A few questions about phishing

x_mode

Carder
Messages
42
Reaction score
25
Points
8
Hello everyone. I recently started working on phishing sites. I have created a copy of my country's bank website and would like to ask for some tips, for example:


- What's the best way to send a message?
sms or mail?
(I would be grateful if you recommend several platforms or programs for this)
- What should you pay attention to when writing a message?
for example - your account is blocked or receiving money from any source and others ...
- Should the text be short or long?
- What mistakes do beginners often make?
- How can people notice that the site is fake?
- What sites can do to make it harder to copy a site?
- Do sites have the ability to find out that the site was copied?
- What are the ways to copy sites?
- What platforms can help me with the creation of sites?

Maybe the questions are trivial, but I would like to hear the opinion of those who have already done this.
Naturally, before publishing these questions, I read a significant amount of topics on this question, so I have some information about how it works and how it should work.
Of course, I will continue to study and read to learn something new.

Thanks to whoever read this and spent their precious time.

Have a nice day everyone!
 
Hello everyone. I recently started working on phishing sites. I have created a copy of my country's bank website and would like to ask for some tips, for example:
Hello, we are glad to welcome you to our forum. Here you can get answers to any questions that interest you, get useful advice and practical recommendations for successful work in any direction.
The main purpose of phishing is to obtain bank accounts and accounts of any payment systems that you need and need. Or force the victims to make money transfers according to the details you need.

- What's the best way to send a message?
sms or mail?
(I would be grateful if you recommend several platforms or programs for this)
You can send phishing messages using the spam method, it works both by e-mail and via SMS messages or phone calls from robots.
You yourself choose how you like best, which method you prefer and how it is easier and more convenient for you to work.
You can find the necessary software for these purposes at the following link:
There will also be links where you can download it.

- What should you pay attention to when writing a message?
for example - your account is blocked or receiving money from any source and others ...
To do this, you can use any posts from social engineering techniques. For instance:
1. "Please confirm the relevance of your account information, please follow the link ..."
2. "Please verify your personal account, follow the link ..."
3. "Please install additional protection for your account and activate two-step authorization ..."
4. "We have noticed suspicious activity on your account, please change your password ..."
5. "A bonus (cash reward) is available to you, please follow the link to receive ..."
6. "Please confirm free use of our services ..."
7. "Please use the reduced commission when making payments ...".
8. "Please read our special offer (conditions) especially for you"
There are many other options, imagine yourself as a fish that would be caught by a fisherman (phisher) and write a message that you yourself would peck at and follow the specified link.

- Should the text be short or long?
The length of the text is not of fundamental importance, the moment of registration of the letter (if it is e-mail) is very important.
The main task is to catch the attention of the fish and arouse its desire to be sure to follow the proposed link.
Pre-study the alerts from the desired bank or payment system that they send to users, carefully read them and create a completely identical design so as not to arouse suspicion and so that the message looks more believable.

- What mistakes do beginners often make?
1. Forget to use email sender spoofing. It is important that the letter comes from a familiar and familiar address.
2. They send mail from one SMTP server and their letters go to the spam folder.
3. Forgetting to restrict the access of search bots to the site and their phishing page is immediately blacklisted. Browsers and plugins warn you that this is a dangerous site.
4. Do not install the https protocol
5. Scripts for collecting information on the site are not debugged or the design of the site is suspicious.
There are many other common beginner mistakes.

- How can people notice that the site is fake?
1. The domain address is too different. It is important to find a good, verified address that will not raise suspicions. You can change 1 number or letter in the name to be similar to the original. Either add a thematic prefix, or register a completely identical domain in a free trust zone.
2. The design of the site is too different and not credible. Or, as I wrote above, the https protocol is not installed.
3. Plugins, antivirus programs and browsers warn that this is a dangerous site.
4. To access your account, you are not asked for the usual confirmation by e-mail or SMS.
Beforehand, be sure to study all the intricacies of the authorization of the donor site.

- What sites can do to make it harder to copy a site?
Copying a site is very easy using various programs for these purposes or manually. They will not be able to hide the html code in any way. The only thing that you will not be able to copy is if a self-written cms engine was written by the coders, but this is not required. It is enough to use standard forms for collecting login and passwords.
There are a huge number of methods and free programs for copying sites completely, here is one of them:

- Do sites have the ability to find out that the site was copied?
Yes, many sites have such a function and their technical specialists determine the actions of suspicious programs and bots and try to intercept or block them. But this in detail cannot affect your work in any way, since they cannot know and predict the domain on which you will place phishing.
The only thing they can do is when they receive complaints from smart users indicating a fake letter and domain, they will write a warning news on their website for all users, make an official warning mailing list, or add a harmful domain to black lists, but this happens very rarely.

- What are the ways to copy sites?
1. Using free special programs to create a copy (duplicate sites).
2. Using free online services, in which it is enough to enter the desired link and receive a complete copy.
And many others.
3. Manual method. Go to the site, open the html code view in the browser, select it, copy it, paste it into a notepad and make the necessary edits. You don't need to have extensive knowledge to do this. Everything is quite simple and elementary.
Please check out this topic and watch the video.

