Countdown - Phishing Kit Type

#CountDown #PhishingKitType #phishing #phishingkit

@ActorExpose documented one of the Countdown till email shutdown phishing kits. It is a pretty common looking phish that has a red countdown clock until your email shuts down, unless of course you give the attacker your password.  It also utilizes

"HTML Encryption provided by www.webtoolhub.com"

which we all know is just simple HTML 101 encode/decoding

document.write(unescape('%3c%74%72%3e



folder structure
\index.html
\connect.html
\pass.php    (contains the HTML encoded login page)
\post.php    (contains the mailer)












example 1:
md5 2ca09b28ee6fc3d355fc9de2159b3579
https://www.virustotal.com/#/file/e18d5fb9ca632393aeff9f8b504615f850c21df770a44ed6c6461501589dc96f/detection
hxxp://sunworld1[.]000webhostapp[.]com

References
https://twitter.com/ActorExpose/status/1133102201864359939

Comments

Popular Posts