Gel4y Mini Shell by Indonesian Darknet

Another PHP web shell that promises it can bypass ‘server security’.
analiticsweb.site (zulhqmnr@netmail[.]tk) skimmer
![analiticsweb.site (zulhqmnr@netmail[.]tk) skimmer](https://lukeleal.com/research/zul.png)
A JavaScript skimmer that loads from analiticsweb[.]site/analytics.js - and opsec failure leads to discovery of more malicious domains.
PHP Minishell Backticks Redux

A variant of the PHP backtick minishell that obfuscates a PHP superglobal to evade detection.
lolzilla Skimmer: PHP or JS?

lolzilla skimmer analyzes a visitor’s HTTP request to determine whether it can capture the visitor’s payment data using a PHP skimmer or if it should deploy a JavaScript skimmer onto the checkout page to capture the data.
PHP skimmer -> secure-authorize.net (malicious)

A PHP skimmer that exfiltrates the stolen payment data to a fake DLL file on the malicious domain secure-authorize.net.