- What platforms can help me with the creation of sites?
There are a huge number of free cms systems and engines. You can independently choose any and use it for its intended purpose.
Please choose which one you like best.
They are very simple and intuitive to set up. There are detailed guides on how to use them correctly.
You can quickly and easily make up any site yourself without using the cms system at all.
It is advisable to place the site on a bulletproof hosting that does not respond to user complaints and hide the real IP address of the site using various free services.

Maybe the questions are trivial, but I would like to hear the opinion of those who have already done this.
Naturally, before publishing these questions, I read a significant amount of topics on this question, so I have some information about how it works and how it should work.
Of course, I will continue to study and read to learn something new.
Thanks to whoever read this and spent their precious time.
You are a great fellow for studying this issue.
The data obtained can be used at your will, many of them log into accounts themselves and make transfers to the necessary accounts of cash-out services, or they simply put accounts for sale, setting the price depending on the balance.

Latest advice:
In addition to the login and password, it is desirable to get cookies and a full fingerprint of the victim's system and browser for more successful and productive work, this can also be done by the scripts installed on the site.
In addition to authorization data, you can set up a form for collecting credit card numbers and other personal information, such as ssn, dob, and others for the subsequent possibility of registering accounts with these data in other banks and payment systems.
Many fish use the same passwords in all their accounts, from social networks to payment systems. This is their big omission and mistake. It is important to always think and take care of your confidential information.

I wish you good and productive work in this direction. Remember to follow the basic rules of anonymity and safety when doing such activities.

P.S. For more information, please see the following topics:
 
Hello, we are glad to welcome you to our forum. Here you can get answers to any questions that interest you, get useful advice and practical recommendations for successful work in any direction.
The main purpose of phishing is to obtain bank accounts and accounts of any payment systems that you need and need. Or force the victims to make money transfers according to the details you need.


You can send phishing messages using the spam method, it works both by e-mail and via SMS messages or phone calls from robots.
You yourself choose how you like best, which method you prefer and how it is easier and more convenient for you to work.
You can find the necessary software for these purposes at the following link:
There will also be links where you can download it.


To do this, you can use any posts from social engineering techniques. For instance:
1. "Please confirm the relevance of your account information, please follow the link ..."
2. "Please verify your personal account, follow the link ..."
3. "Please install additional protection for your account and activate two-step authorization ..."
4. "We have noticed suspicious activity on your account, please change your password ..."
5. "A bonus (cash reward) is available to you, please follow the link to receive ..."
6. "Please confirm free use of our services ..."
7. "Please use the reduced commission when making payments ...".
8. "Please read our special offer (conditions) especially for you"
There are many other options, imagine yourself as a fish that would be caught by a fisherman (phisher) and write a message that you yourself would peck at and follow the specified link.


The length of the text is not of fundamental importance, the moment of registration of the letter (if it is e-mail) is very important.
The main task is to catch the attention of the fish and arouse its desire to be sure to follow the proposed link.
Pre-study the alerts from the desired bank or payment system that they send to users, carefully read them and create a completely identical design so as not to arouse suspicion and so that the message looks more believable.


1. Forget to use email sender spoofing. It is important that the letter comes from a familiar and familiar address.
2. They send mail from one SMTP server and their letters go to the spam folder.
3. Forgetting to restrict the access of search bots to the site and their phishing page is immediately blacklisted. Browsers and plugins warn you that this is a dangerous site.
4. Do not install the https protocol
5. Scripts for collecting information on the site are not debugged or the design of the site is suspicious.
There are many other common beginner mistakes.


1. The domain address is too different. It is important to find a good, verified address that will not raise suspicions. You can change 1 number or letter in the name to be similar to the original. Either add a thematic prefix, or register a completely identical domain in a free trust zone.
2. The design of the site is too different and not credible. Or, as I wrote above, the https protocol is not installed.
3. Plugins, antivirus programs and browsers warn that this is a dangerous site.
4. To access your account, you are not asked for the usual confirmation by e-mail or SMS.
Beforehand, be sure to study all the intricacies of the authorization of the donor site.


Copying a site is very easy using various programs for these purposes or manually. They will not be able to hide the html code in any way. The only thing that you will not be able to copy is if a self-written cms engine was written by the coders, but this is not required. It is enough to use standard forms for collecting login and passwords.
There are a huge number of methods and free programs for copying sites completely, here is one of them:


Yes, many sites have such a function and their technical specialists determine the actions of suspicious programs and bots and try to intercept or block them. But this in detail cannot affect your work in any way, since they cannot know and predict the domain on which you will place phishing.
The only thing they can do is when they receive complaints from smart users indicating a fake letter and domain, they will write a warning news on their website for all users, make an official warning mailing list, or add a harmful domain to black lists, but this happens very rarely.


1. Using free special programs to create a copy (duplicate sites).
2. Using free online services, in which it is enough to enter the desired link and receive a complete copy.
And many others.
3. Manual method. Go to the site, open the html code view in the browser, select it, copy it, paste it into a notepad and make the necessary edits. You don't need to have extensive knowledge to do this. Everything is quite simple and elementary.
Please check out this topic and watch the video.


