Advertisement
PhishTotal

AOL phish running on heelfus.ml

Nov 28th, 2017
470
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.86 KB | None | 0 0
  1. Found: 2017-11-22 15:19:10.563000
  2. URL: http://heelfus.ml/myownnoni/dwn.zip
  3. File: heelfus.ml-myownnoni-dwn.zip
  4. Domain: heelfus.ml
  5. Target: AOL
  6. Name Size Date MD5 dwn/dwn/aa.php 1321 2017-07-27 01:59:42 ee8874913e07f2ac24f51b5ad8320228
  7. dwn/dwn/aodc.php 16989 2017-05-10 13:32:42 6bc3d73a59de8559581de23d19dac346
  8.  
  9. dwn/dwn/error.php 1909 2016-08-22 06:13:42 345fa2b4c557753e0f201e804326f328
  10. File appears in 17 kits
  11. dwn/dwn/geoplugin.class.php 4647 2014-04-25 08:14:28 c8ea1e960b48a620c00bc65d525a721c
  12. File appears in 1009 kits and under 3 different file names
  13. dwn/dwn/index.php 39830 2017-05-23 11:10:22 dc346821bc3b6155aad279e8e04f11aa
  14.  
  15. dwn/dwn/Of365.php 14988 2017-05-23 11:03:48 cfe4c40ae6ba038fde4f34e8fc5da478
  16.  
  17. dwn/dwn/ofp.php 1323 2017-07-27 02:01:38 afa028861b062b9bd4a5d8a9df3d4bf1
  18. dwn/dwn/otdc.php 14952 2017-05-23 11:06:30 1b588e4a80da86bbc6ffbe0b08e2aa61
  19.  
  20. dwn/dwn/otp.php 1331 2017-07-27 02:02:32 12264873bb7de30d7f2cc16cff2969f9
  21. dwn/dwn/ss_files/aodc.png 15857 2017-05-23 01:49:04 ef8a5981db9eb379977dd906bfbb7c88
  22.  
  23. dwn/dwn/ss_files/base.css 3807 2017-05-22 23:33:20 6d1f4c1278de1c5581b9c8ecdf9297d5
  24.  
  25. dwn/dwn/ss_files/bootstrap.css 99961 2017-05-22 23:33:20 8a7442ca6bedd62cec4881040b9a9e83
  26.  
  27. dwn/dwn/ss_files/images.png 2899 2017-05-23 02:23:24 df3829fa7b84d9e92afc174363a61bee
  28.  
  29. dwn/dwn/ss_files/immmm.ico 285 2016-06-13 15:45:06 3e47d71cae18960fcd9772c836da50fd
  30. File appears in 98 kits and under 4 different file names
  31. dwn/dwn/ss_files/index.css 3112 2017-05-22 23:33:18 d594ebc0f6b1c27a44b26e15e7cb0949
  32.  
  33. dwn/dwn/ss_files/logo.png 7635 2017-05-09 08:54:20 1059986618539574ca4fa0bcfd699006
  34. File appears in 46 kits and under 3 different file names
  35. dwn/dwn/ss_files/ofdc.png 6905 2017-05-23 00:47:08 9f68017947e9ec02850b97115add63a6
  36.  
  37. dwn/dwn/ss_files/ofdc1.png 4585 2017-05-23 03:48:54 9f09a27d4f69b3557c7433574a29d726
  38. File appears in 48 kits and under 3 different file names
  39. dwn/dwn/ss_files/pcill.png 203294 2016-06-11 22:14:56 65283b123eb235e6176ae98c02ac5b1c
  40. File appears in 114 kits and under 4 different file names
  41. dwn/dwn/ss_files/rrrr.ico 17174 2016-06-12 00:03:50 12e3dac858061d088023b2bd48e2fa96
  42. File appears in 205 kits and under 8 different file names
  43. dwn/dwn/ss_files/s1.css 7815 2017-05-23 03:51:46 779c4723ad3225c9370378f14fc2f570
  44.  
  45. dwn/dwn/ss_files/s2.css 7815 2017-05-23 04:05:32 8df5769d8da3d0a3ba5f37f6c95207d9
  46.  
  47. dwn/dwn/ss_files/stylesheet.css 37811 2017-05-23 02:21:22 3b9f22bb2fb8e2a10918c1f5be1ed95e
  48.  
  49. dwn/dwn/ss_files/Thumbs.db 393728 2017-05-23 11:21:44 6d00da053fed1bc805765652f4d0f659
  50.  
  51. dwn/dwn/Thumbs.db 49152 2017-05-06 15:22:22 aaa74d950bd965dffd62f7b6c3426770
  52.  
  53. dwn/dwn/verification.php 52873 2017-07-27 02:03:26 03732e57ad77fb8ebe130f77908ed5c0
  54.  
  55. 4 Email addresses found:
  56. officerezult32@gmail.com
  57. office.rezult@yandex.com
  58. gp_support@geoplugin.com (appears in 973 kits)
  59. email@domain.com (appears in 80 kits)
  60.  
  61.  
  62.  
  63. https://texasmalwareblog.blogspot.com @phish_total
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement