUMBER: 678924920
TELEGRAM: @jackhieu or Link https://t.me/jackhieu (Recommend)
WHATSAPP: +84774511893
GMAIL: (ICQ678924920@GMAIL . COM)
FOLLOW WEBSITE:
https : / / sellcvvicq678924920 . blogspot . com (Clear space)
THANK YOUR TIME!
Tag:
sell info ssn dob dl, Sell Info Fullz Company
I Sell Info use it to do PUA and SBA
Sell Info Fullz SBA
cvv for sale,
track 2 dumps, selling dumps cvv fullz,
track 1 track 2 dumps, buy cc dumps,
selling dumps with pin,
dump cvv, track 1&2 dumps with pin,
cc dumps free, track 1 and track 2 dumps,
dump cc, fresh dumps, free cvv dumps, track 2 dumps for sale
Black Market Stolen Credit Card Information cvv fullz dumps, buy cvv dumps verified seller,
buy dumps online, buy fresh Dumps, credit card cvv information for sale, cvv fullz dumps,
cvv2 shop, free dead fullz 2021, free fullz 2021, free fullz info, Fresh fullz, fullz shop,
Legit Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,git Cvv Dumps Vendor, sell cc good dumps, Sell cvv cc fresh good,
VERIFIED SELLER BY ADMIN
FRESH&VALID SPAMMED USA DATABASE/FULLZ/LEADS
ReplyDelete****Contact****
*ICQ :748957107
*Gmail :fullzvendor111@gmail.com
*Telegram :@James307
*Skype : Jamesvince$
<><><><><><><>
USA SSN FULLZ WITH ALL PERSONAL DATA+DL NUMBER
-FULLZ FOR PUA & SBA
-FULLZ FOR TAX REFUND
$2 for each fullz/lead with DL num
$1 for each SSN+DOB
$5 for each with Premium info
ID's Photos For any state (back & front)
(Price can be negotiable if order in bulk)
<><><><><><><><><><><>
+High quality and connectivity
+If you have any trust issue before any deal you may get few to test
+Every leads are well checked and available 24 hours
+Fully cooperate with clients
+Any invalid info found will be replaced
+Payment Method(BTC,USDT,ETH,LTC & PAYPAL)
+Fullz available according to demand too i.e (format,specific state,specific zip code & specifc name etc..)
<><><><><><><><><><>
+US cc Fullz
+(Dead Fullz)
+(Email leads with Password)
+(Dumps track 1 & 2 with pin and without pin)
+Hacking & Carding Tutorials
+Smtp Linux
+Safe Sock
+Server I.P's
+HQ Emails with passwords
<><><><><><><><>
*Let's do a long term business with good profit
*Contact for more details & deal