create account

An Example of an Ourtime.com (Dating Site) Phishing Attack. by balor

View this thread on: hive.blogpeakd.comecency.com
· @balor ·
$0.08
An Example of an Ourtime.com (Dating Site) Phishing Attack.
So this one is a little amusing, we came across it after updating our phishing sample collector to also search for dating-site related keywords. The kit is targeting users of "Ourtime.com", a dating website apparently owned by the same people who own "Match.com" and other dating sites. I did not know until relatively recently that there is actually a rather sizeable market for hacked dating website accounts, and I should probably investigate that sometime.

This one was hosted on an obviously hacked website, and whatever moron was setting up the kit set up about 5 redundant copies of it, as we will see later. 

The panel is rather crude, with a simple landing page that emulates the "Ourtime.com" login interface, as you can see below. It simply asks for the user to log into the site.

![Screenshot 2019-05-16 at 15.15.14.png](https://cdn.steemitimages.com/DQmZkAm4p6vqekHsSnbw8Mjx4AWp68a25Db92efb8XLUn11/Screenshot%202019-05-16%20at%2015.15.14.png)

When you log in, not much happens - your form information is sent on to a script named "next1.php", and you are bounced over to a page named "step2.php", which simply asks you to continue trying to log in. 

So we decided to go straight into traversing directories to find the source code of this phishing kit, and discovered it within seconds.

![Screenshot 2019-05-16 at 15.23.26.png](https://cdn.steemitimages.com/DQmdZrzKKeimCy5R53n28d8VVuWwmgKT87oWvnWgapXLuwd/Screenshot%202019-05-16%20at%2015.23.26.png)

Further traversals showed us that, well, several versions of the kit had been uploaded!

![Screenshot 2019-05-16 at 15.24.01.png](https://cdn.steemitimages.com/DQmREe43AV3wjWc8MWuNRhJgatDYW5UfQvBKhE79oW3uq3y/Screenshot%202019-05-16%20at%2015.24.01.png)

We downloaded everything in the directory, but it was basically all the same garbage. The one different archive was "gonieecw.zip", which we have yet to analyse.

Anyways, on to exploring what goes on behind the scenes in this kit by having a look inside it. We unzip it, and have a look around the files. The "next2.php" script does the bulk of the work, collecting the submitted form data and simply emailing it to some guy with the email "stephenjon60@gmail.com".

![Screenshot 2019-05-16 at 15.29.38.png](https://cdn.steemitimages.com/DQmP5t8kcY2fzFX65ZfrkWAhqdHUCCBQbJK1eaVE7Rznaff/Screenshot%202019-05-16%20at%2015.29.38.png)

As a closing note, we determined that the site had probably been compromised by someone using a Wordpress exploit. 

So that is all for now, showing you the behind the scenes of how yet another rather crude phishing campaign operates. I'll hopefully soon have more examples to share with you all, along with some contact details for reporting phishing campaigns you come across to us so we can investigate and expose their inner workings. We are especially keen to find some good examples of scammers targeting the cryptocurrency community!

If you would like to see more content like this, let us know in the comments section below!
👍  , ,
properties (23)
authorbalor
permlinkan-example-of-an-ourtime-com-dating-site-phishing-attack
categorytechnology
json_metadata{"tags":["technology","phishing","scammers","friedphish","security"],"image":["https://cdn.steemitimages.com/DQmZkAm4p6vqekHsSnbw8Mjx4AWp68a25Db92efb8XLUn11/Screenshot%202019-05-16%20at%2015.15.14.png","https://cdn.steemitimages.com/DQmdZrzKKeimCy5R53n28d8VVuWwmgKT87oWvnWgapXLuwd/Screenshot%202019-05-16%20at%2015.23.26.png","https://cdn.steemitimages.com/DQmREe43AV3wjWc8MWuNRhJgatDYW5UfQvBKhE79oW3uq3y/Screenshot%202019-05-16%20at%2015.24.01.png","https://cdn.steemitimages.com/DQmP5t8kcY2fzFX65ZfrkWAhqdHUCCBQbJK1eaVE7Rznaff/Screenshot%202019-05-16%20at%2015.29.38.png"],"app":"steemit/0.1","format":"markdown"}
created2019-05-16 13:38:39
last_update2019-05-16 13:38:39
depth0
children1
last_payout2019-05-23 13:38:39
cashout_time1969-12-31 23:59:59
total_payout_value0.074 HBD
curator_payout_value0.001 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length2,991
author_reputation50,743,365,752
root_title"An Example of an Ourtime.com (Dating Site) Phishing Attack."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id84,966,548
net_rshares182,077,956,538
author_curate_reward""
vote details (3)
@steemitboard ·
Congratulations @balor! You have completed the following achievement on the Steem blockchain and have been rewarded with new badge(s) :

<table><tr><td><img src="https://steemitimages.com/60x70/http://steemitboard.com/@balor/votes.png?201905170557"></td><td>You made more than 50 upvotes. Your next target is to reach 100 upvotes.</td></tr>
</table>

<sub>_You can view [your badges on your Steem Board](https://steemitboard.com/@balor) and compare to others on the [Steem Ranking](http://steemitboard.com/ranking/index.php?name=balor)_</sub>
<sub>_If you no longer want to receive notifications, reply to this comment with the word_ `STOP`</sub>


To support your work, I also upvoted your post!


**Do not miss the last post from @steemitboard:**
<table><tr><td><a href="https://steemit.com/japanese/@steemitboard/new-japanese-speaking-community-steem-meetup-badge"><img src="https://steemitimages.com/64x128/https://cdn.steemitimages.com/DQmRWbAjbeETEaqSPLcpwYX1JN5pZhdPffv4q6DaBs6xvZm/image.png"></a></td><td><a href="https://steemit.com/japanese/@steemitboard/new-japanese-speaking-community-steem-meetup-badge">New  japanese speaking community Steem Meetup badge</a></td></tr></table>

###### [Vote for @Steemitboard as a witness](https://v2.steemconnect.com/sign/account-witness-vote?witness=steemitboard&approve=1) to get one more award and increased upvotes!
properties (22)
authorsteemitboard
permlinksteemitboard-notify-balor-20190517t063241000z
categorytechnology
json_metadata{"image":["https://steemitboard.com/img/notify.png"]}
created2019-05-17 06:32:39
last_update2019-05-17 06:32:39
depth1
children0
last_payout2019-05-24 06:32:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,367
author_reputation38,975,615,169,260
root_title"An Example of an Ourtime.com (Dating Site) Phishing Attack."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id85,009,530
net_rshares0