AntiPhishingLab (@antiphishinglab) 's Twitter Profile
AntiPhishingLab

@antiphishinglab

Phishing and cyber fraud investigation. Discovering attacks, threat actors and victims. Sharing the results of my own research only. #phishing

ID: 943745214954565632

calendar_today21-12-2017 07:29:27

73 Tweet

54 Takipçi

9 Takip Edilen

AntiPhishingLab (@antiphishinglab) 's Twitter Profile Photo

PHP shell (command panel) and CGI-telnet shell have been found on this host. Using the panel you can upload files, execute commands, etc. Possibly the threat actor uses the host via these interfaces. Meanwhile, a PayPal phishing web application is being built here. #phishing

PHP shell (command panel) and CGI-telnet shell have been found on this host. Using the panel you can upload files, execute commands, etc. Possibly the threat actor uses the host via these interfaces. Meanwhile, a PayPal phishing web application is being built here.
#phishing
AntiPhishingLab (@antiphishinglab) 's Twitter Profile Photo

These phishing web applications have just activated. They targeting PayPal and Scotiabank customers. hXXp://update-paypal.unatransport.ba hXXp://reviewpaypal.dynv6.net/ hXXp://paypal.com.support-limited.verifications-v2l-confirmation.com/ hXXp://scotiabank.trafika.mx/ #phishing

These phishing web applications have just activated. They targeting PayPal and Scotiabank customers.
hXXp://update-paypal.unatransport.ba
hXXp://reviewpaypal.dynv6.net/
hXXp://paypal.com.support-limited.verifications-v2l-confirmation.com/
hXXp://scotiabank.trafika.mx/
#phishing
AntiPhishingLab (@antiphishinglab) 's Twitter Profile Photo

This phishing attack targets Itaú Private Bank. Hundreds of customers are affected. I've also found a control panel here. #phishing

This phishing attack targets Itaú Private Bank. Hundreds of customers are affected. I've also found a control panel here.
#phishing
AntiPhishingLab (@antiphishinglab) 's Twitter Profile Photo

The threat actor of this phishing attack can be easily identified because he used an online PHP obfuscator that saved his IP address in this automatically generated comment section. (See my previous tweet for more info.) #phishing

The threat actor of this phishing attack can be easily identified because he used an online PHP obfuscator that saved his IP address in this automatically generated comment section. (See my previous tweet for more info.)
#phishing
AntiPhishingLab (@antiphishinglab) 's Twitter Profile Photo

I've just found some newly activated phishing web applications (targeting Bank of America, Citibank and Wells Fargo customers). hXXp://bankofamerica.com.access-custumer.instant-canalser.com hXXp://citi-com.tk hXXp://wellsfargo-submit.ml #phishing

I've just found some newly activated phishing web applications (targeting Bank of America, Citibank and Wells Fargo customers).
hXXp://bankofamerica.com.access-custumer.instant-canalser.com
hXXp://citi-com.tk
hXXp://wellsfargo-submit.ml
#phishing
AntiPhishingLab (@antiphishinglab) 's Twitter Profile Photo

This spear phishing web application targets one single person called 'Evan'. The web application pre-populates his e-mail address and continuously increases the amount of transferred money - perhaps because they're blackmailing the victim... #phishing

This spear phishing web application targets one single person called 'Evan'. The web application pre-populates his e-mail address and continuously increases the amount of transferred money - perhaps because they're blackmailing the victim...
#phishing
AntiPhishingLab (@antiphishinglab) 's Twitter Profile Photo

ipay[.]bangkokbank[.]com[.]bblvbvacs[.]adsotp[.]brewerycotton[.]com backoffice[.]bankaccountchecker[.]com fednet[.]federalbanks[.]cf login-accounts[.]paypai[.]dz[.]aliancafm[.]com wellsfargo-secure01[.]serveirc[.]com #phishing

AntiPhishingLab (@antiphishinglab) 's Twitter Profile Photo

This malicious web application seems to be checking PayPal Email addresses. It is implemented on a PayPal phishing server. #phishing

This malicious web application seems to be checking PayPal Email addresses. It is implemented on a PayPal phishing server.
#phishing
AntiPhishingLab (@antiphishinglab) 's Twitter Profile Photo

An Ursnif variant (unknown to VirusTotal) has been found in the wild. hXXp://how-to-get-reg istry-cleaner-windows[.]kinetic otx[.]com/www/crypt_7000.exe #phishing #Malware

An Ursnif variant (unknown to VirusTotal) has been found in the wild.
hXXp://how-to-get-reg  istry-cleaner-windows[.]kinetic otx[.]com/www/crypt_7000.exe
#phishing #Malware