Countdown - Phishing Kit Type
#CountDown #PhishingKitType #phishing #phishingkit
@ActorExpose documented one of the Countdown till email shutdown phishing kits. It is a pretty common looking phish that has a red countdown clock until your email shuts down, unless of course you give the attacker your password. It also utilizes
"HTML Encryption provided by www.webtoolhub.com"
which we all know is just simple HTML 101 encode/decoding
document.write(unescape('%3c%74%72%3e
folder structure
\index.html
\connect.html
\pass.php (contains the HTML encoded login page)
\post.php (contains the mailer)
example 1:
md5 2ca09b28ee6fc3d355fc9de2159b3579
https://www.virustotal.com/#/file/e18d5fb9ca632393aeff9f8b504615f850c21df770a44ed6c6461501589dc96f/detection
hxxp://sunworld1[.]000webhostapp[.]com
References
https://twitter.com/ActorExpose/status/1133102201864359939
@ActorExpose documented one of the Countdown till email shutdown phishing kits. It is a pretty common looking phish that has a red countdown clock until your email shuts down, unless of course you give the attacker your password. It also utilizes
"HTML Encryption provided by www.webtoolhub.com"
which we all know is just simple HTML 101 encode/decoding
document.write(unescape('%3c%74%72%3e
folder structure
\index.html
\connect.html
\pass.php (contains the HTML encoded login page)
\post.php (contains the mailer)
example 1:
md5 2ca09b28ee6fc3d355fc9de2159b3579
https://www.virustotal.com/#/file/e18d5fb9ca632393aeff9f8b504615f850c21df770a44ed6c6461501589dc96f/detection
hxxp://sunworld1[.]000webhostapp[.]com
References
https://twitter.com/ActorExpose/status/1133102201864359939
Comments
Post a Comment