Gel4y Mini Shell by Indonesian Darknet

Gel4y Mini Shell by Indonesian Darknet
Another PHP web shell that promises it can bypass ‘server security’.
Read more →

XBALTI Phishing Kits

XBALTI Phishing Kits
Analysis of the XBALTI phishing kits and their exfiltration techniques.
Read more →

PHP Minishell Backticks Redux

PHP Minishell Backticks Redux
A variant of the PHP backtick minishell that obfuscates a PHP superglobal to evade detection.
Read more →

lolzilla Skimmer: PHP or JS?

lolzilla Skimmer: PHP or JS?
lolzilla skimmer analyzes a visitor’s HTTP request to determine whether it can capture the visitor’s payment data using a PHP skimmer or if it should deploy a JavaScript skimmer onto the checkout page to capture the data.
Read more →

PHP skimmer -> secure-authorize.net (malicious)

PHP skimmer -> secure-authorize.net (malicious)
A PHP skimmer that exfiltrates the stolen payment data to a fake DLL file on the malicious domain secure-authorize.net.
Read more →
Disclaimer: The research posted on this website is for information purposes only. Do not use it for illegal purposes.