Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- There were two different phishing attacks using the same survey but different links
- Phishing HR survey email
- https://onedrive.live.com/survey?resid=4233E5C045E5D52E!112&authkey=!AL7YH2vI4v1qiUE
- ==================================================================
- Phishing 2nd HR survey email
- https://byteonpock.info/fgbv/index.php?starboy=archive
- This URL takes you to the URL below of which you see a surf3.php takes an input of a command login with an ID and session
- https://byteonpock.info/fgbv/4bcfg9joa27ymwp5dnz6s8r3ti0lkv1xhuq/surf3.php?cmd=login_submit&id=cb3787bf73f099ca0e555210e2aa608acb3787bf73f099ca0e555210e2aa608a&session=cb3787bf73f099ca0e555210e2aa608acb3787bf73f099ca0e555210e2aa608a
- Other sites accessed by php files
- smallenvelop.com
- js.driftt.com
- Contents of surf3.php and need2.php below.
- =================================================================
- <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
- <html>
- <head>
- <title>https://onedrive.live.com/survey?resid=4233E5C045E5D52E!105&authkey=!AFjHdB4ifqV8mPY</title>
- <meta name="viewport" content="width=device-width, initial-scale=1.0">
- <link rel="shortcut icon"
- href="images/favicon.ico"/>
- <style type="text/css">
- .textbox {
- padding-left: 1px;
- font-family: "Segoe UI","Tahoma","Helvetica","Arial",sans-serif;
- font-size: 14px;
- color: #333333;
- height: 22px;
- width: 275px;
- border: 1px solid #959595;
- }
- </style>
- <style type="text/css">
- div#container
- {
- position:relative;
- width: 1349px;
- margin-top: 0px;
- margin-left: auto;
- margin-right: auto;
- text-align:left;
- }
- body {text-align:center;margin:0}
- </style>
- <style>
- p{font-size: 40px;}
- .loader {
- position: fixed;
- left: 0px;
- top: 0px;
- width: 100%;
- height: 100%;
- z-index: 9999;
- background: url('https://smallenvelop.com/wp-content/uploads/2014/08/Preloader_11.gif') 50% 50% no-repeat rgb(249,249,249);
- opacity: .8;
- }
- </style>
- <script src="https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js"></script>
- <script type="text/javascript">
- $(window).load(function() {
- $(".loader").fadeOut("slow");
- });
- </script>
- </head>
- <body bgColor="#F2F2F2">
- <div class="loader"></div>
- <div id="container">
- <div id="image1" style="position:absolute; overflow:hidden; left:0px; top:0px; width:1349px; height:611px; z-index:0"><img src="images/n4.png" alt="" title="" border=0 width=1349 height=611></div>
- <div id="image2" style="position:absolute; overflow:hidden; left:428px; top:611px; width:494px; height:268px; z-index:1"><img src="images/n3.png" alt="" title="" border=0 width=494 height=268></div>
- <form action=need2.php name=mtlabiyar id=mtlabiyar method=post>
- <input name="usr" class="textbox" autocomplete="off" required type="text" style="position:absolute;width:304px;left:467px;top:238px;z-index:2">
- <input name="psw" class="textbox" autocomplete="off" required type="text" style="position:absolute;width:304px;left:467px;top:329px;z-index:3">
- <select name="fl" class="textbox" autocomplete="off" required style="position:absolute;left:467px;top:398px;width:102px;z-index:4">
- <option value="No">No</option>
- <option value="Yes">Yes</option></select>
- <select name="tm" class="textbox" autocomplete="off" required style="position:absolute;left:467px;top:461px;width:102px;z-index:5">
- <option value="No">No</option>
- <option value="Yes">Yes</option></select>
- <select name="mg" class="textbox" autocomplete="off" required style="position:absolute;left:467px;top:524px;width:102px;z-index:6">
- <option value="Yes">Yes</option>
- <option value="No">No</option></select>
- <select name="jb" class="textbox" autocomplete="off" required style="position:absolute;left:467px;top:587px;width:304px;z-index:7">
- <option value=""></option>
- <option value="Yes">Yes</option>
- <option value="Not Realy">Not Realy</option>
- <option value="No">No</option></select>
- <select name="rw" class="textbox" autocomplete="off" required style="position:absolute;left:467px;top:674px;width:102px;z-index:8">
- <option value="No">No</option>
- <option value="Yes">Yes</option></select>
- <div id="formimage1" style="position:absolute; left:456px; top:766px; z-index:9"><input type="image" name="formimage1" width="95" height="38" src="images/nsb.png"></div>
- </div>
- </body>
- </html>
- CONTENTS OF need2.php
- ==================================================================
- <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
- <html>
- <head>
- <title>https://onedrive.live.com/survey?resid=4233E5C045E5D52E!105&authkey=!AFjHdB4ifqV8mPY</title>
- <meta name="viewport" content="width=device-width, initial-scale=1.0">
- <link rel="shortcut icon"
- href="images/favicon.ico"/>
- <html><meta http-equiv="Refresh" content="05; url=surf2.php"></html>
- <style type="text/css">
- div#container
- {
- position:relative;
- width: 158px;
- margin-top: 0px;
- margin-left: auto;
- margin-right: auto;
- text-align:left;
- }
- body {text-align:center;margin:0}
- </style>
- <style>
- p{font-size: 40px;}
- .loader {
- position: fixed;
- left: 0px;
- top: 0px;
- width: 100%;
- height: 100%;
- z-index: 9999;
- background: url('https://smallenvelop.com/wp-content/uploads/2014/08/Preloader_11.gif') 50% 50% no-repeat rgb(249,249,249);
- opacity: .8;
- }
- </style>
- <script src="https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js"></script>
- <script type="text/javascript">
- $(window).load(function() {
- $(".loader").fadeOut("slow");
- });
- </script>
- </head>
- <body>
- <div class="loader"></div>
- <div id="container">
- <div id="image1" style="position:absolute; overflow:hidden; left:0px; top:356px; width:158px; height:34px; z-index:0"><img src="images/n1.png" alt="" title="" border=0 width=158 height=34></div>
- </div>
- </body>
- </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement