I didn't look into how GMA.html works, but a quick look just now shows that it posts to https://searchurl.bid/joyceesther0101/finish1.php
I didn't look into how GMA.html works, but a quick look just now shows that it posts to https://searchurl.bid/joyceesther0101/finish1.php
Interesting that it is 'facilitating' phishing (as in dependency in attack chain), but only to the extent that would apply to a number of general-purpose open source libraries, or the browser, or any OS or ISP.
Seems like DigitalOcean made the wrong choice, but the technical complexity of the situation is enough to not put too much blame on them. Unresponsive support is disappointing.
I switched to scaleway afterwards.
https://forum.vestacp.com/viewtopic.php?p=68594#p68594
https://www.digitalocean.com/community/questions/how-do-i-de...
Appears there was a vulnerability in this panel, seems plausible that 'owner' of this page is an additional victim of the attacker.