Files
mthcht-ThreatHunting-Keywords/Phishing_category_detection.csv
mthcht 755048bf5e Mars and April 2025 update
very few additions and some corrections
2025-04-24 05:55:50 +02:00

289 KiB

1keywordmetadata_keyword_regexmetadata_keyword_typemetadata_toolmetadata_descriptionmetadata_tool_techniquesmetadata_tool_tacticsmetadata_malwares_namemetadata_groups_namemetadata_categorymetadata_linkmetadata_enable_endpoint_detectionmetadata_enable_proxy_detectionmetadata_tagsmetadata_commentmetadata_severity_scoremetadata_popularity_scoremetadata_github_starsmetadata_github_forksmetadata_github_updated_atmetadata_github_created_atmetadata_entry_id
2*- {phish_sub: *.{0,1000}\-\s\{phish_sub\:\s.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/Evilginx2-Phishlets10#contentN/A1076702632025-02-06T02:46:16Z2020-05-13T05:58:43Z132
3* 365-Stealer *.{0,1000}\s365\-Stealer\s.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z160
4* camhacker *.{0,1000}\scamhacker\s.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A1010N/AN/AN/AN/A540
5* camhacker:/CamHacker*.{0,1000}\scamhacker\:\/CamHacker.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A541
6* --CollectLinks --apitoken * --outfile *.{0,1000}\s\-\-CollectLinks\s\-\-apitoken\s.{0,1000}\s\-\-outfile\s.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10N/AN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z656
7* --custom-steal.{0,1000}\s\-\-custom\-stealoffensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z754
8* --custom-steal listusers*.{0,1000}\s\-\-custom\-steal\slistusers.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z755
9* --custom-steal onedrive*.{0,1000}\s\-\-custom\-steal\sonedrive.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z756
10* --custom-steal onenote*.{0,1000}\s\-\-custom\-steal\sonenote.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z757
11* --custom-steal outlook*.{0,1000}\s\-\-custom\-steal\soutlook.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z758
12* domainhunter *.{0,1000}\sdomainhunter\s.{0,1000}offensive_tool_keyworddomainhunterChecks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names T1583.002 - T1568.002TA0011 - TA0009N/AN/APhishinghttps://github.com/threatexpress/domainhunter10N/AN/AN/A1015872922024-06-06T21:01:21Z2017-03-01T11:16:26Z912
13* evilginx*.{0,1000}\sevilginx.{0,1000}offensive_tool_keywordgophishCombination of evilginx2 and GoPhishT1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/fin3ss3g0d/evilgophish10N/AN/A101017623402024-06-15T17:48:11Z2022-09-07T02:47:43Z1087
14* EvilnoVNC by @JoelGMSec*.{0,1000}\sEvilnoVNC\sby\s\@JoelGMSec.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#linux #contentN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z1088
15* EvilnoVNC*.{0,1000}\sEvilnoVNC.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z1089
16* evil-proxy*.{0,1000}\sevil\-proxy.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z1090
17* evil-proxy.rb*.{0,1000}\sevil\-proxy\.rb.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z1091
18* ExtensionSpoof.exe*.{0,1000}\sExtensionSpoof\.exe.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer10N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z1140
19* --fuzzers addition*.{0,1000}\s\-\-fuzzers\saddition.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1263
20* --fuzzers bitsquatting*.{0,1000}\s\-\-fuzzers\sbitsquatting.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1264
21* --fuzzers cyrillic*.{0,1000}\s\-\-fuzzers\scyrillic.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1265
22* --fuzzers dictionary*.{0,1000}\s\-\-fuzzers\sdictionary.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1266
23* --fuzzers homoglyph*.{0,1000}\s\-\-fuzzers\shomoglyph.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1267
24* --fuzzers hyphenation*.{0,1000}\s\-\-fuzzers\shyphenation.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1268
25* --fuzzers insertion*.{0,1000}\s\-\-fuzzers\sinsertion.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1269
26* --fuzzers omission*.{0,1000}\s\-\-fuzzers\somission.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1270
27* --fuzzers repetition*.{0,1000}\s\-\-fuzzers\srepetition.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1271
28* --fuzzers replacement*.{0,1000}\s\-\-fuzzers\sreplacement.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1272
29* --fuzzers subdomain*.{0,1000}\s\-\-fuzzers\ssubdomain.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1273
30* --fuzzers transposition*.{0,1000}\s\-\-fuzzers\stransposition.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1274
31* --fuzzers vowel-swap*.{0,1000}\s\-\-fuzzers\svowel\-swap.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z1275
32* --greeting * --personalize *--securelink*.{0,1000}\s\-\-greeting\s.{0,1000}\s\-\-personalize\s.{0,1000}\-\-securelink.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher10N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z1384
33* --Inject --stub *.dll* --app *.{0,1000}\s\-\-Inject\s\-\-stub\s.{0,1000}\.dll.{0,1000}\s\-\-app\s.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10N/AN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z1662
34* install evil-proxy*.{0,1000}\sinstall\sevil\-proxy.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z1686
35* --keyword * --check --ocr * --alexa*.{0,1000}\s\-\-keyword\s.{0,1000}\s\-\-check\s\-\-ocr\s.{0,1000}\s\-\-alexa.{0,1000}offensive_tool_keyworddomainhunterChecks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names T1583.002 - T1568.002TA0011 - TA0009N/AN/APhishinghttps://github.com/threatexpress/domainhunter10N/AN/AN/A1015872922024-06-06T21:01:21Z2017-03-01T11:16:26Z1882
36* pastehakk.sh*.{0,1000}\spastehakk\.sh.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk10#linuxN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z2539
37* Redirect Url After Stealing ==> *.{0,1000}\sRedirect\sUrl\sAfter\sStealing\s\=\=\>\s.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z2811
38* saycheese.sh*.{0,1000}\ssaycheese\.sh.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese10N/AN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z2983
39* smuggler.py*.{0,1000}\ssmuggler\.py.{0,1000}offensive_tool_keywordsmuggler.pyHTML Smuggling GeneratorT1564.001 - T1027 - T1566TA0005N/AN/APhishinghttps://github.com/infosecn1nja/red-team-scripts/blob/main/smuggler.py10N/AN/A93299552024-08-08T06:11:06Z2023-01-15T22:37:34Z3269
40* termux-chroot */cloudflared*.{0,1000}\stermux\-chroot\s.{0,1000}\/cloudflared.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A3502
41* tricky.ps1*.{0,1000}\stricky\.ps1.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z3555
42* tricky.vbs*.{0,1000}\stricky\.vbs.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z3556
43* tricky2.ps1*.{0,1000}\stricky2\.ps1.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z3557
44* --vnc localhost:5900 --listen 5980*.{0,1000}\s\-\-vnc\slocalhost\:5900\s\-\-listen\s5980.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#linuxN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z3672
45*"Evilginx Mastery Course"*.{0,1000}\"Evilginx\sMastery\sCourse\".{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#contentN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z3837
46*${White}A tool to perform clipboard poisoning attack*.{0,1000}\$\{White\}A\stool\sto\sperform\sclipboard\spoisoning\sattack.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk10#linux #contentN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z3937
47*$Green Infecting html file*.{0,1000}\$Green\sInfecting\shtml\sfile.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk10#linux #contentN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z3981
48*$Hc2$w$c$rQW$d$s$w$b$Hc2$v$xZp$f$w$V9z$rQW$L$U$xZp*.{0,1000}\$Hc2\$w\$c\$rQW\$d\$s\$w\$b\$Hc2\$v\$xZp\$f\$w\$V9z\$rQW\$L\$U\$xZp.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A3982
49*$HOME/.tunneler*.{0,1000}\$HOME\/\.tunneler.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A3984
50*$N0q$x$Hc2$rQW*.{0,1000}\$N0q\$x\$Hc2\$rQW.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A4002
51*$tunneler_dir/loclx.log*.{0,1000}\$tunneler_dir\/loclx\.log.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A4024
52*./evil-proxy*.{0,1000}\.\/evil\-proxy.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10#linuxN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z4132
53*.doc.bat*.{0,1000}\.doc\.bat.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4290
54*.doc.dll*.{0,1000}\.doc\.dll.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4291
55*.doc.exe*.{0,1000}\.doc\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4292
56*.doc.htm*.{0,1000}\.doc\.htm.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4293
57*.doc.iso*.{0,1000}\.doc\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4294
58*.doc.jar*.{0,1000}\.doc\.jar.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4295
59*.doc.js*.{0,1000}\.doc\.js.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4296
60*.doc.sfx*.{0,1000}\.doc\.sfx.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4297
61*.doc.vbs*.{0,1000}\.doc\.vbs.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4298
62*.docx.bat*.{0,1000}\.docx\.bat.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4299
63*.docx.exe*.{0,1000}\.docx\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4300
64*.docx.htm*.{0,1000}\.docx\.htm.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4301
65*.docx.iso*.{0,1000}\.docx\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4302
66*.docx.jar*.{0,1000}\.docx\.jar.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4303
67*.docx.js*.{0,1000}\.docx\.js.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4305
68*.docx.sfx*.{0,1000}\.docx\.sfx.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4306
69*.docx.vbs*.{0,1000}\.docx\.vbs.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4307
70*.jpg.exe*.{0,1000}\.jpg\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4680
71*.jpg.iso*.{0,1000}\.jpg\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4681
72*.lab.evilginx.com*.{0,1000}\.lab\.evilginx\.com.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx211N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z4687
73*.pdf.bat*.{0,1000}\.pdf\.bat.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4721
74*.pdf.dll*.{0,1000}\.pdf\.dll.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4722
75*.pdf.exe*.{0,1000}\.pdf\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4723
76*.pdf.htm.{0,1000}\.pdf\.htm.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4724
77*.pdf.iso*.{0,1000}\.pdf\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4725
78*.pdf.jar*.{0,1000}\.pdf\.jar.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4726
79*.pdf.js*.{0,1000}\.pdf\.js.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4728
80*.pdf.sfx*.{0,1000}\.pdf\.sfx.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4729
81*.pdf.vbs*.{0,1000}\.pdf\.vbs.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4730
82*.ppt.bat*.{0,1000}\.ppt\.bat.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4739
83*.ppt.dll*.{0,1000}\.ppt\.dll.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4740
84*.ppt.exe*.{0,1000}\.ppt\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4741
85*.ppt.htm*.{0,1000}\.ppt\.htm.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4742
86*.ppt.iso*.{0,1000}\.ppt\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4743
87*.ppt.jar*.{0,1000}\.ppt\.jar.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4744
88*.ppt.js*.{0,1000}\.ppt\.js.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4745
89*.ppt.sfx*.{0,1000}\.ppt\.sfx.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4746
90*.ppt.vbs*.{0,1000}\.ppt\.vbs.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4747
91*.pptx.bat*.{0,1000}\.pptx\.bat.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4748
92*.pptx.dll*.{0,1000}\.pptx\.dll.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4749
93*.pptx.exe*.{0,1000}\.pptx\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4750
94*.pptx.htm*.{0,1000}\.pptx\.htm.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4751
95*.pptx.iso*.{0,1000}\.pptx\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4752
96*.pptx.jar*.{0,1000}\.pptx\.jar.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4753
97*.pptx.js*.{0,1000}\.pptx\.js.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4755
98*.pptx.sfx*.{0,1000}\.pptx\.sfx.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4756
99*.pptx.vbs*.{0,1000}\.pptx\.vbs.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4757
100*.py -k * -f *.bat -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.bat\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4774
101*.py -k * -f *.docm -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.docm\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4775
102*.py -k * -f *.docx -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.docx\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4776
103*.py -k * -f *.exe -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.exe\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4777
104*.py -k * -f *.js -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.js\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4778
105*.py -k * -f *.pps -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.pps\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4779
106*.py -k * -f *.ppsx -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.ppsx\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4780
107*.py -k * -f *.ppt -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.ppt\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4781
108*.py -k * -f *.ps1 -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.ps1\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4782
109*.py -k * -f *.xll -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xll\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4783
110*.py -k * -f *.xls -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xls\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4784
111*.py -k * -f *.xlsb -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xlsb\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4785
112*.py -k * -f *.xlsm -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xlsm\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4786
113*.py -k * -f *.xlsx -o *.html*.{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xlsx\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4787
114*.py -k * -f *.doc -o *.html*.{0,1000}\.py\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.doc\s\-o\s.{0,1000}\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z4835
115*.rar.exe*.{0,1000}\.rar\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4858
116*.rar.iso*.{0,1000}\.rar\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4859
117*.rtf.bat*.{0,1000}\.rtf\.bat.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4873
118*.rtf.dll*.{0,1000}\.rtf\.dll.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4874
119*.rtf.exe*.{0,1000}\.rtf\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4875
120*.rtf.htm*.{0,1000}\.rtf\.htm.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4876
121*.rtf.jar*.{0,1000}\.rtf\.jar.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4877
122*.rtf.js*.{0,1000}\.rtf\.js.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4878
123*.rtf.sfx*.{0,1000}\.rtf\.sfx.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4879
124*.rtf.vbs*.{0,1000}\.rtf\.vbs.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4880
125*.trycloudfare.com*DavWWWRoot*.{0,1000}\.trycloudfare\.com.{0,1000}DavWWWRoot.{0,1000}greyware_tool_keywordtrycloudflare.comThe subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activitiesT1071.001 - T1090 - T1583.003 - T1102TA0001 - TA0005 - TA0008 - TA0011N/AN/APhishinghttps://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware11N/AN/A1010N/AN/AN/AN/A4923
126*.tunneler/cf.log*.{0,1000}\.tunneler\/cf\.log.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A4925
127*.tunneler/cloudflared*.{0,1000}\.tunneler\/cloudflared.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A4926
128*.tunneler/loclx*.{0,1000}\.tunneler\/loclx.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A4927
129*.tunneler/loclx.log*.{0,1000}\.tunneler\/loclx\.log.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A4928
130*.txt.bat*.{0,1000}\.txt\.bat.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4933
131*.txt.dll*.{0,1000}\.txt\.dll.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4934
132*.txt.exe*.{0,1000}\.txt\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4935
133*.txt.htm*.{0,1000}\.txt\.htm.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4936
134*.txt.iso*.{0,1000}\.txt\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4937
135*.txt.jar*.{0,1000}\.txt\.jar.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4938
136*.txt.js.{0,1000}\.txt\.jsoffensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4940
137*.txt.sfx*.{0,1000}\.txt\.sfx.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4941
138*.txt.vbs*.{0,1000}\.txt\.vbs.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4942
139*.xls.bat*.{0,1000}\.xls\.bat.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4957
140*.xls.dll*.{0,1000}\.xls\.dll.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4958
141*.xls.exe*.{0,1000}\.xls\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4959
142*.xls.htm*.{0,1000}\.xls\.htm.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4960
143*.xls.iso*.{0,1000}\.xls\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4961
144*.xls.jar*.{0,1000}\.xls\.jar.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4962
145*.xls.js*.{0,1000}\.xls\.js.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4963
146*.xls.sfx*.{0,1000}\.xls\.sfx.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4964
147*.xls.vbs*.{0,1000}\.xls\.vbs.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4965
148*.xlsx.bat*.{0,1000}\.xlsx\.bat.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4966
149*.xlsx.dll*.{0,1000}\.xlsx\.dll.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4967
150*.xlsx.exe*.{0,1000}\.xlsx\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4968
151*.xlsx.htm*.{0,1000}\.xlsx\.htm.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4969
152*.xlsx.iso*.{0,1000}\.xlsx\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4970
153*.xlsx.jar*.{0,1000}\.xlsx\.jar.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4971
154*.xlsx.js*.{0,1000}\.xlsx\.js.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4973
155*.xlsx.sfx*.{0,1000}\.xlsx\.sfx.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4974
156*.xlsx.vbs*.{0,1000}\.xlsx\.vbs.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4975
157*.zip.exe*.{0,1000}\.zip\.exe.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4977
158*.zip.iso*.{0,1000}\.zip\.iso.{0,1000}offensive_tool_keyword_Suspicious extensions filesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005 - TA0007 - TA0011N/AN/APhishingN/A11N/AN/A1010N/AN/AN/AN/A4978
159*/.evilginx/*.{0,1000}\/\.evilginx\/.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#linuxN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z5013
160*/.localxpose/.access*.{0,1000}\/\.localxpose\/\.access.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10#linuxN/A10N/A5021
161*/365-Stealer.git*.{0,1000}\/365\-Stealer\.git.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer11N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z5086
162*/agent/stagers/dropbox.py*.{0,1000}\/agent\/stagers\/dropbox\.py.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML11N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z5234
163*/bin/bash -c "php -q -S 0.0.0.0:80 &" > /dev/null 2>&1*.{0,1000}\/bin\/bash\s\-c\s\"php\s\-q\s\-S\s0\.0\.0\.0\:80\s\&\"\s\>\s\/dev\/null\s2\>\&1.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z5621
164*/CamHacker-*.png*.{0,1000}\/CamHacker\-.{0,1000}\.png.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker11N/AN/A10N/A5941
165*/CamHacker.git*.{0,1000}\/CamHacker\.git.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker11N/AN/A10N/A5942
166*/ClickJack.exe.{0,1000}\/ClickJack\.exeoffensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf11N/AN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z6061
167*/CredPhisher/*.{0,1000}\/CredPhisher\/.{0,1000}offensive_tool_keywordCredPhisherPrompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI functionT1056.002 - T1111TA0004 N/AN/APhishinghttps://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher11N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z6265
168*/domainhunter*.{0,1000}\/domainhunter.{0,1000}offensive_tool_keyworddomainhunterChecks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names T1583.002 - T1568.002TA0011 - TA0009N/AN/APhishinghttps://github.com/threatexpress/domainhunter11N/AN/AN/A1015872922024-06-06T21:01:21Z2017-03-01T11:16:26Z6723
169*/Downloads/Keylogger.txt*.{0,1000}\/Downloads\/Keylogger\.txt.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z6769
170*/Downloads/keypress.log*.{0,1000}\/Downloads\/keypress\.log.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z6770
171*/EmbedInHTML.git*.{0,1000}\/EmbedInHTML\.git.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML11N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z6925
172*/EmbedInHTML/*.{0,1000}\/EmbedInHTML\/.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML11N/AN/AN/A54851192017-09-27T13:16:06Z2017-09-11T07:17:20Z6926
173*/EvilClippy-*.zip*.{0,1000}\/EvilClippy\-.{0,1000}\.zip.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy11N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z7073
174*/evilclippy.cs*.{0,1000}\/evilclippy\.cs.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy11N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z7074
175*/EvilClippy.git*.{0,1000}\/EvilClippy\.git.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy11N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z7075
176*/evilginx*.{0,1000}\/evilginx.{0,1000}offensive_tool_keywordgophishCombination of evilginx2 and GoPhishT1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/fin3ss3g0d/evilgophish11N/AN/A101017623402024-06-15T17:48:11Z2022-09-07T02:47:43Z7076
177*/evilginx2.git*.{0,1000}\/evilginx2\.git.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx211N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z7077
178*/evilginx2/*.{0,1000}\/evilginx2\/.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx211#linuxN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z7078
179*/EvilnoVNC.git*.{0,1000}\/EvilnoVNC\.git.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC11N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z7082
180*/evil-proxy.git*.{0,1000}\/evil\-proxy\.git.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy11N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z7083
181*/evil-proxy.rb*.{0,1000}\/evil\-proxy\.rb.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy11N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z7084
182*/evil-proxy/*.{0,1000}\/evil\-proxy\/.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10#linuxN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z7085
183*/evilqr.git*.{0,1000}\/evilqr\.git.{0,1000}offensive_tool_keywordevilqrProof-of-concept to demonstrate dynamic QR swap phishing attacks in practiceT1566.002 - T1204.001 - T1192TA0001 - TA0005N/AN/APhishinghttps://github.com/kgretzky/evilqr11N/AN/AN/A3292452024-06-18T11:27:23Z2023-06-20T12:58:09Z7086
184*/ExtensionSpoof.exe*.{0,1000}\/ExtensionSpoof\.exe.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer11N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z7155
185*/ExtensionSpoofer.git*.{0,1000}\/ExtensionSpoofer\.git.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer11N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z7156
186*/gophish.db*.{0,1000}\/gophish\.db.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/Evilginx-Phishing-Infra-Setup10#linuxN/A104391672024-12-12T04:13:02Z2024-06-08T10:19:45Z7584
187*/gophish.db*.{0,1000}\/gophish\.db.{0,1000}offensive_tool_keywordgophishOpen-Source Phishing ToolkitT1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/gophish/gophish11N/AN/A10101248325282024-09-23T04:24:43Z2013-11-18T23:26:43Z7585
188*/gophish/*.{0,1000}\/gophish\/.{0,1000}offensive_tool_keywordgophishOpen-Source Phishing ToolkitT1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/gophish/gophish11N/AN/A10101248325282024-09-23T04:24:43Z2013-11-18T23:26:43Z7586
189*/gophish_admin.crt*.{0,1000}\/gophish_admin\.crt.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/Evilginx-Phishing-Infra-Setup10#linuxN/A104391672024-12-12T04:13:02Z2024-06-08T10:19:45Z7587
190*/gophish_admin.key*.{0,1000}\/gophish_admin\.key.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/Evilginx-Phishing-Infra-Setup10#linuxN/A104391672024-12-12T04:13:02Z2024-06-08T10:19:45Z7588
191*/HTMLSmuggler.git*.{0,1000}\/HTMLSmuggler\.git.{0,1000}offensive_tool_keywordHTMLSmugglerHTML Smuggling generator&obfuscator for your Red Team operationsT1564.001 - T1027 - T1566TA0005N/AN/APhishinghttps://github.com/D00Movenok/HTMLSmuggler11N/AN/A102162192024-02-27T23:03:55Z2023-07-02T08:10:59Z7824
192*/HTMLSmuggler/*.{0,1000}\/HTMLSmuggler\/.{0,1000}offensive_tool_keywordHTMLSmugglerHTML Smuggling generator&obfuscator for your Red Team operationsT1564.001 - T1027 - T1566TA0005N/AN/APhishinghttps://github.com/D00Movenok/HTMLSmuggler11N/AN/A102162192024-02-27T23:03:55Z2023-07-02T08:10:59Z7825
193*/keygen.exe*.{0,1000}\/keygen\.exe.{0,1000}greyware_tool_keyword_generic suspicious keyword keygen.exe observed in multiple cracked software often packed with malwaresT1204 - T1027 - T1059 - T1055 - T1060 - T1195TA0005 - TA0002 - TA0011N/AN/APhishingN/A10N/AN/A1010N/AN/AN/AN/A8341
194*/lnk2pwn.git*.{0,1000}\/lnk2pwn\.git.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn11N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z8560
195*/lnk2pwn-1.0.0.zip*.{0,1000}\/lnk2pwn\-1\.0\.0\.zip.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn11N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z8561
196*/login/e1837f4d-1d0c-49b8-a242-8f653226c137*.{0,1000}\/login\/e1837f4d\-1d0c\-49b8\-a242\-8f653226c137.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx211N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z8611
197*/mrd0x.html*.{0,1000}\/mrd0x\.html.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing11N/AN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z8907
198*/ngrok http 3333 > /dev/null 2>&1*.{0,1000}\/ngrok\shttp\s3333\s\>\s\/dev\/null\s2\>\&1.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese10#linuxN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z9135
199*/noVNC/index.html*.{0,1000}\/noVNC\/index\.html.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#linuxN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z9247
200*/noVNC/utils/novnc_proxy*.{0,1000}\/noVNC\/utils\/novnc_proxy.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z9248
201*/noVNC/vnc_lite.html*.{0,1000}\/noVNC\/vnc_lite\.html.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#linuxN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z9249
202*/pastehakk.git*.{0,1000}\/pastehakk\.git.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk11N/AN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z9541
203*/pastehakk.sh*.{0,1000}\/pastehakk\.sh.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk11#linuxN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z9542
204*/PAYMENTS.exe*.{0,1000}\/PAYMENTS\.exe.{0,1000}greyware_tool_keyword_suspicious file name - has been used by threat actorsT1566TA0001N/AN/APhishingN/A10N/AN/A1010N/AN/AN/AN/A9567
205*/phishery.exe*.{0,1000}\/phishery\.exe.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery11N/AN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z9661
206*/phishery.git*.{0,1000}\/phishery\.git.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery11N/AN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z9662
207*/phishery/releases/download/*.{0,1000}\/phishery\/releases\/download\/.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery11N/AN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z9663
208*/phishing-HTML-linter.py*.{0,1000}\/phishing\-HTML\-linter\.py.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/Evilginx-Phishing-Infra-Setup10#linuxN/A104391672024-12-12T04:13:02Z2024-06-08T10:19:45Z9668
209*/phishlets/example.yaml*.{0,1000}\/phishlets\/example\.yaml.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx211#linuxN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z9670
210*/PWA-Phishing.git*.{0,1000}\/PWA\-Phishing\.git.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing11N/AN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z10035
211*/recaptcha-phish.git*.{0,1000}\/recaptcha\-phish\.git.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish11N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z10252
212*/recaptcha-phish-main*.{0,1000}\/recaptcha\-phish\-main.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish11N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z10253
213*/releases/latest/download/cloudflared-darwin-amd64.tgz*.{0,1000}\/releases\/latest\/download\/cloudflared\-darwin\-amd64\.tgz.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker11#linuxN/A10N/A10350
214*/saycheese.html*.{0,1000}\/saycheese\.html.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese11N/AN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z10693
215*/saycheese.sh*.{0,1000}\/saycheese\.sh.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese11N/AN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z10694
216*/smuggler.py*.{0,1000}\/smuggler\.py.{0,1000}offensive_tool_keywordsmuggler.pyHTML Smuggling GeneratorT1564.001 - T1027 - T1566TA0005N/AN/APhishinghttps://github.com/infosecn1nja/red-team-scripts/blob/main/smuggler.py11N/AN/A93299552024-08-08T06:11:06Z2023-01-15T22:37:34Z11448
217*/start.sh dynamic *.{0,1000}\/start\.sh\sdynamic\s.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z11657
218*/startVNC.sh*.{0,1000}\/startVNC\.sh.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z11661
219*/Teamphisher.txt*.{0,1000}\/Teamphisher\.txt.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher11N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z11833
220*/Teamphisher/targets.txt*.{0,1000}\/Teamphisher\/targets\.txt.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher11N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z11834
221*/tmp/resolution.txt*server.sh*.{0,1000}\/tmp\/resolution\.txt.{0,1000}server\.sh.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z11990
222*/tricky.lnk.git*.{0,1000}\/tricky\.lnk\.git.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk11N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z12087
223*/tricky.ps1*.{0,1000}\/tricky\.ps1.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk11N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z12088
224*/tricky.vbs*.{0,1000}\/tricky\.vbs.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk11N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z12089
225*/tricky2.ps1*.{0,1000}\/tricky2\.ps1.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk11N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z12090
226*/usr/share/evilginx*.{0,1000}\/usr\/share\/evilginx.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#linuxN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z12374
227*/utils/novnc_proxy*.{0,1000}\/utils\/novnc_proxy.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#linuxN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z12384
228*/var/log/evilginx*.{0,1000}\/var\/log\/evilginx.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#linuxN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z12404
229*/VisualBasicObfuscator*.{0,1000}\/VisualBasicObfuscator.{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z12458
230*/windows-login-phish*.{0,1000}\/windows\-login\-phish.{0,1000}offensive_tool_keywordwindows-login-phishWindows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposesT1566N/AN/AN/APhishinghttps://github.com/CipherKill/windows-login-phish11N/AN/AN/A11762022-03-25T05:49:01Z2022-03-13T20:02:15Z12608
231*@mitm_pattern = *.{0,1000}\@mitm_pattern\s\=\s.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z12880
232*@mitm_port = *.{0,1000}\@mitm_port\s\=\s.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z12881
233*@mitm_servers =*.{0,1000}\@mitm_servers\s\=.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z12882
234*[!] Looks like Victim * doesn't have office365 Licence!*.{0,1000}\[!\]\sLooks\slike\sVictim\s.{0,1000}\sdoesn\'t\shave\soffice365\sLicence!.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10#contentN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z12944
235*[!] Stealing processes delayed with *.{0,1000}\[!\]\sStealing\sprocesses\sdelayed\swith\s.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10#contentN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z12961
236*[!] Swithed to custom stealing. *.{0,1000}\[!\]\sSwithed\sto\scustom\sstealing\.\s.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10#contentN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z12963
237*[!] This application can not be injected*.{0,1000}\[!\]\sThis\sapplication\scan\snot\sbe\sinjected.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10#contentN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z12968
238*[+] This application is injectable!*.{0,1000}\[\+\]\sThis\sapplication\sis\sinjectable!.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10#contentN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z13370
239*[+] Victim * have office365 Licence!*.{0,1000}\[\+\]\sVictim\s.{0,1000}\shave\soffice365\sLicence!.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10#contentN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z13417
240*[CamHacker]*.{0,1000}\[CamHacker\].{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A13448
241*\CamHacker\*.{0,1000}\\CamHacker\\.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A14464
242*\ClickJack.csproj*.{0,1000}\\ClickJack\.csproj.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10N/AN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z14542
243*\ClickJack.exe.{0,1000}\\ClickJack\.exeoffensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10N/AN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z14543
244*\Content\.Outlook\*\*.rdp*.{0,100}\\Content\.Outlook\\[A-Z0-9]{8}\\[^\\]{1,255}\.rdp.{0,100}greyware_tool_keywordrdprdp file received in emails - abused by attackersT1204 - T1566 - T1078 - T1105TA0001 - TA0002 - TA0010 - TA0011N/AMidnight Blizzard - APT29 - UNC2452 - Cozy BearPhishinghttps://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files10N/Ahttps://x.com/cyb3rops/status/185188015864009967598N/AN/AN/AN/A14616
245*\Desktop\FakeText.lnk*.{0,1000}\\Desktop\\FakeText\.lnk.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z14911
246*\EvilClippy-*.zip*.{0,1000}\\EvilClippy\-.{0,1000}\.zip.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy10N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z15344
247*\evilclippy.cs*.{0,1000}\\evilclippy\.cs.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy10N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z15345
248*\evilginx2\*.{0,1000}\\evilginx2\\.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z15346
249*\EvilnoVNC*.{0,1000}\\EvilnoVNC.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1566.001 - T1071 - T1071.001TA0043 - TA0001N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z15348
250*\evil-proxy.rb*.{0,1000}\\evil\-proxy\.rb.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z15349
251*\evil-proxy\*.{0,1000}\\evil\-proxy\\.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z15350
252*\ExtensionSpoof.exe*.{0,1000}\\ExtensionSpoof\.exe.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer10N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z15400
253*\ExtensionSpoof.sln*.{0,1000}\\ExtensionSpoof\.sln.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer10N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z15401
254*\ExtensionSpoofer\*.{0,1000}\\ExtensionSpoofer\\.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer10N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z15402
255*\HTMLSmuggler\*.{0,1000}\\HTMLSmuggler\\.{0,1000}offensive_tool_keywordHTMLSmugglerHTML Smuggling generator&obfuscator for your Red Team operationsT1564.001 - T1027 - T1566TA0005N/AN/APhishinghttps://github.com/D00Movenok/HTMLSmuggler10N/AN/A102162192024-02-27T23:03:55Z2023-07-02T08:10:59Z15834
256*\keygen.exe*.{0,1000}\\keygen\.exe.{0,1000}greyware_tool_keyword_generic suspicious keyword keygen.exe observed in multiple cracked software often packed with malwaresT1204 - T1027 - T1059 - T1055 - T1060 - T1195TA0005 - TA0002 - TA0011N/AN/APhishingN/A10N/AN/AN/AN/AN/AN/AN/AN/A16119
257*\Keylogger.txt*.{0,1000}\\Keylogger\.txt.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1566.001 - T1071 - T1071.001TA0043 - TA0001N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z16129
258*\Lnk2Pwn.java*.{0,1000}\\Lnk2Pwn\.java.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z16304
259*\Lnk2PwnFrame.java*.{0,1000}\\Lnk2PwnFrame\.java.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z16305
260*\lnk2pwn-master*.{0,1000}\\lnk2pwn\-master.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z16306
261*\notavirus.exe*.{0,1000}\\notavirus\.exe.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z16961
262*\PAYMENT.hta*.{0,1000}\\PAYMENT\.hta.{0,1000}greyware_tool_keyword_suspicious file name - has been used by threat actorsT1566TA0001N/AN/APhishingN/A10N/AN/A1010N/AN/AN/AN/A17152
263*\PAYMENT.hta*.{0,1000}\\PAYMENT\.hta.{0,1000}greyware_tool_keyword_suspicious file name - has been used by threat actorsT1566TA0001N/AN/APhishingN/A10N/AN/A1010N/AN/AN/AN/A17153
264*\PAYMENTS.exe*.{0,1000}\\PAYMENTS\.exe.{0,1000}greyware_tool_keyword_suspicious file name - has been used by threat actorsT1566TA0001N/AN/APhishingN/A10N/AN/A1010N/AN/AN/AN/A17154
265*\phishery.exe*.{0,1000}\\phishery\.exe.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery10N/AN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z17240
266*\phishlets\example.yaml*.{0,1000}\\phishlets\\example\.yaml.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z17241
267*\PWA-Phishing*.{0,1000}\\PWA\-Phishing.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing10N/AN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z17661
268*\recaptcha-phish-main*.{0,1000}\\recaptcha\-phish\-main.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z17828
269*\smuggler.py*.{0,1000}\\smuggler\.py.{0,1000}offensive_tool_keywordsmuggler.pyHTML Smuggling GeneratorT1564.001 - T1027 - T1566TA0005N/AN/APhishinghttps://github.com/infosecn1nja/red-team-scripts/blob/main/smuggler.py10N/AN/A93299552024-08-08T06:11:06Z2023-01-15T22:37:34Z18916
270*\tricky.lnk\*.{0,1000}\\tricky\.lnk\\.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z19418
271*\tricky.ps1*.{0,1000}\\tricky\.ps1.{0,1000}offensive_tool_keywordMacroMeterVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z19419
272*\tricky.vbs*.{0,1000}\\tricky\.vbs.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z19420
273*\tricky2.ps1*.{0,1000}\\tricky2\.ps1.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z19421
274*\uac_bypass.vbs*.{0,1000}\\uac_bypass\.vbs.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z19465
275*_EvilClippy.*.{0,1000}_EvilClippy\..{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy10N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z20123
276*= "evil-proxy"*.{0,1000}\=\s\"evil\-proxy\".{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z20265
277*=ogIXFlckIzYIRCekEHMORiIgwWY2VmCpICcahHJVRCTkcVUyRie5YFJ3RiZkAnW4RidkIzYIRiYkcHJzRCZkcVUyRyYkcHJyMGSkICIsFmdlhCJ9gnC*.{0,1000}\=ogIXFlckIzYIRCekEHMORiIgwWY2VmCpICcahHJVRCTkcVUyRie5YFJ3RiZkAnW4RidkIzYIRiYkcHJzRCZkcVUyRyYkcHJyMGSkICIsFmdlhCJ9gnC.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A20297
278*00895d7e0a42f794de5f471a41c0cd996ee3298a4183834cb8b99f10552a5e1c*.{0,1000}00895d7e0a42f794de5f471a41c0cd996ee3298a4183834cb8b99f10552a5e1c.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z20669
279*02FAF312-BF2A-466B-8AD2-1339A31C303B*.{0,1000}02FAF312\-BF2A\-466B\-8AD2\-1339A31C303B.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10#GUIDprojectN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z20861
280*0675558d182096b75d100d91c77c1119d229c315f12bb86e353e49894b9e1d62*.{0,1000}0675558d182096b75d100d91c77c1119d229c315f12bb86e353e49894b9e1d62.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A101N/AN/AN/AN/A21110
281*0bc38984ce64aa213a77c2c9125a68a057f76f354a44060f8342d5375368ef04*.{0,1000}0bc38984ce64aa213a77c2c9125a68a057f76f354a44060f8342d5375368ef04.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A21494
282*10c9d70217e5a3915a6c09feea4110991dae5d9a1b6ae5d32c4d69dd6b6eaf50*.{0,1000}10c9d70217e5a3915a6c09feea4110991dae5d9a1b6ae5d32c4d69dd6b6eaf50.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10#filehashN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z21914
283*11fcbd067d55ddaa11e622be03a55ea342efe497cbcb14abf4dc410cb5d7a203*.{0,1000}11fcbd067d55ddaa11e622be03a55ea342efe497cbcb14abf4dc410cb5d7a203.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10#filehashN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z22006
284*127.0.0.1:#{mitm_port}*.{0,1000}127\.0\.0\.1\:\#\{mitm_port\}.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z22043
285*1446b2b7ac055dd73177e7610141376dcdb8419b0422f81d69c589ce60e83e42*.{0,1000}1446b2b7ac055dd73177e7610141376dcdb8419b0422f81d69c589ce60e83e42.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z22188
286*16bb30509efac0ba13c42eade477ab4454c5951c1c20f7c991c62798284aa3b0*.{0,1000}16bb30509efac0ba13c42eade477ab4454c5951c1c20f7c991c62798284aa3b0.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery10#filehashN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z22350
287*1827f84465eaa41ba584561ae108be14e693ba4c992e9d58ef0148959cc9efc1*.{0,1000}1827f84465eaa41ba584561ae108be14e693ba4c992e9d58ef0148959cc9efc1.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A22438
288*187622b4abcd679d2a8b74ba1ea8cec9d517a4026fc58ea7c33ff13ad5c1ca88*.{0,1000}187622b4abcd679d2a8b74ba1ea8cec9d517a4026fc58ea7c33ff13ad5c1ca88.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z22461
289*18c54c69f41d0b7e5928c34e1e9350ed99ecd0278ea37df11a429018ca3d05ed*.{0,1000}18c54c69f41d0b7e5928c34e1e9350ed99ecd0278ea37df11a429018ca3d05ed.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing10#filehashN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z22480
290*1a571ac5b806ffce2605b57753f74653ddb392e5afdb0e49c3e9e8d76e561568*.{0,1000}1a571ac5b806ffce2605b57753f74653ddb392e5afdb0e49c3e9e8d76e561568.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#filehashN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z22599
291*1c267e901a65d142bf532bc0d26926dd9ceaa43e16b48df37c0739ba050a1c50*.{0,1000}1c267e901a65d142bf532bc0d26926dd9ceaa43e16b48df37c0739ba050a1c50.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A22731
292*1c7e93ed2b3eed1303cc11d09b4fea4b183fb0e7041f9584c81ca4c989d8a46f*.{0,1000}1c7e93ed2b3eed1303cc11d09b4fea4b183fb0e7041f9584c81ca4c989d8a46f.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A22756
293*1dd63a324303ac18c64c435bf6acfff6efa419b20c305dddb9905cde41feeb4c*.{0,1000}1dd63a324303ac18c64c435bf6acfff6efa419b20c305dddb9905cde41feeb4c.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A22853
294*1de0d1e7805edcd36247e2c224aa8c691c774ba8497f88f2e2dea157c30906a9*.{0,1000}1de0d1e7805edcd36247e2c224aa8c691c774ba8497f88f2e2dea157c30906a9.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A22854
295*1e00cb67cc7d0f6610235ae151268e1aa8c38fe8f2675f9884baf1dde23d9303*.{0,1000}1e00cb67cc7d0f6610235ae151268e1aa8c38fe8f2675f9884baf1dde23d9303.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z22868
296*1f7552f9d41f1e64d15e8cface42784b169d197992a072cf0072072dc640f58d*.{0,1000}1f7552f9d41f1e64d15e8cface42784b169d197992a072cf0072072dc640f58d.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A22986
297*216361a2e00d7514c8300d3171dfd5cb8a5e6a061216125119a0d656d812de79*.{0,1000}216361a2e00d7514c8300d3171dfd5cb8a5e6a061216125119a0d656d812de79.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A23132
298*22379d69fa7ac3ae6679aba9a2346d5e66e819384641782e033f4a6efc4097c3*.{0,1000}22379d69fa7ac3ae6679aba9a2346d5e66e819384641782e033f4a6efc4097c3.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A23198
299*2443660c8c3e8fcf80e028c6417a0110fde1f3a0961f70ffb960cbf64958e244*.{0,1000}2443660c8c3e8fcf80e028c6417a0110fde1f3a0961f70ffb960cbf64958e244.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A23341
300*2609239cc8bc517f684285133622e8b11192fb456e2dc2937aa2c6c2379a9d38*.{0,1000}2609239cc8bc517f684285133622e8b11192fb456e2dc2937aa2c6c2379a9d38.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A23460
301*2711dda772bc1073c031d6044b5fe5eddc6943420ebd7e214e0b5e60adcd89d6*.{0,1000}2711dda772bc1073c031d6044b5fe5eddc6943420ebd7e214e0b5e60adcd89d6.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A23541
302*298047e6ce299b73ea411a8ed2d67484db6c8c276a299403e0b9766cc9079456*.{0,1000}298047e6ce299b73ea411a8ed2d67484db6c8c276a299403e0b9766cc9079456.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A23696
303*2d3ce0b49997314a863aa4a9ef25fe06021aac1107aaf63af18ba9730f13e7e3*.{0,1000}2d3ce0b49997314a863aa4a9ef25fe06021aac1107aaf63af18ba9730f13e7e3.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A23929
304*2f2673bba488dc6bfd8e64f2d9b14049a4b495b7149a2e16980547467afc3fba*.{0,1000}2f2673bba488dc6bfd8e64f2d9b14049a4b495b7149a2e16980547467afc3fba.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A24079
305*31795b2f772b6ad00274cc4eb40aaf81b5d38d6eeae56bace80a07bbb1aeac35*.{0,1000}31795b2f772b6ad00274cc4eb40aaf81b5d38d6eeae56bace80a07bbb1aeac35.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A24262
306*334a8657b76c88f5d7b6a2be78cc4e9e6c5ecaeea5a104cea5e6d0c4250674a7*.{0,1000}334a8657b76c88f5d7b6a2be78cc4e9e6c5ecaeea5a104cea5e6d0c4250674a7.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery10#filehashN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z24387
307*335ac01e952db33997b844a2e7c506d541e353d6e82ead3fde51e4879fde736a*.{0,1000}335ac01e952db33997b844a2e7c506d541e353d6e82ead3fde51e4879fde736a.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A24394
308*365-Stealer.py*.{0,1000}365\-Stealer\.py.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer11N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z24596
309*365-Stealer-master*.{0,1000}365\-Stealer\-master.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer11N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z24597
310*36ff05fc406bf6a2e677374028ba00cb622b2219e44c198d5dd6efae4ae963c3*.{0,1000}36ff05fc406bf6a2e677374028ba00cb622b2219e44c198d5dd6efae4ae963c3.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z24648
311*3a3bd44b20afbb14ce14e70e474491383c2fcc87a554e4fbdc489c65ee7ace2a*.{0,1000}3a3bd44b20afbb14ce14e70e474491383c2fcc87a554e4fbdc489c65ee7ace2a.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A24881
312*3b1e2b01bfa6ad0deefa3bf8e7a81e9fc295e56b8f087ef402d9a06e42ec3b95*.{0,1000}3b1e2b01bfa6ad0deefa3bf8e7a81e9fc295e56b8f087ef402d9a06e42ec3b95.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing10#filehashN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z24939
313*3b3fd00d44c44dbb8387dcd1b41772fb3fdd14b15d24d2af981d9da783545b68*.{0,1000}3b3fd00d44c44dbb8387dcd1b41772fb3fdd14b15d24d2af981d9da783545b68.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z24945
314*3ba7ec45c5017f57077a98ed61ce1f24dacddfb4928c20351aba2c0ae4398e39*.{0,1000}3ba7ec45c5017f57077a98ed61ce1f24dacddfb4928c20351aba2c0ae4398e39.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z24972
315*3ccb81e184f94e47a9a7c7e75978ad9eda2850967b0a2e03a505776e4969b8a2*.{0,1000}3ccb81e184f94e47a9a7c7e75978ad9eda2850967b0a2e03a505776e4969b8a2.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A25056
316*3d27ba8268164db337978538c6e6c33e0b91194d184e6b6b73f1089a425a60f5*.{0,1000}3d27ba8268164db337978538c6e6c33e0b91194d184e6b6b73f1089a425a60f5.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A25080
317*3e3b34ad2eaa319676168ff54b63f3219c517cbd50c3df43b2fb4cfe141b5ab2*.{0,1000}3e3b34ad2eaa319676168ff54b63f3219c517cbd50c3df43b2fb4cfe141b5ab2.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z25141
318*3xploitGuy/pastehakk*.{0,1000}3xploitGuy\/pastehakk.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk11N/AN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z25300
319*40e8b756d0f996d7127ffc76d3fb122dd014455bc6b0c007e6d5d77e5bb6211b*.{0,1000}40e8b756d0f996d7127ffc76d3fb122dd014455bc6b0c007e6d5d77e5bb6211b.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10#filehashN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z25372
320*43bc3fe471a81b11c2e59cd0fd55630cee7860f8caad44fb8ee54d109e01a5e5*.{0,1000}43bc3fe471a81b11c2e59cd0fd55630cee7860f8caad44fb8ee54d109e01a5e5.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A25595
321*4614a6da343623fc820d89d35b8c2a26fe69abf357af7ef7602e52808fbe8611*.{0,1000}4614a6da343623fc820d89d35b8c2a26fe69abf357af7ef7602e52808fbe8611.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A25760
322*4aa27ae37edfbfe57f3ab989d192caf21b3c871516958eb77205c9ad700c3f67*.{0,1000}4aa27ae37edfbfe57f3ab989d192caf21b3c871516958eb77205c9ad700c3f67.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A26059
323*4f2678fa0f90074ae304f8fdb9174d0c577f1a0587af44a4e8e756a547e5c2e4*.{0,1000}4f2678fa0f90074ae304f8fdb9174d0c577f1a0587af44a4e8e756a547e5c2e4.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10#filehashN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z26411
324*520f529151f419ccb0e75d9f9d2c9a24fb4809468dbd95360e4483672db46407*.{0,1000}520f529151f419ccb0e75d9f9d2c9a24fb4809468dbd95360e4483672db46407.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A26646
325*52b1b3fa12706c1cc7ca2da321e23b151f812a5f7660f0114cc8470de3a3065d*.{0,1000}52b1b3fa12706c1cc7ca2da321e23b151f812a5f7660f0114cc8470de3a3065d.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A26683
326*53a9c6eed3ee5ed0ea6fe900bbcdac2b9c0709c57c8d82688ef32f7e2b784f60*.{0,1000}53a9c6eed3ee5ed0ea6fe900bbcdac2b9c0709c57c8d82688ef32f7e2b784f60.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk10#linux #filehashN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z26744
327*5406c993ef16ac875804185a8f37db5b2473def489a613de0b667f304b498c97*.{0,1000}5406c993ef16ac875804185a8f37db5b2473def489a613de0b667f304b498c97.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z26769
328*55049f7690abbbb5c8dc844e54b63269d111c0cd21e98854c666a27788dc5de6*.{0,1000}55049f7690abbbb5c8dc844e54b63269d111c0cd21e98854c666a27788dc5de6.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A26848
329*55a3bbb8a62578b455e478cb197aadd389f2e65418595e5df4636972be878710*.{0,1000}55a3bbb8a62578b455e478cb197aadd389f2e65418595e5df4636972be878710.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A26895
330*5740d6067561fcd27239374abbfd7076d3df5909b107a32bbb2e9eec0e9f4d61*.{0,1000}5740d6067561fcd27239374abbfd7076d3df5909b107a32bbb2e9eec0e9f4d61.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27027
331*57630a0b38ad185ff8a8d0706ff9cebfd12f47526ceeeb90cc3a17e124316fe2*.{0,1000}57630a0b38ad185ff8a8d0706ff9cebfd12f47526ceeeb90cc3a17e124316fe2.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27040
332*57f5a53203d19daa9bb094b442bc029a374686af5be71741e5536e35590e9f9c*.{0,1000}57f5a53203d19daa9bb094b442bc029a374686af5be71741e5536e35590e9f9c.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27083
333*595a77ddfb6f674bd5bc1c297ae912f5ebf6ba218a2f857ff46b7b37d1a9678b*.{0,1000}595a77ddfb6f674bd5bc1c297ae912f5ebf6ba218a2f857ff46b7b37d1a9678b.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z27188
334*5a2845a19dc310535eec5c74dd770db258e90160ea63e5cc9d97ab87de8081ff*.{0,1000}5a2845a19dc310535eec5c74dd770db258e90160ea63e5cc9d97ab87de8081ff.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27235
335*5a3ae8d1bf88a4415c293623ca868e718bf2addbfc88953267bed9c9cf57c2ad*.{0,1000}5a3ae8d1bf88a4415c293623ca868e718bf2addbfc88953267bed9c9cf57c2ad.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27239
336*5ae17ceeb8dcfb5eb56fc27876c5047ddfebcb9114beb0a03db81000c46d7054*.{0,1000}5ae17ceeb8dcfb5eb56fc27876c5047ddfebcb9114beb0a03db81000c46d7054.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27280
337*5c5bd260c00111edc55b4bc8a82d72e0a510f738ce3696ab2bbcd4a38a84bb12*.{0,1000}5c5bd260c00111edc55b4bc8a82d72e0a510f738ce3696ab2bbcd4a38a84bb12.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27415
338*5c78c058c8278438ce30b86b3ccda222410206ec0ea5727b93b74bb8c6748bd5*.{0,1000}5c78c058c8278438ce30b86b3ccda222410206ec0ea5727b93b74bb8c6748bd5.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27423
339*5d447208b1a06d45b5563f56da869e3c6ffa8e67247809798d24065d719160e8*.{0,1000}5d447208b1a06d45b5563f56da869e3c6ffa8e67247809798d24065d719160e8.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27495
340*5d494fc79356aeb1e983aab7188e729550c1f54ffcdcb02270acc492f2164afa*.{0,1000}5d494fc79356aeb1e983aab7188e729550c1f54ffcdcb02270acc492f2164afa.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27497
341*5d848352fb3ae2109dd1ee927717c8c004f2e07f33b14d7fd25dba71784f5579*.{0,1000}5d848352fb3ae2109dd1ee927717c8c004f2e07f33b14d7fd25dba71784f5579.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27508
342*5ebd789e726c94beb41e0934df6fb9bf62af28cc87093b9785dc9baa4ecde96b*.{0,1000}5ebd789e726c94beb41e0934df6fb9bf62af28cc87093b9785dc9baa4ecde96b.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27600
343*613e5ca15d9bab3a0bad0c5eb8d63894c1b9fbab924385296c29d3b4f3479ee3*.{0,1000}613e5ca15d9bab3a0bad0c5eb8d63894c1b9fbab924385296c29d3b4f3479ee3.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27757
344*62eb5977f66221339e954ea9e4947966ad4558966264814a406b93dab8b275df*.{0,1000}62eb5977f66221339e954ea9e4947966ad4558966264814a406b93dab8b275df.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy10#filehashN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z27870
345*64591a6674fa71f5bf6858e009d487a56dc13d306cdab14a76e7b6fe49d4338b*.{0,1000}64591a6674fa71f5bf6858e009d487a56dc13d306cdab14a76e7b6fe49d4338b.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery10#filehashN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z27978
346*64853db4da2d13a82c795e1eb6e7e2c4efc2d673be34b5f65398f54b7277a5de*.{0,1000}64853db4da2d13a82c795e1eb6e7e2c4efc2d673be34b5f65398f54b7277a5de.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A27987
347*6522659bfa7046803bb28a749799fb9b876d656fa46037fe28709fb4ad15d115*.{0,1000}6522659bfa7046803bb28a749799fb9b876d656fa46037fe28709fb4ad15d115.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28035
348*652c0669b041362a1ece950a33752cca4940146934d651c04f992b8f11b0fba0*.{0,1000}652c0669b041362a1ece950a33752cca4940146934d651c04f992b8f11b0fba0.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z28036
349*6555c9310f7087fcf0b38eab5ad4efc6ec91566ff5bf2fbbed4e63c88611c395*.{0,1000}6555c9310f7087fcf0b38eab5ad4efc6ec91566ff5bf2fbbed4e63c88611c395.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28043
350*65696f93bce6d78c8e377fc3c4c56123f49f26a621a332bc764c274aa7c81632*.{0,1000}65696f93bce6d78c8e377fc3c4c56123f49f26a621a332bc764c274aa7c81632.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28048
351*676766b4b6296303a601cf2191da028cc39681fa69b1da408242882f760c849b*.{0,1000}676766b4b6296303a601cf2191da028cc39681fa69b1da408242882f760c849b.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10#filehashN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z28181
352*67831df0ff8ed3ffacc3678a5c4c09a3fcb755ffbfc110d6f1ff61fe65f31d28*.{0,1000}67831df0ff8ed3ffacc3678a5c4c09a3fcb755ffbfc110d6f1ff61fe65f31d28.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28186
353*69ee333eaf49be76d5bde1d3abfbd2e9a006a316284394e92aa71db1970d927d*.{0,1000}69ee333eaf49be76d5bde1d3abfbd2e9a006a316284394e92aa71db1970d927d.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28331
354*6a5607a6886ad393bd1926b90a6364fb8b6546ad6963f42571c609279b446faa*.{0,1000}6a5607a6886ad393bd1926b90a6364fb8b6546ad6963f42571c609279b446faa.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28362
355*6e9cafc470be9e0db016266a1e663e39d0c764649629a6d0e28c18f103b67a43*.{0,1000}6e9cafc470be9e0db016266a1e663e39d0c764649629a6d0e28c18f103b67a43.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z28625
356*7076e114583006ebcf8f50ab7540ce8552af788431ef2a89227e74876dd13e17*.{0,1000}7076e114583006ebcf8f50ab7540ce8552af788431ef2a89227e74876dd13e17.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28763
357*7148724805f706f8da206b24e03f2f6381bb9bc6959bbf51b6414ea8903caddd*.{0,1000}7148724805f706f8da206b24e03f2f6381bb9bc6959bbf51b6414ea8903caddd.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28822
358*72af248c9e2b92add20bde3532f73569fe2c3e941fd12c72f13696f6ccd60813*.{0,1000}72af248c9e2b92add20bde3532f73569fe2c3e941fd12c72f13696f6ccd60813.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28921
359*72dcd04c582db154eee02cde9a14312542b86615a88bf47d6529b26f8c87914c*.{0,1000}72dcd04c582db154eee02cde9a14312542b86615a88bf47d6529b26f8c87914c.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A28938
360*75d0adaef55ce5b4670e7634d3f440e9d7e0eb1e04cb98c3919d0ad66dffbdfe*.{0,1000}75d0adaef55ce5b4670e7634d3f440e9d7e0eb1e04cb98c3919d0ad66dffbdfe.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A29133
361*7612416d8bde145810923ed8f75d2c1fb81cdecc1aa7a997ae68cffb5dc99f43*.{0,1000}7612416d8bde145810923ed8f75d2c1fb81cdecc1aa7a997ae68cffb5dc99f43.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A29152
362*7760d7ef318933db6b09dba08ec12ddf25ead0512c45bd914256c97470c4eb29*.{0,1000}7760d7ef318933db6b09dba08ec12ddf25ead0512c45bd914256c97470c4eb29.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A29239
363*79816edc41cd5e2aeb19f0227e9cb9ab0b5abcc54931c6bf29813f8762828805*.{0,1000}79816edc41cd5e2aeb19f0227e9cb9ab0b5abcc54931c6bf29813f8762828805.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A29396
364*7a6baa66cbbfa32e37a003017e6a24ae5ba2764f39039a56d7556f2931824e49*.{0,1000}7a6baa66cbbfa32e37a003017e6a24ae5ba2764f39039a56d7556f2931824e49.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A29466
365*7bc9e0e60db343690d6dcb61dd7f19c69fbd154234cbc38f7631f4a4a75fca8c*.{0,1000}7bc9e0e60db343690d6dcb61dd7f19c69fbd154234cbc38f7631f4a4a75fca8c.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10#filehashN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z29560
366*7ce9ff1b4f75bf4289a2f1a1c33bef9719109712019989d28c14b51703b973fc*.{0,1000}7ce9ff1b4f75bf4289a2f1a1c33bef9719109712019989d28c14b51703b973fc.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A29648
367*7fcc036a7fba571b7f2928f0a6a0e0838cb9e1a2a8231f9c30ce5baa144e8108*.{0,1000}7fcc036a7fba571b7f2928f0a6a0e0838cb9e1a2a8231f9c30ce5baa144e8108.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A29845
368*80 253 149 118 169 176 183 169 182 184*.{0,1000}80\s253\s149\s118\s169\s176\s183\s169\s182\s184.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#contentN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z29868
369*809f540f580fc0e192a1c0432ec04105a3faf51f9d7c20f5e15423b78774052d*.{0,1000}809f540f580fc0e192a1c0432ec04105a3faf51f9d7c20f5e15423b78774052d.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z29924
370*80e5d08cc3b73bf1c8e1b9ad7280936bb8d83f0a41f6fdd277e19511e3340cf6*.{0,1000}80e5d08cc3b73bf1c8e1b9ad7280936bb8d83f0a41f6fdd277e19511e3340cf6.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A29944
371*81c02fac6308e64ef8eba1bf4088b04daf1d33ac295c9a376b31e616cd3d4cec*.{0,1000}81c02fac6308e64ef8eba1bf4088b04daf1d33ac295c9a376b31e616cd3d4cec.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A30001
372*821a3a1dee846b299275f7cc29f51b3d20c651db082832b904ea15f8a73ad9bb*.{0,1000}821a3a1dee846b299275f7cc29f51b3d20c651db082832b904ea15f8a73ad9bb.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z30028
373*823c3d2bbca46e7aedadfef6893babcbf14b0182e598a9ba958b84892daaeeb1*.{0,1000}823c3d2bbca46e7aedadfef6893babcbf14b0182e598a9ba958b84892daaeeb1.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A30037
374*88113ededbda181be6c6f9bd4ba8145666b48bf9e9b8dc170e66e884b10fdc91*.{0,1000}88113ededbda181be6c6f9bd4ba8145666b48bf9e9b8dc170e66e884b10fdc91.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A30429
375*88f333f2f21ca05e44a91c376022997c2bbec79b9d9982d59ee6d38183df86f3*.{0,1000}88f333f2f21ca05e44a91c376022997c2bbec79b9d9982d59ee6d38183df86f3.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10#filehashN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z30499
376*8a65c348023a1a5555beb0cde66891fd39dcbd8e6fc02c1ce2022ac2afe68a5e*.{0,1000}8a65c348023a1a5555beb0cde66891fd39dcbd8e6fc02c1ce2022ac2afe68a5e.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A30611
377*8aac7bb51d605351a79f988d1b1772ae94d4b8ab4622118259effad125719e99*.{0,1000}8aac7bb51d605351a79f988d1b1772ae94d4b8ab4622118259effad125719e99.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A30619
378*8d1f3e17106324aad99a98f5dd921db9d27a620b37cadc06a4c470f4404dfca2*.{0,1000}8d1f3e17106324aad99a98f5dd921db9d27a620b37cadc06a4c470f4404dfca2.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A30806
379*8fa8dcae188d04bb3bb48782d5f97019c3a122816d9f48a6a8554ce211acb1f8*.{0,1000}8fa8dcae188d04bb3bb48782d5f97019c3a122816d9f48a6a8554ce211acb1f8.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery10#filehashN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z30989
380*91b1c7537e69ff7ade05c1c3a6051c2981a022a11b71c6e355891e294574a066*.{0,1000}91b1c7537e69ff7ade05c1c3a6051c2981a022a11b71c6e355891e294574a066.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A31136
381*91f2f27015c46a8de16a364b3c2455dc2cbf43a7b678141d907660f26c3d3f69*.{0,1000}91f2f27015c46a8de16a364b3c2455dc2cbf43a7b678141d907660f26c3d3f69.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z31152
382*945efb5ef7d46cf1e4f5383fb158ea5cd63d42214ea44abd73592f6ceeb6cf33*.{0,1000}945efb5ef7d46cf1e4f5383fb158ea5cd63d42214ea44abd73592f6ceeb6cf33.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A31318
383*94aaedf468e4187388ab53a01bfdd820a47ebc3a78e2404285c040ccfea9161f*.{0,1000}94aaedf468e4187388ab53a01bfdd820a47ebc3a78e2404285c040ccfea9161f.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z31334
384*9593cc106f75cc415faadbeb5b16fa79cfe8c047ad007d50dbf8cb1d242126de*.{0,1000}9593cc106f75cc415faadbeb5b16fa79cfe8c047ad007d50dbf8cb1d242126de.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10#filehashN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z31411
385*95b9a6d12b978a6c1bbd6a33369e39008e7d64544d50c98c9c3f2b93a9466e79*.{0,1000}95b9a6d12b978a6c1bbd6a33369e39008e7d64544d50c98c9c3f2b93a9466e79.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing10#filehashN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z31420
