Sunday, 11 October 2009

Phishing for Dummies

There was a phishing mail in my inbox today which caught my interest and resulted in some hours of research. The result was discovery of a bunch of web sites distributing 'Phish Kits' for free - ready to use packages. Some screen captures of my findings:

The first one



... Then searching some more



... and more


... and more



... even more



... and finally



Most of these sites also point to additional pages containing malicious tools for mass mailing, doing certain kind of scanning for vulnerable hosts, ddos attacks and other nasty things.
Close observation of these sites reveals similarities and that is no wonder because they are all created by the same criminal(s). The provided phish kits do contain PHP scripts which will send the harvested data to the creator in addition to the malicious user who tries to use them.
This scheme is used since more than a year and in the past several similar sites have appeared and were taken down eventually:

scam-pags.net
scam4u.com
thebadboys.org
freescam.webobo.com
online-scams.net
scam7.com
www .scam-page.fr
www .mafia8doc.com
scams-mafia.com
worldpowerz.com
sakhsookh.100webspace.net

Some more technical details might make it into this post soon.

0 comments: