CartaSi phishing email part 2/2
Behind this phishing emails there are several people or just one guy ? What i think is that there is only one guy because if you check the title of this script you see the write assembled by ME, if it was a team should be written Assembled by XYZ team. Where is he from ? His mother language is romanian and i think he lives in Italy. As you can see below there are several files written in romanian and the stolen information are sent to a fastweb email that you cannot made if you don't leave in Italy. I was wrong in the previous article saying that the pisher hacked the webstie because was defaced by FERID23 from anti-armenia.org. I suppose that at the end of September 2011 this phisher found it, uploaded a shell and created several folders in this order: d3b (postepay information stealer) stf (cartasi, uk paypal, banca intesa, it paypal, postepay, VISA) pastote (cartasi, paypal, VISA, bancopostaclick) Taking a look to pastote folder we see that he uses a