386*9748cdfecb95fd7bb1706a566e79d3fccb1418bbb4307f7a7a1de1809db83afe*.{0,1000}9748cdfecb95fd7bb1706a566e79d3fccb1418bbb4307f7a7a1de1809db83afe.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A31522
387*97499fbdae8e2c952f21da5834caf06b11dcc28d74b034b509bd174f3d1f1739*.{0,1000}97499fbdae8e2c952f21da5834caf06b11dcc28d74b034b509bd174f3d1f1739.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A31523
388*97e7f134cfbb11e0e3ade71cdb5de36ea8cfdffe5272ea7293e35bd2b91f3449*.{0,1000}97e7f134cfbb11e0e3ade71cdb5de36ea8cfdffe5272ea7293e35bd2b91f3449.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A31558
389*98aa8eec1bda59ea57693a6312bae2b76b2e71dd29cd0f85453c3d867ec69394*.{0,1000}98aa8eec1bda59ea57693a6312bae2b76b2e71dd29cd0f85453c3d867ec69394.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10#filehashN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z31610
390*98fa9af535fd48260a65e18ceb9553187786742c6c77486bb27e5fe61758ea77*.{0,1000}98fa9af535fd48260a65e18ceb9553187786742c6c77486bb27e5fe61758ea77.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A31628
391*9c9cc73f47b3b509df0845593e6b2f8d900f34772e4aaf3438bb0120303d5670*.{0,1000}9c9cc73f47b3b509df0845593e6b2f8d900f34772e4aaf3438bb0120303d5670.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk10#filehashN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z31881
392*9d571b529b8c97f1d95d00147a98ca6a208446100108993377ef74f7bfab0ced*.{0,1000}9d571b529b8c97f1d95d00147a98ca6a208446100108993377ef74f7bfab0ced.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A31937
393*9e83b2e2efe2a751a735f413dee7582e8ba8a0639b8d092cf165b87b166639c2*.{0,1000}9e83b2e2efe2a751a735f413dee7582e8ba8a0639b8d092cf165b87b166639c2.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z32007
394*A ruby http/https proxy to do EVIL things.*.{0,1000}A\sruby\shttp\/https\sproxy\sto\sdo\sEVIL\sthings\..{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z32134
395*a16a8ed5999b3b90c7f5a7a80b7a55fe62941d3a1300ea8f0fcdd8550e93a947*.{0,1000}a16a8ed5999b3b90c7f5a7a80b7a55fe62941d3a1300ea8f0fcdd8550e93a947.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A32245
396*a2b03c173484ada281f36aeabeedc6ced6d4289d4c204aa69b8a65c3f45037db*.{0,1000}a2b03c173484ada281f36aeabeedc6ced6d4289d4c204aa69b8a65c3f45037db.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z32346
397*a760cde750a65dd7e7ea970c57f662c91c7614d33d69b4720ea630db4961ff1e*.{0,1000}a760cde750a65dd7e7ea970c57f662c91c7614d33d69b4720ea630db4961ff1e.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z32678
398*a7a5c912263b0207145bd9c2397a4fa338ec82217df2ab83471bb884e473cc9e*.{0,1000}a7a5c912263b0207145bd9c2397a4fa338ec82217df2ab83471bb884e473cc9e.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A32698
399*aa14822e2f2acd7b8aff1ebf1f2e7e9f800f6089f868ec7464af6ac01d7f9b3c*.{0,1000}aa14822e2f2acd7b8aff1ebf1f2e7e9f800f6089f868ec7464af6ac01d7f9b3c.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A32880
400*aa5838415ca20f0b6fe7858f457f129cf442940b3d4676cd243575809e53988e*.{0,1000}aa5838415ca20f0b6fe7858f457f129cf442940b3d4676cd243575809e53988e.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A32892
401*ac03d370bbdfc9037c1dfb4fc9a4fc5a3914acb58e082a33fc5c52bdbc8768f4*.{0,1000}ac03d370bbdfc9037c1dfb4fc9a4fc5a3914acb58e082a33fc5c52bdbc8768f4.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z33051
402*aeebbc6ea13dde53ffa47ec90eb80c571c81da63e36f2c8539a9924f54933a09*.{0,1000}aeebbc6ea13dde53ffa47ec90eb80c571c81da63e36f2c8539a9924f54933a09.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A33582
403*afd28d12d55e823076544802e23776a6150aa3095f8c9b5904cf35af8d258186*.{0,1000}afd28d12d55e823076544802e23776a6150aa3095f8c9b5904cf35af8d258186.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z33660
404*AlteredSecurity/365-Stealer*.{0,1000}AlteredSecurity\/365\-Stealer.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer11N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z33822
405*An0nUD4Y/Evilginx2-Phishlets*.{0,1000}An0nUD4Y\/Evilginx2\-Phishlets.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/Evilginx2-Phishlets10N/AN/A1076702632025-02-06T02:46:16Z2020-05-13T05:58:43Z33867
406*Arno0x/EmbedInHTML*.{0,1000}Arno0x\/EmbedInHTML.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML11N/AN/AN/A54851192017-09-27T13:16:06Z2017-09-11T07:17:20Z34066
407*AttackerSetup(windows).exe*.{0,1000}AttackerSetup\(windows\)\.exe.{0,1000}offensive_tool_keywordwindows-login-phishWindows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposesT1566N/AN/AN/APhishinghttps://github.com/CipherKill/windows-login-phish11N/AN/AN/A11762022-03-25T05:49:01Z2022-03-13T20:02:15Z34224
408*AttackerSetup.py*.{0,1000}AttackerSetup\.py.{0,1000}offensive_tool_keywordwindows-login-phishWindows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposesT1566N/AN/AN/APhishinghttps://github.com/CipherKill/windows-login-phish11N/AN/AN/A11762022-03-25T05:49:01Z2022-03-13T20:02:15Z34225
409*AttackerSetup4linux*.{0,1000}AttackerSetup4linux.{0,1000}offensive_tool_keywordwindows-login-phishWindows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposesT1566N/AN/AN/APhishinghttps://github.com/CipherKill/windows-login-phish11#linuxN/AN/A11762022-03-25T05:49:01Z2022-03-13T20:02:15Z34226
410*b18d778b4e4b6bf1fd5b2d790c941270145a6a6d*.{0,1000}b18d778b4e4b6bf1fd5b2d790c941270145a6a6d.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#contentN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z34496
411*b6ac954c208f9e813cbacebfbea30e9b71e252c9c35cea2aad4864cd9f1c492b*.{0,1000}b6ac954c208f9e813cbacebfbea30e9b71e252c9c35cea2aad4864cd9f1c492b.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z34873
412*b89570294bb08b6ac4245fe0db6e35c1b23fa01ad3a9ac0bfe07043c7af3350c*.{0,1000}b89570294bb08b6ac4245fe0db6e35c1b23fa01ad3a9ac0bfe07043c7af3350c.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A35020
413*b898e52e3799d4c3c4fa328c400ba620c814c11ca23d0b7ec2f3fd7917a7e8a1*.{0,1000}b898e52e3799d4c3c4fa328c400ba620c814c11ca23d0b7ec2f3fd7917a7e8a1.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A35021
414*Backdoor:Script/HustleCon.A*.{0,1000}Backdoor\:Script\/HustleCon\.A.{0,1000}signature_keywordrdprdp file received in emails - abused by attackersT1204 - T1566 - T1078 - T1105TA0001 - TA0002 - TA0010 - TA0011N/AMidnight Blizzard - APT29 - UNC2452 - Cozy BearPhishinghttps://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files10#AvsignatureN/A98N/AN/AN/AN/A35197
415*bbtfr/evil-proxy*.{0,1000}bbtfr\/evil\-proxy.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy11N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z35415
416*bd78ea00b16797551d4f40297f42e9b1f9d912f416a115c3eb10f340246a9d54*.{0,1000}bd78ea00b16797551d4f40297f42e9b1f9d912f416a115c3eb10f340246a9d54.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A35546
417*bdcfb9b63fd01bdd50427f205338e26e8001015b4fe14b6016cfb08e37c08a6e*.{0,1000}bdcfb9b63fd01bdd50427f205338e26e8001015b4fe14b6016cfb08e37c08a6e.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A35565
418*bdf7dee28fc21a09ae10d5e3a75e3a7713e705e78a40f55a4c003c9358174372*.{0,1000}bdf7dee28fc21a09ae10d5e3a75e3a7713e705e78a40f55a4c003c9358174372.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A35576
419*beb982a616c2c4cd716387b6a4c7a4b86ddcca0bc76faa94b4c5f10ed7abd592*.{0,1000}beb982a616c2c4cd716387b6a4c7a4b86ddcca0bc76faa94b4c5f10ed7abd592.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A35743
420*best*phish her*.{0,1000}best.{0,1000}phish\sher.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher10N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z35823
421*bfa9dc4c4b911b6777cb98d17a82b28531c26600698699cbe658749684818f28*.{0,1000}bfa9dc4c4b911b6777cb98d17a82b28531c26600698699cbe658749684818f28.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing10#filehashN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z35879
422*build/evilginx*.{0,1000}build\/evilginx.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z36355
423*c086c1e601dbde7b31cbaea56b915f22b1ebc21d744a431984406e6062b4b865*.{0,1000}c086c1e601dbde7b31cbaea56b915f22b1ebc21d744a431984406e6062b4b865.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A36671
424*c121f7d62fa5ecd27c3aaae5737a3de8f2e4def0c182058b6dd824aa92351e9c*.{0,1000}c121f7d62fa5ecd27c3aaae5737a3de8f2e4def0c182058b6dd824aa92351e9c.{0,1000}offensive_tool_keywordgophishGophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training.T1566 - T1598TA0008 - TA0009N/ABlack BastaPhishinghttps://github.com/gophish/gophish10#filehashN/A10101248325282024-09-23T04:24:43Z2013-11-18T23:26:43Z36715
425*c2935d032a38a5a6d3251d22b9d93d08223b8dbf90efedbb0e6716cdafe76367*.{0,1000}c2935d032a38a5a6d3251d22b9d93d08223b8dbf90efedbb0e6716cdafe76367.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery10#filehashN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z36818
426*c6bd027f5269a980cd4deffcdbdab77eb317db2a9737d727b55fe37710cd2f95*.{0,1000}c6bd027f5269a980cd4deffcdbdab77eb317db2a9737d727b55fe37710cd2f95.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A37164
427*c7ffb81b3cd5cfcfe18363f998cd64428423814d5a8713d89e7992941884587d*.{0,1000}c7ffb81b3cd5cfcfe18363f998cd64428423814d5a8713d89e7992941884587d.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A37258
428*c923b2051d3e822e390e80c7e8d56f6b2cc62ae6688ca73745684b57154f3ecb*.{0,1000}c923b2051d3e822e390e80c7e8d56f6b2cc62ae6688ca73745684b57154f3ecb.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A37339
429*CamHacker has a new update!*.{0,1000}CamHacker\shas\sa\snew\supdate!.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A37541
430*CamHacker updated successfully*.{0,1000}CamHacker\supdated\ssuccessfully.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A37542
431*CamHacker/releases/latest/download/websites.zip*.{0,1000}CamHacker\/releases\/latest\/download\/websites\.zip.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker11N/AN/A10N/A37543
432*cb0a620a960506193df32016f825248dec7fe504d8b857ee54a88ad1bdf8d9ce*.{0,1000}cb0a620a960506193df32016f825248dec7fe504d8b857ee54a88ad1bdf8d9ce.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A37634
433*cb4a4a24fdd61493e58d83befacd93981771c5e8e7ff206b1c6050134613ae4a*.{0,1000}cb4a4a24fdd61493e58d83befacd93981771c5e8e7ff206b1c6050134613ae4a.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A37658
434*cdb6b0d366c80ef521a59334a58f95ea5b7dbddc6e9f81ff28a11ec44ceba696*.{0,1000}cdb6b0d366c80ef521a59334a58f95ea5b7dbddc6e9f81ff28a11ec44ceba696.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A37893
435*cf2f9d4e499c45cf102ede7ccb8e0e4e44005f9cf0313024771dda337bd6e1dd*.{0,1000}cf2f9d4e499c45cf102ede7ccb8e0e4e44005f9cf0313024771dda337bd6e1dd.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A38055
436*clear; history -c*.{0,1000}clear\;\shistory\s\-c.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk10#linuxN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z38301
437*Cloudflared and Loclx have started successfully!*.{0,1000}Cloudflared\sand\sLoclx\shave\sstarted\ssuccessfully!.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A38356
438*Cloudflared has started successfully!*.{0,1000}Cloudflared\shas\sstarted\ssuccessfully!.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A38357
439*com.itgorillaz.lnk2pwn.model*.{0,1000}com\.itgorillaz\.lnk2pwn\.model.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z38636
440*const commandToRun = "mshta " + htaPath*.{0,1000}const\scommandToRun\s\=\s\"mshta\s\"\s\+\shtaPath.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10#contentN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z38787
441*core/http_proxy.go*.{0,1000}core\/http_proxy\.go.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx211N/AFalse positives expected10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z38895
442*CredPhisher.csproj*.{0,1000}CredPhisher\.csproj.{0,1000}offensive_tool_keywordCredPhisherPrompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI functionT1056.002 - T1111TA0004 N/AN/APhishinghttps://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher11N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z39059
443*CredPhisher.exe*.{0,1000}CredPhisher\.exe.{0,1000}offensive_tool_keywordCredPhisherPrompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI functionT1056.002 - T1111TA0004 N/AN/APhishinghttps://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher11N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z39060
444*cscript ..\\temp.vbs*.{0,1000}cscript\s\.\.\\\\temp\.vbs.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z39156
445*D0:B6:9D:86:6D:AE:B4:E1:CA:F0:C1:F5:4D:82:45:7E:13:06:CD:1A:DE:49:A3:80:DC:21:6A:5C:A8:F4:84:1B*.{0,1000}D0\:B6\:9D\:86\:6D\:AE\:B4\:E1\:CA\:F0\:C1\:F5\:4D\:82\:45\:7E\:13\:06\:CD\:1A\:DE\:49\:A3\:80\:DC\:21\:6A\:5C\:A8\:F4\:84\:1B.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#certificae #linuxN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z39329
446*D00Movenok/HTMLSmuggler*.{0,1000}D00Movenok\/HTMLSmuggler.{0,1000}offensive_tool_keywordHTMLSmugglerHTML Smuggling generator&obfuscator for your Red Team operationsT1564.001 - T1027 - T1566TA0005N/AN/APhishinghttps://github.com/D00Movenok/HTMLSmuggler11N/AN/A102162192024-02-27T23:03:55Z2023-07-02T08:10:59Z39335
447*d0659e8489bc633b617e86f4e7994a593ada5cfc8463f79631d9672623b79750*.{0,1000}d0659e8489bc633b617e86f4e7994a593ada5cfc8463f79631d9672623b79750.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A39356
448*d10833b7d54745c35eec76ce48c1d8a4d90a9455bcd8b81cacdc95b9304b3be3*.{0,1000}d10833b7d54745c35eec76ce48c1d8a4d90a9455bcd8b81cacdc95b9304b3be3.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese10#filehashN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z39410
449*d1fccb8acadbdefaf27f8680c74c40dba94e52734dd9704d38c0de7b10066f14*.{0,1000}d1fccb8acadbdefaf27f8680c74c40dba94e52734dd9704d38c0de7b10066f14.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10#filehashN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z39487
450*d546105ee91da0a53a26ed53f90414ea5f56a272caa137629125d018354f6b77*.{0,1000}d546105ee91da0a53a26ed53f90414ea5f56a272caa137629125d018354f6b77.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A39721
451*d5591f81fb5bd90d3af0954008ecfd433eeaf6ecc99941324747ca7433ae5985*.{0,1000}d5591f81fb5bd90d3af0954008ecfd433eeaf6ecc99941324747ca7433ae5985.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A39728
452*d561756dd8152cceb60d50ae5650eedcdb022f306f193017aede737428ff2452*.{0,1000}d561756dd8152cceb60d50ae5650eedcdb022f306f193017aede737428ff2452.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A39730
453*d9c7dc1a5a792486cc3853620eb700e26a047238ba92c757b4f9d40605dbd3b8*.{0,1000}d9c7dc1a5a792486cc3853620eb700e26a047238ba92c757b4f9d40605dbd3b8.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A40033
454*da2e2e4a0d34d63a452322f2fe5f57416aa79b6abb8a2a7cc3917a3b772d4cea*.{0,1000}da2e2e4a0d34d63a452322f2fe5f57416aa79b6abb8a2a7cc3917a3b772d4cea.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A40054
455*DancingRightToLeft.py*.{0,1000}DancingRightToLeft\.py.{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z40123
456*dc25fef1e036e80dbbf1a5665fa13dc1ed6f8c56875161608cdf532d8a21a4a5*.{0,1000}dc25fef1e036e80dbbf1a5665fa13dc1ed6f8c56875161608cdf532d8a21a4a5.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A40307
457*ddb178cbaaab362c61d3d061b366625d205f208553ddf341b1c8fae466e5bd6f*.{0,1000}ddb178cbaaab362c61d3d061b366625d205f208553ddf341b1c8fae466e5bd6f.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A40469
458*Device architecture unknown. Download cloudflared/loclx manually*.{0,1000}Device\sarchitecture\sunknown\.\sDownload\scloudflared\/loclx\smanually.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A40777
459*'Disable all http access logs'*.{0,1000}\'Disable\sall\shttp\saccess\slogs\'.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z40947
