Posts

Showing posts from June, 2021

#Office365 2019 New Scam by Ex-Robotos Malware - cracked by IK Zeus

Image
 Around 1:45PM June 19, 2021 (+8gmt), I was contacted by one of my web development clients. He's in shock that they can't access their MLM Website, and get redirected to 404 Page. I asked him the CPanel account login, and promptly opened the CPanel, only to find out, the Member's Area directory was gone, and there this new folder named "Journal" was created few hours ago. Journal folder containes some php files named after the missing files I created before, and some text files. When I open the files for editing (to view its content) through File Manager, I was presented with javascript codes (which I didn't examined). Voicemail Scmpage 2019 by Ex-Robotos In the top most part of each php files were found commented the phrase "Office365 2019 New Scam by Ex-Robotos - cracked by IK Zeus" Readme.txt inside the Journal folder Upon examining the Journal folder, I realized that it is a Office365 2019 Phishing Script. How did that script put in there? I don&