There are a huge number of free cms systems and engines. You can independently choose any and use it for its intended purpose.
Please choose which one you like best.
They are very simple and intuitive to set up. There are detailed guides on how to use them correctly.
You can quickly and easily make up any site yourself without using the cms system at all.
It is advisable to place the site on a bulletproof hosting that does not respond to user complaints and hide the real IP address of the site using various free services.


You are a great fellow for studying this issue.
The data obtained can be used at your will, many of them log into accounts themselves and make transfers to the necessary accounts of cash-out services, or they simply put accounts for sale, setting the price depending on the balance.

Latest advice:
In addition to the login and password, it is desirable to get cookies and a full fingerprint of the victim's system and browser for more successful and productive work, this can also be done by the scripts installed on the site.
In addition to authorization data, you can set up a form for collecting credit card numbers and other personal information, such as ssn, dob, and others for the subsequent possibility of registering accounts with these data in other banks and payment systems.
Many fish use the same passwords in all their accounts, from social networks to payment systems. This is their big omission and mistake. It is important to always think and take care of your confidential information.

I wish you good and productive work in this direction. Remember to follow the basic rules of anonymity and safety when doing such activities.

P.S. For more information, please see the following topics:
For the beginning I want to say a huge thank you!
I didn't think that people could answer that way. everything is clear and detailed.

I read all the themes you sent.
I was looking for answers to my questions, but I did not find anything, but thanks to you, now I know much more than before your post.

I have a few more questions...

- Сan you recommend a hosting for me and where is the best place to buy a domain? (It is advisable to be able to buy with bitcoin) Or is it all the same where to buy from?

I read the topic about "How to be a good spammer"
but I did not find a information of bulk sms or I just did not notice her.
So, can you recommend me about the service or a program that can send at least several hundred thousand SMS? or send the topic on this issue if you are not difficult.

Finally, I want to thank you again for your excellent answer.
 
I am very pleased if you liked my answer. I will be happy to help you.

- Сan you recommend a hosting for me and where is the best place to buy a domain? (It is advisable to be able to buy with bitcoin) Or is it all the same where to buy from?
Hosting is best to buy bulletproof.
Here is a list of good free hosting providers that hold and are loyal to phishing pages:
Do not forget that at any time, hosting can change the policy of free provision of services.

If you need a 100% guarantee that your hosting will not be blocked for complaints, then you can choose any of the checked section
and use their services.
The forum is also full of newcomers who offer dedicated virtual bulletproof servers for only $ 1-2 per month.
If you want paid hosting, of course, it is best to pay for services with cryptocurrency to remain anonymous, there are thousands of such hosters, you can choose whichever you like best.

So, can you recommend me about the service or a program that can send at least several hundred thousand SMS? or send the topic on this issue if you are not difficult.
You can send spam via SMS using the services provided in the section, the link to which I indicated to you above. They will perform the service in any volume.
There are a bunch of legal services on the Internet that send SMS messages for a small price to your and their databases.
But you need to use link shortening (masking) services so that these services do not suspect phishing and provide the service properly.

If you want to do it yourself:
First you need to prepare (collect) a database of phone numbers.
Then carry out the mailing using the software designed for this purpose. The Internet is full of free and paid programs, you can choose which one you like best and which suits you best.

The databases of valid numbers for any parameters (country, city, gender, age, etc.) are also sold on the Internet and can be bought.

P.S. Also, many ready-made templates for fake banks and payment systems will be posted in the resources section of our forum.
Some of them you can already download for free now.
For example Chase Bank:
Ready-made store script:
I have over 1000 ready-made templates, gradually I will add them for free.
 
I am very pleased if you liked my answer. I will be happy to help you.


Hosting is best to buy bulletproof.
Here is a list of good free hosting providers that hold and are loyal to phishing pages:
Do not forget that at any time, hosting can change the policy of free provision of services.

If you need a 100% guarantee that your hosting will not be blocked for complaints, then you can choose any of the checked section
and use their services.
The forum is also full of newcomers who offer dedicated virtual bulletproof servers for only $ 1-2 per month.
If you want paid hosting, of course, it is best to pay for services with cryptocurrency to remain anonymous, there are thousands of such hosters, you can choose whichever you like best.


You can send spam via SMS using the services provided in the section, the link to which I indicated to you above. They will perform the service in any volume.
There are a bunch of legal services on the Internet that send SMS messages for a small price to your and their databases.
But you need to use link shortening (masking) services so that these services do not suspect phishing and provide the service properly.

If you want to do it yourself:
First you need to prepare (collect) a database of phone numbers.
Then carry out the mailing using the software designed for this purpose. The Internet is full of free and paid programs, you can choose which one you like best and which suits you best.

The databases of valid numbers for any parameters (country, city, gender, age, etc.) are also sold on the Internet and can be bought.

P.S. Also, many ready-made templates for fake banks and payment systems will be posted in the resources section of our forum.
Some of them you can already download for free now.
For example Chase Bank:
Ready-made store script:
I have over 1000 ready-made templates, gradually I will add them for free.
And again you helped me thank you very much!
I hope everything will be fine, and I wish you the same.
Have a nice day!
 
Top