460*dnsmorph*.{0,1000}dnsmorph.{0,1000}offensive_tool_keyworddnsmorphDNSMORPH is a domain name permutation engine. inspired by dnstwist. It is written in Go making for a compact and very fast tool. It robustly handles any domain or subdomain supplied and provides a number of configuration options to tune permutation runs.T1568.002 - T1568.003 - T1568.001 - T1568.004TA0009 - TA0011N/AN/APhishinghttps://github.com/netevert/dnsmorph11N/AN/AN/A3266432023-08-08T06:38:59Z2018-02-20T19:13:35Z41273
461*dnstwist*.{0,1000}dnstwist.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist10N/AN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z41291
462*docker rmi evilnginx*.{0,1000}docker\srmi\sevilnginx.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z41326
463*docker rmi evilnovnc*.{0,1000}docker\srmi\sevilnovnc.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z41327
464*domainhunter.py*.{0,1000}domainhunter\.py.{0,1000}offensive_tool_keyworddomainhunterChecks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names T1583.002 - T1568.002TA0011 - TA0009N/AN/APhishinghttps://github.com/threatexpress/domainhunter11N/AN/AN/A1015872922024-06-06T21:01:21Z2017-03-01T11:16:26Z41377
465*Don't_blindly_trust_obfuscated_code_it_might_do_something_bad*.{0,1000}Don\'t_blindly_trust_obfuscated_code_it_might_do_something_bad.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A41418
466*downloadMalwareDomains*.{0,1000}downloadMalwareDomains.{0,1000}offensive_tool_keyworddomainhunterChecks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names T1583.002 - T1568.002TA0011 - TA0009N/AN/APhishinghttps://github.com/threatexpress/domainhunter10N/AN/AN/A1015872922024-06-06T21:01:21Z2017-03-01T11:16:26Z41485
467*e094dc2a9ec5fe9800948a640f416fe610fdf155874e897d3cba6cc86f854083*.{0,1000}e094dc2a9ec5fe9800948a640f416fe610fdf155874e897d3cba6cc86f854083.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A41766
468*e0cc8936e11dcf4e016ff32f5a81aa15f352cb71ec8a24b383dc263e56425018*.{0,1000}e0cc8936e11dcf4e016ff32f5a81aa15f352cb71ec8a24b383dc263e56425018.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A41779
469*e22080246ffecef9d922c07fe2511b93f8b7d585b6a2c9b2d6332a93b2e5cf87*.{0,1000}e22080246ffecef9d922c07fe2511b93f8b7d585b6a2c9b2d6332a93b2e5cf87.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z41883
470*e3130262a4adfed3a225075d6eb93c5caeeba93b1253dc1b148f8a80c5c35a03*.{0,1000}e3130262a4adfed3a225075d6eb93c5caeeba93b1253dc1b148f8a80c5c35a03.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A41954
471*e5474ff71a5e81a3fde493dde6141b25fbcff158367cc0fc492c063f0e59ca6a*.{0,1000}e5474ff71a5e81a3fde493dde6141b25fbcff158367cc0fc492c063f0e59ca6a.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z42101
472*e5f220215fdf2ccc6b92dcbf95b6967d7a4f2bd4b0668413728c37bdd3833304*.{0,1000}e5f220215fdf2ccc6b92dcbf95b6967d7a4f2bd4b0668413728c37bdd3833304.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z42144
473*e62d0d5e71daca0aa1c2e899b0da9668167fcbd20060ef8c01a8d8b66f0a32b3*.{0,1000}e62d0d5e71daca0aa1c2e899b0da9668167fcbd20060ef8c01a8d8b66f0a32b3.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A42159
474*e988e9a36810fb0fa0fb32556cb93c8ea4117e4176402ff74e397bd4a4d125d6*.{0,1000}e988e9a36810fb0fa0fb32556cb93c8ea4117e4176402ff74e397bd4a4d125d6.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A42414
475*ec57e5c4d592d1ad0a0e79b22e85f8173bcb3c03f4497957f90def4175ca383d*.{0,1000}ec57e5c4d592d1ad0a0e79b22e85f8173bcb3c03f4497957f90def4175ca383d.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A42630
476*echo 'user ALL=(ALL) NOPASSWD:ALL' >> /etc/sudoers*.{0,1000}echo\s\'user\sALL\=\(ALL\)\sNOPASSWD\:ALL\'\s\>\>\s\/etc\/sudoers.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z42739
477*ed4d66eac260c54457ea1b9fa50be035dc89b32e7a318bff1296606413f25cbb*.{0,1000}ed4d66eac260c54457ea1b9fa50be035dc89b32e7a318bff1296606413f25cbb.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A42770
478*ef0602ea7c5cfe523cd58fbfb20f835a908c5d3873fcb14510a042d13de53863*.{0,1000}ef0602ea7c5cfe523cd58fbfb20f835a908c5d3873fcb14510a042d13de53863.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A42923
479*embedInHTML.html*.{0,1000}embedInHTML\.html.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML11N/AN/AN/A54851192017-09-27T13:16:06Z2017-09-11T07:17:20Z43082
480*embedInHTML.py*.{0,1000}embedInHTML\.py.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML11N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z43083
481*EmbedInHTML-master*.{0,1000}EmbedInHTML\-master.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML11N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z43084
482*Enter your loclx authtoken:*.{0,1000}Enter\syour\sloclx\sauthtoken\:.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A43178
483*EvilClippy.exe*.{0,1000}EvilClippy\.exe.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy11N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z43333
484*EvilClippy-master*.{0,1000}EvilClippy\-master.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy11N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z43336
485*evilfeed.go*.{0,1000}evilfeed\.go.{0,1000}offensive_tool_keywordgophishCombination of evilginx2 and GoPhishT1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/fin3ss3g0d/evilgophish11N/AN/A101017623402024-06-15T17:48:11Z2022-09-07T02:47:43Z43338
486*evilginx -p *.{0,1000}evilginx\s\-p\s.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#linuxN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43339
487*evilginx -p*.{0,1000}evilginx\s\-p.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43340
488*evilginx*.{0,1000}evilginx.{0,1000}offensive_tool_keywordevilginx2evilginx2 is a man-in-the-middle attack framework used for phishing login credentials along with session cookies. which in turn allows to bypass 2-factor authentication protection.This tool is a successor to Evilginx. released in 2017. which used a custom version of nginx HTTP server to provide man-in-the-middle functionality to act as a proxy between a browser and phished website. Present version is fully written in GO as a standalone application. which implements its own HTTP and DNS server. making it extremely easy to set up and useT1556 - T1565 - T1056 - T1558 - T1110TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210N/AN/A7101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43341
489*evilginx.exe*.{0,1000}evilginx\.exe.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx211N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43342
490*evilginx_linux*.{0,1000}evilginx_linux.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43343
491*evilginx_windows_*.{0,1000}evilginx_windows_.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43344
492*evilginx2*.{0,1000}evilginx2.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx211N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43345
493*evilginx2/releases/*.{0,1000}evilginx2\/releases\/.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx211N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43346
494*Evilginx2-Phishlets*.{0,1000}Evilginx2\-Phishlets.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/Evilginx2-Phishlets10N/AN/A1076702632025-02-06T02:46:16Z2020-05-13T05:58:43Z43347
495*evilginx-linux*.{0,1000}evilginx\-linux.{0,1000}offensive_tool_keywordgophishCombination of evilginx2 and GoPhishT1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/fin3ss3g0d/evilgophish11#linuxN/A101017623402024-06-15T17:48:11Z2022-09-07T02:47:43Z43348
496*evilginx-mastery*.{0,1000}evilginx\-mastery.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx211N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43349
497*evilginx-v3*.{0,1000}evilginx\-v3.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z43350
498*evilgophish*.{0,1000}evilgophish.{0,1000}offensive_tool_keywordgophishCombination of evilginx2 and GoPhishT1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/fin3ss3g0d/evilgophish11N/AN/A101017623402024-06-15T17:48:11Z2022-09-07T02:47:43Z43351
499*EvilnoVNC () *.{0,1000}EvilnoVNC\s\(\)\s.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#linux #contentN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z43358
500*EvilnoVNC by @JoelGMSec*.{0,1000}EvilnoVNC\sby\s\@JoelGMSec.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z43359
501*EvilnoVNC Server*.{0,1000}EvilnoVNC\sServer.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z43360
502*evilnovnc.Dockerfile*.{0,1000}evilnovnc\.Dockerfile.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z43361
503*EvilnoVNC/run.sh*.{0,1000}EvilnoVNC\/run\.sh.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#linuxN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z43362
504*EvilnoVNC/tmp/*.{0,1000}EvilnoVNC\/tmp\/.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#linuxN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z43363
505*EvilnoVNC-main*.{0,1000}EvilnoVNC\-main.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC11N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z43364
506*eviloffice.exe *.{0,1000}eviloffice\.exe\s.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy10N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z43365
507*eviloffice.exe*.{0,1000}eviloffice\.exe.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy11N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z43366
508*evil-proxy.gemspec*.{0,1000}evil\-proxy\.gemspec.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy11N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43369
509*evil-proxy/agentproxy*.{0,1000}evil\-proxy\/agentproxy.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43370
510*evil-proxy/httpproxy*.{0,1000}evil\-proxy\/httpproxy.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43371
511*evil-proxy/selenium*.{0,1000}evil\-proxy\/selenium.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43372
512*evil-proxy/version*.{0,1000}evil\-proxy\/version.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43373
513*EvilProxy::HTTPProxyServer*.{0,1000}EvilProxy\:\:HTTPProxyServer.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43374
514*EvilProxy::MITMProxyServer*.{0,1000}EvilProxy\:\:MITMProxyServer.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43375
515*evil-proxy-0.1.0*.{0,1000}evil\-proxy\-0\.1\.0.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy11N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43376
516*evil-proxy-0.2.0*.{0,1000}evil\-proxy\-0\.2\.0.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy11N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43377
517*evil-proxy-master*.{0,1000}evil\-proxy\-master.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z43378
518*evilqr-main*.{0,1000}evilqr\-main.{0,1000}offensive_tool_keywordevilqrProof-of-concept to demonstrate dynamic QR swap phishing attacks in practiceT1566.002 - T1204.001 - T1192TA0001 - TA0005N/AN/APhishinghttps://github.com/kgretzky/evilqr11N/AN/AN/A3292452024-06-18T11:27:23Z2023-06-20T12:58:09Z43379
519*evilqr-phishing*.{0,1000}evilqr\-phishing.{0,1000}offensive_tool_keywordevilqrProof-of-concept to demonstrate dynamic QR swap phishing attacks in practiceT1566.002 - T1204.001 - T1192TA0001 - TA0005N/AN/APhishinghttps://github.com/kgretzky/evilqr11N/AN/AN/A3292452024-06-18T11:27:23Z2023-06-20T12:58:09Z43380
520*evilqr-server*.{0,1000}evilqr\-server.{0,1000}offensive_tool_keywordevilqrProof-of-concept to demonstrate dynamic QR swap phishing attacks in practiceT1566.002 - T1204.001 - T1192TA0001 - TA0005N/AN/APhishinghttps://github.com/kgretzky/evilqr11N/AN/AN/A3292452024-06-18T11:27:23Z2023-06-20T12:58:09Z43381
521*ExtensionSpoof.vbproj*.{0,1000}ExtensionSpoof\.vbproj.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer10N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z43632
522*ExtensionSpoof.xml*.{0,1000}ExtensionSpoof\.xml.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer10N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z43633
523*ExtensionSpoofer-1.zip*.{0,1000}ExtensionSpoofer\-1\.zip.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer11N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z43634
524*-f payloads_examples/calc.*.{0,1000}\-f\spayloads_examples\/calc\..{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML10N/AN/AN/A54851192017-09-27T13:16:06Z2017-09-11T07:17:20Z43669
525*f5a5a21ee3a7dfaddae81cae7ef2df852cbfa44fdba51dfa0678a1c2d9d91c36*.{0,1000}f5a5a21ee3a7dfaddae81cae7ef2df852cbfa44fdba51dfa0678a1c2d9d91c36.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A44048
526*f90e3e0ba8b25e863b1d994d088376b2caedeed3b7bb5ee6c3f6e0e89bcaf023*.{0,1000}f90e3e0ba8b25e863b1d994d088376b2caedeed3b7bb5ee6c3f6e0e89bcaf023.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A44277
527*f9103918917348bf95b972701d8d4ccec36fdfd843792aa705b15454113cdfef*.{0,1000}f9103918917348bf95b972701d8d4ccec36fdfd843792aa705b15454113cdfef.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z44279
528*FakeImageExploiter*.{0,1000}FakeImageExploiter.{0,1000}offensive_tool_keywordFakeImageExploiterThis module takes one existing image.jpg and one payload.ps1 (input by user) and builds a new payload (agent.jpg.exe) that if executed it will trigger the download of the 2 previous files stored into apache2 (image.jpg + payload.ps1) and execute them.T1564 - T1218 - T1204 - T1558.001TA0002 - TA0008 - TA0010N/AN/APhishinghttps://github.com/r00t-3xp10it/FakeImageExploiter11N/AN/AN/A109123382019-12-06T20:59:26Z2017-04-04T20:53:47Z44443
529*fb5ae202219536d7864043594d2c0b2909a956c5c88e33afc8efe588f5d84296*.{0,1000}fb5ae202219536d7864043594d2c0b2909a956c5c88e33afc8efe588f5d84296.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#filehashN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z44490
530*FCD5E13D-1663-4226-8280-1C6A97933AB7*.{0,1000}FCD5E13D\-1663\-4226\-8280\-1C6A97933AB7.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer10#GUIDprojectN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z44605
531*fd36746c68cdf7b32e63adaaa7b3e863b9769582f703722b88d9bf0b94030434*.{0,1000}fd36746c68cdf7b32e63adaaa7b3e863b9769582f703722b88d9bf0b94030434.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery10#filehashN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z44638
532*fdb2a63af6a5ae9aa60ceceb9e928188ac793a89f5282ed44c0d4be5f79559bb*.{0,1000}fdb2a63af6a5ae9aa60ceceb9e928188ac793a89f5282ed44c0d4be5f79559bb.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A44678
533*fdc984c09659c0ebf330d319bdebc772440dde7543aa6f74fd523a02fca2811d*.{0,1000}fdc984c09659c0ebf330d319bdebc772440dde7543aa6f74fd523a02fca2811d.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A44685
534*fe8db7541bc0c9d05dbd2e44e5eaa2bfd5c79968983860416636ea2792abfa5e*.{0,1000}fe8db7541bc0c9d05dbd2e44e5eaa2bfd5c79968983860416636ea2792abfa5e.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A44748
535*ff0f7b3bceac2a15be7b35bc7c1933b46ba6eeca6bba97dbd5227b59b913cb26*.{0,1000}ff0f7b3bceac2a15be7b35bc7c1933b46ba6eeca6bba97dbd5227b59b913cb26.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A44798
536*ffa5514b45c48061e412487d4defdeffa87a338213aa1bc4aabb3259ce18d7aa*.{0,1000}ffa5514b45c48061e412487d4defdeffa87a338213aa1bc4aabb3259ce18d7aa.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A44832
537*ffe1396fa56e5f86812443498cd6c8abfca613099df1261d08f06a73b14be042*.{0,1000}ffe1396fa56e5f86812443498cd6c8abfca613099df1261d08f06a73b14be042.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#filehashN/A10N/A44851
538*FiercePhish*.{0,1000}FiercePhish.{0,1000}offensive_tool_keywordFiercePhishFiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns. schedule sending of emails. and much more. The features will continue to be expanded and will include website spoofing. click tracking. and extensive notification options. T1566 - T1566.001 - T1566.002 - T1566.003TA0001 - TA0002 - TA0003 - TA0006N/AN/APhishinghttps://github.com/Raikia/FiercePhish11N/AN/AN/A1013512552024-01-09T02:59:26Z2016-12-31T19:41:24Z44886
