FudTool - Phishing Kit Author

#FudTool #FudToolSu #FudToolRu #FudPages #PhishingKitAuthor #phishing #phishingkit 


FudTool is a phishing kit author that authors numerous phishing kits that can vary greatly in functionality, look, and code.

They may contain text like
   Fudtool[dot]su
   FUDTOOL [.] RU
   fudpages@gmail.com
   Created BY fudpages(doit)com
   Created BY fudpages
   FUDPAGES [.] RU 




Both the website
     fudtool.su
     fudtool.ru

Are near identical and say "Fresh Spam Tools"
and reference accounts like
    ICQ 672970106
    Skype game.changer12





example 1
md5 7475613294925a86a9d13f18ac5ee345
https://www.virustotal.com/#/file/f8c46c72fb952da1a013ad34a9d5761d1859998c6b5afe08565a689708d22b86/detection
http://linkconsultores.com.uy/file/OneDriveFiles.zip

example 2
md5 fd8d58053d947ad17dce49f707f4846a
https://www.virustotal.com/#/file/a9d405875eafc65a6159c7e8c6a56bf8afef06ce67ab3e5e5e50e56133a2559d/detection
http://seirawa.com/..ll/azn.zip

References
https://urlscan.io/result/9cca9efd-c563-4df5-98fc-df63c97cc76b/ (linkconsultores[.]com[.]uy)
https://urlscan.io/result/ea3be793-d63a-4be6-9053-b7e107dbadd7/ ( seirawa.com )
https://urlscan.io/result/da7db0e1-a5cb-44f9-a9b9-3aa0cdb41ad3/ (fudtool.su)
https://urlscan.io/result/54b0f3de-8183-41c3-8478-d651f7e9470f/ (fudtoo.ru)


Note:
I am confident that FudTool and FudPages are the same threat actor
See more about FudPages here ( https://phishingkittracker.blogspot.com/2019/05/fudpages.html )

I am confident of this link because of these 2 phishing kits
https://www.virustotal.com/#/file/d96b5d599cd9473af97a12ca71b2a6da500794590c0ebb38bb63709d95f45060/detection
md5 babb656cbe519fd32250119bd149aa10
https://www.virustotal.com/#/file/f8c46c72fb952da1a013ad34a9d5761d1859998c6b5afe08565a689708d22b86/detection
md5 7475613294925a86a9d13f18ac5ee345

because both had identical files including "kancha.php" and mispelled "eror.php" yet the only difference was in "next1.php" where one said
FUDPAGES [.] RU
and one said
Fudtool[dot]su

Comments

Popular Posts