539*FluxionNetwork*.{0,1000}FluxionNetwork.{0,1000}offensive_tool_keywordFluxionNetworkFluxion is a security auditing and social-engineering research tool. It is a remake of linset by vk496 with (hopefully) fewer bugs and more functionality. The script attempts to retrieve the WPA/WPA2 key from a target access point by means of a social engineering (phishing) attack. Its compatible with the latest release of Kali (rolling). Fluxions attacks' setup is mostly manual. but experimental auto-mode handles some of the attacks' setup parameters. Read the FAQ before requesting issuesT1559 - T1189 - T1059 - T1566 - T1056TA0001 - TA0002 - TA0009N/AN/APhishinghttps://github.com/FluxionNetwork/fluxion11N/AN/AN/A10520714302023-11-03T23:16:30Z2017-04-29T10:22:27Z45183
540*fopen('credentials.txt'*.{0,1000}fopen\(\'credentials\.txt\'.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing10N/AN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z45195
541*gem 'evil-proxy'*.{0,1000}gem\s\'evil\-proxy\'.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z45541
542*gophish*phish.go*.{0,1000}gophish.{0,1000}phish\.go.{0,1000}offensive_tool_keywordgophishGophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training.T1566 - T1598TA0008 - TA0009N/ABlack BastaPhishinghttps://github.com/gophish/gophish11N/AN/A10101248325282024-09-23T04:24:43Z2013-11-18T23:26:43Z46605
543*gophish.go*.{0,1000}gophish\.go.{0,1000}offensive_tool_keywordgophishOpen-Source Phishing ToolkitT1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/gophish/gophish11N/AN/A10101248325282024-09-23T04:24:43Z2013-11-18T23:26:43Z46606
544*gophish/gophish*.{0,1000}gophish\/gophish.{0,1000}offensive_tool_keywordgophishGophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training.T1566 - T1598TA0008 - TA0009N/ABlack BastaPhishinghttps://github.com/gophish/gophish11N/AN/A10101248325282024-09-23T04:24:43Z2013-11-18T23:26:43Z46607
545*gophish-send-mail.py*.{0,1000}gophish\-send\-mail\.py.{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z46608
546*handlePhishlets*.{0,1000}handlePhishlets.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVERPhishinghttps://github.com/kgretzky/evilginx210#linux #contentN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z46996
547*henriksb/ExtensionSpoofer*.{0,1000}henriksb\/ExtensionSpoofer.{0,1000}offensive_tool_keywordExtensionSpooferSpoof file icons and extensions in WindowsT1036 - T1027.005 - T1218TA0005 - TA0040N/AN/APhishinghttps://github.com/henriksb/ExtensionSpoofer10N/AN/A92179652024-12-12T18:05:28Z2017-11-11T16:02:17Z47117
548*Hey Dear! You Have Won Free Rs 399 Jio Recharge*.{0,1000}Hey\sDear!\sYou\sHave\sWon\sFree\sRs\s399\sJio\sRecharge.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A47142
549*'Host the Phising App'*.{0,1000}\'Host\sthe\sPhising\sApp\'.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z47282
550*HTMLSmuggler-main*.{0,1000}HTMLSmuggler\-main.{0,1000}offensive_tool_keywordHTMLSmugglerHTML Smuggling generator&obfuscator for your Red Team operationsT1564.001 - T1027 - T1566TA0005N/AN/APhishinghttps://github.com/D00Movenok/HTMLSmuggler11N/AN/A102162192024-02-27T23:03:55Z2023-07-02T08:10:59Z47317
551*http://*.trycloudfare.com*.{0,1000}http\:\/\/.{0,1000}\.trycloudfare\.com.{0,1000}greyware_tool_keywordtrycloudflare.comThe subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activitiesT1071.001 - T1090 - T1583.003 - T1102TA0001 - TA0005 - TA0008 - TA0011N/AN/APhishinghttps://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware11N/AN/A1010N/AN/AN/AN/A47390
552*http://101.251.217.210*.{0,1000}http\:\/\/101\.251\.217\.210.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy11N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z47403
553*http://127.0.0.1:35000*.{0,1000}http\:\/\/127\.0\.0\.1\:35000.{0,1000}offensive_tool_keywordevilqrProof-of-concept to demonstrate dynamic QR swap phishing attacks in practiceT1566.002 - T1204.001 - T1192TA0001 - TA0005N/AN/APhishinghttps://github.com/kgretzky/evilqr11N/AN/AN/A3292452024-06-18T11:27:23Z2023-06-20T12:58:09Z47418
554*HTTPClient.post('https://httpbin.org/post*.{0,1000}HTTPClient\.post\(\'https\:\/\/httpbin\.org\/post.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z47570
555*https://*.trycloudfare.com*.{0,1000}https\:\/\/.{0,1000}\.trycloudfare\.com.{0,1000}greyware_tool_keywordtrycloudflare.comThe subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activitiesT1071.001 - T1090 - T1583.003 - T1102TA0001 - TA0005 - TA0008 - TA0011N/AN/APhishinghttps://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware11N/AN/A1010N/AN/AN/AN/A47616
556*https://api.localxpose.io/api/v2/downloads/loclx-darwin-amd64.zip*.{0,1000}https\:\/\/api\.localxpose\.io\/api\/v2\/downloads\/loclx\-darwin\-amd64\.zip.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker11#linuxN/A10N/A47663
557*https://best-wishes-to-you*.{0,1000}https\:\/\/best\-wishes\-to\-you.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A47685
558*https://free-399rs-jio-recharge*.{0,1000}https\:\/\/free\-399rs\-jio\-recharge.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A47767
559*https://googleweblight.com/i?u=*ipfs.*.html*.{0,1000}https\:\/\/googleweblight\.com\/i\?u\=.{0,1000}ipfs\..{0,1000}\.html.{0,1000}greyware_tool_keywordgoogleweblight.comOpen Redirect vulnerability being exploited by threat actors in Google Web LightT1584.001 - T1534TA0008N/AN/APhishinghttps://x.com/1ZRR4H/status/172306203968000025511N/AN/A910N/AN/AN/AN/A47786
560*https://join-zoom-online-meeting*.{0,1000}https\:\/\/join\-zoom\-online\-meeting.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A47802
561*https://mrd0x.com/progressive-web-apps-pwa-phishing*.{0,1000}https\:\/\/mrd0x\.com\/progressive\-web\-apps\-pwa\-phishing.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing11N/AN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z47843
562*https://raw.githubusercontent.com/KasRoudra/CamHacker*.{0,1000}https\:\/\/raw\.githubusercontent\.com\/KasRoudra\/CamHacker.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker11N/AN/A10N/A47903
563*https://saycheese*.serveo.net*.{0,1000}https\:\/\/saycheese.{0,1000}\.serveo\.net.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese11N/AN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z47918
564*https://watch-youtube-videos-live*.{0,1000}https\:\/\/watch\-youtube\-videos\-live.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A47986
565*https://we.tl/t-*.{0,1000}https\:\/\/we\.tl\/t\-.{0,1000}greyware_tool_keywordwetransferWeTransfer is a popular file sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share filesT1608.001 - T1566 - T1002 - T1048 - T1204TA0001 - TA0002 - TA0010N/AEXOTIC LILYPhishinghttps://twitter.com/mthcht/status/165885384832318259711N/Agreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47987
566*https://wetransfer.com/api/v4/transfers/*.{0,1000}https\:\/\/wetransfer\.com\/api\/v4\/transfers\/.{0,1000}greyware_tool_keywordwetransferWeTransfer is a popular file-sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share filesT1608.001 - T1566 - T1002 - T1048 - T1204TA0001 - TA0002 - TA0010N/AEXOTIC LILYPhishinghttps://twitter.com/mthcht/status/165885384832318259711#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47991
567*https://wetransfer.com/downloads/*.{0,1000}https\:\/\/wetransfer\.com\/downloads\/.{0,1000}greyware_tool_keywordwetransferWeTransfer is a popular file-sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share filesT1608.001 - T1566 - T1002 - T1048 - T1204TA0001 - TA0002 - TA0010N/AEXOTIC LILYPhishinghttps://twitter.com/mthcht/status/165885384832318259711N/Agreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47992
568*I am not a robot - reCAPTCHA Verification ID: 2165*.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s2165.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z48093
569*I am not a robot - reCAPTCHA Verification ID: 3029*.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s3029.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z48094
570*I am not a robot - reCAPTCHA Verification ID: 4202*.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s4202.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z48095
571*I am not a robot - reCAPTCHA Verification ID: 7537*.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s7537.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z48096
572*I am not a robot - reCAPTCHA Verification ID: 7624*.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s7624.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z48097
573*I am not a robot - reCAPTCHA Verification ID: 93752*.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s93752.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z48098
574*Import stealed session to Chromium..*.{0,1000}Import\sstealed\ssession\sto\sChromium\.\..{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#contentN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z48401
575*InjectApp.InfectClickonceApp(*.{0,1000}InjectApp\.InfectClickonceApp\(.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10N/AN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z48513
576*Injected Word document has been saved!*.{0,1000}Injected\sWord\sdocument\shas\sbeen\ssaved!.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery10#contentN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z48524
577*it-gorillaz/lnk2pwn*.{0,1000}it\-gorillaz\/lnk2pwn.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn11N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z49955
578*JoelGMSec - https://darkbyte.net*.{0,1000}JoelGMSec\s\-\shttps\:\/\/darkbyte\.net.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z50074
579*JoelGMSec/EvilnoVNC*.{0,1000}JoelGMSec\/EvilnoVNC.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1566.001 - T1071 - T1071.001TA0043 - TA0001N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC11N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z50075
580*JohnHammond/recaptcha-phish*.{0,1000}JohnHammond\/recaptcha\-phish.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish11N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z50116
581*KasRoudra/CamHacker*.{0,1000}KasRoudra\/CamHacker.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker11N/AN/A10N/A50228
582*kasroudrard@gmail.com*.{0,1000}kasroudrard\@gmail\.com.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10#emailN/A10N/A50229
583*keylogger.py*.{0,1000}keylogger\.py.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10N/AN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z50424
584*kgretzky/evilginx2*.{0,1000}kgretzky\/evilginx2.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx211N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z50439
585*kgretzky/evilqr*.{0,1000}kgretzky\/evilqr.{0,1000}offensive_tool_keywordevilqrProof-of-concept to demonstrate dynamic QR swap phishing attacks in practiceT1566.002 - T1204.001 - T1192TA0001 - TA0005N/AN/APhishinghttps://github.com/kgretzky/evilqr11N/AN/AN/A3292452024-06-18T11:27:23Z2023-06-20T12:58:09Z50440
586*kiosk.sh*startVNC.sh*.{0,1000}kiosk\.sh.{0,1000}startVNC\.sh.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z50484
587*localhost:1337*.{0,1000}localhost\:1337.{0,1000}offensive_tool_keywordgophishCombination of evilginx2 and GoPhishT1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/fin3ss3g0d/evilgophish11N/AN/A101017623402024-06-15T17:48:11Z2022-09-07T02:47:43Z51213
588*location:\\*.trycloudfare.com*.{0,1000}location\:\\\\.{0,1000}\.trycloudfare\.com.{0,1000}greyware_tool_keywordtrycloudflare.comThe subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activitiesT1071.001 - T1090 - T1583.003 - T1102TA0001 - TA0005 - TA0008 - TA0011N/AN/APhishinghttps://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware10#emailN/A1010N/AN/AN/AN/A51253
589*lures create *.{0,1000}lures\screate\s.{0,1000}offensive_tool_keywordgophishCombination of evilginx2 and GoPhishT1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/fin3ss3g0d/evilgophish10N/AN/A101017623402024-06-15T17:48:11Z2022-09-07T02:47:43Z51478
590*MacroDetectSandbox.vbs*.{0,1000}MacroDetectSandbox\.vbs.{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z51532
591*Malicious Shortcut(.lnk) Generator*.{0,1000}Malicious\sShortcut\(\.lnk\)\sGenerator.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z51599
592*MIIEowIBAAKCAQEAvZtOCbMyFKJN3n89nctTfYLSeiCTNG01rAFl06hMkobyzr0c*.{0,1000}MIIEowIBAAKCAQEAvZtOCbMyFKJN3n89nctTfYLSeiCTNG01rAFl06hMkobyzr0c.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z51990
593*mitmproxy.rb*.{0,1000}mitmproxy\.rb.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z52160
594*module EvilProxy*.{0,1000}module\sEvilProxy.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z52234
595*Mozilla/5.0 (*-bit) dnstwist*.{0,1000}Mozilla\/5\.0\s\(.{0,1000}\-bit\)\sdnstwist.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist11#useragentN/A31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z52297
596*mrd0x/PWA-Phishing*.{0,1000}mrd0x\/PWA\-Phishing.{0,1000}offensive_tool_keywordPWA-PhishingPhishing with Progressive Web Apps and UI manipulationT1071.003 - T1204.002 - T1608.003 - T1071.004TA0006N/AN/APhishinghttps://github.com/mrd0x/PWA-Phishing11N/AN/A103288522024-06-16T17:47:15Z2024-06-09T19:47:52Z52318
597*mshta*I am not a robot - *Verification ID: *.{0,1000}mshta.{0,1000}I\sam\snot\sa\srobot\s\-\s.{0,1000}Verification\sID\:\s.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/Ahttps://x.com/skocherhan/status/1888762808948367410/photo/21065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z52406
598*mshta.exe*I am not a robot - reCAPTCHA Verification ID: *.{0,1000}mshta\.exe.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s.{0,1000}greyware_tool_keywordmshtaPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z52415
599*mshta.exe*I am not a robot - reCAPTCHA Verification ID: *.{0,1000}mshta\.exe.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z52416
600*myreallycooltotallyrealtenant.onmicrosoft.com*.{0,1000}myreallycooltotallyrealtenant\.onmicrosoft\.com.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher11N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z52530
601*namespace CredPhisher*.{0,1000}namespace\sCredPhisher.{0,1000}offensive_tool_keywordCredPhisherPrompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI functionT1056.002 - T1111TA0004 N/AN/APhishinghttps://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher10N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z52603
602*nandydark/Linux-keylogger*.{0,1000}nandydark\/Linux\-keylogger.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z52627
603*novnc_proxy --vnc localhost:*.{0,1000}novnc_proxy\s\-\-vnc\slocalhost\:.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linuxN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z53587
604*o365-Attack-Toolkit*.{0,1000}o365\-Attack\-Toolkit.{0,1000}offensive_tool_keyword365-Stealer365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant AttackT1111 - T1566.001 - T1078.004TA0004 - TA0001 - TA0040N/AN/APhishinghttps://github.com/AlteredSecurity/365-Stealer10N/AN/A105488892024-06-08T21:03:50Z2020-09-20T18:22:36Z53791
605*objShell.Run "calc.exe"*.{0,1000}objShell\.Run\s\"calc\.exe\".{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10#contentN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z53826
606*Octoberfest7/TeamsPhisher*.{0,1000}Octoberfest7\/TeamsPhisher.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher11N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z53833
607*Office-DDE-Payloads*.{0,1000}Office\-DDE\-Payloads.{0,1000}offensive_tool_keywordOffice-DDE-PayloadsCollection of scripts and templates to generate Word and Excel documents embedded with the DDE. macro-less command execution technique described by @_staaldraad and @0x5A1F (blog post link in References section below). Intended for use during sanctioned red team engagements and/or phishing campaigns.T1221 - T1222 - T1223TA0001 - TA0002 - TA0003N/AN/APhishinghttps://github.com/0xdeadbeefJERKY/Office-DDE-Payloads11N/AN/AN/A76381552023-07-16T08:22:24Z2017-10-27T22:19:17Z53849
608*outflanknl/EvilClippy*.{0,1000}outflanknl\/EvilClippy.{0,1000}offensive_tool_keywordEvilClippyA cross-platform assistant for creating malicious MS Office documentsT1566.001 - T1059.001 - T1204.002TA0004 - TA0002N/AN/APhishinghttps://github.com/outflanknl/EvilClippy11N/AN/A101021654022023-12-27T12:37:47Z2019-03-26T12:14:03Z54056
609*pastehakk_generate*.{0,1000}pastehakk_generate.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk10#linux #contentN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z54497
610*payloads_examples*calc.js*.{0,1000}payloads_examples.{0,1000}calc\.js.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML11N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z54555
611*payloads_examples*calc.xll*.{0,1000}payloads_examples.{0,1000}calc\.xll.{0,1000}offensive_tool_keywordEmbedInHTMLWhat this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.T1027 - T1566.001TA0005 - TA0002N/AN/APhishinghttps://github.com/Arno0x/EmbedInHTML11N/AN/A1054851192017-09-27T13:16:06Z2017-09-11T07:17:20Z54556
612*phish_test.go*.{0,1000}phish_test\.go.{0,1000}offensive_tool_keywordgophishOpen-Source Phishing ToolkitT1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/gophish/gophish11N/AN/A10101248325282024-09-23T04:24:43Z2013-11-18T23:26:43Z54774
613*Phish-Creds.ps1*.{0,1000}Phish\-Creds\.ps1.{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z54776
614*phishDomain = phishDomain +*.{0,1000}phishDomain\s\=\sphishDomain\s\+.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#contentN/A10N/A54777
615*phishing-HTML-linter.*.{0,1000}phishing\-HTML\-linter\..{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z54778
616*phishlets *.{0,1000}phishlets\s.{0,1000}offensive_tool_keywordgophishCombination of evilginx2 and GoPhishT1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/fin3ss3g0d/evilgophish10N/AN/A101017623402024-06-15T17:48:11Z2022-09-07T02:47:43Z54779
617*PhoenixMiner.exe*.{0,1000}PhoenixMiner\.exe.{0,1000}greyware_tool_keywordphoenix minerPhoenix Miner is a popular. efficient. fast. and cost-effective Ethereum miner with support for both AMD and Nvidia GPUs. It's intended to be used for legitimate cryptocurrency mining purposes.Attackers can secretly install Phoenix Miner on unsuspecting users' computers to mine cryptocurrency for themselves. This is often done by bundling the miner with other software or hiding it within malicious attachments or downloads. The computer then slow down due to the high CPU and GPU usageT1059.001 - T1057 - T1027 - T1105 - T1064 - T1053.005 - T1089TA0002 - TA0005 - TA0011 - TA0040 - TA0003N/AN/APhishingN/A11N/AN/AN/AN/AN/AN/AN/AN/A54782
618*PhoenixMiner_*_Windows\*.{0,1000}PhoenixMiner_.{0,1000}_Windows\\.{0,1000}greyware_tool_keywordphoenix minerPhoenix Miner is a popular. efficient. fast. and cost-effective Ethereum miner with support for both AMD and Nvidia GPUs. It's intended to be used for legitimate cryptocurrency mining purposes.Attackers can secretly install Phoenix Miner on unsuspecting users' computers to mine cryptocurrency for themselves. This is often done by bundling the miner with other software or hiding it within malicious attachments or downloads. The computer then slow down due to the high CPU and GPU usageT1059.001 - T1057 - T1027 - T1105 - T1064 - T1053.005 - T1089TA0002 - TA0005 - TA0011 - TA0040 - TA0003N/AN/APhishingN/A10N/AN/AN/AN/AN/AN/AN/AN/A54783
619*php -q -S 0.0.0.0:8111*.{0,1000}php\s\-q\s\-S\s0\.0\.0\.0\:8111.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/ms101/EvilKnievelnoVNC10#linuxN/A914482025-03-08T19:34:41Z2024-04-13T22:05:04Z54790
620*PShlSpy*.{0,1000}PShlSpy.{0,1000}signature_keywordAntivirus Signaturehighly revelant Antivirus signature. phishing toolsN/AN/AN/AN/APhishingN/A11N/AN/A710N/AN/AN/AN/A55703
621*QNAME*.trycloudfare.com*.{0,1000}QNAME.{0,1000}\.trycloudfare\.com.{0,1000}greyware_tool_keywordtrycloudflare.comThe subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activitiesT1071.001 - T1090 - T1583.003 - T1102TA0001 - TA0005 - TA0008 - TA0011N/AN/APhishinghttps://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware11#dnsqueryN/A1010N/AN/AN/AN/A56150
622*randomalice1986@*.{0,1000}randomalice1986\@.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist11#emailemail user name31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z56238
623*randombob1986@*.{0,1000}randombob1986\@.{0,1000}offensive_tool_keyworddnstwistSee what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.T1560 - T1565 - T1566 - T1568 - T1569TA0002 - TA0005N/AN/APhishinghttps://github.com/elceef/dnstwist11#emailemail user name31051138012025-04-15T18:41:47Z2015-06-11T12:24:17Z56240
624*reCAPTCHA Verification ID: <span id="verification-id">146820</span>*.{0,1000}reCAPTCHA\sVerification\sID\:\s\<span\sid\=\"verification\-id\"\>146820\<\/span\>.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish10#contentN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z56512
625*recaptcha-phish-main.zip*.{0,1000}recaptcha\-phish\-main\.zip.{0,1000}offensive_tool_keywordrecaptcha-phishPhishing with a fake reCAPTCHAT1566.001 - T1204.002 - T1071.003TA0001 - TA0002Lumma StealerN/APhishinghttps://github.com/JohnHammond/recaptcha-phish11N/AN/A1065341042024-09-13T11:18:29Z2024-09-13T07:00:40Z56513
626*ReelPhish*.{0,1000}ReelPhish.{0,1000}offensive_tool_keywordReelPhishReelPhish consists of two components: the phishing site handling code and this script. The phishing site can be designed as desired. Sample PHP code is provided in /examplesitecode. The sample code will take a username and password from a HTTP POST request and transmit it to the phishing script. The phishing script listens on a local port and awaits a packet of credentials. Once credentials are received. the phishing script will open a new web browser instance and navigate to the desired URL (the actual site where you will be entering a users credentials). Credentials will be submitted by the web browserT1566 - T1114 - T1071 - T1547 - T1546TA0001 - TA0003 - TA0008N/AN/APhishinghttps://github.com/fireeye/ReelPhish10N/AN/AN/A65141532023-08-11T01:40:07Z2018-02-01T20:35:11Z56598
627*require 'evil-proxy'*.{0,1000}require\s\'evil\-proxy\'.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z57145
628*require 'evil-proxy/async'*.{0,1000}require\s\'evil\-proxy\/async\'.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z57146
629*require 'evil-proxy/store'*.{0,1000}require\s\'evil\-proxy\/store\'.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z57147
630*RobustPentestMacro*.{0,1000}RobustPentestMacro.{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z57425
631*ryhanson/phishery*.{0,1000}ryhanson\/phishery.{0,1000}offensive_tool_keywordphisheryPhishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.T1566.001 - T1071 - T1204.002TA0001 N/ABERSERK BEARPhishinghttps://github.com/ryhanson/phishery11N/AN/A9109932092017-09-11T15:42:10Z2016-09-25T02:19:24Z57805
632*sandeshyadavm46@gmail.com*.{0,1000}sandeshyadavm46\@gmail\.com.{0,1000}offensive_tool_keywordpastehakkperform clipboard poisoning or paste jacking attackT1115T0001 - T0002 - T0005N/AN/APhishinghttps://github.com/3xploitGuy/pastehakk10#linux #emailN/A7156102020-06-22T01:17:53Z2020-06-17T19:32:24Z57931
633*saycheese-master.zip*.{0,1000}saycheese\-master\.zip.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese11N/AN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z57940
634*sneaky_gophish*.{0,1000}sneaky_gophish.{0,1000}offensive_tool_keywordgophishHiding GoPhish from the boys in blueT1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001TA0002 - TA0003N/ABlack BastaPhishinghttps://github.com/puzzlepeaches/sneaky_gophish/11N/AN/A102180582022-12-06T11:58:00Z2021-06-24T12:41:54Z59789
635*Social Engineer Toolkit*.{0,1000}Social\sEngineer\sToolkit.{0,1000}offensive_tool_keywordsocial-engineer-toolkitThe Social-Engineer Toolkit is an open-source penetration testing framework designed for social engineering. SET has a number of custom attack vectors that allow you to make a believable attack quickly. SET is a product of TrustedSec. LLC an information security consulting firm located in Cleveland. Ohio.T1566 - T1059.004 - T1564.001TA0001 - TA0002 - TA0007N/AN/APhishinghttps://github.com/trustedsec/social-engineer-toolkit10N/AN/AN/A101179829222024-10-21T15:46:18Z2012-12-31T22:01:33Z59838
636*ssh -o StrictHostKeyChecking=no -o ServerAliveInterval=60 -R *serveo.net*.{0,1000}ssh\s\-o\sStrictHostKeyChecking\=no\s\-o\sServerAliveInterval\=60\s\-R\s.{0,1000}serveo\.net.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese10N/AN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z60135
637*Starting php server at localhost:*.{0,1000}Starting\sphp\sserver\sat\slocalhost\:.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10#contentN/A10N/A60330
638*TARGET=evilginx*.{0,1000}TARGET\=evilginx.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#contentN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z60912
639*TeamsPhisher.git*.{0,1000}TeamsPhisher\.git.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher11N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z61076
640*teamsphisher.log*.{0,1000}teamsphisher\.log.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher11N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z61077
641*teamsphisher.py*.{0,1000}teamsphisher\.py.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher11N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z61078
642*TeamsPhisher-main.zip*.{0,1000}TeamsPhisher\-main\.zip.{0,1000}offensive_tool_keywordteamsphisherSend phishing messages and attachments to Microsoft Teams usersT1566.001 - T1566.002 - T1204.001TA0001 - TA0005N/ABlack BastaPhishinghttps://github.com/Octoberfest7/TeamsPhisher11N/AN/AN/A1010731382024-06-19T21:41:55Z2023-07-03T02:19:47Z61079
643*thelinuxchoice/saycheese*.{0,1000}thelinuxchoice\/saycheese.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese11#linuxN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z61244
644*This is the modified maintained version of Evilginx2. No one will be held responsible for your activities*.{0,1000}This\sis\sthe\smodified\smaintained\sversion\sof\sEvilginx2\.\sNo\sone\swill\sbe\sheld\sresponsible\sfor\syour\sactivities.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/An0nUD4Y/evilginx210#contentN/A10N/A61263
645*this.is.not.a.phishing.site.evilsite.com*.{0,1000}this\.is\.not\.a\.phishing\.site\.evilsite\.com.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#contentN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z61265
646*Tunneling failed! Start your own port forwarding/tunneling service at port *.{0,1000}Tunneling\sfailed!\sStart\syour\sown\sport\sforwarding\/tunneling\sservice\sat\sport\s.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A61711
647*UACBypassConfig.java*.{0,1000}UACBypassConfig\.java.{0,1000}offensive_tool_keywordlnk2pwnMalicious Shortcut(.lnk) GeneratorT1204 - T1059.007TA0001 - TA0002N/AN/APhishinghttps://github.com/it-gorillaz/lnk2pwn10N/AN/A82193342018-11-23T17:18:49Z2018-11-23T00:12:48Z61779
648*unzip websites.zip -d sites > /dev/null*.{0,1000}unzip\swebsites\.zip\s\-d\ssites\s\>\s\/dev\/null.{0,1000}offensive_tool_keywordCamHackerCamera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!T1598 - T1204 - T1566.001TA0009 - TA0010 - TA0043N/AN/APhishinghttps://github.com/KasRoudra/CamHacker10N/AN/A10N/A61921
649*url: 'forwarding_link/post.php',*.{0,1000}url\:\s\'forwarding_link\/post\.php\',.{0,1000}offensive_tool_keywordsaycheeseGrab target's webcam shots by linkT1213 - T1071 - T1102 - T1123 - T1185 - T1200TA0001 - TA0005 - TA0009 - TA0011N/AN/APhishinghttps://github.com/hangetzzu/saycheese10N/AN/A91011759622024-06-18T23:39:41Z2019-04-29T04:07:00Z61962
650*using ClickJack.Extensions*.{0,1000}using\sClickJack\.Extensions.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10N/AN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z62074
651*using ClickJack.Modules*.{0,1000}using\sClickJack\.Modules.{0,1000}offensive_tool_keywordclickjackautomate abuse of clickonce applicationsT1210 - T1204 - T1071.001TA0001 - TA0002 - TA0005N/AN/APhishinghttps://github.com/trustedsec/The_Shelf10N/AN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z62075
652*vba-macro-mac-persistence.vbs*.{0,1000}vba\-macro\-mac\-persistence\.vbs.{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z62128
653*vba-windows-persistence.vbs*.{0,1000}vba\-windows\-persistence\.vbs.{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z62130
654*vil-proxy/quickcert*.{0,1000}vil\-proxy\/quickcert.{0,1000}offensive_tool_keywordevil-proxyA ruby http/https proxy to do EVIL thingsT1557 - T1110.001 - T1563.001TA0006 - TA0001 - TA0009 - TA0040N/AN/APhishinghttps://github.com/bbtfr/evil-proxy10N/AN/A92172962023-10-30T07:49:40Z2015-07-30T01:54:40Z62188
655*Wanetty inspired by @JoelGMSec*.{0,1000}Wanetty\sinspired\sby\s\@JoelGMSec.{0,1000}offensive_tool_keywordEvilnoVNCEvilnoVNC is a Ready to go Phishing PlatformT1566 - T1110 - T1555 - T1204 - T1592TA0001 - TA0006 - TA0009N/AN/APhishinghttps://github.com/JoelGMSec/EvilnoVNC10#linux #contentN/A9109601692025-03-04T15:59:27Z2022-09-04T10:48:49Z62351
656*WMIPersistence.vbs*.{0,1000}WMIPersistence\.vbs.{0,1000}offensive_tool_keywordphishing-HTML-linterPhishing and Social-Engineering related scriptsT1566.001 - T1056.001TA0040 - TA0001N/AN/APhishinghttps://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing11N/AN/A101026895272023-06-27T19:16:49Z2018-02-02T21:24:03Z62994
657*X-Evilginx*.{0,1000}X\-Evilginx.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210N/AN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z63217
658*X-Gophish-Contact*.{0,1000}X\-Gophish\-Contact.{0,1000}offensive_tool_keywordgophishGophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training.T1566 - T1598TA0008 - TA0009N/ABlack BastaPhishinghttps://github.com/gophish/gophish10N/AN/A10101248325282024-09-23T04:24:43Z2013-11-18T23:26:43Z63224
659*xillwillx/tricky.lnk*.{0,1000}xillwillx\/tricky\.lnk.{0,1000}offensive_tool_keywordtricky.lnkVBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and executeT1027 - T1036 - T1218.010TA0002 - TA0003 - TA0008N/AN/APhishinghttps://github.com/xillwillx/tricky.lnk11N/AN/AN/A2114332020-12-19T23:42:10Z2016-10-26T21:25:06Z63229
660*you need to provide the path to directory where your phishlets are stored:*.{0,1000}you\sneed\sto\sprovide\sthe\spath\sto\sdirectory\swhere\syour\sphishlets\sare\sstored\:.{0,1000}offensive_tool_keywordevilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authenticationT1557.002 - T1114 - T1539TA0001N/ABlackCat - COLDRIVER - Black BastaPhishinghttps://github.com/kgretzky/evilginx210#contentN/A10101287922342025-01-21T15:16:19Z2018-07-10T09:59:52Z63378
661https://*.xyz/*.ps1http.*\.(country|stream|gdn|mom|xin|kim|men|loan|download|racing|online|science|ren|gb|win|top|review|vip|party|tech|xyz|date|faith|cricket|space|info|vn|cm|am|cc|asia|ws|tk|biz|su|st|ge|pk|nu|me|ph|to|tt|name|tv|kz|tc|mobi|study|click|link|trade|accountant|cf|gq|ml|ga|pw)\/.*\.(exe|vbs|bat|rar|ps1|doc|docm|xls|xlsm|pptm|rtf|hta|dll|ws|wsf|sct|zip|bin)$greyware_tool_keyword_Suspicious tlds with suspicious file typesT1204 - T1212 - T1562TA0001 - TA0003 - TA0005N/AN/APhishingN/A01N/AN/A810N/AN/AN/AN/A63564
662*/invoices.hta*.{0,1000}\/invoices\.hta.{0,1000}greyware_tool_keyword_suspicious file name often used by attackers in phishing attempts (threat hunting only)T1059.005 - T1204.002TA0002 - TA0001N/AN/APhishingN/A01N/AN/A68N/AN/AN/AN/A63718